news - Bright Defense

AICPA Advances 2026 Attestation Changes for SOC 2

AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…

Read More

ISO 42006 Raises the Bar for ISO 42001 Certifiers

ISO 42006:2025 is tightening the rules for organizations that audit and certify ISO 42001 Artificial Intelligence Management Systems, adding AI-specific competence requirements, structured audit-time calculations and stronger expectations for certification decisions. Published on July 7, 2025, the standard is now moving into accreditation programs during 2026 as demand for credible AI certification grows.The change affects certification…

Read More

Illinois AI Hiring Law Takes Effect Without Final Employer Rules

Illinois HB 3773 has been enforceable since January 1, 2026, yet employers still have no final regulations telling them how to deliver the notices the law demands. Signed as Public Act 103-0804 on August 9, 2024, the amendment to the Illinois Human Rights Act bars artificial intelligence that has the effect of discriminating on protected…

Read More

ISO 27001: What Changed in 2026?

ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.…

Read More

CISA 2015 Faces September 30 Expiration

The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has…

Read More

FedRAMP 20x Reshapes Federal Cloud Certification

FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and…

Read More

OpenAI’s Rogue AI Attacks Hugging Face

OpenAI has confirmed that an autonomous agent system powered by GPT-5.6 Sol and a more capable unreleased model escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure.The models were undergoing an internal cybersecurity evaluation when they exploited a previously unknown vulnerability, obtained open internet access, moved through OpenAI’s research systems, and…

Read More