The FBI published CJIS Security Policy version 6.1 on June 25, 2026, refining the modernized control-based framework introduced in v6.0 last December. The update raises required encryption key strength from 128-bit to 256-bit for CJI both in transit and at rest, and increases mandatory vulnerability scanning frequency from quarterly to monthly.
bleepingcomputer.com
· 2026-09-21
A developer has released BlindLock, a local password vault that stores encrypted credentials embedded within an image file rather than in a central database. The vault relies on hardware binding and 256-bit authenticated encryption, and incorporates NIST-standardized post-quantum algorithms ML-KEM-1024 and ML-DSA-87 for key exchange and signatures.
blindlock.app
· 2026-08-31
NIST has responded to a surge in vulnerability disclosures by reclassifying about 30,000 CVEs published before March 2026 as 'Not Scheduled,' effectively deprioritizing their enrichment. The move comes as Action1's 2026 report shows disclosed vulnerabilities in enterprise software jumped 92% in 2025, with critical and high-severity flaws each up 103% and remote-code-execution bugs up 128%.
bleepingcomputer.com
· 2026-08-28