OmniTech

OmniTech Managed IT & vCIO services for secure, scalable growth. Tech leadership built for small businesses.

09/04/2026

The Department of Defense has moved CMMC from the planning phase into active enforcement, and defense contractors are feeling it. The Senate NDAA is even proposing grant programs just to help contractors meet the requirements.

This matters beyond the defense sector too. When the federal government tightens compliance requirements, the standards tend to flow down to subcontractors, state agencies, and eventually private industry.

A few things to watch:
- If you are anywhere in the defense supply chain, now is the time to assess your compliance gaps
- CMMC is not just a checklist. It requires documented processes, evidence, and ongoing maintenance
- Managed IT providers who understand CMMC can be a real advantage for contractors trying to meet the deadline
- The cost of preparation is always less than the cost of losing a contract

Compliance is not exciting. But losing business because you missed a deadline is worse.

Source: https://federalnewsnetwork.com/cybersecurity/2026/06/cmmc-has-moved-from-planning-to-enforcement-and-contractors-are-feeling-it/

09/03/2026

Security researchers just uncovered a supply chain attack that is different from the usual compromise. The Shai-Hulud worm is self-propagating. Once it infects one package, it automatically spreads to others, compromising over 100 NPM and PyPI packages in a chain reaction.

This is not someone manually inserting malicious code into one library. It is an automated worm that uses the trust relationships between packages to spread itself.

For businesses, the implications are significant:
- Your dependencies have dependencies, and you probably do not audit all of them
- A single compromised upstream package can cascade into your stack without anyone on your team making a mistake
- Software composition analysis and dependency pinning are no longer optional
- The best defense is knowing exactly what is in your environment and who maintains it

Open source is not the problem. Unmanaged open source is.

Source: https://www.cyberscoop.com/mini-shai-hulud-malware-npm-pypi-supply-chain-attack/

09/01/2026

CISA just warned that over 86,000 FortiGate devices are exposed by a vulnerability called FortiBleed. That is not a small number. It means tens of thousands of businesses could be running firewalls that are already compromised without knowing it.

This is a pattern we see often. The tools meant to protect you become the weak link when they are not patched or replaced on time.

A few practical takeaways:
- Check your firewall firmware against vendor advisories at least monthly
- Have a replacement lifecycle for security hardware (most vendors publish end-of-life dates)
- Do not assume a firewall means you are protected. It needs updates just like everything else
- Managed IT providers should be auditing infrastructure proactively, not waiting for alerts

The perimeter is not dead. It just needs more attention than most people give it.

Source: https://www.thehackernews.com/2026/06/cisa-warns-fortinet-customers-as-fortibleed-hits-86644-fortigate-devices.html

Time is running out for cyber security.The BBC is reporting what a lot of IT teams already know: the threat landscape is...
08/28/2026

Time is running out for cyber security.

The BBC is reporting what a lot of IT teams already know: the threat landscape is moving faster than many businesses can keep up with.

At OmniTech, we see the same pattern over and over. The organizations that stay ahead are the ones that treat security as an ongoing process, not a one-time setup:

- layered protection
- proactive monitoring
- timely patching
- strong access controls
- tested recovery plans

Cyber security is not just about stopping attacks. It’s about keeping your business resilient when something does go wrong.

Source: https://www.bbc.co.uk/news/articles/cwyz11475l1o?at_medium=RSS&at_campaign=rss

How is your team tightening security this year?

08/18/2026

A big thank you to our Tee Up Cedar Valley sponsors!

We’re grateful to have so many businesses helping make the day a success. Businesses from across the Cedar Valley are coming together for a day of connection, golf, and plenty of fun. Tee Up Cedar Valley wouldn’t be possible without you!

Cyber risk in transportation is not slowing down.A January report said attacks on logistics are up almost 1,000 percent ...
08/11/2026

Cyber risk in transportation is not slowing down.

A January report said attacks on logistics are up almost 1,000 percent since 2021, and another 2026 industry report points to the same trend. The scary part is not just stolen credentials. It is what happens after that, like freight redirects, shipment disruption, and lost customers.

We have seen attempts like this in action over the past couple of years. The good news is we have also been able to stop them before they turned into bigger problems.

If your business depends on freight, dispatch, or connected systems, this is no longer just an IT issue. It is an operations issue.

Source: https://share.google/qP2eF81eQ33c9ZNDU

Here we go again.Meta is the second AI company in a matter of weeks to say its AI was involved in hacking another compan...
08/06/2026

Here we go again.

Meta is the second AI company in a matter of weeks to say its AI was involved in hacking another company.

That is starting to look less like a fluke and more like a warning. AI capability is moving fast, and AI security is not keeping up.

If businesses are going to use AI at work, they need access controls, monitoring, testing, and real guardrails around what these tools can do.

Source: https://www.bbc.com/news/articles/cx2kgdnyk2po

What do you think matters more right now, capability or control?

Happy SysAdmin Day.To the people who keep the servers humming, the patches moving, the tickets closing, and the weird pr...
07/24/2026

Happy SysAdmin Day.

To the people who keep the servers humming, the patches moving, the tickets closing, and the weird printer issues from becoming everyone else's problem: thank you.

Good IT looks invisible when it is working, but there is a whole lot of skill behind that calm.

Source: https://sysadminday.com/



What is the best save-the-day moment you have seen from an IT pro?

07/24/2026
Law enforcement has dismantled Kratos, a phishing kit built to steal Microsoft 365 session cookies and help attackers by...
07/23/2026

Law enforcement has dismantled Kratos, a phishing kit built to steal Microsoft 365 session cookies and help attackers bypass MFA.

The takeaway is clear: passwords and basic MFA are not enough if an attacker can capture a live session. Businesses need phishing-resistant sign-in, fast session revocation, and active monitoring for suspicious Microsoft 365 activity.

If your incident response plan still stops at a password reset, it may not be enough.

Read more: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html?m=1

Are your Microsoft 365 protections ready for adversary-in-the-middle phishing?

Address

1829 Breckenridge Street
Cedar Falls, IA
50613

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+13192224485

Alerts

Be the first to know and let us send you an email when OmniTech posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to OmniTech:

Shortcuts

Share