<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Lattix Blog</title>
    <link>https://lattix.io/blog</link>
    <description>Long-form writing on post-quantum cryptography, federal Zero Trust, MCP, supply chain, and data-centric security.</description>
    <language>en-US</language>
    <atom:link href="https://lattix.io/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Thu, 10 Sep 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Ransomware Doesn&apos;t Work on Policy-Bound Data</title>
      <link>https://lattix.io/blog/ransomware-doesnt-work-on-policy-bound-data</link>
      <guid isPermaLink="true">https://lattix.io/blog/ransomware-doesnt-work-on-policy-bound-data</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <description>Modern ransomware exfiltrates before it encrypts and demands payment under the threat of public release. Neither lever works when the data is already encrypted and policy-bound at the object layer.</description>
      <category>Ransomware</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>The Harvest-Now-Decrypt-Later Threat Is Already Here</title>
      <link>https://lattix.io/blog/harvest-now-decrypt-later-quantum-threat</link>
      <guid isPermaLink="true">https://lattix.io/blog/harvest-now-decrypt-later-quantum-threat</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>Adversaries do not need a working quantum computer today to compromise tomorrow&apos;s cryptography. They need storage, patience, and a sufficiently long-lived secret. The act that matters has already happened by the time the cryptanalysis is feasible.</description>
      <category>Post-Quantum Cryptography</category>
      <category>Cybersecurity</category>
      <category>Nation-State</category>
    </item>
    <item>
      <title>SonicWall SMA1000 Zero-Days Chain to Root. The Gateway Is Not the Data Boundary.</title>
      <link>https://lattix.io/blog/sonicwall-sma1000-cve-2026-15409-gateway-not-data-boundary</link>
      <guid isPermaLink="true">https://lattix.io/blog/sonicwall-sma1000-cve-2026-15409-gateway-not-data-boundary</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <description>CISA added SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410 to KEV on July 14, 2026. Chained, an unauthenticated SSRF and a root code injection hand an attacker the remote-access gateway. Object-level enforcement is what still refuses the reach it grants.</description>
      <category>Zero Trust</category>
      <category>KEV</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>AD FS CVE-2026-56155 Forges Federation Tokens. Identity Is Not the Data Boundary.</title>
      <link>https://lattix.io/blog/adfs-cve-2026-56155-federation-token-forgery-data-boundary</link>
      <guid isPermaLink="true">https://lattix.io/blog/adfs-cve-2026-56155-federation-token-forgery-data-boundary</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <description>CISA added AD FS CVE-2026-56155 to KEV on July 14, 2026 with a July 28 federal deadline. The flaw hands an attacker the token-signing keys, and a forged federation token replays against every connected application. Object-level enforcement is what still refuses it.</description>
      <category>Zero Trust</category>
      <category>Identity Security</category>
      <category>KEV</category>
    </item>
    <item>
      <title>HHS HC3 Q2 2026 Threat Brief: Healthcare Data Is the Target. The Response Is Architectural.</title>
      <link>https://lattix.io/blog/hhs-hc3-healthcare-q2-2026-data-centric-threat-response</link>
      <guid isPermaLink="true">https://lattix.io/blog/hhs-hc3-healthcare-q2-2026-data-centric-threat-response</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>HHS HC3 quarterly threat briefs catalog the threat actor groups and tactics targeting healthcare data through Q2 2026. The pattern across Medtronic, Change Healthcare aftermath, and recent intrusions is consistent. Healthcare data is high-value and weakly bound to enforcement.</description>
      <category>Healthcare</category>
      <category>HIPAA</category>
      <category>Threat Intelligence</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>Federal Cloud Migration ATO Acceleration Lives at the Data Layer</title>
      <link>https://lattix.io/blog/federal-cloud-migration-ato-acceleration-data-layer</link>
      <guid isPermaLink="true">https://lattix.io/blog/federal-cloud-migration-ato-acceleration-data-layer</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>ATO timelines for federal cloud workloads consistently exceed the planned program schedule. Boundary, identity, and configuration controls converge quickly. Data controls do not. The architecture that produces ATO evidence by construction is the architecture that compresses the cycle.</description>
      <category>Federal</category>
      <category>FedRAMP</category>
      <category>Data Security</category>
      <category>Compliance</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>Defense Industrial Base Audit Failure Patterns Point to the Same Data Controls</title>
      <link>https://lattix.io/blog/dib-cyber-compliance-audit-failure-patterns-data-controls</link>
      <guid isPermaLink="true">https://lattix.io/blog/dib-cyber-compliance-audit-failure-patterns-data-controls</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <description>CMMC Phase 1 assessment data, DCMA audit findings, and GAO supply chain reports converge on the same NOT MET controls. SC.L2-3.13.11 on cryptographic protection. MP.L2-3.8.9 on backup encryption. AC.L2-3.1.20 on external information system flows. The pattern is architectural.</description>
      <category>CMMC</category>
      <category>Defense</category>
      <category>Compliance</category>
      <category>Audit</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>CISA Secure by Design AI Pledge: A Year In, Evidence Is What Is Missing</title>
      <link>https://lattix.io/blog/cisa-secure-by-design-ai-pledge-one-year-evidence</link>
      <guid isPermaLink="true">https://lattix.io/blog/cisa-secure-by-design-ai-pledge-one-year-evidence</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <description>The CISA Secure by Design AI pledge launched in 2024 with broad industry signatories. A year later, evidence supporting the pledge commitments remains uneven. Data provenance, training-set lineage, and access governance over model outputs are the evidence categories vendors cannot produce.</description>
      <category>CISA</category>
      <category>AI Security</category>
      <category>Secure by Design</category>
      <category>Supply Chain</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Chromium V8 CVE-2026-11645 Is in KEV. The Browser Is an Endpoint Data Surface.</title>
      <link>https://lattix.io/blog/chromium-v8-cve-2026-11645-kev-browser-data-surface</link>
      <guid isPermaLink="true">https://lattix.io/blog/chromium-v8-cve-2026-11645-kev-browser-data-surface</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>Chromium V8 CVE-2026-11645 is an actively exploited out-of-bounds flaw giving an attacker read and write access inside the renderer. CISA added it to KEV with a June 23, 2026 federal deadline. The browser is where enterprise data is read, and the renderer holds the cleartext.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Browser Security</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Microsoft Purview Sensitivity Labels and ZTDF Diverge When the Label Stops Carrying Policy</title>
      <link>https://lattix.io/blog/microsoft-purview-sensitivity-labels-ztdf-policy-divergence</link>
      <guid isPermaLink="true">https://lattix.io/blog/microsoft-purview-sensitivity-labels-ztdf-policy-divergence</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>Microsoft Purview sensitivity labels travel with files and provide a useful classification overlay. The label is metadata; the policy lives in the Purview service. ZTDF binds policy to the object cryptographically. Compare what survives a cross-tenant transfer in each model.</description>
      <category>Zero Trust</category>
      <category>Data Security</category>
      <category>ZTDF</category>
      <category>Microsoft Purview</category>
      <category>Architecture</category>
    </item>
    <item>
      <title>Arista EOS CVE-2026-7473 Forwards Untrusted Tunnel Traffic. The Fabric Is Not the Boundary.</title>
      <link>https://lattix.io/blog/arista-eos-cve-2026-7473-tunnel-decap-data-layer</link>
      <guid isPermaLink="true">https://lattix.io/blog/arista-eos-cve-2026-7473-tunnel-decap-data-layer</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <description>Arista EOS CVE-2026-7473 is an actively exploited tunnel decapsulation flaw that makes a switch forward attacker traffic into isolated segments. CISA added it to KEV with a June 23, 2026 federal deadline, and Arista will not patch it.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Network Security</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>JADC2 Cross-Domain Data Sharing Requires a Data-Centric Substrate</title>
      <link>https://lattix.io/blog/jadc2-cross-domain-data-sharing-zero-trust-architecture</link>
      <guid isPermaLink="true">https://lattix.io/blog/jadc2-cross-domain-data-sharing-zero-trust-architecture</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>DoD JADC2 and CJADC2 milestones depend on cross-domain release of mission data at operational tempo. Guard-appliance cross-domain solutions do not scale to that tempo. ABAC at the policy enforcement point over ZTDF-formatted objects is the substrate that does.</description>
      <category>DoD</category>
      <category>JADC2</category>
      <category>Zero Trust</category>
      <category>Defense</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>TDF and ZTDF for Procurement Officers: What the Specification Actually Specifies</title>
      <link>https://lattix.io/blog/tdf-ztdf-procurement-officers-specification-binds</link>
      <guid isPermaLink="true">https://lattix.io/blog/tdf-ztdf-procurement-officers-specification-binds</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>NSA Phase Two named ZTDF and IC-TDF as the interoperability schemas. The two specifications differ in scope, lifecycle, and required cryptographic agility. The differences matter when writing FY27 acquisition language. Walk through what each binds and how that maps to procurable capability.</description>
      <category>ZTDF</category>
      <category>TDF</category>
      <category>Procurement</category>
      <category>Zero Trust</category>
      <category>Defense</category>
    </item>
    <item>
      <title>DORA Pushes Operational Resilience Past the Contract. ICT Provider Evidence Is Technical.</title>
      <link>https://lattix.io/blog/dora-third-country-ict-provider-data-control-evidence</link>
      <guid isPermaLink="true">https://lattix.io/blog/dora-third-country-ict-provider-data-control-evidence</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <description>EU DORA effective January 17 2025 reaches ICT third-party providers including non-EU vendors serving EU financial entities. Tier 1 supervisory examinations are ramping in 2026. Contract clauses do not satisfy DORA&apos;s evidence expectations. Technical evidence for data-level control does.</description>
      <category>DORA</category>
      <category>EU Regulation</category>
      <category>Third-Party Risk</category>
      <category>Compliance</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>SolarWinds Serv-U CVE-2026-28318 Is in KEV. The File Transfer Appliance Is the Trust Boundary.</title>
      <link>https://lattix.io/blog/solarwinds-serv-u-cve-2026-28318-file-transfer-trust-boundary</link>
      <guid isPermaLink="true">https://lattix.io/blog/solarwinds-serv-u-cve-2026-28318-file-transfer-trust-boundary</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
      <description>SolarWinds Serv-U CVE-2026-28318 is an actively exploited, unauthenticated flaw that crashes the file transfer service. CISA added it to KEV with a June 19, 2026 federal deadline. Managed file transfer keeps proving the appliance is a transport, not a trust boundary.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>File Transfer</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>NIST AI 600-1 GenAI Profile Maps Cleanly to Data-Centric Controls</title>
      <link>https://lattix.io/blog/nist-ai-600-1-genai-profile-data-centric-controls</link>
      <guid isPermaLink="true">https://lattix.io/blog/nist-ai-600-1-genai-profile-data-centric-controls</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <description>NIST AI 600-1 names the unique risks of foundation models. The mitigations the profile recommends — training data provenance, output attribution, access governance over model artifacts — are evidence categories that process attestation cannot supply. Data-centric architecture supplies them by construction.</description>
      <category>AI Security</category>
      <category>NIST</category>
      <category>AI RMF</category>
      <category>Data Security</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>Microsoft Defender CVE-2026-41091 Escalates to SYSTEM. The Endpoint Control Is the Attack Surface.</title>
      <link>https://lattix.io/blog/microsoft-defender-cve-2026-41091-endpoint-control-attack-surface</link>
      <guid isPermaLink="true">https://lattix.io/blog/microsoft-defender-cve-2026-41091-endpoint-control-attack-surface</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <description>Microsoft Defender CVE-2026-41091 is an actively exploited link-following flaw that elevates a local user to SYSTEM. CISA added it to KEV with a June 3, 2026 federal deadline. When the security tool is the escalation path, object-level enforcement is what survives.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Endpoint Security</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>PCI DSS 4.0.1 Requires Cryptographic Agility. Cardholder Data Architectures Have to Move.</title>
      <link>https://lattix.io/blog/pci-dss-4-0-1-cryptographic-agility-cardholder-data</link>
      <guid isPermaLink="true">https://lattix.io/blog/pci-dss-4-0-1-cryptographic-agility-cardholder-data</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <description>PCI DSS 4.0.1 effective April 2024 introduced future-dated cryptographic requirements that bite in 2025 and 2026. Cardholder Data Environments tightly coupling crypto to application code cannot migrate inside the PCI assessment window. Data-centric encryption is the architectural path.</description>
      <category>PCI DSS</category>
      <category>Compliance</category>
      <category>Cryptography</category>
      <category>Data Security</category>
      <category>Post-Quantum Cryptography</category>
    </item>
    <item>
      <title>NIST IR 8547 Sets the PQC Migration Floor. The Calendar Bites in 2027.</title>
      <link>https://lattix.io/blog/nist-ir-8547-pqc-migration-mid-2026-status</link>
      <guid isPermaLink="true">https://lattix.io/blog/nist-ir-8547-pqc-migration-mid-2026-status</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <description>NIST IR 8547 establishes the federal post-quantum migration timeline. Mid-2026 progress data shows the schedule is tighter than most program offices have modeled. FIPS 140-3 module validation backlog compounds the risk. Cryptographic agility patterns are the schedule mitigation.</description>
      <category>Post-Quantum Cryptography</category>
      <category>NIST</category>
      <category>Compliance</category>
      <category>FIPS</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Cross-Domain Solutions Modernize From Guard Appliances to Object-Level Release</title>
      <link>https://lattix.io/blog/cross-domain-solutions-guard-appliances-object-level-release</link>
      <guid isPermaLink="true">https://lattix.io/blog/cross-domain-solutions-guard-appliances-object-level-release</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <description>Guard appliances have served twenty years of joint and coalition cross-domain release. They evaluate data at the boundary. NSA Phase Two named ZTDF and IC-TDF as the schemas that move release evaluation to the object itself, at cryptographic speed. FY27 procurement is converging on object-level release.</description>
      <category>Zero Trust</category>
      <category>Data Security</category>
      <category>Defense</category>
      <category>ZTDF</category>
      <category>Cross-Domain</category>
    </item>
    <item>
      <title>AI Agents Form Credential Delegation Chains. Static Tokens Cannot Hold.</title>
      <link>https://lattix.io/blog/ai-agent-credential-delegation-chains-policy-bound-tokens</link>
      <guid isPermaLink="true">https://lattix.io/blog/ai-agent-credential-delegation-chains-policy-bound-tokens</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description>Autonomous agent workflows now span multiple hops, multiple vendors, and multiple identity domains. A bearer token at any hop is the failure point. Treating each delegated credential as a policy-bound data object closes the chain. The architecture is procurable today.</description>
      <category>AI Security</category>
      <category>Agentic AI</category>
      <category>Identity</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>CMMC Level 2 Compliance Through Data-Centric Security</title>
      <link>https://lattix.io/blog/cmmc-level-2-compliance-data-centric-security</link>
      <guid isPermaLink="true">https://lattix.io/blog/cmmc-level-2-compliance-data-centric-security</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description>CMMC Level 2 requires 110 practices across 14 domains. Data-centric security maps to 76 of them through a single architectural primitive bound to the CUI object.</description>
      <category>CMMC</category>
      <category>Compliance</category>
      <category>Defense</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Anthropic&apos;s Zero Trust for AI Agents Framework Reaches the Data Layer at the Optimized Tier</title>
      <link>https://lattix.io/blog/anthropic-zero-trust-ai-agents-framework-data-layer-optimized-tier</link>
      <guid isPermaLink="true">https://lattix.io/blog/anthropic-zero-trust-ai-agents-framework-data-layer-optimized-tier</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>Anthropic published a Zero Trust framework for autonomous AI agents on May 27, 2026. The framework names the right architecture for the agent threat model. The Optimized tier reaches the data layer. Data-centric enforcement is how organizations get there.</description>
      <category>AI Security</category>
      <category>Zero Trust</category>
      <category>Agentic AI</category>
      <category>Data Security</category>
      <category>Industry Analysis</category>
    </item>
    <item>
      <title>Cisco SD-WAN CVE-2026-20182 Bypasses the Network Controller. The Data Layer Holds.</title>
      <link>https://lattix.io/blog/cisco-sd-wan-cve-2026-20182-data-layer-isolation</link>
      <guid isPermaLink="true">https://lattix.io/blog/cisco-sd-wan-cve-2026-20182-data-layer-isolation</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>Cisco confirmed CVE-2026-20182 against Catalyst SD-WAN Controller as exploited in the wild in May 2026. Unauthenticated attackers gain admin on affected systems. CISA added the flaw to KEV. SD-WAN is the East-West choke point that perimeter zero trust depends on. Data-level enforcement does not.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Network Security</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Langflow CVE-2025-34291 Hands Over the AI Orchestrator&apos;s Credential Stash</title>
      <link>https://lattix.io/blog/langflow-cve-2025-34291-ai-orchestrator-credential-data</link>
      <guid isPermaLink="true">https://lattix.io/blog/langflow-cve-2025-34291-ai-orchestrator-credential-data</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>CISA added Langflow CVE-2025-34291 to KEV on May 21, 2026 with a June 4 FCEB deadline. The CVSS 9.4 flaw turns a visit to a malicious page into account takeover plus RCE on a Langflow workspace. The harvested material is the operator&apos;s full AI credential stash.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>AI Security</category>
      <category>Supply Chain</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>The Linux Copy Fail CVE-2026-31431 Reaches Root. Object-Level Enforcement Reaches the Data.</title>
      <link>https://lattix.io/blog/linux-copy-fail-cve-2026-31431-kev-data-layer</link>
      <guid isPermaLink="true">https://lattix.io/blog/linux-copy-fail-cve-2026-31431-kev-data-layer</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-31431 escalates an unprivileged Linux user to root with a 732-byte Python script. CISA added it to KEV May 1 with a federal remediation deadline of May 15. Patching closes the vector. Object-level cryptographic enforcement closes the consequence.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Linux</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>The Nx Console Supply Chain Attack Is a Credentials-as-Data Story</title>
      <link>https://lattix.io/blog/nx-console-supply-chain-credentials-as-data</link>
      <guid isPermaLink="true">https://lattix.io/blog/nx-console-supply-chain-credentials-as-data</guid>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <description>On May 18, 2026, a compromised Nx Console VS Code extension exfiltrated credentials from developer workstations. By May 19, GitHub disclosed that 3,800 internal repositories had been exfiltrated as a result. The pivot was static credentials. The architectural answer is to treat credentials as policy-bound data.</description>
      <category>Supply Chain</category>
      <category>Developer Security</category>
      <category>Incident Analysis</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>Data Classification: The Foundation You Can&apos;t Skip</title>
      <link>https://lattix.io/blog/data-classification-foundation-zero-trust</link>
      <guid isPermaLink="true">https://lattix.io/blog/data-classification-foundation-zero-trust</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <description>You cannot enforce a policy you have not defined, and you cannot define a policy on data you have not classified. Classification is where zero trust actually begins.</description>
      <category>Data Security</category>
      <category>Data Governance</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>CMMC Phase 2 Starts November 10. Here Is What Level 2 C3PAO Actually Requires.</title>
      <link>https://lattix.io/blog/cmmc-phase-2-november-2026-c3pao-level-2</link>
      <guid isPermaLink="true">https://lattix.io/blog/cmmc-phase-2-november-2026-c3pao-level-2</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>Phase 2 of the CMMC 2.0 rollout begins November 10, 2026. Level 2 self-attestation ends. Third-party C3PAO certification becomes the contract gate for CUI work. The 110 NIST SP 800-171 practices stop being aspirational at that point.</description>
      <category>CMMC</category>
      <category>Compliance</category>
      <category>Defense</category>
      <category>Data Security</category>
      <category>DFARS</category>
    </item>
    <item>
      <title>CNSA 2.0 and the January 2027 Deadline for National Security Systems</title>
      <link>https://lattix.io/blog/cnsa-2-january-2027-national-security-systems</link>
      <guid isPermaLink="true">https://lattix.io/blog/cnsa-2-january-2027-national-security-systems</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>CNSA 2.0 binds new National Security System acquisitions to ML-KEM-1024 and ML-DSA-87 effective January 1, 2027. Twenty months remain on the clock. The target is not the hard part. The transition pattern is.</description>
      <category>Post-Quantum Cryptography</category>
      <category>NSA</category>
      <category>CNSA</category>
      <category>Defense</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>DOJ 28 CFR Part 202 Enforcement Starts October 6. Data-Centric Controls Carry the Evidence.</title>
      <link>https://lattix.io/blog/doj-28-cfr-202-bulk-sensitive-data-rule</link>
      <guid isPermaLink="true">https://lattix.io/blog/doj-28-cfr-202-bulk-sensitive-data-rule</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>The DOJ Bulk Sensitive Data rule under 28 CFR Part 202 took effect April 8, 2025. Active enforcement actions begin October 6, 2026. Most compliance frameworks treat the rule as a contract control. The evidence the rule actually requires is technical.</description>
      <category>Compliance</category>
      <category>Data Security</category>
      <category>Data Sovereignty</category>
      <category>DOJ</category>
      <category>National Security</category>
    </item>
    <item>
      <title>The EU AI Act High-Risk Deadline Slipped to December 2027. The Architecture Window Did Not.</title>
      <link>https://lattix.io/blog/eu-ai-act-high-risk-data-governance-conformity-evidence</link>
      <guid isPermaLink="true">https://lattix.io/blog/eu-ai-act-high-risk-data-governance-conformity-evidence</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>The May 7, 2026 political agreement pushed the EU AI Act Article 6 deadline from August 2026 to December 2027. The substantive obligations under Articles 10, 12, and 14 did not change. The architecture that produces conformity evidence takes twelve to eighteen months to build.</description>
      <category>AI Governance</category>
      <category>EU AI Act</category>
      <category>AI Security</category>
      <category>Data Security</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>The HIPAA Security Rule NPRM Demands Cryptographic Safeguards the Current Rule Only Implies</title>
      <link>https://lattix.io/blog/hipaa-security-rule-nprm-cryptographic-safeguards</link>
      <guid isPermaLink="true">https://lattix.io/blog/hipaa-security-rule-nprm-cryptographic-safeguards</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>HHS issued the first major HIPAA Security Rule update since 2003 in December 2024. OCR targets May 2026 for the final rule, with 4,700 comments under review. The NPRM raises the bar on encryption, MFA, inventory, and audit. The architecture window is shorter.</description>
      <category>HIPAA</category>
      <category>Healthcare</category>
      <category>Compliance</category>
      <category>Data Security</category>
      <category>Cryptography</category>
    </item>
    <item>
      <title>The SEC&apos;s Four-Day Clock Starts on Materiality, Not Discovery</title>
      <link>https://lattix.io/blog/sec-cyber-disclosure-four-day-materiality-rule</link>
      <guid isPermaLink="true">https://lattix.io/blog/sec-cyber-disclosure-four-day-materiality-rule</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>Form 8-K Item 1.05 starts the four-business-day clock on the materiality determination, not on incident discovery. The clock is shorter than most response playbooks assume. The architecture that shortens the materiality analysis is data-centric.</description>
      <category>SEC</category>
      <category>Compliance</category>
      <category>Risk Management</category>
      <category>Incident Response</category>
      <category>Governance</category>
    </item>
    <item>
      <title>Vercel + Context.ai: OAuth Is the Quiet Supply Chain</title>
      <link>https://lattix.io/blog/vercel-context-ai-oauth-supply-chain-policy-bound-secrets</link>
      <guid isPermaLink="true">https://lattix.io/blog/vercel-context-ai-oauth-supply-chain-policy-bound-secrets</guid>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <description>Vercel&apos;s April 19, 2026 security bulletin documented an OAuth compromise that exfiltrated environment variables through an authorized AI integration. Identity, network, and device controls all evaluated correctly. The data did not enforce its own policy.</description>
      <category>Supply Chain</category>
      <category>OAuth</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
      <category>Incident Analysis</category>
    </item>
    <item>
      <title>CISA&apos;s PQC Product Categories Move Quantum-Safe From Roadmap to Procurement</title>
      <link>https://lattix.io/blog/cisa-pqc-product-categories-federal-acquisition</link>
      <guid isPermaLink="true">https://lattix.io/blog/cisa-pqc-product-categories-federal-acquisition</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>CISA&apos;s January 23, 2026 product categories list, issued under Executive Order 14306, defines where federal buyers should acquire only PQC-capable products. The list is advisory. The procurement language built on it will not be.</description>
      <category>Post-Quantum Cryptography</category>
      <category>CISA</category>
      <category>Federal Acquisition</category>
      <category>Compliance</category>
      <category>Procurement</category>
    </item>
    <item>
      <title>The DoD Zero Trust Overlays Already Describe a Data-Centric Architecture</title>
      <link>https://lattix.io/blog/dod-zt-symposium-capability-overlays-data-centric</link>
      <guid isPermaLink="true">https://lattix.io/blog/dod-zt-symposium-capability-overlays-data-centric</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>The September 2024 DoD Zero Trust Overlays define 152 capability outcomes across seven pillars. The Data Pillar outcomes do not name a vendor and do not name a product category. They describe the architecture data-centric security has been building toward since the original strategy.</description>
      <category>Zero Trust</category>
      <category>DoD</category>
      <category>Data Pillar</category>
      <category>Architecture</category>
      <category>Defense</category>
    </item>
    <item>
      <title>The Medtronic Breach Is the Canvas Playbook Run Against a Medical Device Maker</title>
      <link>https://lattix.io/blog/medtronic-shinyhunters-breach-healthcare-data-enforcement</link>
      <guid isPermaLink="true">https://lattix.io/blog/medtronic-shinyhunters-breach-healthcare-data-enforcement</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>Medtronic confirmed a ShinyHunters extortion event in an SEC 8-K on April 24, 2026. Nine million records claimed, the leak site listing pulled before the deadline. The architectural lesson is the same one the Canvas breach already wrote: containment closes the access path, not the copies that already left.</description>
      <category>Healthcare</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
      <category>Incident Analysis</category>
      <category>HIPAA</category>
    </item>
    <item>
      <title>NIST&apos;s Critical Infrastructure AI RMF Profile Turns Trustworthy AI Into System Requirements</title>
      <link>https://lattix.io/blog/nist-critical-infrastructure-ai-rmf-profile-system-requirements</link>
      <guid isPermaLink="true">https://lattix.io/blog/nist-critical-infrastructure-ai-rmf-profile-system-requirements</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>NIST published the concept note for a Trustworthy AI in Critical Infrastructure Profile on April 7, 2026. The profile turns the AI RMF Govern, Map, Measure, Manage functions into system requirements for energy, water, and transportation operators. Data provenance and lineage map directly to the profile controls.</description>
      <category>AI Security</category>
      <category>Critical Infrastructure</category>
      <category>NIST</category>
      <category>Risk Management</category>
      <category>Data Provenance</category>
    </item>
    <item>
      <title>NSA&apos;s Zero Trust Implementation Guidelines Turn Target-Level Maturity Into Sequence</title>
      <link>https://lattix.io/blog/nsa-zero-trust-implementation-guidelines-target-level-sequence</link>
      <guid isPermaLink="true">https://lattix.io/blog/nsa-zero-trust-implementation-guidelines-target-level-sequence</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>NSA published Phase One of its Zero Trust Implementation Guidelines in January 2026 and Phase Two later that month. The market did not need another zero trust definition. It needed the sequence, and the guidelines provide it.</description>
      <category>Zero Trust</category>
      <category>NSA</category>
      <category>DoD</category>
      <category>Implementation</category>
      <category>Data Pillar</category>
    </item>
    <item>
      <title>NSA Named ZTDF and IC-TDF the Interoperability Schemas. Procurement Catches Up Next.</title>
      <link>https://lattix.io/blog/nsa-ztdf-interoperability-standard-phase-two</link>
      <guid isPermaLink="true">https://lattix.io/blog/nsa-ztdf-interoperability-standard-phase-two</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>NSA&apos;s Zero Trust Implementation Guideline Phase Two, released January 30, 2026, names Zero Trust Data Format and IC-Trusted Data Format as the DRM schemas for interoperable data rights enforcement. The defense-grade naming is the validation data-centric security has been waiting for.</description>
      <category>ZTDF</category>
      <category>Zero Trust</category>
      <category>NSA</category>
      <category>Defense</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Why Network Zero Trust Stops at the Data Boundary</title>
      <link>https://lattix.io/blog/why-network-zero-trust-stops-at-data-boundary</link>
      <guid isPermaLink="true">https://lattix.io/blog/why-network-zero-trust-stops-at-data-boundary</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>NIST SP 800-207 and the CISA Zero Trust Maturity Model define five pillars. Most enterprise programs stop at networks. The data pillar requires cryptographic enforcement bound to the object, not perimeter or session controls, and the gap is architectural rather than budgetary.</description>
      <category>Zero Trust</category>
      <category>Data Security</category>
      <category>ABAC</category>
      <category>Federal</category>
      <category>Architecture</category>
    </item>
    <item>
      <title>Coalition Data Sharing Without Infrastructure Agreement</title>
      <link>https://lattix.io/blog/classified-data-sharing-coalition-partners</link>
      <guid isPermaLink="true">https://lattix.io/blog/classified-data-sharing-coalition-partners</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>When allied partners operate separate networks and classification systems, data-centric security moves enforcement from infrastructure to the data itself.</description>
      <category>Defense</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>Confidential Computing and Data-Centric Zero Trust: Composable Protection</title>
      <link>https://lattix.io/blog/confidential-computing-meets-data-centric-security</link>
      <guid isPermaLink="true">https://lattix.io/blog/confidential-computing-meets-data-centric-security</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Trusted execution environments protect data in use. Zero trust data fabrics protect it at rest and in transit. Together, they create architectural closure across all three states.</description>
      <category>Confidential Computing</category>
      <category>Data Security</category>
      <category>Encryption</category>
    </item>
    <item>
      <title>M&amp;A Data Rooms After Deal Close: Policy-Bound Due Diligence</title>
      <link>https://lattix.io/blog/data-rooms-mergers-acquisitions-due-diligence</link>
      <guid isPermaLink="true">https://lattix.io/blog/data-rooms-mergers-acquisitions-due-diligence</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Virtual data rooms protect documents while deals are live. The hard question: what happens after the deal closes or collapses? Policy-bound data with cryptographic enforcement ensures revocation is real.</description>
      <category>M&amp;A</category>
      <category>Data Security</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>Data Sovereignty Beyond Storage: Policy-Bound Access in Multi-Cloud</title>
      <link>https://lattix.io/blog/data-sovereignty-multi-cloud</link>
      <guid isPermaLink="true">https://lattix.io/blog/data-sovereignty-multi-cloud</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Regulatory mandates from GDPR to China PIPL require demonstrable access control at the data layer, not region-pinning. Policy-bound data with attribute-based access control collapses jurisdictional rules into a single enforcement primitive.</description>
      <category>Data Sovereignty</category>
      <category>Compliance</category>
      <category>Multi-Cloud</category>
    </item>
    <item>
      <title>Federated Learning: Training AI Without Surrendering Data</title>
      <link>https://lattix.io/blog/federated-learning-training-without-surrendering-data</link>
      <guid isPermaLink="true">https://lattix.io/blog/federated-learning-training-without-surrendering-data</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Federated learning trains models by sharing gradients, not data. Combined with data-centric zero trust, it makes privacy-preserving AI a realistic architectural choice, not an academic one.</description>
      <category>AI Safety</category>
      <category>Federated Learning</category>
      <category>Privacy</category>
    </item>
    <item>
      <title>FedRAMP High Baseline: 421 Controls and the Data-Centric Path</title>
      <link>https://lattix.io/blog/fedramp-high-cloud-native-government-workloads</link>
      <guid isPermaLink="true">https://lattix.io/blog/fedramp-high-cloud-native-government-workloads</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>FedRAMP High imposes 421 controls on cloud service providers seeking federal authorization. Data-centric zero trust collapses several of the hardest controls into cryptographic enforcement at the policy enforcement point.</description>
      <category>FedRAMP</category>
      <category>Government</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>HIPAA Security Rule Enforcement Starts With Data, Not Paper</title>
      <link>https://lattix.io/blog/healthcare-hipaa-beyond-business-associate-agreements</link>
      <guid isPermaLink="true">https://lattix.io/blog/healthcare-hipaa-beyond-business-associate-agreements</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Business Associate Agreements transfer liability, not enforcement. HIPAA&apos;s Security Rule is explicit about what must be protected and how. Real compliance means cryptographic policy at the PHI object.</description>
      <category>Healthcare</category>
      <category>HIPAA</category>
      <category>Compliance</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>The Canvas Breach Is a Data Enforcement Story, Not a Containment Story</title>
      <link>https://lattix.io/blog/instructure-canvas-breach-data-enforcement</link>
      <guid isPermaLink="true">https://lattix.io/blog/instructure-canvas-breach-data-enforcement</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>ShinyHunters claimed 275 million records from Instructure across 9,000 institutions. Containment closed the access path. The records had already crossed the policy boundary. The disclosure surface is what FERPA, schools, and downstream subjects have to deal with now.</description>
      <category>Data Security</category>
      <category>Zero Trust</category>
      <category>Education</category>
      <category>FERPA</category>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Key Management in Data-Centric Security: Who Holds the Keys</title>
      <link>https://lattix.io/blog/key-management-data-centric-security</link>
      <guid isPermaLink="true">https://lattix.io/blog/key-management-data-centric-security</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>A wrapped data object is only as secure as the policy authority that releases the key. Key management is where data-centric security becomes operational reality.</description>
      <category>Key Management</category>
      <category>Data Security</category>
      <category>Encryption</category>
    </item>
    <item>
      <title>Translating Data-Centric Security Into Board Language</title>
      <link>https://lattix.io/blog/measuring-security-roi-data-centric-board-presentation</link>
      <guid isPermaLink="true">https://lattix.io/blog/measuring-security-roi-data-centric-board-presentation</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Boards fund security investments they can measure. Data-centric architecture produces three measurable outcomes: faster authorization, lower third-party overhead, reduced breach liability.</description>
      <category>Business</category>
      <category>Risk Management</category>
      <category>Strategy</category>
    </item>
    <item>
      <title>Secure File Transfer in the Age of Zero Trust</title>
      <link>https://lattix.io/blog/secure-file-transfer-age-of-zero-trust</link>
      <guid isPermaLink="true">https://lattix.io/blog/secure-file-transfer-age-of-zero-trust</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Every managed file transfer product trusts the endpoint. Recent MFT breaches proved that trust fails at scale. Zero Trust requires the file itself to carry its own security policy.</description>
      <category>File Transfer</category>
      <category>Zero Trust</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>Identity and Authority at Machine Speed</title>
      <link>https://lattix.io/blog/securing-autonomous-ai-agents</link>
      <guid isPermaLink="true">https://lattix.io/blog/securing-autonomous-ai-agents</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Autonomous agents make decisions and move data at machine speed. Zero Trust identity architecture must evolve to grant and audit authority at that pace.</description>
      <category>AI Safety</category>
      <category>Zero Trust</category>
      <category>Identity</category>
    </item>
    <item>
      <title>SBOM to Provenance: Verifiable Supply Chains on Immutable Ledgers</title>
      <link>https://lattix.io/blog/software-supply-chain-sbom-to-signed-provenance</link>
      <guid isPermaLink="true">https://lattix.io/blog/software-supply-chain-sbom-to-signed-provenance</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>SBOMs inventory what is in the box. Signed provenance anchored to an immutable ledger proves the box was assembled as claimed. A walkthrough of SLSA, Sigstore, and why transparency logs matter.</description>
      <category>Supply Chain</category>
      <category>SBOM</category>
      <category>Cybersecurity</category>
      <category>Provenance</category>
    </item>
    <item>
      <title>Data-Centric Security Closes the Third-Party Risk Assurance Gap</title>
      <link>https://lattix.io/blog/third-party-risk-data-centric-answer</link>
      <guid isPermaLink="true">https://lattix.io/blog/third-party-risk-data-centric-answer</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Questionnaire fatigue and point-in-time audits cannot track vendor risk continuously. Policy authority retained at the data layer does.</description>
      <category>Third-Party Risk</category>
      <category>Data Security</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>Trusted Data Format: From IC Origin to ZTDF Standard</title>
      <link>https://lattix.io/blog/trusted-data-format-origin-evolution-future</link>
      <guid isPermaLink="true">https://lattix.io/blog/trusted-data-format-origin-evolution-future</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>The Trusted Data Format began in the intelligence community as a solution to cross-domain data sharing. Its evolution reflects the shift from network-centric to data-centric security.</description>
      <category>TDF</category>
      <category>Data Security</category>
      <category>Open Standards</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>ABAC vs RBAC: Why Attribute-Based Access Control Is the Zero Trust Default</title>
      <link>https://lattix.io/blog/abac-vs-rbac-zero-trust-default</link>
      <guid isPermaLink="true">https://lattix.io/blog/abac-vs-rbac-zero-trust-default</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <description>Role-based access grants standing privileges that outlive their purpose. Attribute-based access evaluates every request in context. For zero trust, only one of these actually works.</description>
      <category>Zero Trust</category>
      <category>ABAC</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>DoD Zero Trust Strategy 2.0 Extends to OT and Weapon Systems</title>
      <link>https://lattix.io/blog/dod-zero-trust-strategy-2-data-pillar-ot-weapons</link>
      <guid isPermaLink="true">https://lattix.io/blog/dod-zero-trust-strategy-2-data-pillar-ot-weapons</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <description>DoD Zero Trust Strategy 2.0, published March 2026, brings operational technology, IoT, defense critical infrastructure, and weapon systems under the same target-level maturity expectations as enterprise IT. The data pillar is where the new scope hits hardest.</description>
      <category>Zero Trust</category>
      <category>DoD</category>
      <category>OT Security</category>
      <category>Weapon Systems</category>
      <category>Data Pillar</category>
    </item>
    <item>
      <title>Federal Zero Trust Deadlines Are Binding. Data Layer Enforcement Is Not.</title>
      <link>https://lattix.io/blog/federal-zero-trust-deadlines-data-layer-enforcement</link>
      <guid isPermaLink="true">https://lattix.io/blog/federal-zero-trust-deadlines-data-layer-enforcement</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <description>CISA&apos;s April 2026 binding directive sets Q3/Q4 2026 deadlines for identity, network, and device zero trust controls. The data layer remains optional. Programs that hit every milestone without object-level enforcement still fail on a compromised service account.</description>
      <category>Zero Trust</category>
      <category>CISA</category>
      <category>Compliance</category>
      <category>Government</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>CISA&apos;s April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed</title>
      <link>https://lattix.io/blog/cisa-ot-zero-trust-april-2026-data-plane-gap</link>
      <guid isPermaLink="true">https://lattix.io/blog/cisa-ot-zero-trust-april-2026-data-plane-gap</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <description>On April 30, 2026, CISA and four federal partners released a joint guide adapting zero trust principles to operational technology. The guide advances identity, network, and visibility maturity for OT. The data plane remains an open enforcement gap.</description>
      <category>Zero Trust</category>
      <category>Operational Technology</category>
      <category>CISA</category>
      <category>Data Security</category>
      <category>Federal</category>
    </item>
    <item>
      <title>CNSA 2.0 Just Narrowed the PQC Field. ML-KEM-768 Will Not Clear NSS.</title>
      <link>https://lattix.io/blog/cnsa-2-0-ml-kem-1024-ml-dsa-87-exclusive-clarification</link>
      <guid isPermaLink="true">https://lattix.io/blog/cnsa-2-0-ml-kem-1024-ml-dsa-87-exclusive-clarification</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <description>NSA&apos;s April 2026 clarification narrowed the post-quantum field for National Security Systems to ML-KEM-1024 and ML-DSA-87. ML-KEM-768 will not clear NSS. Vendors that staked PQC-ready claims on the smaller parameter set need new statements.</description>
      <category>Post-Quantum Cryptography</category>
      <category>NSA</category>
      <category>CNSA</category>
      <category>Compliance</category>
      <category>Defense</category>
    </item>
    <item>
      <title>Post-Quantum Cryptography: Why the Transition Has to Happen Now</title>
      <link>https://lattix.io/blog/post-quantum-cryptography-why-transition-now</link>
      <guid isPermaLink="true">https://lattix.io/blog/post-quantum-cryptography-why-transition-now</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <description>Two PQC deadlines are already running. September 21, 2026 sunsets FIPS 140-2 for federal procurement. January 2027 binds CNSA 2.0 for National Security Systems. The migration that matters is not the algorithm. It is the cryptographic agility to swap one.</description>
      <category>Post-Quantum Cryptography</category>
      <category>Cybersecurity</category>
      <category>Compliance</category>
      <category>Federal</category>
      <category>Data Security</category>
    </item>
    <item>
      <title>How Cryptographic Data Enforcement Contains the MCP Blast Radius</title>
      <link>https://lattix.io/blog/mcp-blast-radius-cryptographic-data-enforcement</link>
      <guid isPermaLink="true">https://lattix.io/blog/mcp-blast-radius-cryptographic-data-enforcement</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
      <description>AI agents acting on injected instructions are now the dominant exfiltration vector. Two April 2026 incidents show why ABAC enforcement at the data object, not the network or the identity plane, is the control that actually contains MCP.</description>
      <category>Zero Trust</category>
      <category>AI Security</category>
      <category>MCP</category>
      <category>Data Security</category>
      <category>Post-Quantum</category>
    </item>
    <item>
      <title>SharePoint CVE-2026-32201 Is in KEV. The Disclosure Surface Is the Real Issue.</title>
      <link>https://lattix.io/blog/sharepoint-cve-2026-32201-kev-disclosure-surface</link>
      <guid isPermaLink="true">https://lattix.io/blog/sharepoint-cve-2026-32201-kev-disclosure-surface</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description>CISA added the April SharePoint spoofing zero-day to KEV on April 14 with an FCEB remediation deadline of April 28. Patching closes the vector. It does not answer what an attacker read, modified, or signed before the update landed.</description>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>KEV</category>
      <category>Data Security</category>
      <category>SharePoint</category>
    </item>
    <item>
      <title>The Mercor Breach Is a Data-Centric Security Story. Not an Identity One.</title>
      <link>https://lattix.io/blog/mercor-breach-data-centric-security-story</link>
      <guid isPermaLink="true">https://lattix.io/blog/mercor-breach-data-centric-security-story</guid>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <description>A malicious LiteLLM package pushed March 27, 2026 cascaded into a four-terabyte exfiltration from an AI training-data vendor whose customer list reads like the frontier lab leaderboard. Identity controls were present. They were not the control that mattered.</description>
      <category>Supply Chain</category>
      <category>AI Security</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title>Protecting Sensitive AI Training Data with Data-Centric Security</title>
      <link>https://lattix.io/blog/protecting-sensitive-ai-training-data-with-data-centric-security</link>
      <guid isPermaLink="true">https://lattix.io/blog/protecting-sensitive-ai-training-data-with-data-centric-security</guid>
      <pubDate>Tue, 13 May 2025 00:00:00 GMT</pubDate>
      <description>AI systems are only as trustworthy as the data they train on. A data-centric security approach shifts protection from infrastructure to the data itself.</description>
      <category>AI Safety</category>
      <category>Data Security</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>How Blockchain Enhances Cybersecurity in the Era of Digital Threats</title>
      <link>https://lattix.io/blog/blockchain-for-cybersecurity</link>
      <guid isPermaLink="true">https://lattix.io/blog/blockchain-for-cybersecurity</guid>
      <pubDate>Tue, 29 Apr 2025 00:00:00 GMT</pubDate>
      <description>Blockchain technology offers unique capabilities for cybersecurity: tamper-proof audit trails, smart contracts for access control, and decentralized identity management.</description>
      <category>Blockchain</category>
      <category>Cybersecurity</category>
      <category>Smart Contract</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>Can You Trust AI? Not Without Securing the Data It Trains On</title>
      <link>https://lattix.io/blog/can-you-trust-ai-not-without-securing-the-data-it-trains-on</link>
      <guid isPermaLink="true">https://lattix.io/blog/can-you-trust-ai-not-without-securing-the-data-it-trains-on</guid>
      <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
      <description>AI trustworthiness depends entirely on training data integrity. Without securing the data pipeline, AI outputs cannot be trusted.</description>
      <category>AI Safety</category>
      <category>Data Security</category>
      <category>Zero Trust</category>
    </item>
    <item>
      <title>What is Zero Trust Data Format (ZTDF) and Why Does It Matter?</title>
      <link>https://lattix.io/blog/what-is-zero-trust-data-format-and-why-does-it-matter</link>
      <guid isPermaLink="true">https://lattix.io/blog/what-is-zero-trust-data-format-and-why-does-it-matter</guid>
      <pubDate>Sun, 09 Feb 2025 00:00:00 GMT</pubDate>
      <description>ZTDF creates a self-enforcing security boundary around every data object with embedded encryption, access policies, and audit capabilities.</description>
      <category>Zero Trust</category>
      <category>Data Security</category>
      <category>ZTDF</category>
    </item>
    <item>
      <title>Why Zero Trust is the Future of Data Security</title>
      <link>https://lattix.io/blog/why-zero-trust-is-the-future-of-data-security</link>
      <guid isPermaLink="true">https://lattix.io/blog/why-zero-trust-is-the-future-of-data-security</guid>
      <pubDate>Sun, 09 Feb 2025 00:00:00 GMT</pubDate>
      <description>Traditional perimeter-based security is failing. Zero Trust architecture operates on a simple principle: never trust, always verify.</description>
      <category>Zero Trust</category>
      <category>Data Security</category>
    </item>
  </channel>
</rss>
