Not only is Center for Internet Security, Inc. (CIS) still sending these, but they still have no multi-factor authentication for accounts.

From https://www.cisecurity.org/about-us

The CIS Vision
Leading the global community to secure our ever-changing connected world.

The CIS Mission
Our mission is to make the connected world a safer place by developing, validating, and
promoting timely best practice solutions that help people, businesses, and governments
protect themselves against pervasive cyber threats.

https://www.youtube.com/watch?v=51gf648nRyE&t=118s

#Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #MFA #2FA #InfoSec #InformationSecurity #CyberSecurity

About us - CIS®

CIS is a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks®, globally recognized best practices for securing IT systems and data.

Center for Internet Security

The Register: Feds cut funding to program that shared cyber threat info with local governments. “The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday will cut its ties to – and funding for – the Center for Internet Security, a nonprofit that provides free and low-cost cybersecurity services to state and local governments.”

https://rbfirehose.com/2025/09/30/the-register-feds-cut-funding-to-program-that-shared-cyber-threat-info-with-local-governments/

The Register: Feds cut funding to program that shared cyber threat info with local governments | ResearchBuzz: Firehose

ResearchBuzz: Firehose | Individual posts from ResearchBuzz
US #CybersecurityandInfrastructureSecurityAgency, known as #CISA, Was denied about $10 million in annual funding to the nonprofit #CenterforInternetSecurity “I have grave concern for state and local election officials and for the security of our elections going forward” apnews.com/article/elec...

RE: https://bsky.app/profile/did:plc:pvcxicdndphhuiqczyzu43dw/post/3lvtqc3nxns2m


Trump administration halts fun...

How average folks don't stand a chance against phishing, example #80,144,963: "Security" "Professionals"

"Warning! Your account is about to be deactivated."
Log in soon or terrible things will happen.
Consider clicking on a link in this email.
BUTTON [Click it... Click it... Click it...]
Grey on grey because accessibility is for losers.

Click the password manager plugin icon on a browser tab,
start typing "cis...",
click to open and autofill credentials and login (in one step),
click the (old) password field to autofill,
click to accept the suggested very long and random password suggestion which autofills both the new password field and the one to check that the autofill typed it correctly the first time then automatically submit,
log out, and
wait for the next email from Compliance Isn't Security inviting me to the next dance.

For the historians: this is during the current wave of phishing campaigns claiming that your service is being shut down, retired, updated or otherwise changed in a way which requires you to click urgently before all that you love is lost.

PS. "This email was sent with love from" <[email protected]>

PPS. NIST SP 800-63B §3.1.1.2 #6 - https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver

#Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #InfoSec #InformationSecurity #CyberSecurity

NIST Special Publication 800-63B

NIST Special Publication 800-63B