Contact Us
[contact-form-7 id="ceb4db8" title="Contact form 1"]

This month’s brief addresses the OCC’s June 2026 Cybersecurity and Financial System Resilience Report and its clear message that cybersecurity is now an operational resilience issue for community banks. We cover the largest-ever Microsoft Patch Tuesday release (206 vulnerabilities including 3 zero-days), confirmation that last month’s Netlogon vulnerability is now being exploited in the wild.
We also cover the Nacha Phase 2 ACH fraud monitoring deadline arriving June 22 and the emergence of AI-assisted vulnerability discovery as a driver of unprecedented patch volumes. We provide staff training on strengthening operational resilience thinking, and outline best practices leadership and IT teams can use together to close the gap between prevention and resilience.
CVEs in June Patch Tuesday
(Largest Release Ever at the Time)
Days Average Time to
Detect a Breach in Finance
Nacha Phase 2 ACH Fraud
Monitoring Now in Effect
The following threats have been identified as having significant relevance to community banks, credit unions, and savings institutions during the current reporting period.

On June 27, the Office of the Comptroller of the Currency (OCC) released its annual Cybersecurity and Financial System Resilience Report to Congress. This year’s report contains a direct message for community banks: cybersecurity can no longer function primarily as an IT responsibility or a periodic compliance exercise. It has become an operational resilience issue. The report highlights AI-enabled threat actors, expanded third-party interconnection, and regulatory expectations for rapid incident escalation as forces reshaping what examiners look for.
While OCC guidance most directly binds national banks and federal savings associations, the FDIC and NCUA typically align with these themes, and examination priorities across the FFIEC agencies are converging. The report signals a change in how examiners will assess programs. The question is no longer just “do you have controls in place” but “does your program work as intended when tested against a real incident scenario?” Prevention remains critical, but the report explicitly states that mature programs must assume systems can fail, vendors can experience outages, and sophisticated attackers may occasionally penetrate defenses.
What this means for your institution: This is a governance-level shift for every community bank, credit union, and savings institution. Examiners will increasingly ask whether the Board is exercising oversight of operational resilience (not just cybersecurity spending), whether tabletop exercises test real-world scenarios, and whether the institution can effectively communicate with regulators, customers, vendors, and stakeholders during an incident. This is also an opportunity: institutions that reframe their programs around resilience often find they can meet regulator expectations with existing resources.
For Leadership: Review your cybersecurity program with your IT team and, if applicable, your vCISO to identify where the emphasis is prevention-only versus operational resilience. Ask whether your last tabletop exercise tested response and recovery (resilience) or just detection (prevention). Confirm your Board has visibility into third-party concentration risk. Update your annual IT risk assessment to explicitly address operational resilience alongside preventive controls.
For IT/Operations: Review incident response playbooks for gaps between detection and recovery. Ensure tabletop exercises test communication workflows, not just technical response. Map third-party dependencies for critical services and identify single points of failure. Validate that backup and recovery procedures actually restore operations within documented RTO/RPO targets. Coordinate with the risk management function to align cybersecurity metrics with operational resilience reporting.

On June 10, Microsoft released the largest single-month security update in the history of the Patch Tuesday program—206 vulnerabilities, breaking the previous record of 167 set in October 2025. This included three publicly disclosed zero-days: a privilege escalation flaw in the Windows Collaborative Translation Framework (CVE-2026-45586), a denial-of-service flaw in Windows HTTP.sys (CVE-2026-49160), and a security-feature bypass in BitLocker (CVE-2026-50507).
Notably, Microsoft credited OpenAI’s Codex with reporting CVE-2026- 49160—the first widely publicized case of an AI system contributing to Patch Tuesday. Security researchers warn that AI-assisted vulnerability discovery is a structural change: the operational load of testing and deploying patches will grow accordingly, and 200 CVEs in a month may become the new planning baseline.
Separately, Microsoft confirmed on June 1 that CVE-2026-41089 (the Netlogon RCE vulnerability patched in May) is now being actively exploited in the wild. Institutions that have not yet applied the May 12 or June cumulative update to domain controllers should treat this as an emergency.
What this means for your institution: Every institution running Microsoft products has substantial patching work this month, on top of remediation for the actively exploited Netlogon flaw from May. The scale of the June release makes prioritization more important than ever—institutions cannot patch everything equally. AI-assisted vulnerability research means the pace will continue to accelerate, and IT teams and TSPs need scalable processes to keep pace.
For Leadership: Ask your IT team or TSP for confirmation that (1) the May Netlogon patch (CVE-2026-41089) has been applied to all domain controllers, given confirmed active exploitation, and (2) the June 10 updates have been applied per your patching SLA. Ask whether your team is using CISA’s Known Exploited Vulnerabilities catalog as a prioritization signal. Discuss with your IT team whether your current patching cadence can sustain the new normal of 200+ CVEs per month.
For IT/Operations: Prioritize CVE-2026-41089 (Netlogon RCE, now KEV-listed, actively exploited) if not already applied. Deploy June 10 updates focused on 37 Critical-rated vulnerabilities including CVE-2026-45657 (Windows Kernel RCE, CVSS 9.8). Address zero-days CVE-2026-45586 (CTFMON EoP), CVE-2026-49160 (HTTP.sys DoS), and CVE-2026-50507 (BitLocker bypass). Review whether your patch management process can handle sustained 200+ CVE monthly volumes; adjust staffing, tooling, or SLAs as needed. Document patch timing for examination evidence.

The second phase of Nacha’s ACH fraud monitoring rules takes effect June 22, 2026 (the practical compliance date, since the formal June 19 date falls on a federal holiday). Phase 2 removes the previous volume threshold, meaning the fraud monitoring requirements now apply to ALL non-consumer originators, third-party service providers, and third-party senders regardless of transaction volume—and to all remaining RDFIs for credit monitoring. The rule requires institutions to establish written, risk-based fraud monitoring processes designed to detect ACH entries initiated due to fraud, including business email compromise and “false pretenses” schemes.
What this means for your institution: Every community bank, credit union, and savings institution that originates or receives ACH transactions is subject to Phase 2 requirements as of June 22—even those below the Phase 1 volume threshold that took effect in March. Examiners will begin looking for evidence of compliance immediately. The rule specifically calls out business email compromise, vendor impersonation, and payroll diversion as the fraud types institutions must be prepared to detect.
For Leadership: Confirm with your core processor and ACH service provider that Phase 2 fraud monitoring processes are documented and operational before June 22. Ask for evidence of the written procedures and how they will be reviewed annually. Coordinate with your BSA/AML team so ACH fraud monitoring is integrated with existing suspicious activity detection. Update your policies to explicitly reference the “false pretenses” fraud category. Brief your Board on Phase 2 compliance status before the deadline.
For IT/Operations: Verify implementation of risk-based fraud monitoring covering velocity checks, anomaly detection, and behavioral baselines for ACH activity. Ensure standardized Company Entry Descriptions (“PAYROLL” and “PURCHASE”) are properly used for applicable transaction types. Document the written fraud monitoring process, the annual review schedule, and the escalation procedures. Coordinate with core processor and third-party providers to confirm their compliance status by June 22.

This month’s record-breaking Patch Tuesday is not a one-time anomaly. Security researchers have broadly adopted AI tooling for vulnerability discovery, and June’s release contained direct evidence of the shift: Microsoft credited OpenAI’s Codex with reporting one of the three publicly disclosed zero-days.
AI-assisted research finds more bugs per researcher per month, meaning vendors will fix more bugs per cycle, and the operational load of testing and deploying patches will grow accordingly. Industry analysts predict that 200 or more CVEs per month may become the new baseline rather than a headline number.
The implication is structural: institutions that sized their patching programs against 2024-2025 volumes are already operating at a disadvantage. Attackers are also using AI tooling, so the window between disclosure and active exploitation continues to shrink. Institutions need to shift from thinking about patching as a monthly operational task to thinking about it as a continuous, risk-prioritized program.
What this means for your institution: This is a resource and process issue as much as a technical one. Community banks and credit unions with limited IT staff face the largest scaling challenge. Institutions relying primarily on TSPs for patch management should verify the TSP is prepared for sustained high volumes. Board-level cybersecurity metrics may need to be updated to reflect the new reality—a 30-day patching SLA that was reasonable in 2023 may not be reasonable in 2026.
For Leadership: Review with IT whether current patching capacity can sustain 200+ CVE monthly volumes indefinitely. If not, discuss whether additional resources (staff, automation tools, TSP services) are needed. Update Board-level cybersecurity metrics to reflect the AI-driven acceleration of vulnerability disclosure. Include patch management performance as a recurring topic in IT steering committee meetings. Ensure your risk assessment addresses the shortening window between disclosure and exploitation.
For IT/Operations: Implement risk-based patch prioritization frameworks; do not attempt to patch all vulnerabilities equally. Subscribe to CISA KEV catalog updates as the primary prioritization signal for active exploitation. Deploy automated patch management tooling for standard endpoints and servers where feasible. Consider vulnerability management platforms that incorporate threat intelligence for prioritization. Document exception handling and compensating controls for delayed patches.

Recent industry reporting continues to underscore vendor concentration as one of the most exploitable weaknesses in the financial services sector. Black Kite’s 2026 Financial Services Cybersecurity Report documented that 78% of critical financial services vendors have at least one critical-level patch management failure, and 50.2% of the broader ecosystem of 17,000+ finance-related vendors shows similar exposure.
The Korean Leaks campaign continues to serve as a cautionary example: attackers gained access to a single managed service provider and used its privileged credentials to move laterally into 32 South Korean financial institutions simultaneously, without independently breaching each. Similar risks exist in the U.S. community banking and credit union ecosystem due to concentrated use of a small number of core processors and TSPs.
What this means for your institution: Your institution’s security is only as strong as your vendor ecosystem’s. Recent examination trends emphasize this: examiners increasingly ask about fourth-party concentration risk (who your vendors depend on), not just third-party controls. Community institutions with limited procurement flexibility are particularly exposed because they cannot easily diversify away from concentrated core processing relationships
For Leadership: Review your vendor management program to specifically address concentration risk. Ask your IT team to identify which of your critical vendors share the same downstream providers (fourth parties). Request updated SOC 2 Type II reports from all critical vendors and personally review the exceptions. Include vendor concentration risk in your annual IT risk assessment and Board reporting. Consider whether your institution has contingency plans if a critical vendor experiences a multi-day outage.
For IT/Operations: Map fourth-party dependencies for all critical vendor relationships. Assess whether critical vendors have documented incident notification procedures with 24-hour SLAs. Review vendor DMARC/DKIM/SPF configurations; Black Kite found 47 finance vendors with misconfigured DMARC and 37 with misconfigured DKIM. Verify vendor CUEC compliance. Update vendor risk assessments to explicitly address concentration risk.
The OCC’s June 2026 Cybersecurity Report highlighted an important shift: mature cybersecurity programs cannot rely on prevention alone. Even with the best controls, employees make mistakes, vendors have outages, and sophisticated attackers occasionally get through.
The measure of a good program is not just whether it prevents every attack—that’s impossible—but whether the institution can detect, respond to, and recover from an attack quickly and effectively. Every employee has a role to play in that resilience. This training module is designed to be shared with all staff, including non-technical employees.


FFIEC IT Examination Handbook: ithandbook.ffiec.gov
CISA Alerts & Advisories: cisa.gov/known-exploited-vulnerabilities-catalog
CISA Ransomware / Scattered Spider Advisory: cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Microsoft May 2026 Patch Tuesday: msrc.microsoft.com/update-guide
Cisco SD-WAN Security Advisory: sec.cloudapps.cisco.com/security/center/publicationListing.x
FS-ISAC Threat Intelligence: fsisac.com