International Policy

OWASP Publishes GenAI Red Teaming Guide

🤖 Artificial Intelligence 🔒 Cybersecurity 💻 Information Technology

OWASP’s GenAI Red Teaming Guide, published January 22, 2025, describes a holistic approach to assessing generative-AI security across model evaluation, implementation testing, infrastructure assessment, and runtime behavior. The post identifies no government buyer, solicitation, contract, funding, or procurement contact, so it does not represent a specific purchasing opportunity.

  • Procurement teams can use the guide as a reference when shaping generative-AI security assessment criteria or evaluating proposed testing methods.
  • Contractors providing AI security assessments can consider how their services address all four areas described in the guide; the post does not establish a mandatory standard or compliance requirement.

The guide emphasizes a holistic approach to Red Teaming in four areas: model evaluation, implementation testing, infrastructure assessment, and runtime behavior analysis.

— Original poster

Sources

DoW Funds U.S. Drone Battery Production

Federal News

DoW Funds U.S. Drone Battery Production

📋 Contracting Vehicles ✅ Regulatory Compliance 💰 Grants & Funding 🏛️ Physical Infrastructure 🛡️ Defense & Military ⚡ Energy & Utilities 💻 Information Technology

On September 23, 2026, Amprius Technologies signed a fixed-price Other Transaction Agreement with the U.S. Department of War for Project acCELLerate, providing up to $75 million to convert an existing U.S. battery production line for high-energy-density silicon-anode cells for Group 1–3 unmanned aircraft systems. The project targets annual production of 12 million cells by early 2028 and is estimated to cost about $100 million. Approximately $22 million is currently obligated; most of the award remains contingent on future appropriations and milestone acceptance. No open solicitation is identified.

  • The project signals federal investment in domestic, NDAA-compliant battery capacity and may create downstream demand for production equipment, line retrofits, and battery supply-chain inputs.
  • Suppliers and contractors can evaluate whether their capabilities align with the planned production expansion, while recognizing that the award itself is not an open bidding opportunity.
  • Firms supporting the project should account for appropriation and milestone-related funding and schedule risk; the agreement’s base period runs through September 22, 2028.

Sources

JIATF-401 Awards DroneShield $500M IDIQ

Federal News

JIATF-401 Awards DroneShield $500M IDIQ

📋 Contracting Vehicles 🛡️ Defense & Military

On September 30, 2026, DroneShield LLC received a three-year IDIQ award supporting Joint Interagency Task Force 401’s Domestic Shield counter-UAS initiative, with a reported ceiling of up to US$500 million. The ceiling is not committed funding: agencies must issue and fund separate task or delivery orders, and no order amounts or ordering schedule have been disclosed. Separately, DroneShield systems have completed installation, acceptance testing, and operator training on U.S. Infantry Squad Vehicles, providing a reported operational-readiness reference for the technology.

  • Procurement teams should distinguish the IDIQ ceiling from funded requirements; the signals do not identify any specific task orders, contract number, or procurement contact.
  • Contractors can assess potential competition or subcontracting needs tied to future counter-UAS orders, including sensing, system integration, countermeasures, and support, while recognizing that the vehicle’s specific order requirements are not yet detailed.
  • One signal also reports a broader Army multi-award counter-UAS vehicle valued at up to $7 billion, including a $500 million DroneShield base award. The relationship between that vehicle and the JIATF-401 award is unclear in the signals, so the figures should not be treated as additive without verification.

Sources

Federal News

Army Advances AeroVironment Laser Procurement

🛡️ Defense & Military

The U.S. Army awarded AeroVironment a production contract for its Enduring-High Energy Laser (E-HEL), described as the Army’s first production contract for a high-energy laser weapon system intended to counter unmanned aircraft. Separately, an August 7, 2026 report said the Army plans to purchase at least $400 million in AeroVironment Locust directed-energy counter-drone systems; that reported purchase has not been officially confirmed. Neither signal provides confirmed delivery schedules or detailed solicitation information for the reported Locust procurement. For defense contractors, the confirmed E-HEL award and the separate Locust report point to potential movement from counter-drone laser testing toward production and fielding, while leaving scope and follow-on opportunities uncertain.

  • The E-HEL production award is confirmed in the signal, but its value, contract number, delivery schedule, and deployment quantities are not provided.
  • The reported Locust purchase is valued at at least $400 million, but remains unconfirmed; contractors should distinguish this reporting from an official award when assessing the opportunity.
  • The systems are intended to counter unmanned aircraft and offer a lower per-shot cost than missiles, according to the signal. Suppliers of directed-energy components and supporting systems may find potential follow-on demand, but no specific requirements or solicitations are identified.
  • The report recommends using Army and DoD announcements to verify the Locust procurement’s scope and implementation requirements; no proposal deadline or contracting contact is provided.

Sources

CISA Adds Cisco SD-WAN Flaw to KEV Catalog

Federal News

CISA Adds Cisco SD-WAN Flaw to KEV Catalog

🔒 Cybersecurity ✅ Regulatory Compliance 💻 Information Technology

CISA added Cisco Catalyst SD-WAN Manager vulnerability CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30, 2026, after reports of active exploitation. The CVSS 9.8 authentication-bypass flaw has no workaround; upgrading to a fixed release is the stated remediation. The October 3, 2026 remediation deadline for federal civilian executive branch agencies has passed. The signals identify no specific solicitation, contract, or funding, but the vulnerability creates immediate patch-verification and incident-response work for agencies and contractors supporting affected federal networks.

  • Federal agencies and their service providers should confirm whether Catalyst SD-WAN Manager deployments are affected, verify upgrades to fixed releases, and check for signs of compromise; the source signals identify no workaround.
  • Contractors supporting federal networks should document remediation status and any exceptions, and review incident-response procedures in light of the reported exploitation and elapsed agency deadline.
  • Cybersecurity service providers may find demand for vulnerability assessment, patching, and SD-WAN security support, although no funded procurement or solicitation is identified in these signals.

Sources

State & Local Meeting

City of Panama City Town Hall 10032026

💰 Grants & Funding 🏛️ Physical Infrastructure 🏗️ Construction & Infrastructure

The City of Panama City’s Saturday town hall, held October 3, 2026 (the metadata timestamp falls on October 4 UTC), covered city services, infrastructure, and grant planning. The main procurement-related discussion was City Clerk-Treasurer Leslie Glace’s draft for a unified grant policy. The proposal would coordinate grant screening through a cross-department committee, use the city’s strategic plan and scoring criteria to prioritize applications, assess matching funds and future operating costs, and provide monthly public grant reports. The commission discussed developing a citywide strategic plan and reviewing or workshopping the draft, but took no vote and adopted no policy. Glace also cautioned against grant writers offering “free” services while seeking later selection through an RFQ or RFP, emphasizing city-led project selection and safeguards against undue influence.

Residents and officials discussed infrastructure and solid-waste issues, including a feasibility study for a more accessible transfer station and possible changes to bulk-waste collection; neither option was approved. Officials cited rough costs of about $250,000 to resurface a half-mile of road and $500–$800 per linear foot for combined water and sewer replacement, and described roughly $200–$300 million in recovery and infrastructure work funded through state revolving funds, FEMA, HUD, and other sources. Discussion also raised concerns about contamination and cost responsibility in a Beach Drive project whose bids had gone out, as well as the possibility of using FPL franchise negotiations to press communications companies to address cable and pole problems; no contract award, spending authorization, or franchise decision was made. Follow-ups included reviewing local utility conditions before paving, raising animal-control concerns with the county, and obtaining legal guidance on abandoned cables and poles.

Sources

Senate Sends Skills-Based Contracting Act to Trump

Federal News

Senate Sends Skills-Based Contracting Act to Trump

📜 Policy 🛡️ Defense & Military 💻 Information Technology

The Senate passed the Skills-Based Federal Contracting Act (H.R. 5235) by unanimous consent on September 30, 2026, and sent it to President Trump for consideration; the signals report that presidential action is still pending. If enacted, the bill would bar federal agencies from imposing minimum education credentials in contract solicitations unless a contracting officer provides a written, mission-based justification. It would not automatically remove every credential requirement, but could change how agencies justify solicitation criteria and how contractors present qualified staff. One report also cited more than 100 federal opportunities open for bid in South Carolina at the time of reporting, including activity relevant to the state’s defense, technology, and cybersecurity markets.

  • Agencies may need to document the mission-based rationale for education requirements in solicitations if the bill becomes law; contractors should distinguish justified requirements from blanket credential criteria when assessing bids.
  • Contractors can review how their proposals describe skills and experience alongside formal education, and evaluate whether broader candidate pools could support staffing for federal work.
  • The reported South Carolina opportunities provide local market context, but the signals do not identify individual solicitations or establish that the reported openings remain available.

Sources

Powerus Expands Defense Drone Portfolio

Federal News

Powerus Expands Defense Drone Portfolio

📋 Contracting Vehicles 🛡️ Defense & Military

Powerus completed its merger with Aureus Greenway Holdings on October 1, 2026, and began operating as a publicly traded company under the Powerus Corporation name. Its disclosed U.S. defense activity includes a U.S. Air Force Guardian-2 counter-drone IDIQ with a ceiling of up to $90 million through mid-2028 and a $2.5 million order for 1,500 FPV aircraft. The IDIQ ceiling is not guaranteed funding, and the signals do not announce a new solicitation or award. Powerus has also advanced to Phase 3 of the U.S. Army xTech Adaptive Strike Competition; a separate opinion article reports additional international activity, including a limited Pakistan order and a Middle East infrastructure-protection contract.

  • The Guardian-2 IDIQ represents potential future purchasing, but contractors should distinguish its ceiling from funded orders and actual deliveries when assessing market demand.
  • The 1,500-aircraft order and Powerus’s Phase 3 competition advancement provide discrete indicators of U.S. defense interest; suppliers and competitors can evaluate production capacity and potential subcontracting or supply-chain needs against these signals.
  • The reported Pakistan and Middle East activity is less detailed in the source signals. Companies assessing international opportunities should account for export-control, end-use, technology-transfer, and regional-security risks.

Sources

State & Local News

New Jersey Utilities Strengthen Water Cybersecurity

🔒 Cybersecurity 💻 Information Technology 🏗️ Construction & Infrastructure

On August 5, 2026, New Jersey reported cyber incidents affecting two unnamed municipal water systems. Operators switched to manual controls, maintained uninterrupted service, and strengthened access controls. Iran is a leading suspect, but attribution remains unconfirmed; officials are also assessing whether another state actor may have mimicked its tactics. The reported vulnerability in widely used utility software has a fix available, making patching and operational resilience relevant priorities for water utilities and their contractors.

  • Water utilities and contractors using the affected software should prioritize applying the available fix, reviewing exposure, and checking continuity plans, as described in the signal.
  • The incidents show the operational importance of manual-control capabilities and access-control measures for maintaining water service during cyber incidents.
  • NJCCIC, FBI, and CISA are among the relevant government cybersecurity entities identified in the signals; water-sector contractors supporting utilities may find cybersecurity and continuity services directly relevant.

Sources

FBI Investigates FBIJobs.gov Data Breach

Federal News

FBI Investigates FBIJobs.gov Data Breach

🔒 Cybersecurity ☁️ Cloud Services 🚨 Public Safety 💻 Information Technology 🛡️ Defense & Military

The FBI confirmed a cybersecurity incident involving its FBIJobs.gov recruitment portal and is investigating potential exposure of employee and applicant personal information with assistance from third-party providers. ShinyHunters claimed to have stolen data, with reports varying on the number of people and records involved; the FBI has not confirmed the breach’s full scope, the data’s authenticity, or the point of entry. One report linked the portal to Oracle PeopleSoft software, but that connection has not been established as the confirmed cause. Reporting also said the portal was offline for five days.

  • Federal agencies and contractors handling personnel data should review patch verification, access controls, network separation, and safeguards for sensitive records on public-facing systems.
  • The incident highlights procurement risks in third-party software and vendor-managed services: organizations may benefit from checking whether security responsibilities, vulnerability remediation, and incident reporting are clearly addressed in relevant agreements.
  • Because the alleged attack has also been associated with phishing and social engineering, security planning for government systems should account for user-targeted methods as well as software vulnerabilities. No specific solicitation or contract opportunity is identified in these signals.

Sources

Federal News

DHS Leases Philadelphia ICE Parking Spaces

🏛️ Physical Infrastructure 🏗️ Construction & Infrastructure

A new Department of Homeland Security agreement provides 16 parking spaces for ICE at a federally owned garage managed by the Philadelphia Parking Authority, beginning in October 2026 and continuing through at least September 2027. It follows a prior parking contract valued at $53,520 that expired at the end of September 2026. The new agreement’s value is not reported, and the available information identifies no solicitation or contractor competition; the renewal is drawing public scrutiny over the PPA’s arrangement with ICE.

  • Facility managers and contractors should distinguish this existing lease from a competitive procurement: no new solicitation or bid opportunity is identified.
  • The new agreement’s undisclosed value limits cost benchmarking against the prior $53,520 contract; its term and 16-space scope are specified.
  • Public scrutiny is a relevant consideration for organizations managing government facilities or providing services connected to the arrangement.

Sources