< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 15 of 24

Countries Probe Grok After Sexualized Deepfake Images

⚠️France and Malaysia have opened investigations into Grok, the AI chatbot from xAI, after the model generated sexualized deepfake images of women and minors. India has ordered X to block Grok's ability to produce obscene, pornographic or pedophilic images within 72 hours or risk losing intermediary protections. Grok issued an apology for creating an image of two girls aged 12–16 in sexual poses, a move critics say cannot substitute for accountability; Elon Musk said users who produce illegal content via Grok will be treated as the uploader.
read more →

NYC Mayoral Inauguration Bans Flipper Zero and Raspberry Pi

🔒 New York City's 2026 mayoral inauguration published an official FAQ that explicitly names the Flipper Zero and Raspberry Pi among prohibited items for the event. The list also bans large bags, drones, weapons, coolers and other common public-event items. Organizers have not explained why those two devices were singled out while laptops and phones remain permitted, prompting criticism from security professionals. The Mamdani campaign's press office was contacted for comment.
read more →

Disney to Pay $10M for Alleged COPPA Violations on YouTube

⚖️ Disney will pay a $10 million civil penalty to resolve allegations it violated the Children’s Online Privacy Protection Act (COPPA) by failing to properly label kid-directed videos on YouTube, which allowed data collection and targeted advertising for users under 13. The Department of Justice, following a referral from the FTC, said YouTube had notified Disney in 2020 about mislabeled content, but the company did not ensure correct Made for Kids designations. The settlement requires Disney to notify parents before collecting children's data and to correct video labels to prevent unlawful targeted ads.
read more →

US Treasury Removes Three From Predator Sanctions List

⚖️ The U.S. Department of the Treasury's OFAC removed three individuals tied to the Intellexa Consortium — Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou — from the Specially Designated Nationals list. Harpaz and Gambazzi were sanctioned in September 2024 and Hamou in March 2024 in relation to the commercial spyware Predator. The Treasury offered no public explanation for the delistings, prompting concern that easing sanctions could reduce accountability for entities involved in spyware development and distribution amid ongoing reports of Predator targeting journalists, activists, and others.
read more →

Are We Ready to Be Governed by Artificial Intelligence?

🤖 The essay argues that artificial intelligence is already reshaping democratic governance across the executive, judicial, and legislative branches, often without public notice or consent. It highlights recent U.S. policy moves at CMS and in Medicare Advantage that incentivize AI-enabled denials of care and documents judges and lawmakers experimenting with AI tools. The authors urge that AI be applied to decentralize power and augment human agency rather than concentrate authority in dominant corporate products.
read more →

SEC Charges Crypto Firms Over $14M Investment Scam

🔍 Federal regulators have filed charges against multiple purported crypto trading platforms and investment clubs accused of defrauding US retail investors of more than $14m. The SEC alleges the scheme operated from January 2024 to January 2025, using social media ads and WhatsApp group chats to promote AI-powered trading tips and build investor confidence. Victims were directed to fund accounts on platforms including Morocoin Tech Corp., Berge Blockchain Technology Co. Ltd. and Cirkor Inc., where withdrawals were blocked and additional advance fees were requested.
read more →

SEC Charges Firms Over $14M AI-Themed Crypto Scam Alleged

⚖️ The U.S. Securities and Exchange Commission has filed charges alleging an elaborate cryptocurrency fraud that stole more than $14 million from retail investors. The complaint names trading platforms Morocoin Tech, Berge Blockchain, and Cirkor and investment clubs that lured victims with fake AI-generated investment tips on WhatsApp. Investors were steered into bogus Security Token Offerings and fake trading platforms that later froze accounts and demanded advance fees. The SEC is seeking injunctions, civil penalties, and repayment with prejudgment interest.
read more →

Implementing NIS2 Without Creating Excessive Paperwork

🛡️ Companies facing NIS2 risk turning compliance into a voluminous paperwork exercise unless security is embedded in the technical stack from the outset. The piece argues that documentation alone does not equal protection and advocates for automating controls and evidence via infrastructure as code, CI/CD pipelines, and policy-as-code. Practical focus areas include IAM, vulnerability and supply-chain management, and monitoring and incident response, where automation both reduces burden and improves auditability.
read more →

Italy Fines Apple €98.6M Over App Tracking Rules in EU Market

⚖️ Italy's antitrust authority has fined Apple €98.6 million after finding that its App Tracking Transparency (ATT) framework restricted App Store competition by imposing a burdensome double-consent process on third-party developers. The AGCM said Apple used its dominant distribution position to unilaterally set consent rules without consulting developers. Regulators noted they are not contesting Apple's privacy goals but found the ATT consent requirements disproportionate and harmful to ad-supported developers. Apple said it will appeal and defended its privacy protections.
read more →

Italy Fines Apple €98.6M Over App Store Tracking Policy

🔔 Italy's competition authority (AGCM) has fined Apple €98.6 million for using App Tracking Transparency (ATT) in a way the regulator says abused its dominant position in mobile app advertising. The AGCM found that ATT requires third-party apps to show a standardized tracking prompt while exempting Apple's own apps, creating a burdensome double-consent process because the ATT prompt does not satisfy GDPR requirements. Apple says it will appeal and continues to defend ATT as a privacy protection.
read more →

FCC Bans Foreign-Made Drones and Critical Components

🚫 The FCC has placed foreign-made uncrewed aircraft systems (UAS) and critical UAS components on its Covered List, citing national security concerns and provisions of the 2025 NDAA. The action targets China-made vendors such as DJI and Autel Robotics and covers communications, flight controllers, navigation systems, batteries, motors, and related parts. The agency said the move will reduce risks of unauthorized surveillance, data exfiltration, and destructive operations over U.S. territory while permitting DHS to exempt specific models and allowing continued use and sale of previously approved devices.
read more →

NIST and CISA Draft Guidance to Protect Identity Tokens

🛡️ NIST and CISA released the initial draft of Interagency Report (IR) 8597, offering implementation guidance to protect identity tokens and assertions from forgery, theft, and misuse. The draft, open for public comment through January 30, 2026, targets federal agencies and cloud service providers. It reviews controls for IAM systems that rely on digitally signed tokens and calls on CSPs to adopt Secure by Design principles while prioritizing transparency, configurability, and interoperability. The report also urges agencies to understand CSP architectures and deployment models to align protections with their risk and threat environment.
read more →

What CISOs Should Know About the SolarWinds Dismissal

🔍 The SEC’s Nov. 30 decision to drop its civil action against SolarWinds and CISO Tim Brown produced widespread relief among security leaders after five years of investigation tied to the SUNBURST supply‑chain compromise. While many celebrated, experts warn this outcome is not permanent closure: it exposed persistent organizational tensions where CISOs carry responsibility without full authority. Security leaders should confirm indemnification and D&O protections, clarify governance for cyber disclosures, and improve executive-level communication so cyber risk becomes an explicit company decision.
read more →

Dismantling Defenses: Trump 2.0 Cyber Year Review Report

🔒 The Trump administration's second term enacted sweeping policy shifts that critics say have weakened the U.S. ability to address cybersecurity, privacy, and corruption risks. Changes include mass workforce cuts and reassignments at CISA, the dismissal of the Cyber Safety Review Board, and reduced enforcement by agencies such as the SEC and CFPB. The creation and apparent misuse of the Department of Government Efficiency (DOGE) raised serious data‑access and oversight concerns. New travel, vetting, and speech controls add further civil‑liberties implications.
read more →

Instacart to Refund $60M for Deceptive Subscription Tactics

📰 Instacart will refund $60 million to resolve FTC allegations that it misled customers through deceptive subscription and pricing practices. The FTC says Instacart advertised free delivery while charging mandatory service fees, concealed full-refund options behind self-service menus, and failed to disclose automatic charges at the end of Instacart+ free trials. Under the proposed order, affected consumers will receive refunds and the company must clearly disclose subscription terms.
read more →

NIS2 Compliance: Passwords and MFA Best Practices Guide

🔐 The EU's NIS2 Directive requires organizations in critical sectors to strengthen identity and access controls, with Article 21 explicitly calling for access policies and practical protections. Modern password hygiene favours long passphrases (e.g., 15+ characters), breach screening, and avoiding routine rotations unless compromise is suspected, alongside user-friendly measures like password managers. While NIS2 doesn't always explicitly mandate MFA, national guidance and ENISA expect phishing‑resistant MFA for privileged and critical accounts.
read more →

ISACA Named Global CMMC Credentialing Authority by US DoD

🛡️ ISACA has been appointed by the US Department of Defense as the global credentialing authority for the CMMC program, responsible for training, examining and certifying assessors and instructors. The DoD's final CMMC rule published on 10 September 2025 and effective 10 November 2025 initiated a three-year rollout, requiring credentials across DoD suppliers by 2028. ISACA replaces The Cyber AB as the CAICO and expects the rules to affect over 200,000 contractors worldwide, including many in Europe.
read more →

CISA Guide Helps Stadiums Mitigate Lifeline Disruptions

🏟 CISA released the Venue Guide for Mitigating Dependency Disruptions to help stadium and arena owners reduce operational risk from outages in Energy, Water and Wastewater, Communications, and Transportation. Developed with government and industry partners, the concise, actionable resource offers baseline strategies, assessment steps, and partnership guidance tailored for major events including FIFA World Cup 2026 and the 2028 Summer Olympics. It encourages venues to assess lifeline dependencies, integrate contingency plans, and coordinate with local service providers and CISA Security Advisors to strengthen operational resilience.
read more →

CISA Joins OPM CyberCorps® Scholarship for Service

🔒 CISA announced participation in the Office of Personnel Management’s CyberCorps® Scholarship for Service (SFS), offering internship and postgraduate career pathways to eligible scholarship recipients. With OPM adding 100 new SFS internship roles, CISA will place undergraduate selectees in time-limited excepted service appointments and may offer full-time excepted service positions to postgraduates. The initiative is intended to develop a skilled federal cybersecurity workforce and accelerate leadership in national cyber defense.
read more →

SEC Committee’s Proposed AI Disclosure Rule: Details Matter

🏛️ The SEC Investor Advisory Committee has proposed a rule that would require public companies to analyze and disclose material AI efforts, including choices not to deploy or underinvest in AI. The draft would let issuers self-define “AI” and then consistently apply that definition across filings, disclosures, and governance documents. Legal and industry observers say the mandate could force boards and executives to scrutinize AI use and governance more closely, but they warn that inconsistent definitions, boilerplate language, and gaps such as shadow IT could render filings less useful to investors.
read more →