< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles

TikTok to Pay $400M in U.S. Child Privacy Settlement

📰 The U.S. Department of Justice announced that ByteDance-owned TikTok agreed to pay $400 million to resolve a 2024 lawsuit alleging violations of child privacy laws. The settlement includes $300 million payable immediately and $100 million contingent on vacating a prior consent decree tied to Musical.ly. The complaint, filed with the FTC, accused TikTok of enabling under-13 accounts and improperly collecting data in "Kids Mode," claims the company has disputed as largely tied to past practices. The DoJ called the recovery among the largest under COPPA and noted TikTok has since strengthened age controls and parental oversight.
read more →

ICO urges police to tighten facial recognition governance

🔎 The UK Information Commissioner’s Office (ICO) has called on police forces using live facial recognition (LFR) to strengthen data governance and align practice with legal requirements. Emily Keaney, deputy commissioner for regulatory policy, highlighted audits showing inconsistent compliance across five forces and urged improvements in oversight, record-keeping, training and accuracy checks. The ICO noted forces are engaging with the findings and stressed robust protections are essential to maintain public trust.
read more →

Canadian Hacker Pleads Guilty in Snowflake Extortion Case

🛡️ Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting more than 165 Snowflake customers and stealing AT&T call and text metadata for over 100 million users. Authorities say the conspirators used stolen credentials where multi-factor authentication was not enforced, exfiltrated terabytes of sensitive data, and extorted victims for ransom. Moucka admitted to threatening officials and security researchers and faces significant prison time at his October sentencing.
read more →

Cybersecurity needs a new operating model for AI era

🔒 The article argues that AI has compressed the timeline between exposure and exploitation, undermining a longstanding security operating model built for human-speed attackers. The ECB’s July 7, 2026 supervisory letter requires major banks to submit AI-focused cybersecurity action plans by Oct. 31, 2026, signaling that AI-driven threats are a long-term, operational reality. Regulators and agencies now emphasize risk-based prioritization, evidence-based decisions, and accelerated remediation to maintain resilience.
read more →

Ransom Cartel founder sentenced to 16 years

📰 Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison after pleading to conspiracy, wire fraud, and aggravated identity theft. US prosecutors say he recruited affiliates, supplied stolen credentials and encryption tools, and ran a portal to coordinate attacks and split ransom payments. The scheme targeted at least 18 companies worldwide and sought over $5.2 million in extortion.
read more →

UK police national legal database breached

🔒 The Police National Legal Database (PNLD), managed by West Yorkshire Police, has suffered a data security incident identified on July 26 and disclosed on August 3. Information including names, organizations and work email addresses of police officers, criminal justice professionals and partners was published on the dark web, though there is no evidence of compromised passwords. The breach also affected the Ask the Police service, and PNLD is working with cybersecurity specialists and the National Crime Agency to investigate.
read more →

KT fined for security failures after customer fraud

🔒 South Korea’s largest telco, KT, was fined after security lapses allowed attackers to exploit a stolen femtocell and conduct fraudulent micropayments. The PIPC found that long-lived certificates, unrestricted femtocell IP access and weak internal controls enabled the intrusion, exposing PII for 16,647 users and defrauding 368 customers. Investigators also discovered malware infections on internal servers and criticized KT for delayed reporting and log deletions.
read more →

South Korea fines KT over prolonged customer data breach

🔒 South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion ($39 million) after an internal network compromise persisted nearly 11 months from October 2024 to September 2025. The breach exposed personal data of 16,647 subscribers and enabled fraudulent micropayments for at least 368 customers. Investigators found a lost femtocell with a valid certificate used to create a rogue base station, enabling interception of IMSI, IMEI, phone numbers, and authentication codes. PIPC also discovered BPFDoor malware on 38 IT servers dating to March 2024 and criticized KT for inadequate controls, evidence deletion, and delayed reporting, ordering stronger security and governance measures.
read more →

FCC Blocks New Foreign-Produced Robots and Inverters

🔒 The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally blocking new models from receiving US equipment authorization for import, marketing, or sale. Previously authorized units and existing owners are unaffected, and federal purchases remain permitted. A waiver allows security and compatibility software updates through at least January 1, 2029, while manufacturers may seek Conditional Approval by January 1, 2028.
read more →

AWS publishes updated IRAP Phase 1a report for Australia

🔒 Amazon Web Services (AWS) announced the release of the Information Security Registered Assessors Program (IRAP) Phase 1a full assessment report, now available via AWS Artifact. The assessment, completed by an ASD-certified IRAP assessor in June 2026, adds four services to the PROTECTED-level scope, bringing the total to 167 assessed services. AWS also released an IRAP documentation pack, updated consumer guidance, and Reference Architectures for ISM PROTECTED workloads to help Australian customers plan and assess cloud risk.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →

Europol flags thousands of URLs linked to The Com

🔎 Europol coordinated multi-week Referral Action Days in June–July 2026, identifying 4,340 URLs tied to "The Com," a diffuse network of nihilistic violent extremist groups. Investigators from nine EU countries participated to disrupt online propaganda and generate investigative leads, focusing on content that includes violent imagery, self-harm encouragement, and child sexual abuse material. The operation, run by the EU IRU and Spain's CITCO, supports the European Commission's ProtectEU agenda and builds on earlier Project Compass efforts.
read more →

Practical Roadmap for Post‑Quantum Cryptography Readiness

🔒 The shift to Post‑Quantum Cryptography (PQC) is now a practical priority for security, architecture, procurement, and compliance teams. The White House EO sets firm federal deadlines for PQC adoption in 2030–2031 and prompts broader supply‑chain impacts, making 2026–2027 critical planning years. Organizations should inventory cryptographic dependencies, assess vendor readiness, prioritize systems vulnerable to “harvest now, decrypt later” threats, and build crypto‑agility. Fortinet tools like FortiManager, FortiAnalyzer, and FortiGate hardware acceleration support discovery, risk measurement, and targeted protection to help operationalize PQC migration.
read more →

EU fines Google €890M for Digital Markets Act breaches

📰 The European Commission fined Google €890 million for violating the EU's Digital Markets Act, finding the company favoured its own services in Google Search and restricted app developers on Google Play. Google was designated a DMA gatekeeper in September 2023 and investigated from March 2024. The fine splits into €460 million for search favouritism and €430 million for app store steering, and Google must comply within 60 days or face further penalties.
read more →

Microsoft Ends Exchange 2016/2019 ESU Support in October

📢 Microsoft confirmed it will stop shipping security updates for Exchange Server 2016 and Exchange Server 2019 under the Extended Security Update (ESU) program in October 2026. The announcement follows a six-month extension granted in April 2026 and reiterates there will be no further extensions. Administrators are urged to upgrade to Exchange Server Subscription Edition or migrate to Exchange Online.
read more →

EU orders Google to open Android to rival AI agents

📰 The European Commission issued two rulings under the Digital Markets Act requiring Google to open Android to third-party AI assistants and to share search data with rival engines. Google warned the measures could harm user privacy and security, while EU regulators said the steps are needed to ensure fair competition. Security leaders caution CISOs to reassess device and data governance as agents gain system-level reach.
read more →

23andMe Agrees $18M Settlement and New Security Terms

🔒 A coalition of 42 US attorneys general has secured an $18m settlement with genetic testing firm 23andMe following the 2023 credential-stuffing breach that exposed profile and ancestry data for over six million individuals. The settlement, led by New York Attorney General Letitia James, includes more than $705,000 payable to New York and imposes new data protection requirements on the company and its successor. As 23andMe entered bankruptcy in March 2025, its customer data was transferred to TTAM Research; the agreement mandates risk analysis, an advisory board on data security, and continued consumer deletion rights to safeguard that information.
read more →

EU orders Google to open Android sensors to rivals

🔎 The European Commission has ordered Google to grant rival AI assistants the same access to Android sensors and system features that Gemini enjoys, including camera, microphone, screen contents, background controls, and wake-word activation. Google must deliver the changes in the next major release, Android 18, or by 1 August 2027, with some concurrent hotword features delayed until Android 19. The decision, adopted under the Digital Markets Act on 16 July, also requires Google to provide anonymised Search query datasets to competing search engines and AI chatbots under strict safeguards and cost-based fees. The measures define a mix of restricted features requiring certification and open features available to all third-party apps, set up a Qualified AI Assistant Programme, and impose timelines and audit and anonymisation conditions.
read more →

US Charges Two for Laundering $43M in Investment Fraud

💼 U.S. prosecutors charged two New York residents, Zhuoying Chen and Haojie Zhang, for operating a money-laundering network that moved at least $43 million stolen in investment fraud schemes between 2020 and 2022. The indictment alleges they used roughly 45 shell companies and 140 bank accounts to funnel proceeds to China while coordinating a network of over a dozen associates. Authorities say the scams used social media and fake profiles to lure victims and show fabricated profits to induce further investments. If convicted of conspiracy to commit money laundering, both face up to 20 years in prison.
read more →

Regulating Corporate Responsibility for AI Privacy

🛡️ Daniel Solove argues in the Wall Street Journal that individual control over personal data is insufficient to protect privacy in the AI era. He urges shifting regulatory focus to hold companies accountable—similar to food and drug oversight—through measures like data minimization, fiduciary duties, and liability for negligent design. Solove also recommends liability for harmful algorithms and multi-stakeholder review of technologies to ensure safer outcomes.
read more →