< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles · page 4 of 20

Palo Alto Networks PBMM Assessment Expands Cloud Coverage

🔒 Palo Alto Networks announced successful completion of a Cloud Medium security assessment by the Canadian Centre for Cyber Security, expanding PBMM coverage across Cortex®, Cortex Cloud and Strata. The assessment validates these cloud services for Protected B / Medium Integrity / Medium Availability environments, enabling organizations handling sensitive Canadian data to use a unified, AI-driven security architecture while maintaining compliance and operational resilience. This milestone highlights PBMM's growing relevance beyond government into critical infrastructure and private sector organizations.
read more →

South Korea levies record fine after Coupang breach

🔒 The Personal Information Protection Commission (PIPC) fined e-commerce firm Coupang 624.6 billion won (~$409M) after a major data breach that exposed about 37.55 million people’s information. A subsidiary, Coupang Fulfillment Service, was also fined 248 million won for unlawful handling of personal and sensitive data. Investigators cited poor authentication key management, inadequate access controls, delayed breach disclosure, interference with the data protection officer’s independence, and obstruction of the probe.
read more →

CISA Directive Pushes Risk-Based, Contextual Patching

🔒 CISA issued Binding Operational Directive 26-04 to prioritize vulnerabilities by contextual risk rather than CVSS alone. The directive uses four factors — internet exposure, KEV listing, exploit automation, and post-exploitation impact — to set dynamic remediation timelines, including a three-day requirement for the highest-risk cases. The guidance aims to help agencies focus scarce resources on flaws most likely to be exploited amid faster discovery driven by AI.
read more →

White House EO Aligns AI Policy with Cybersecurity

🔒 The White House Executive Order on advanced AI seeks practical public–private coordination to address AI-driven cyber risks while preserving innovation. It prioritizes voluntary model assessments, improved federal defenses, faster vulnerability discovery and remediation, and expanded cybersecurity talent. Successful implementation will hinge on operationalizing AI-assisted defense, translating insights into timely guidance and mitigations, and supporting resource-constrained critical infrastructure operators.
read more →

IG Report Criticizes NIST Over NVD Backlog

🔍 A U.S. Commerce Department inspector general report faults NIST for management and strategy shortcomings that contributed to a growing backlog in the National Vulnerability Database (NVD). The report cites duplicated effort with CISA, insufficient communication, and inconsistent severity scoring as key issues, while NIST points to budget cuts and disputed the report’s tone. Industry experts say the backlog reflects broader funding and process failures and warn that AI-driven increases in vulnerability discovery demand rethinking NVD processes.
read more →

OpenAI Proposes Federal Evaluations for Frontier AI

🔎 OpenAI proposed mandatory federal evaluations for the most capable AI models before public release while arguing regulators should not have authority to approve or block deployments. The company urged pre-release assessments by the Center for AI Standards and Innovation (CAISI) alongside audits, transparency reports, incident reporting, and whistleblower protections. OpenAI framed this approach as a middle ground that enhances government visibility and preserves developer responsibility for release decisions.
read more →

Police dismantle fake ID marketplace aiding smugglers

🔍 French and Spanish authorities dismantled an online marketplace selling counterfeit identity documents used by migrant smuggling rings across the EU. On May 27, police arrested a suspect in Alicante and seized document-production equipment and about 800 fake European IDs from an apartment rented under a false name. Europol said the platform provided forged physical and digital documents to facilitate border evasion, fraudulent residence claims, and secondary movements within the Schengen Area.
read more →

US Sanctions Nobitex Exchange Over Ties to IRGC

🛡️ The U.S. Treasury's OFAC has sanctioned Nobitex, Iran's largest crypto exchange, accusing it of facilitating payments for terrorist activities and sanctions evasion. The designation names several Nobitex executives and founders and is part of the broader "Economic Fury" campaign that also targets Wallex, Bitpin, and Ramzinex. OFAC cites Chainalysis data showing Iran's crypto ecosystem received nearly $7.8 billion in 2025, with IRGC-linked addresses receiving over half of Q4 inflows. Sanctions freeze U.S.-jurisdiction assets and bar U.S. persons from transacting with the designated entities.
read more →

Police dismantle nine groups in illegal streaming crackdown

🔎 European and international law enforcement agencies concluded a seven-month operation that dismantled nine organised crime groups and arrested 29 suspects tied to illegal streaming services. Coordinated by Bulgaria with Europol support and involving 13 countries, the action identified over 18,000 IPs, 4,370 piracy-linked domains, and removed more than 27,000 illegal streaming URLs. Authorities conducted 148 searches, referred 59 cases for prosecution, and continue work on dozens of related investigations.
read more →

Law enforcement seizes hosting tied to Iranian campaigns

🔎 On May 22, 2026, Dutch investigators seized roughly 800 servers from WorkTitans B.V., a hosting provider that allegedly operated as a successor to a sanctioned ISP. The seized infrastructure supported multiple Iranian cyber espionage groups—MuddyWater, Agrius (UNC2428), and Nimbus Manticore—each using the provider for command-and-control, lure hosting, and scanning. This takedown disrupted active operations and highlights the need to evaluate hosting environments, ASNs, and passive DNS history rather than relying solely on individual IP flags.
read more →

California AG Sues 23andMe Over 2023 Data Breach

🔒 Attorney General Rob Bonta has sued 23andMe (now Chrome Holding Co.) for failing to protect sensitive genetic and personal information after a 2023 breach exposed data of nearly 7 million customers, including 855,541 Californians. The suit alleges inadequate safeguards against credential-stuffing, missed detection opportunities, a coding error in the DNA Relatives feature, and misleading public statements about security. It seeks injunctions and statutory penalties under multiple California laws, including CCPA and the California Genetic Information Privacy Act.
read more →

GDPR’s legacy and the coming AI regulatory battles

📰 Over eight years GDPR set global data-protection norms, notably the 72-hour breach notification standard, but nearly 40% of announced EU fines by value are annulled or under appeal. Experts say large tech firms contesting fines isn’t surprising and that rulings provide practical guidance for compliance teams. As the EU’s AI Act and proposed GDPR reforms arrive, regulators must shore up procedural robustness while organisations adapt governance to evolving AI risks.
read more →

Dutch police arrest suspect in Ajax football hack

🔒 The Dutch National Police arrested a 35-year-old man from Buren suspected of multiple unlawful intrusions into AFC Ajax's computer systems earlier this year. The intrusions allowed access to data belonging to a few hundred individuals, modification of fewer than 20 stadium bans, and reassignment of purchased tickets. Ajax patched the exploited vulnerabilities, reported the breach to the Dutch Data Protection Authority and police, and the investigation remains ongoing.
read more →

Dutch raid seizes servers, arrests hosting co-owners

🛡️ Dutch authorities arrested two co-owners of related hosting companies and seized over 800 servers on May 18, alleging they operated infrastructure used by Russia for cyberattacks and influence operations targeting the EU. The arrests follow investigative reporting that linked MIRhosting and WorkTitans to Stark Industries, an ISP sanctioned by the EU for facilitating DDoS, proxy, and anonymity services tied to Russia-backed actors. Officials searched businesses and data centers and charged the suspects with violating sanctions law by making economic resources available to sanctioned entities. Both suspects deny wrongdoing and one company says it has paused services to the implicated client pending internal review.
read more →

European takedown targets VPN linked to crime

🛡️ European investigators dismantled First VPN in a joint operation led by France and the Netherlands, assisted by Europol and Eurojust. The service, widely promoted in Russia, was used by criminals for ransomware, fraud, and data theft to conceal identities and infrastructure. While the takedown is seen as warranted, experts warn that broad restrictions on VPNs risk harming legitimate privacy and business uses and could face legal challenges.
read more →

UK Regulators Warn Financial Firms on Frontier AI Risks

⚠️ On May 15 the UK government, the Financial Conduct Authority and the Bank of England issued a joint warning about cybersecurity threats from frontier AI. They noted models can outperform skilled practitioners at greater speed, scale and lower cost, amplifying risks to firms, customers and financial stability. The statement urges firms to strengthen governance, vulnerability management, third-party controls, protection and response capabilities and points to NCSC resources and prior resilience guidance.
read more →

UK Cyber Sector Revenue Rises as Cyber Resilience Grows

📈The UK cybersecurity sector generated £14.7bn in revenue last year and contributed £9.1bn in gross value added, the government reported on 13 May. Employment rose to nearly 70,000 and the number of firms climbed to 2,603, with AI-focused cybersecurity vendors growing sharply. The government unveiled the Cyber Resilience Pledge and plans legislation via the Cyber Security and Resilience Bill to tighten standards. Experts warn that advances in AI increase risks and call for stronger, harmonized incident reporting and defences.
read more →

US Committee Seeks Instructure Testimony on Canvas Breach

📢 The U.S. House Committee on Homeland Security has requested Instructure CEO Steve Daly to testify about two recent ShinyHunters attacks that breached the Canvas learning platform and disrupted final exams. The incidents exposed student and staff data and defaced login portals, impacting institutions nationwide. The committee seeks details on containment, notification, coordination with federal agencies, and raises concerns about Instructure’s incident response.
read more →

UK Fines Water Supplier £963,900 After Data Breach

🔒 The ICO fined South Staffordshire Water Plc and parent South Staffordshire Plc £963,900 after a cyberattack that exposed the personal data of 663,887 customers and employees. The incident, traced back to September 2020 and active mainly between May and July 2022, began with a phishing intrusion that enabled malware to remain undetected for 20 months. The regulator identified multiple security failures, including insufficient privilege controls, monitoring that covered only about 5% of the IT estate, use of obsolete software and poor vulnerability and patch management.
read more →

GM Agrees to $12.75M California Settlement Over Data Sale

⚖️ California Attorney General Rob Bonta reached a $12.75 million settlement with General Motors after an investigation found GM collected and sold Californians’ driving and location data through OnStar and the Smart Driver program without proper notice or consent. The probe identified transfers to brokers Verisk and LexisNexis between 2020–2024. In addition to a record civil penalty, GM must stop sales for five years, delete retained data absent consent, require brokers to purge received records, and bolster privacy compliance with periodic assessments.
read more →