< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles · page 5 of 20

FCC Extends Deadline for Security Patches to 2029 Nationwide

⚠️ The FCC has extended the deadline for suppliers of banned foreign-made consumer routers to deliver security updates to US customers until at least 1 January 2029. The March 2026 import and sale ban put these devices on the FCC’s covered list, with limited exceptions for devices conditionally approved by the DoD or DHS. The extension, announced by the Commission’s Office of Engineering and Technology on 8 May, permits only software and firmware updates that mitigate harm and maintain functionality, not the addition of new features, and it also covers foreign-made drone systems and critical components.
read more →

CISA Orders Federal Agencies to Patch Ivanti EPMM Zero-Day

⚠ CISA has ordered U.S. federal agencies to patch a high-severity vulnerability in Ivanti Endpoint Manager Mobile within four days after the flaw was observed exploited as a zero-day (CVE-2026-6973). Ivanti published updates (12.6.1.1, 12.7.0.1, 12.8.0.1) and urged customers to review and rotate Admin credentials. The issue requires administrative authentication, affects only on-prem EPMM appliances, and Shadowserver reports over 800 exposed instances online.
read more →

Former Contractor Convicted for Deleting Federal Databases

🔒 A jury found former federal contractor Sohaib Akhter guilty of conspiring to destroy dozens of government databases after being fired during a remote meeting in February 2025. Prosecutors say Akhter and his twin brother Muneeb ran write-protect commands and deleted roughly 96 databases hosting sensitive investigative and FOIA records for more than 45 agencies. They allegedly sought to hide their activity — even consulting an AI assistant about clearing system logs — and destroyed evidence; sentencing is set for September 9, 2026.
read more →

NOYB Sues LinkedIn Over Paywalled 'Who Viewed' Data

⚖️ NOYB has filed a complaint in an Austrian court arguing that LinkedIn’s paywalled "Who’s Viewed Your Profile" feature violates GDPR Article 15 by denying EU users free access to profile-visitor data. The group says LinkedIn refuses Data Subject Access Requests (DSARs) from non-paying users while providing the same information to Premium subscribers. LinkedIn rejects the claim, saying it discloses the information via its Privacy Policy and that users can control visibility settings. NOYB seeks regulatory enforcement and potential fines to stop what it calls illegal monetization of access rights.
read more →

ICE's Smart Glasses Program Raises Surveillance Concerns

🔎 ICE is developing prototype smart glasses that pair wearable cameras with on-device facial recognition and real-time queries to immigration, criminal, and watchlist databases. Reporting by Ken Klippenstein, linked in Bruce Schneier's post, describes efforts to integrate hardware and software for in-field identification and instant database matches. The program raises immediate concerns about accuracy, bias, data quality, oversight, and civil liberties if deployed without transparent safeguards.
read more →

Ten Years of GDPR: Achievements, Gaps, and Next Steps

🔒 Ten years after the EU adopted the General Data Protection Regulation (GDPR), experts say it fundamentally reshaped corporate privacy culture but left important gaps. Analysts credit the GDPR with embedding privacy into daily operations, raising standards, and creating accountability by forcing organizations to know and document their processing. Yet enforcement inconsistencies, international transfer disputes, widespread consent fatigue and the rise of generative AI expose legal and practical tensions that require clarification and coordination with newer digital rules.
read more →

FTC to Bar Kochava From Selling Americans' Location Data

🔒 The Federal Trade Commission will ban data broker Kochava and its subsidiary Collective Data Solutions (CDS) from selling precise geolocation data without consumers' affirmative express consent as part of a settlement stemming from an August 2022 suit. The FTC alleged Kochava supplied paid clients — via an AWS Marketplace feed — with high-volume raw latitude/longitude transactions that enabled tracking to sensitive sites. Under the proposed court order, sales or transfers of precise location data are prohibited unless consumers directly request a service and explicitly consent; the companies must also implement a sensitive location program, supplier assessments, consent withdrawal and disclosure mechanisms, incident reporting to the FTC, and retention/deletion schedules.
read more →

Karakurt Negotiator Sentenced to 8.5 Years in U.S. Prison

🔒Deniss Zolotarjovs, a Latvian national extradited to the United States, was sentenced to 8.5 years after pleading guilty to conspiracy to commit wire fraud and money laundering for his role as a negotiator in the Karakurt extortion operation. Prosecutors say he handled "cold case" extortions, researching targets and using stolen personal and health data to pressure victims. He is the first Karakurt member sentenced in the U.S.
read more →

15-Year-Old Detained Over ANTS Data Breach in France

🔒 French authorities have detained a 15-year-old on suspicion of selling data stolen from France Titres (ANTS) after the agency detected suspicious activity on April 13 and alerted prosecutors on April 16. Investigators say a user going by the alias breach3d offered between 12 and 18 million records on a cybercriminal forum; ANTS later reported 11.7 million impacted accounts. Exposed fields include full names, email addresses, dates of birth, postal addresses, and phone numbers, although ANTS said the stolen data could not be used for unauthorized access. Prosecutors are seeking formal charges and judicial supervision; the alleged offenses carry up to seven years’ imprisonment and a €300,000 fine.
read more →

Regulator Warns: Frontier AI Models Heighten Bank Cyber Risk

⚠ APRA warns that frontier AI models such as Claude Mythos pose a rapidly evolving cyber risk to the banking sector by enabling faster, more automated discovery of vulnerabilities. The regulator found governance often treats AI as “just another technology,” missing distinctive features like predictive behavior, adaptability, bias and data risks, and urged firms to accelerate vulnerability identification and remediation. APRA called for robust security testing of AI‑generated code and deeper assessment of major AI platforms to avoid attackers outpacing current patch cycles.
read more →

Romanian Leader of Swatting Ring Sentenced to 4 Years

🚨 A Romanian national, Thomasz Szabo, was sentenced to four years in U.S. federal prison after pleading guilty to conspiracy and threats involving explosives. Extradited from Romania in November 2024, Szabo led an online swatting community that organized bomb threats and swatting calls beginning in late 2020 and targeting more than 75 public officials, journalists, and religious institutions. The court also ordered three years of supervised release.
read more →

UK Education Sector Sees Sharp Rise in Cyber Breaches

📚 The UK public education sector experienced a marked increase in reported cyber breaches in the Cyber Security Breaches Survey 2025/2026, published on 30 April by the Department for Science, Innovation and Technology (DSIT) and the Home Office. The report's Education Annex records rises across primary, secondary, further and higher education — notably higher education breaches climbed from 91% to 98% and secondary schools from 60% to 73%. While national breach levels for businesses and charities remained broadly stable, the education surge, falling small-business cyber hygiene and the low uptake of Cyber Essentials are being flagged as significant resilience concerns.
read more →

Check Point Achieves GovRAMP Authorization for Government

🛡️ Check Point has earned GovRAMP Authorization for the Check Point Infinity Platform for Government, extending its cloud security offering to U.S. federal, state, local, and tribal agencies. This follows its 2025 FedRAMP Authorization and is backed by prevention-first capabilities that ranked #1 in Miercom’s 2026 assessment. The authorization provides a vetted, consistent cybersecurity framework to support public-sector procurement and deployment. Organizations can expect unified protection with high effectiveness against phishing and AI-powered malware.
read more →

Authorities Dismantle Nine Crypto Scam Centers, 276 Arrests

🚨 Dubai-led authorities shut down nine cryptocurrency investment fraud centers and arrested 276 suspects in a coordinated international operation. Investigators said the networks ran pig-butchering (romance baiting) schemes that built trust with victims and pushed them to fake crypto platforms where funds were quickly seized and laundered. Several individuals now face wire fraud and money-laundering charges, and U.S. agencies linked millions in losses through FBI IC3 complaints.
read more →

Europol Busts Albanian Call Centres Behind €50m Scam

🔎 Europol announced arrests and seizures after a two‑year probe into professionalised Albanian scam call centres that ran an investment fraud operation estimated to have cost victims at least €50m. Authorities arrested 10 suspects and searched three call centres and nine homes, seizing nearly €900,000, 443 computers, 238 mobile phones and multiple storage devices. Victims were lured via misleading ads and pressured by retention agents posing as investment advisors.
read more →

Police dismantle €50M crypto investment fraud ring

🔍 Austrian and Albanian authorities, supported by Europol and Eurojust, dismantled a large-scale cryptocurrency investment fraud operation responsible for estimated losses of €50 million. The coordinated action, which began in June 2023 and culminated in raids on April 17, resulted in 10 arrests and seizures of cash, hundreds of computers and mobile devices for forensic analysis. The ring operated professional call centres with up to 450 employees, using fake trading platforms and "retention agents" who used remote-access tools and psychological pressure to extract funds and later re-scam victims with bogus recovery fees.
read more →

French police arrest HexDex for about 100 data breaches

🔒 French authorities have arrested a 21-year-old who used the alias 'HexDex', suspected of carrying out around 100 data breaches since late 2025. Prosecutors say he was preparing another data dump when detained and has been charged with six offences, including aggravators for organised gang activity. Alleged victims include the Ministry of National Education, where the Compas trainee-teacher system exposed roughly 243,000 employee records, as well as registries, unions, cultural institutions, sports federations, food banks and hotel chains. Stolen files were redistributed on criminal marketplaces; his account page now displays a message saying it was seized.
read more →

House GOP Privacy Bills Challenge Enterprise Data Practices

📜 The House Republican proposals — the SECURE Data Act and the GUARD Financial Data Act — would establish federal privacy standards that broadly preempt stronger state laws while limiting private lawsuits and centralizing enforcement with the FTC and state attorneys general. The bills emphasize data minimization, controller-processor obligations, a federal data broker registry, and new limits on automated profiling and teen data. Critics warn the measures could weaken existing protections, impose heavy operational burdens on CIOs and CISOs, and force vendors and legal teams to rework procurement, retention, and AI training practices.
read more →

Scattered Spider Co-conspirator Pleads Guilty in US Case

🔒 Tyler Buchanan has pleaded guilty in a Florida court to conspiring with others to hack company computer systems and steal at least $8 million in virtual currency. He faces sentencing later this year. Buchanan is tied to the notorious Scattered Spider group, which has used SMS phishing and colleague impersonation to target employees. Security leaders are urged to reinforce defenses and train staff against social engineering.
read more →

DORA and Operational Resilience: Credential Controls

🔐 DORA's Article 9 makes credential management a binding financial risk control for EU financial entities, requiring least-privilege access, phishing‑resistant FIDO2/WebAuthn authentication, and cryptographic key protection. The regulation extends to third-party providers and mandates evidenceable controls. Organisations must deploy vaulting, JIT access, and continuous monitoring to reduce dwell time and meet supervisory expectations.
read more →