< ciso
brief />
Tag Banner

All news with #regulatory action tag

407 articles · page 5 of 21

US asks Anthropic to block foreign access to Fable

🔒 Anthropic suspended access to its two most capable models, Fable 5 and Mythos 5, after receiving a US government export control directive on June 12 ordering it to block access by any foreign national. The order, citing national security, applies to foreign nationals inside and outside the United States and forced Anthropic to disable both models for all customers; other models such as Claude Opus 4.8 remain available. Anthropic says the directive followed a reported narrow jailbreak demo and is working to restore access while disputing the government's assessment.
read more →

U.S. Orders Anthropic to Suspend Claude Fable 5 Access

🔒 Anthropic said it will "abruptly disable" its latest models, Claude Fable 5 and Mythos 5, for all users after receiving a U.S. government directive to suspend access for foreign nationals due to national security concerns. The company said it believes the order reflects a "misunderstanding" and is working to restore access while noting other models remain available. Anthropic said a demonstrated narrow jailbreak identified minor, publicly discoverable vulnerabilities, and emphasized its safety classifiers and guardrails to limit misuse. The move follows findings that Mythos-class models can rapidly convert disclosed software flaws into working exploits, raising concerns about fast weaponization of vulnerabilities.
read more →

Maine Shuts Public Breach Portal After Hoax Filings

🔒 Maine has taken its public data breach reporting portal offline after fraudulent disclosures impersonating Discord and VRChat were published. The Attorney General's Office confirmed the reports were hoaxes and removed them, stating there is no evidence of actual breaches by the named companies. Public access to the database is temporarily disabled while the office reviews procedures; companies may still submit notices but the public must request disclosures directly.
read more →

Short lapse in Section 702 surveillance affects US monitoring

🔍 Congress failed to extend Section 702 of the Foreign Intelligence Surveillance Act, creating a short pause in warrantless monitoring of foreign communications. The extension vote was rejected, leaving surveillance put on hold until the next possible vote on June 28, and creating uncertainty about immediate intelligence collection practices. CISOs should note potential impacts on cross-border communications and legal challenges ahead.
read more →

Palo Alto Networks PBMM Assessment Expands Cloud Coverage

🔒 Palo Alto Networks announced successful completion of a Cloud Medium security assessment by the Canadian Centre for Cyber Security, expanding PBMM coverage across Cortex®, Cortex Cloud and Strata. The assessment validates these cloud services for Protected B / Medium Integrity / Medium Availability environments, enabling organizations handling sensitive Canadian data to use a unified, AI-driven security architecture while maintaining compliance and operational resilience. This milestone highlights PBMM's growing relevance beyond government into critical infrastructure and private sector organizations.
read more →

South Korea levies record fine after Coupang breach

🔒 The Personal Information Protection Commission (PIPC) fined e-commerce firm Coupang 624.6 billion won (~$409M) after a major data breach that exposed about 37.55 million people’s information. A subsidiary, Coupang Fulfillment Service, was also fined 248 million won for unlawful handling of personal and sensitive data. Investigators cited poor authentication key management, inadequate access controls, delayed breach disclosure, interference with the data protection officer’s independence, and obstruction of the probe.
read more →

CISA Directive Pushes Risk-Based, Contextual Patching

🔒 CISA issued Binding Operational Directive 26-04 to prioritize vulnerabilities by contextual risk rather than CVSS alone. The directive uses four factors — internet exposure, KEV listing, exploit automation, and post-exploitation impact — to set dynamic remediation timelines, including a three-day requirement for the highest-risk cases. The guidance aims to help agencies focus scarce resources on flaws most likely to be exploited amid faster discovery driven by AI.
read more →

White House EO Aligns AI Policy with Cybersecurity

🔒 The White House Executive Order on advanced AI seeks practical public–private coordination to address AI-driven cyber risks while preserving innovation. It prioritizes voluntary model assessments, improved federal defenses, faster vulnerability discovery and remediation, and expanded cybersecurity talent. Successful implementation will hinge on operationalizing AI-assisted defense, translating insights into timely guidance and mitigations, and supporting resource-constrained critical infrastructure operators.
read more →

IG Report Criticizes NIST Over NVD Backlog

🔍 A U.S. Commerce Department inspector general report faults NIST for management and strategy shortcomings that contributed to a growing backlog in the National Vulnerability Database (NVD). The report cites duplicated effort with CISA, insufficient communication, and inconsistent severity scoring as key issues, while NIST points to budget cuts and disputed the report’s tone. Industry experts say the backlog reflects broader funding and process failures and warn that AI-driven increases in vulnerability discovery demand rethinking NVD processes.
read more →

OpenAI Proposes Federal Evaluations for Frontier AI

🔎 OpenAI proposed mandatory federal evaluations for the most capable AI models before public release while arguing regulators should not have authority to approve or block deployments. The company urged pre-release assessments by the Center for AI Standards and Innovation (CAISI) alongside audits, transparency reports, incident reporting, and whistleblower protections. OpenAI framed this approach as a middle ground that enhances government visibility and preserves developer responsibility for release decisions.
read more →

Police dismantle fake ID marketplace aiding smugglers

🔍 French and Spanish authorities dismantled an online marketplace selling counterfeit identity documents used by migrant smuggling rings across the EU. On May 27, police arrested a suspect in Alicante and seized document-production equipment and about 800 fake European IDs from an apartment rented under a false name. Europol said the platform provided forged physical and digital documents to facilitate border evasion, fraudulent residence claims, and secondary movements within the Schengen Area.
read more →

US Sanctions Nobitex Exchange Over Ties to IRGC

🛡️ The U.S. Treasury's OFAC has sanctioned Nobitex, Iran's largest crypto exchange, accusing it of facilitating payments for terrorist activities and sanctions evasion. The designation names several Nobitex executives and founders and is part of the broader "Economic Fury" campaign that also targets Wallex, Bitpin, and Ramzinex. OFAC cites Chainalysis data showing Iran's crypto ecosystem received nearly $7.8 billion in 2025, with IRGC-linked addresses receiving over half of Q4 inflows. Sanctions freeze U.S.-jurisdiction assets and bar U.S. persons from transacting with the designated entities.
read more →

Police dismantle nine groups in illegal streaming crackdown

🔎 European and international law enforcement agencies concluded a seven-month operation that dismantled nine organised crime groups and arrested 29 suspects tied to illegal streaming services. Coordinated by Bulgaria with Europol support and involving 13 countries, the action identified over 18,000 IPs, 4,370 piracy-linked domains, and removed more than 27,000 illegal streaming URLs. Authorities conducted 148 searches, referred 59 cases for prosecution, and continue work on dozens of related investigations.
read more →

Law enforcement seizes hosting tied to Iranian campaigns

🔎 On May 22, 2026, Dutch investigators seized roughly 800 servers from WorkTitans B.V., a hosting provider that allegedly operated as a successor to a sanctioned ISP. The seized infrastructure supported multiple Iranian cyber espionage groups—MuddyWater, Agrius (UNC2428), and Nimbus Manticore—each using the provider for command-and-control, lure hosting, and scanning. This takedown disrupted active operations and highlights the need to evaluate hosting environments, ASNs, and passive DNS history rather than relying solely on individual IP flags.
read more →

California AG Sues 23andMe Over 2023 Data Breach

🔒 Attorney General Rob Bonta has sued 23andMe (now Chrome Holding Co.) for failing to protect sensitive genetic and personal information after a 2023 breach exposed data of nearly 7 million customers, including 855,541 Californians. The suit alleges inadequate safeguards against credential-stuffing, missed detection opportunities, a coding error in the DNA Relatives feature, and misleading public statements about security. It seeks injunctions and statutory penalties under multiple California laws, including CCPA and the California Genetic Information Privacy Act.
read more →

GDPR’s legacy and the coming AI regulatory battles

📰 Over eight years GDPR set global data-protection norms, notably the 72-hour breach notification standard, but nearly 40% of announced EU fines by value are annulled or under appeal. Experts say large tech firms contesting fines isn’t surprising and that rulings provide practical guidance for compliance teams. As the EU’s AI Act and proposed GDPR reforms arrive, regulators must shore up procedural robustness while organisations adapt governance to evolving AI risks.
read more →

Dutch police arrest suspect in Ajax football hack

🔒 The Dutch National Police arrested a 35-year-old man from Buren suspected of multiple unlawful intrusions into AFC Ajax's computer systems earlier this year. The intrusions allowed access to data belonging to a few hundred individuals, modification of fewer than 20 stadium bans, and reassignment of purchased tickets. Ajax patched the exploited vulnerabilities, reported the breach to the Dutch Data Protection Authority and police, and the investigation remains ongoing.
read more →

Dutch raid seizes servers, arrests hosting co-owners

🛡️ Dutch authorities arrested two co-owners of related hosting companies and seized over 800 servers on May 18, alleging they operated infrastructure used by Russia for cyberattacks and influence operations targeting the EU. The arrests follow investigative reporting that linked MIRhosting and WorkTitans to Stark Industries, an ISP sanctioned by the EU for facilitating DDoS, proxy, and anonymity services tied to Russia-backed actors. Officials searched businesses and data centers and charged the suspects with violating sanctions law by making economic resources available to sanctioned entities. Both suspects deny wrongdoing and one company says it has paused services to the implicated client pending internal review.
read more →

European takedown targets VPN linked to crime

🛡️ European investigators dismantled First VPN in a joint operation led by France and the Netherlands, assisted by Europol and Eurojust. The service, widely promoted in Russia, was used by criminals for ransomware, fraud, and data theft to conceal identities and infrastructure. While the takedown is seen as warranted, experts warn that broad restrictions on VPNs risk harming legitimate privacy and business uses and could face legal challenges.
read more →

UK Regulators Warn Financial Firms on Frontier AI Risks

⚠️ On May 15 the UK government, the Financial Conduct Authority and the Bank of England issued a joint warning about cybersecurity threats from frontier AI. They noted models can outperform skilled practitioners at greater speed, scale and lower cost, amplifying risks to firms, customers and financial stability. The statement urges firms to strengthen governance, vulnerability management, third-party controls, protection and response capabilities and points to NCSC resources and prior resilience guidance.
read more →