< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles · page 8 of 20

CVE Program Funding Secured, Avoiding 2026 Crisis Threat

🔒 The Cybersecurity and Infrastructure Security Agency and MITRE have renegotiated the contract supporting the 26-year-old CVE program, averting the imminent funding cliff that triggered a one-day panic in 2025. Sources indicate the program has been elevated from a discretionary line to a protected budget item within CISA, providing multi-year operational stability. While the move reduces near-term shutdown risk, the agreement remains opaque to many stakeholders and raises outstanding questions about modernization, performance measurement, and governance.
read more →

UK launches Online Crime Centre to tackle cyber fraud

🔒 The UK government will establish an Online Crime Centre in April to disrupt large-scale cyber-enabled fraud by combining expertise from government, intelligence agencies, police, banks, mobile networks and major tech firms. The centre will identify and shut down scam accounts, websites and phone numbers, block scam texts, freeze criminal accounts and target overseas scam compounds. The strategy also plans to deploy AI for fraud detection and scam-baiting chatbots to gather intelligence, while introducing a new fraud victims charter to standardise support and reimbursements.
read more →

Germany enacts NIS-2 law; BSI reports surge in sign-ups

🛡️ The German implementation of the NIS-2 directive came into force on December 6, 2025, prompting a last-minute rush of registrations to the Federal Office for Information Security (BSI). The BSI recorded more than 4,000 new registrations in the final week as organisations checked whether the rules apply to them. The law mandates rapid incident reporting — initial notification within 24 hours, updates within 72 hours and a final report after one month — and serious violations may lead to fines.
read more →

Germany enacts NIS-2 law; thousands register late now

🛡️ The German law implementing the NIS-2 directive came into force on 6 December 2025, introducing stricter incident reporting and registration requirements. The Bonn-based Federal Office for Information Security (BSI) reported a surge of more than 4,000 registrations in the final week before the deadline and expects further last-minute filings. Affected organisations must report significant incidents within 24 hours, provide updates within 72 hours and submit a final report after one month, with potential fines for serious violations.
read more →

EU Adviser: Banks Must Immediately Refund Phishing Victims

⚖️ Advocate General Athanasios Rantos advised that, under PSD2, banks must immediately refund customers for unauthorised transactions resulting from phishing unless the bank has reasonable grounds to suspect the customer committed fraud and communicates those grounds in writing to the competent national authority. Banks may later seek reimbursement if they can prove the customer acted intentionally or with gross negligence. This opinion is advisory, not a final CJEU ruling.
read more →

U.S. Cyber Strategy Prioritizes Offensive Operations

⚔️ The White House released a concise seven-page cybersecurity strategy developed by the Office of the National Cyber Director that places offensive cyber operations at the center of U.S. policy while also pushing deregulation and accelerated AI adoption. It articulates six implementation pillars including shaping adversary behavior, modernizing federal networks with AI and zero-trust, securing critical infrastructure, and building workforce capacity. Industry responses were broadly positive from vendors emphasizing AI and quantum-safe security, but defenders warn the emphasis on proactive offense and deregulatory moves could raise escalation and resilience concerns.
read more →

Cognizant TriZetto Breach Exposes 3.4M Patient Records

🔒 TriZetto Provider Solutions, part of Cognizant, disclosed a breach that exposed sensitive health and insurance records for about 3,433,965 individuals. The company detected suspicious portal activity on October 2, 2025, and determined that unauthorized access began on November 19, 2024. Exposed data may include names, addresses, dates of birth, Social Security numbers, Medicare and insurance identifiers, provider and insurer names, and other demographic or health information. TriZetto says no payment card or bank account data were exposed, has engaged external cybersecurity experts, notified law enforcement, alerted providers on December 9, 2025, and began customer notifications in early February 2026; affected individuals are being offered 12 months of credit monitoring and identity protection services from Kroll.
read more →

Tycoon 2FA phishing kit dismantled after global takedown

🔒In a coordinated takedown, law enforcement and industry partners dismantled Tycoon 2FA, a commercial phishing-as-a-service platform that automated MFA bypasses via a real-time proxy. The kit, sold for about US $120/month through private Telegram channels, forwarded credentials and one-time codes to legitimate sites to capture authenticated sessions. It was linked to tens of millions of phishing emails and widespread attacks on healthcare and education before seizures and blocks by Microsoft, multi-country law enforcement, and Cloudflare largely disrupted the operation. Users are reminded that not all MFA is equal: hardware security keys or passkeys provide stronger protection against proxying than SMS-based codes.
read more →

Anthropic vs. Pentagon: AI Supply, Ethics, and Policy

⚖️ The Pentagon’s removal of Anthropic from US defense contracts, and the swift substitution by OpenAI, marks a high-profile clash over AI use for military and surveillance purposes. Anthropic refused DoD terms that would permit mass surveillance or fully autonomous weapons, provoking political backlash and a presidential order halting its federal partnerships. OpenAI has agreed to supply classified systems, raising questions about vendor politicization and how safety commitments will be enforced. The episode underscores procurement power, potential legal battles, and the limits of corporate ethical posturing.
read more →

International Takedown of LeakBase Cybercrime Marketplace

🔒 Law enforcement across 14 countries seized the LeakBase cyberforum, taking its database and two domains and targeting roughly 142,000 users. Authorities executed around 100 coordinated actions beginning March 3, including arrests, search warrants, and interviews in multiple jurisdictions. The captured data reportedly contained credential pairs, payment card details, bank account information, and other sensitive personally identifiable and business data. Investigators say the technical seizure unmasked users who believed they were operating anonymously and that authorities delivered prevention messages while continuing to trace digital trails.
read more →

FBI Arrests Suspect in $46M U.S. Marshals Crypto Theft

🔒 John Daghita, a U.S. government contractor and son of CMDSS's CEO, was arrested on Saint Martin after a joint operation by the FBI and France's elite Gendarmerie unit. He is accused of stealing more than $46 million in cryptocurrency seized and managed by the U.S. Marshals Service, including funds tied to the 2016 Bitfinex hack. Authorities seized cash, hard drives, and security keys, and investigators say public blockchain analysis played a key role in identifying him.
read more →

Europol and Amsterdam Police Shut Down Leakbase Market

🔒 Europol coordinated a multi-country operation with Amsterdam police that shut down Leakbase, described as one of the world's largest marketplaces for stolen data. Authorities seized the platform's servers in Amsterdam and said Leakbase had about 142,000 registered users worldwide. Investigators in 14 countries executed around 100 raids, targeting roughly 37 main users. The probe began in the Netherlands in 2023 and involved close cooperation with the U.S. FBI.
read more →

Europol, Amsterdam Police Shut Down LeakBase Data Market

🔒 Amsterdam police, working with Europol and international partners, have shut down LeakBase, a major online marketplace for stolen data whose servers were located in Amsterdam. The platform had about 142,000 registered users and has been seized as part of a joint operation involving investigators from 14 countries and the FBI. Authorities conducted around 100 targeted operations aimed at 37 primary users. The site now displays a police notice warning that trading stolen data is a criminal offense.
read more →

Europol-led Operation Seizes LeakBase Data Breach Forum

🔒 Europol and international partners have taken down LeakBase, an English-language forum that trafficked stolen credentials and stealer logs, seizing two domains and the site's customer database. Coordinated actions on March 3 included arrests, house searches and interviews across the US, Australia, Belgium, Poland, Portugal, Romania, Spain and the UK. Europol said 37 of the forum’s most active users were targeted and vowed to continue tracing offenders as part of Operation Leak.
read more →

Phobos Ransomware Administrator Pleads Guilty in U.S. Case

🔐 A Russian national, Evgenii Ptitsyn, pleaded guilty to a wire fraud conspiracy for administering the Phobos ransomware operation that victimized hundreds worldwide. Extradited from South Korea in November 2024, prosecutors say the RaaS campaign — linked to the Crysis family — collected over $39 million from more than 1,000 victims and accounted for roughly 11% of ID Ransomware submissions in mid‑2024. Affiliates paid about $300 per deployment for decryption keys; Ptitsyn faces up to 20 years and is scheduled for sentencing on July 15. International law enforcement actions, including Operation Aether, have disrupted parts of the gang and warned over 400 companies.
read more →

Navigating Fragmented Cybersecurity Regulation in Europe

🔎 This Fortinet podcast episode examines the evolving EU-centric cybersecurity regulatory landscape and its implications for global businesses. Host Joe Robertson speaks with Dr. Tommaso De Zan of Access Partnership about layered rules such as NIS2, the Cyber Resilience Act, DORA, and emerging cloud sovereignty initiatives. They contrast horizontal and vertical regulations, highlight differences between regulations and directives, and emphasize that industry accepts rules but resents uncertainty. Practical advice includes early policy monitoring, engagement in consultations, and embedding security into products and operations.
read more →

Florida woman jailed for large Microsoft license fraud

🔒 A Florida woman was sentenced to 22 months in prison and fined $50,000 for operating a years‑long scheme that trafficked thousands of stolen Microsoft Certificate of Authenticity (COA) labels. Heidi Richards, who ran Trinity Software Distribution, purchased tens of thousands of genuine COAs, had employees extract and transcribe product keys, and sold those keys in bulk to customers worldwide. Prosecutors reported she wired $5,148,181.50 to the supplier between July 2018 and January 2023.
read more →

Pentagon Labels Anthropic Supply-Chain Risk in AI Dispute

⚠️The Pentagon has directed the Department of War to designate Anthropic a supply-chain risk after talks over military use of its AI model, Claude, reached an impasse. President Donald Trump ordered federal agencies to phase out Anthropic technology within six months, while Secretary of Defense Pete Hegseth ordered immediate cessation of contractor activity. Anthropic says the designation followed its refusal to allow mass domestic surveillance or fully autonomous weapons and calls the move legally unsound and limited to DoW contracts under 10 USC 3252. The dispute has drawn industry pushback and reignited debate over civil liberties, procurement policy, and how safeguards should apply in defense settings.
read more →

DoJ Seizes $61M in Tether Linked to Pig-Butchering Scams

🔒 The U.S. Department of Justice announced the seizure of $61 million in Tether allegedly tied to pig-butchering crypto scams that lured victims through romance and fake investment platforms. Authorities say the funds were traced to wallets used to launder stolen proceeds, with rapid routing across many addresses to obscure ownership. HSI officials highlighted global tracing efforts while Tether noted extensive freezing of illicit assets.
read more →

UK Data Watchdog Reorganises to Board-Led Agency Structure

🔒 A forthcoming overhaul to the UK GDPR will convert the Information Commissioner's Office from a single-commissioner model into a board-run government agency, with Paul Arnold appointed as the first CEO of the new structure. The changes, to be enacted through the Data (Use and Access) Act 2025, aim to improve continuity, broaden expertise and manage a growing workload. The reform also grants the ICO new investigatory and compulsory powers and expands duties affecting businesses, while Data Essentials training will be scaled up.
read more →