< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles · page 9 of 20

New York Sues Valve Over Loot Boxes for Illegal Gambling

⚖️New York Attorney General Letitia James sued Valve Corporation, alleging the company facilitated illegal gambling through randomized loot boxes in Counter-Strike 2, Dota 2, and Team Fortress 2 on Steam. The complaint says rare virtual items can be exchanged for real money, that odds are skewed to increase value, and that the mechanics are addictive and harmful to children. James is seeking injunctive relief, disgorgement of profits, and fines.
read more →

CISA Emergency Directive: Mitigate Cisco SD‑WAN Risks

⚠ CISA issued Emergency Directive 26-03 requiring immediate mitigation of critical vulnerabilities in Cisco SD‑WAN systems, citing exploitable flaws including CVE-2026-20127 and CVE-2022-20775. Agencies must inventory systems, collect virtual snapshots and logs, apply patches, hunt for evidence of compromise, and implement vendor hardening guidance. CISA will monitor compliance, provide technical assistance, and deliver additional resources as needed. The directive is supported by the NSA, ASD’s ACSC, Canada’s Cyber Centre, NCSC-NZ, and NCSC-UK.
read more →

CISA and Partners: Guidance on Cisco SD‑WAN Exploits

🔔 CISA and international partners warn of active exploitation of Cisco SD-WAN systems, adding CVE-2026-20127 and CVE-2022-20775 to the Known Exploited Vulnerabilities Catalog. FCEB agencies are required by Emergency Directive 26-03 to inventory, update, and assess SD-WAN deployments. Organizations should collect artifacts, apply vendor updates, follow the Catalyst SD-WAN Hardening Guide, and hunt for evidence of compromise immediately.
read more →

U.S. Sanctions Russian Exploit Broker for Stolen Zero‑Days

🔒 The U.S. Treasury Department's Office of Foreign Assets Control designated Matrix LLC (doing business as Operation Zero) and its owner, Sergey Zelenyuk, under the Protecting American Intellectual Property Act, marking the first use of that law. The move coincided with the sentencing of former L3Harris manager Peter Williams, who was given 87 months for stealing eight zero‑day exploits and selling them to Operation Zero for about $1.3 million in cryptocurrency. OFAC also named related companies and individuals, including a UAE front company and a suspected Trickbot affiliate, freezing U.S. assets and warning of potential secondary sanctions for U.S. persons who transact with the designated parties.
read more →

Ex-L3Harris Executive Sentenced for Selling Zero-Day Exploits

🔒 A former senior executive at L3Harris cyber-division Trenchant, Australian national Peter Williams, has been sentenced to 87 months in prison after pleading guilty to stealing and selling zero-day exploits to a Russian broker. He admitted taking eight cyber-exploit components over three years, accepting cryptocurrency payments and providing paid follow-on support. Authorities say the theft cost Trenchant/L3Harris about $35m and posed significant national security risks. Williams was ordered to forfeit $1.3m, cryptocurrency, property and luxury items, and to serve three years of supervised release with special conditions.
read more →

ICO fines Reddit £14.47m over inadequate age checks

🔒 The UK Information Commissioner's Office (ICO) has fined Reddit £14.47m for failing to implement robust age verification and for not conducting a required DPIA before January 2025. The regulator found that children under 13 had personal data processed without a lawful basis and were potentially exposed to inappropriate content. Reddit maintains it avoids collecting identity data to protect privacy, while experts warn heavy-handed identity checks could introduce new privacy and security risks.
read more →

Defense Contractor Employee Jailed for Selling Zero-Days

🔒 Peter Williams, a 39-year-old former senior employee at L3Harris, was sentenced to just over seven years in prison after pleading guilty to selling eight zero-day exploits to the Russian exploit broker Operation Zero. Prosecutors say he received up to $4 million in cryptocurrency and has been ordered to forfeit proceeds, including properties and luxury items. The theft, which occurred between 2022 and 2025, targeted tools intended for sale only to the U.S. government and select allies and prompted criminal charges and sanctions.
read more →

UK fines Reddit £14.47M for unlawfully using children's data

🔒 The UK Information Commissioner's Office has fined Reddit £14.47 million for collecting and processing the personal information of children under 13 without adequate safeguards. The ICO found Reddit lacked a meaningful age-verification system until July 2025 and judged the measures introduced then could be easily bypassed. Reddit said it will appeal and disputes the regulator's assessment.
read more →

ShinyHunters Claims Breach of Dutch Telecom Odido

🔒 The ShinyHunters extortion gang claims it stole millions of user records from Dutch telecom Odido, adding the company to its dark‑web leak site and asserting nearly 21 million records were taken. Odido disclosed the incident on February 12, reporting that attackers accessed its customer contact system on February 7 and that exposed fields vary by customer. The carrier said no Mijn Odido passwords, call records, location data, billing data, or identity scans were exposed; ShinyHunters, however, alleges internal corporate data and plaintext passwords were also taken. Odido reported the breach to the Dutch Data Protection Authority, blocked the attackers' access, and engaged external cybersecurity specialists while investigations continue.
read more →

Time to Rethink CISO Reporting Lines and Biases Today

🔍 Security leaders remain largely removed from top executive decision-making despite growing prominence. IANS Research and Artico Search’s 2026 State of the CISO Benchmark Report finds 64% of CISOs still report into IT while only 11% report to the CEO. Experts argue that such arrangements can create conflicts of interest as CIO incentives favor efficiency and delivery over enterprise risk reduction. Many urge giving CISOs independence, a clear seat at the table, and reporting aligned to enterprise risk owners.
read more →

Spain Arrests Suspected Anonymous Fénix Hacktivists

🔒 Spanish authorities arrested four alleged members of the hacktivist group Anonymous Fénix for a series of distributed denial-of-service (DDoS) attacks that targeted government ministries, political parties, and public institutions. The Spanish Civil Guard said the group first struck in April 2023 and intensified activity after severe floods in Valencia in late October 2024, using X and Telegram for recruitment and propaganda. Courts ordered seizure of the group's X and YouTube accounts and closure of its Telegram channel following the arrests.
read more →

Texas Sues TP-Link Over Alleged Chinese Hacking Risks

🔒 Texas Attorney General Ken Paxton has sued TP-Link, alleging the company deceptively marketed routers as secure while obscuring Chinese supply-chain ties and labeling devices Made in Vietnam. The complaint cites firmware vulnerabilities exploited by Chinese state-backed actors and a large credential-theft botnet built from compromised routers. Paxton seeks monetary penalties and injunctions forcing disclosure of Chinese origins and limits on data collection; TP-Link denies the allegations and says U.S. user data is stored on domestic AWS servers.
read more →

Spain Court Orders NordVPN, ProtonVPN to Block Piracy

⚖️ A Spanish court has ordered NordVPN and ProtonVPN to block 16 websites and a dynamic set of IP addresses in Spain that facilitate illegal streaming of LaLiga matches. The measures were issued inaudita parte, meaning the providers were not called to a hearing and will have no opportunity to appeal. Rights holders argue VPNs fall under the EU Digital Services Regulation; the vendors say they were not notified and question the efficacy and legality of the order.
read more →

Ireland launches GDPR probe into X's Grok for sexual images

🔎 Ireland's Data Protection Commission has opened a formal probe into X over the use of its Grok AI to generate non‑consensual sexual images of real people, including children. The inquiry will assess whether X Internet Unlimited Company complied with core GDPR duties such as lawful processing, data protection by design, and required impact assessments. The DPC said it has been engaging with XIUC since media reports emerged and has commenced a large‑scale inquiry. As X's EU lead regulator, the DPC's findings could trigger cross‑border enforcement and significant penalties.
read more →

CISA Hosts Town Halls to Seek Input on CIRCIA Rulemaking

📣 CISA will host a series of virtual town hall meetings beginning March 9 to collect stakeholder input on the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) rulemaking. The sessions will solicit feedback on the Notice of Proposed Rulemaking and implementation details; schedule information is published in the Federal Register and updates will be posted to CISA’s CIRCIA webpage. CIRCIA would require covered entities to report certain cyber incidents within 72 hours and ransom payments within 24 hours. CISA emphasized the need to balance improved national cybersecurity outcomes with minimizing unnecessary burden on critical infrastructure sectors.
read more →

US Court Hands Crypto Scammer 20-Year Sentence in $73M Case

🔒 A California court has sentenced Daren Li, a 42-year-old dual China and St. Kitts and Nevis national, to 20 years in prison in absentia for his role in a global crypto-investment fraud that siphoned at least $73.6m from victims. Li admitted directing co-conspirators to open US bank accounts under sham companies to launder proceeds, with an estimated $59.8m routed through US shell entities. The operation used romance-baiting and tech-support ruses to coerce transfers and convert funds to cryptocurrency.
read more →

CISA Orders Federal Agencies to Remove EOS Edge Devices

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 26-02 requiring federal civil executive branch agencies to decommission end-of-support (EOS) edge devices within specified timelines. Agencies must identify and remediate vulnerabilities within three months and remove EOS devices from external-facing network edges within 18 months, replacing them with vendor-supported hardware. The directive also mandates continuous discovery and inventory processes to prevent future exposure.
read more →

EU Says TikTok Faces Fine Over Addictive Design in EU

⚖️ The European Commission says TikTok may face a substantial penalty under the Digital Services Act after preliminary findings concluded that core design elements — infinite scroll, autoplay, push notifications and personalized recommendation systems — promote compulsive use and can harm minors and vulnerable adults. Regulators say TikTok failed to adequately assess and mitigate risks, pointing to nighttime usage and frequent app openings as ignored indicators of harm. If confirmed, the violations could trigger a fine of up to 6% of global turnover and the Commission has demanded screen-time breaks, adapted recommendation systems and the disabling of key addictive features; existing parental controls were judged insufficient.
read more →

Incognito Market Admin Sentenced to 30 Years, $105M

⚖️ A Taiwanese operator, Rui-Siang Lin (alias Pharaoh), ran the Incognito Market from October 2020 to March 2024, facilitating more than $105 million in illicit drug sales through a Tor-accessible marketplace that hosted over 1,800 vendors and served over 400,000 customers. Despite using an in-site crypto payment system called Incognito Bank, Lin made a critical OPSEC error by registering the domain with his real name, phone number and address. After a fentanyl-laced pill sold on the site was linked to a fatal 2022 overdose and Lin abruptly shut the market while stealing user deposits and attempting extortion, he was arrested at JFK in May 2024, pleaded guilty, and has been sentenced to 30 years in federal prison with forfeiture of roughly $105 million.
read more →

CISA Directs Agencies to Secure End-of-Support Edge Devices

🔒 CISA issued Binding Operational Directive 26-02, requiring Federal Civilian Executive Branch agencies to mitigate risks from unsupported edge devices. Agencies must inventory devices, update vendor-supported software, remove end-of-support hardware and software, and implement mature lifecycle management within specified timeframes. CISA will monitor compliance, assess progress, and encourage non-federal organizations to adopt similar measures to reduce technical debt and strengthen cyber resilience.
read more →