EFF to Governor Newsom: Veto California’s AB 1709

The Electronic Frontier Foundation (EFF) is urging California Governor Gavin Newsom to veto Assembly Bill 1709, which would impose a sweeping ban on social media use for individuals under 16. The EFF argues that the bill, by restricting recommendation algorithms and other essential online tools, infringes on free speech, privacy, and access to information, while also potentially forcing invasive age-verification methods.

EFF to Courts: Don’t Rewrite Copyright Over AI Hype

The Electronic Frontier Foundation (EFF) is urging courts not to expand copyright protections based on what they describe as AI hype. They argue that historical technological advancements, such as VTRs and cameras, did not destroy creative markets as feared, and that copyright law should continue to promote innovation rather than restrict it by empowering existing gatekeepers. The EFF is advocating against a "market dilution" theory that could grant copyright holders control over non-infringing AI-generated works.

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

Several US states, including Connecticut, Maryland, New Jersey, Oregon, and Virginia, have enacted new laws to restrict commercial location tracking, addressing concerns about pervasive surveillance. Despite this progress, significant gaps remain in these laws, highlighting the need for broader action from other states and Congress to ensure comprehensive location data protection.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities, CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities pose significant risks and are a frequent attack vector for malicious actors.

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The U.S. Department of Justice has corrected a previous statement, clarifying that several of its agencies were targeted by Chinese threat actors rather than being victims of the attacks. The correction indicates that agencies like NASA, the Federal Reserve, and the Department of Energy were among those identified as targets.

Risky Bulletin: Dutch intel services to get extensive new powers

Dutch intelligence services are set to receive expanded powers. Separately, an Israeli security expert has been arrested for hacking, and a hacker connected to BTS has received a 20-year sentence. Additionally, a German politician from the AfD party is reportedly linked to Russian cybercrime operations.

Defining an AI Kill Switch Is Hard, But Necessary

Proposed legislation may require companies to implement mechanisms to "throttle, suspend, or shut down" AI agents. However, the practical implementation of such AI kill switches, including when and how to deploy them, remains a significant challenge.

CISA: Most exploited vulnerabilities should have been eradicated decades ago

CISA has identified that the most frequently exploited vulnerabilities are decades old, indicating a systemic failure in secure development practices and organizational culture. This persistent reliance on outdated and unpatched vulnerabilities suggests that organizations have not adequately embraced "Secure by Design" principles.

Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

Nearly 130 tech and cybersecurity companies have pledged to collaborate on improving cyber defenses in response to the increasing sophistication of AI-enabled attacks. This initiative, spearheaded by OpenAI, aims to foster a united front against emerging cyber threats.

Industry that built the problem offers to sell you the solution

Over 100 major technology companies have warned that AI-powered attacks are an imminent threat. However, they are reportedly seeking to avoid responsibility for funding the necessary defenses against these emerging threats.

Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

The White House has issued a new executive order (14420) aimed at increasing scrutiny of industrial control systems within the US power grid. This order seeks to prevent foreign actors from introducing backdoors and engaging in cyber sabotage against critical energy infrastructure.

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including ones affecting ownCloud, the Linux Kernel, and JFrog Artifactory, due to evidence of active exploitation. These additions align with Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize the remediation of these high-risk vulnerabilities.

A call for collective action on cyber defense

Sophos is advocating for a unified and responsible strategy in cybersecurity defense. This call to action encourages global organizations to collaborate on improving cyber resilience.

A List of ICE Subpoenas to Tech Companies

Immigration and Customs Enforcement (ICE) has used administrative subpoenas to request user data from technology companies for investigations into individuals, including social media users critical of the government and international students. The EFF is compiling a list of these subpoenas, highlighting instances where they have been challenged for exceeding authority and violating First Amendment rights.

EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms

The Electronic Frontier Foundation (EFF) argues that Automated License Plate Readers (ALPRs) enable mass surveillance and are inherently harmful. They advocate for the complete elimination of ALPR mass surveillance and, failing that, for strict legal restrictions like warrant requirements and data deletion deadlines.

EFF Statement on Meta Settlement

The Electronic Frontier Foundation (EFF) has released a statement regarding a settlement with Meta, arguing that it will restrict young users' access to Meta products and negatively impact their rights to expression and association. The EFF also contends that the settlement mandates increased personal data collection for age assurance, further embedding Meta's surveillance practices and potentially compromising user privacy and anonymity.

French Top Court Gets It Right, Strikes Down Social Media Ban For Youths

France's top court has struck down a law that would have banned social media use for individuals under 15 years old, ruling it an infringement on freedom of expression. The decision noted that the ban did not distinguish between different online services or individual user circumstances, and highlighted the negative impact such laws can have on all users' free speech.

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating evidence of active exploitation. These vulnerabilities are considered frequent attack vectors for malicious actors and pose significant risks. CISA encourages all organizations, especially Federal Civilian Executive Branch (FCEB) agencies, to prioritize remediation of these vulnerabilities as part of their risk-based vulnerability management efforts.

Nigeria Looks to Sovereign Cloud for Cyber, National Security

Nigeria has launched policies aimed at financing, procurement, and infrastructure to advance its sovereign cloud initiative. This move is intended to strengthen the nation's cybersecurity posture and national security capabilities, while also increasing domestic technical expertise.

Risky Bulletin: Russia starts blocking DoH and DoT

Russia has begun blocking DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols, which are designed to enhance privacy and security by encrypting DNS queries. In unrelated news, the hacking group NoName057 has leaked data on Spanish police and military targets, and China and South Korea have detained a vishing gang.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize the remediation of such high-risk vulnerabilities on publicly exposed assets.

TikTok reaches $400M settlement with US over COPPA violations

TikTok, ByteDance, and affiliated companies have reached a $400 million settlement with the U.S. Department of Justice. The settlement resolves allegations that the companies violated the Children's Online Privacy Protection Act (COPPA). This agreement addresses concerns regarding the handling of children's data and online privacy practices.

Criminal Deception in Silicon Valley

A research paper analyzes entrepreneurial fraud in Silicon Valley, finding that founders construct illusory appearances, or "façades," to mask underperformance and defraud audiences. The study categorizes these façading techniques into surface, reinforced, and deep forms based on the severity of the expectation-reality gap, and proposes methods for deterrence and detection.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-73570 affecting Zimbra Collaboration Suite (ZCS) with an OS Command Injection flaw, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition is based on evidence of active exploitation, highlighting the significant risks such vulnerabilities pose. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk, exploited vulnerabilities listed in the KEV Catalog on publicly exposed assets.

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Two industry surveys from Kiteworks and CyberSheath indicate that defense contractors are increasingly confident in their ability to meet CMMC requirements, but this confidence is not matched by their actual ability to prove compliance. This suggests a growing gap between perceived readiness and demonstrated adherence to cybersecurity standards within the defense industrial base.

Intermediary Liability in Brazil: The Intricate Path Ahead

Brazil is implementing a new internet intermediary liability regime, including notice and takedown mechanisms and duty of care obligations for online platforms. These changes, clarified by the Supreme Court and detailed in recent presidential decrees, aim to address unlawful content while raising concerns about potential overreach and censorship of protected speech.

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Law enforcement officers face significant challenges in keeping up with the rapidly evolving landscape of cybercrime. Progress is hindered by a lack of focus and insufficient budgets, despite the fact that officers primarily need to learn foundational cybercrime investigation skills.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities, CVE-2026-72529 and CVE-2026-72530, both related to TrueConf Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize patching vulnerabilities listed in the KEV Catalog.

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

This article discusses a proposal for a private hacker memo related to former President Trump. It highlights potential benefits and concerns surrounding such an initiative, framing it within the context of cybersecurity and national security.

Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.

Tech companies have privately challenged some ICE subpoenas seeking user data, particularly when the data was requested for investigating individuals criticizing the government or tracking immigration activities. EFF encourages these companies to do more by publicly challenging unlawful subpoenas and taking legal action against them to protect user privacy and deter future misuse.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849) to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action is in line with Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

The United States has indicted 17 Iranian hackers associated with the Mabna Institute for targeting hundreds of universities and organizations globally. The US Department of Justice has also announced rewards totaling $10 million for information leading to the capture of five of these individuals.

Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230

A Ninth Circuit ruling in the case of California v. Meta states that denials of Section 230 immunity are not immediately appealable. This decision could force online platforms to face lengthy and costly lawsuits over user-generated content before such cases are dismissed, potentially impacting free speech online.

ZKP’s Aren’t Age Verification Silver Bullets

The article discusses the increasing implementation of age verification laws globally, noting that many of these laws are ineffective and pose significant privacy risks. It specifically addresses the promotion of Zero-Knowledge Proofs (ZKPs) as a solution, arguing that ZKP-based age verification schemes are gameable, hackable, and could centralize power while creating further harms.

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These include vulnerabilities in Microsoft IKE Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS. The addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize patching these high-risk vulnerabilities.

What you say during a cyber breach can — and will — be used against you

Communications made during the initial chaotic hours of a cyber incident can have significant legal and financial repercussions long after the attack. What is said and documented can become evidence in litigation and investigations, and simply copying legal counsel does not automatically grant attorney-client privilege.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2025-62593 (Ray-Project Ray Code Injection Vulnerability), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition is part of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

The European Union has released its upcoming cybersecurity standards. In related news, hackers have breached France's tax agency, a GeoServer zero-day vulnerability is being actively exploited, and an exploit has been developed to unlock old AMD CPUs.

IAM Compliance Requirements and Best Practices

IAM compliance involves proving that identity and access controls are consistently enforced for all entities, including users, applications, and infrastructure. This guide covers the essential requirements, relevant regulations, and methods for organizations to transition from manual access reviews to continuous, auditor-friendly verification processes.

What Boards Need to Know About Tech Risk

Boards of directors often underestimate technology risk until a crisis occurs, leading to reactive rather than proactive security measures. This underestimation stems from a lack of understanding of complex tech risks and their potential business impact.