The Electronic Frontier Foundation (EFF) is urging California Governor Gavin Newsom to veto Assembly Bill 1709, which would impose a sweeping ban on social media use for individuals under 16. The EFF argues that the bill, by restricting recommendation algorithms and other essential online tools, infringes on free speech, privacy, and access to information, while also potentially forcing invasive age-verification methods.
The Electronic Frontier Foundation (EFF) is urging courts not to expand copyright protections based on what they describe as AI hype. They argue that historical technological advancements, such as VTRs and cameras, did not destroy creative markets as feared, and that copyright law should continue to promote innovation rather than restrict it by empowering existing gatekeepers. The EFF is advocating against a "market dilution" theory that could grant copyright holders control over non-infringing AI-generated works.
Several US states, including Connecticut, Maryland, New Jersey, Oregon, and Virginia, have enacted new laws to restrict commercial location tracking, addressing concerns about pervasive surveillance. Despite this progress, significant gaps remain in these laws, highlighting the need for broader action from other states and Congress to ensure comprehensive location data protection.
CISA has added two new vulnerabilities, CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities pose significant risks and are a frequent attack vector for malicious actors.
A judge has ruled that the Pentagon's actions against Anthropic, labeling the AI company as a supply chain risk, were illegal and baseless. This decision is part of Anthropic's ongoing legal dispute with the government.
The U.S. Department of Justice has corrected a previous statement, clarifying that several of its agencies were targeted by Chinese threat actors rather than being victims of the attacks. The correction indicates that agencies like NASA, the Federal Reserve, and the Department of Energy were among those identified as targets.
Dutch intelligence services are set to receive expanded powers. Separately, an Israeli security expert has been arrested for hacking, and a hacker connected to BTS has received a 20-year sentence. Additionally, a German politician from the AfD party is reportedly linked to Russian cybercrime operations.
An IT specialist with the Defense Intelligence Agency's (DIA) Insider Threat Division has pleaded guilty to leaking state secrets to foreign spies. The individual began communicating with a foreign government shortly after being assigned to a sensitive role within the DIA.
Proposed legislation may require companies to implement mechanisms to "throttle, suspend, or shut down" AI agents. However, the practical implementation of such AI kill switches, including when and how to deploy them, remains a significant challenge.
CISA has identified that the most frequently exploited vulnerabilities are decades old, indicating a systemic failure in secure development practices and organizational culture. This persistent reliance on outdated and unpatched vulnerabilities suggests that organizations have not adequately embraced "Secure by Design" principles.
Nearly 130 tech and cybersecurity companies have pledged to collaborate on improving cyber defenses in response to the increasing sophistication of AI-enabled attacks. This initiative, spearheaded by OpenAI, aims to foster a united front against emerging cyber threats.
Over 100 major technology companies have warned that AI-powered attacks are an imminent threat. However, they are reportedly seeking to avoid responsibility for funding the necessary defenses against these emerging threats.
The White House has issued a new executive order (14420) aimed at increasing scrutiny of industrial control systems within the US power grid. This order seeks to prevent foreign actors from introducing backdoors and engaging in cyber sabotage against critical energy infrastructure.
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including ones affecting ownCloud, the Linux Kernel, and JFrog Artifactory, due to evidence of active exploitation. These additions align with Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize the remediation of these high-risk vulnerabilities.
Sophos is advocating for a unified and responsible strategy in cybersecurity defense. This call to action encourages global organizations to collaborate on improving cyber resilience.
Immigration and Customs Enforcement (ICE) has used administrative subpoenas to request user data from technology companies for investigations into individuals, including social media users critical of the government and international students. The EFF is compiling a list of these subpoenas, highlighting instances where they have been challenged for exceeding authority and violating First Amendment rights.
The Electronic Frontier Foundation (EFF) argues that Automated License Plate Readers (ALPRs) enable mass surveillance and are inherently harmful. They advocate for the complete elimination of ALPR mass surveillance and, failing that, for strict legal restrictions like warrant requirements and data deletion deadlines.
The Electronic Frontier Foundation (EFF) has released a statement regarding a settlement with Meta, arguing that it will restrict young users' access to Meta products and negatively impact their rights to expression and association. The EFF also contends that the settlement mandates increased personal data collection for age assurance, further embedding Meta's surveillance practices and potentially compromising user privacy and anonymity.
France's top court has struck down a law that would have banned social media use for individuals under 15 years old, ruling it an infringement on freedom of expression. The decision noted that the ban did not distinguish between different online services or individual user circumstances, and highlighted the negative impact such laws can have on all users' free speech.
The FBI has disrupted a proxy network used by China for cyber espionage. This network provided reconnaissance, proxy management, and routing for Chinese state-sponsored hacking operations.
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating evidence of active exploitation. These vulnerabilities are considered frequent attack vectors for malicious actors and pose significant risks. CISA encourages all organizations, especially Federal Civilian Executive Branch (FCEB) agencies, to prioritize remediation of these vulnerabilities as part of their risk-based vulnerability management efforts.
Nigeria has launched policies aimed at financing, procurement, and infrastructure to advance its sovereign cloud initiative. This move is intended to strengthen the nation's cybersecurity posture and national security capabilities, while also increasing domestic technical expertise.
Russia has begun blocking DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols, which are designed to enhance privacy and security by encrypting DNS queries. In unrelated news, the hacking group NoName057 has leaked data on Spanish police and military targets, and China and South Korea have detained a vishing gang.
The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors involved in critical infrastructure breaches. This action is part of a broader economic campaign by the U.S. government targeting Iran's financial networks.
CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize the remediation of such high-risk vulnerabilities on publicly exposed assets.
Taiwan has charged nine individuals, including employees from Nvidia and Super Micro, for allegedly exporting illegal AI servers to China. This action highlights the geopolitical competition surrounding advanced AI infrastructure, particularly semiconductors produced in Taiwan.
TikTok, ByteDance, and affiliated companies have reached a $400 million settlement with the U.S. Department of Justice. The settlement resolves allegations that the companies violated the Children's Online Privacy Protection Act (COPPA). This agreement addresses concerns regarding the handling of children's data and online privacy practices.
Uber has been fined nearly $1 billion by Dutch regulators for violating the EU's General Data Protection Regulation. The fine stems from the company's automated suspension of driver accounts, which the Dutch Data Protection Authority deemed a breach of data protection rules.
A research paper analyzes entrepreneurial fraud in Silicon Valley, finding that founders construct illusory appearances, or "façades," to mask underperformance and defraud audiences. The study categorizes these façading techniques into surface, reinforced, and deep forms based on the severity of the expectation-reality gap, and proposes methods for deterrence and detection.
TikTok has reached a $400 million settlement with the US Justice Department concerning violations of children's privacy laws. The settlement includes an immediate payment of $300 million, with an additional $100 million contingent on the vacating of a previous consent decree against Musical.ly.
TikTok has agreed to a $400 million settlement to resolve a U.S. lawsuit alleging violations of child privacy laws. The settlement requires ByteDance-owned TikTok to pay $300 million immediately and an additional $100 million later.
CISA has added a new vulnerability, CVE-2026-73570 affecting Zimbra Collaboration Suite (ZCS) with an OS Command Injection flaw, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition is based on evidence of active exploitation, highlighting the significant risks such vulnerabilities pose. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk, exploited vulnerabilities listed in the KEV Catalog on publicly exposed assets.
Two industry surveys from Kiteworks and CyberSheath indicate that defense contractors are increasingly confident in their ability to meet CMMC requirements, but this confidence is not matched by their actual ability to prove compliance. This suggests a growing gap between perceived readiness and demonstrated adherence to cybersecurity standards within the defense industrial base.
Brazil is implementing a new internet intermediary liability regime, including notice and takedown mechanisms and duty of care obligations for online platforms. These changes, clarified by the Supreme Court and detailed in recent presidential decrees, aim to address unlawful content while raising concerns about potential overreach and censorship of protected speech.
Law enforcement officers face significant challenges in keeping up with the rapidly evolving landscape of cybercrime. Progress is hindered by a lack of focus and insufficient budgets, despite the fact that officers primarily need to learn foundational cybercrime investigation skills.
France's tax authority, Direction Générale des Finances Publiques (DGFiP), has reported a security breach that exposed the data of approximately 600,000 individuals. The stolen information includes sensitive details such as contact information, household finances, and tax withholding rates.
CISA has added two new vulnerabilities, CVE-2026-72529 and CVE-2026-72530, both related to TrueConf Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize patching vulnerabilities listed in the KEV Catalog.
This article discusses a proposal for a private hacker memo related to former President Trump. It highlights potential benefits and concerns surrounding such an initiative, framing it within the context of cybersecurity and national security.
Tech companies have privately challenged some ICE subpoenas seeking user data, particularly when the data was requested for investigating individuals criticizing the government or tracking immigration activities. EFF encourages these companies to do more by publicly challenging unlawful subpoenas and taking legal action against them to protect user privacy and deter future misuse.
EPIC, alongside a coalition of civil rights and privacy organizations, has sent a letter to Congressional leaders advocating for reforms to FISA Section 702. The letter specifically calls for closing the "backdoor search" and "data broker" loopholes, which critics argue allow warrantless access to Americans' communications.
CISA has added a new Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849) to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action is in line with Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.
The United States has indicted 17 Iranian hackers associated with the Mabna Institute for targeting hundreds of universities and organizations globally. The US Department of Justice has also announced rewards totaling $10 million for information leading to the capture of five of these individuals.
A Ninth Circuit ruling in the case of California v. Meta states that denials of Section 230 immunity are not immediately appealable. This decision could force online platforms to face lengthy and costly lawsuits over user-generated content before such cases are dismissed, potentially impacting free speech online.
The article discusses the increasing implementation of age verification laws globally, noting that many of these laws are ineffective and pose significant privacy risks. It specifically addresses the promotion of Zero-Knowledge Proofs (ZKPs) as a solution, arguing that ZKP-based age verification schemes are gameable, hackable, and could centralize power while creating further harms.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These include vulnerabilities in Microsoft IKE Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS. The addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize patching these high-risk vulnerabilities.
Communications made during the initial chaotic hours of a cyber incident can have significant legal and financial repercussions long after the attack. What is said and documented can become evidence in litigation and investigations, and simply copying legal counsel does not automatically grant attorney-client privilege.
CISA has added a new vulnerability, CVE-2025-62593 (Ray-Project Ray Code Injection Vulnerability), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition is part of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.
The European Union has released its upcoming cybersecurity standards. In related news, hackers have breached France's tax agency, a GeoServer zero-day vulnerability is being actively exploited, and an exploit has been developed to unlock old AMD CPUs.
IAM compliance involves proving that identity and access controls are consistently enforced for all entities, including users, applications, and infrastructure. This guide covers the essential requirements, relevant regulations, and methods for organizations to transition from manual access reviews to continuous, auditor-friendly verification processes.
Boards of directors often underestimate technology risk until a crisis occurs, leading to reactive rather than proactive security measures. This underestimation stems from a lack of understanding of complex tech risks and their potential business impact.