EFF to Courts: Don’t Rewrite Copyright Over AI Hype

The Electronic Frontier Foundation (EFF) is urging courts not to expand copyright protections based on what they describe as AI hype. They argue that historical technological advancements, such as VTRs and cameras, did not destroy creative markets as feared, and that copyright law should continue to promote innovation rather than restrict it by empowering existing gatekeepers. The EFF is advocating against a "market dilution" theory that could grant copyright holders control over non-infringing AI-generated works.

Key Reasons Why Identity Fabric Matters in 2026

An Identity Fabric integrates disparate identity systems to provide a unified view of identity behavior across various applications, APIs, and infrastructure. As enterprises adopt more cloud services and automated workloads, maintaining identity security increasingly relies on real-time visibility rather than static configurations.

Beyond compliance: Designing systems that earn customer trust

Building customer trust in digital systems requires more than just compliance; it hinges on how data is handled daily. Key areas for security leaders include ensuring consistency of customer intent across all systems, treating privacy as a distributed-systems challenge, minimizing unnecessary data, designing for potential failures, and understanding AI's impact on trust boundaries.

CTEM can give your security team a contextual edge

Continuous Threat Exposure Management (CTEM) is an emerging approach that moves beyond traditional vulnerability management by continuously assessing an organization's entire risk exposure. It expands scope to include misconfigurations, identity risks, and excessive permissions, and focuses on validating exploitability and assigning responsibility for remediation.

EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity

EFF and allies are advocating for stronger privacy and data protection measures in Brazil's elections, arguing that violations of these rights enable the spread of misinformation and manipulation. Their recommendations aim to foster better collaboration between oversight bodies, civil society, and digital platforms to ensure electoral integrity, especially in the age of AI-generated disinformation.

Webinar: How Google Workspace breaches happen and what to do next

This article describes an upcoming webinar that will explore common methods of Google Workspace breaches, including social engineering and compromised third-party integrations. The webinar will detail the critical initial hours of a breach and highlight effective security controls defenders can implement.

The Future of AI-Driven Security Depends on Complete Data

The article discusses how the future of AI-driven security hinges on having complete data, moving beyond traditional log and event analysis which represent a lossy view of reality. It suggests that a more comprehensive understanding of data is crucial for effective AI security.

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

This article discusses the importance of managing administrative rights within Entra ID (formerly Azure AD) to prevent unauthorized access or modifications. It highlights the risks associated with former employees retaining privileges and the common issue of having too many administrators with excessive permissions, noting this is a key security control.

French Top Court Gets It Right, Strikes Down Social Media Ban For Youths

France's top court has struck down a law that would have banned social media use for individuals under 15 years old, ruling it an infringement on freedom of expression. The decision noted that the ban did not distinguish between different online services or individual user circumstances, and highlighted the negative impact such laws can have on all users' free speech.

CISA Vulnerability Review

CISA's Vulnerability Review analyzes data from FY2024 and FY2025 to identify common software weaknesses and provide practical steps for organizations to prevent exploitation. The review emphasizes the importance of Secure by Design principles and offers a framework for prioritizing vulnerabilities based on risk, using criteria such as exposure status, KEV Catalog status, automated exploit potential, and technical impact.

Estate planning of credentials

The article discusses the challenges of managing digital credentials after a person's death, using an anecdote about a tech-savvy individual who used strong, unique passwords and stored them in an encrypted Excel spreadsheet. It highlights the importance of having a plan for accessing these credentials to ensure smooth transitions for families.

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp has introduced support for multiple passkeys per account, allowing users on both iOS and Android to sign in using this phishing-resistant method. This feature aims to enhance account security by offering a more robust alternative to traditional passwords. Over a billion users now reportedly utilize passkeys for WhatsApp logins.

WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update

WhatsApp has enhanced its account security by introducing support for multiple passkeys, allowing users to use different passkeys for their accounts. Additionally, the platform has strengthened its two-step verification (2SV) process, requiring users to set up a 6-digit PIN for added protection during account setup. The update also provides more caller information for calls from non-contacts, including the caller's country.

A Tale of Two SOCs: Insights From Two Red Team Assessments

CISA conducted simultaneous red team assessments at two organizations, finding that while both environments were fully compromised, one organization rapidly detected and contained the activity, while the other failed to do so. The advisory highlights the importance of tuned detection tools, breaking down organizational silos for effective incident response, and addressing underestimated risks in cloud environments.