Tag: law
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
How New Laws Will Help Guard Seniors Against Scams
In a rare show of bipartisan agreement, both the U.S. House and the Senate have voted to approve bills aimed at battling fraud, especially scams aimed at older adults. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-new-laws-will-help-guard-seniors-against-scams/
-
Italy’s new facial recognition policy sparks EU law debate
Tags: lawFirst seen on scworld.com Jump to article: www.scworld.com/brief/italys-new-facial-recognition-policy-sparks-eu-law-debate
-
AiTM phishing overtakes credential theft as top threat to law firms
First seen on scworld.com Jump to article: www.scworld.com/brief/aitm-phishing-overtakes-credential-theft-as-top-threat-to-law-firms
-
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot? First seen on wired.com Jump to article: www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
-
Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot? First seen on wired.com Jump to article: www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
Interpol Leverages Global System to Curtail Fraud Payments
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/interpol-leverages-global-system-curtail-fraud-payments
-
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
-
Flailing Ransomware Hackers Resorting to Extreme Tactics
Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do. Fewer ransomware victims are choosing to pay a ransom than ever before, bar some big payoffs that largely trace to high-profile law firms that got hit by a group called Silent Ransom, which the FBI says has a penchant for infiltrating…
-
IoT Sector Given Final EU Cyber Resilience Act Guidance
Incident Reporting Starts Sept. 11, Other Mandates Wait Until Dec. 11, 2027. The European Commission published final guidance for complying with the Cyber Resilience Act, a 2024 law that aims to boost the cybersecurity of software and internet-connected hardware products. The greatest change from a previous draft is which software falls within the CRA’s scope.…
-
FBI sees Anthropic’s Mythos as a law enforcement challenge
Tags: lawThe post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop. First seen on fedscoop.com Jump to article: fedscoop.com/fbi-anthropic-mythos-law-enforcement-challenge/
-
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
-
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese First seen…
-
US House Votes to Extend Cyber Sharing Law for 10 Years
Lawmakers Advance 10-Year Renewal of Key Cyber Law, Setting Up Looming Senate Fight. The U.S. House of Representatives passed a fiscal year 2027 defense authorization bill with a provision extending the Cybersecurity Information Sharing Act of 2015 through 2036. The decade-long renewal faces an uphill climb in the Senate. First seen on govinfosecurity.com Jump to…
-
US government to consider AI Kill Switch law
Two US congressmen have introduced a bill to give Washington the power to pull the plug on rogue AI models in an emergency. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646128/US-government-to-consider-AI-Kill-Switch-law
-
How CIOs can navigate federal, state AI regulation uncertainty
AI laws are evolving across the EU, U.S. states and the U.S. federal government. An effective governance framework helps organizations meet requirements across all jurisdictions. First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366646236/How-CIOs-can-navigate-federal-state-AI-regulation-uncertainty
-
Europol Flags 4,340 URLs Tied to The Com Network
9 Countries Referred Thousands of URLs Tied to Grooming and Violent Content. European law enforcement notified hosting providers of 4,340 URLs containing nihilistic violent extremism in a weeks-long international crackdown on propaganda created by the loosely connected network of young hackers known as The Com. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/europol-flags-4340-urls-tied-to-com-network-a-32325
-
Nigeria consolidates digital identity under NIMC with new law
First seen on scworld.com Jump to article: www.scworld.com/brief/nigeria-consolidates-digital-identity-under-nimc-with-new-law
-
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House’s fiscal 2027 defense authorization bill. First seen on therecord.media Jump to article: therecord.media/cisa-2015-extension-passes-house-ndaa
-
States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them
Tags: lawFederal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work. First seen on wired.com Jump to article: www.wired.com/story/states-want-ice-agents-to-show-their-faces-the-trump-administration-is-blocking-them/
-
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/bka-fbi-kratos-phishing-platform-takedown/
-
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal…
-
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-future-of-age-verification-your-face-never-leaves-your-device/
-
UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.” First seen on therecord.media Jump to article: therecord.media/ofcom-investigation-tiktok-age-verification
-
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects
Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than Euro100 million every month. The investigation has resulted in arrests in Poland, Cyprus, Belgium, and Greece, targeting a network that operated around twenty fraudulent call centers staffed by more…
-
Illinois Enacts First US Law Mandating AI Safety Audits
SB 315 Requires Annual Independent Audits, 72-Hour Incident Reporting for AI Giants. Gov. JB Pritzker signed bipartisan legislation making Illinois the first state to require annual independent safety audits of frontier AI developers, going beyond California and New York frameworks with incident reporting deadlines, whistleblower protections and penalties up to $3 million. First seen on…

