Four U.S. states are challenging Meta over allegedly addictive social media design, turning product behavior into a high-stakes legal and risk question.
A federal review points to a quieter risk inside critical infrastructure: overlapping cyber reporting rules that can drain time, money, and operational focus from defense itself.
Kiteworks and A-LIGN are pairing secure data handling with independent assessment support, a sign that CMMC readiness is becoming as much about evidence as it is about controls.
OTCC is pressing U.S. policymakers to formally recognize ISA/IEC 62443, a move that could simplify industrial security language without erasing the messy realities of legacy operations.
Two proposed U.S. bills signal a sharper focus on controlling advanced AI models, even as the technical details behind the triggering episode remain unclear.
The halt to CMMC Phase II is not a breach, but it is a reminder that when compliance timelines shift, security teams still have to keep moving.
A GAO review highlights a compliance trap with real security consequences: overlapping reporting rules can force repeated submissions and, in some cases, conflicting ones.
A legal brief can look polished and still be poisoned by invented citations, turning generative AI from a productivity tool into an integrity risk.
The European Commission's €890 million penalty under the Digital Markets Act is a regulatory action, but it also highlights how search and app distribution can shape the security choices users make.
A new executive order puts domestic sourcing and tighter supply-chain oversight at the center of defense buying, turning materials origin into a security question.
A new legislative agenda points to a harder line on frontier AI, where testing, disclosure, and supply-chain security could become part of the operating model rather than optional best practice.
A Marketplace listing for an OT remote-access platform is less about hype than about how federal cloud assurance is shifting toward living evidence, tighter identity controls, and a harder look at operational risk.
A major donation to a policy advocacy group puts front-end AI governance, model oversight, and cyber-misuse concerns into the same frame.
A law-enforcement takedown of the Kratos phishing kit underscores a harder truth for cloud defenders: attackers are increasingly chasing live Microsoft 365 sessions, not just login credentials.
Chris Fall’s abrupt exit from CAISI is a leadership story, but it also exposes how much modern AI governance depends on continuity inside a small technical office.
Chris Fall’s resignation after roughly three months puts attention on whether the federal office behind AI standards and evaluation can keep its work moving without a leadership pause.
A U.S. enforcement action against more than 1,000 websites and 1,970 domains shows how quickly online piracy can be disrupted when the naming layer is targeted.
A lawsuit over alleged book training data shows how AI model pipelines can turn provenance, permissions, and governance into security-grade risks.
A Florida arrest tied to alleged malware spread through Steam games shows how trusted consumer software channels can become useful cover for endpoint infection and financial theft.
A directive aimed at dozens of “nudify” apps puts the spotlight on how major mobile marketplaces can be asked to police harmful software at speed.