Policy & LegalCyberScoop·1 day ago

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

Policy & LegalThe Hacker News·1 day ago

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to pay $400 million to settle a U.S. Department of Justice lawsuit alleging violations of child privacy laws, with $300 million due immediately and the remaining $100 million conditional on vacating a prior consent decree. The settlement resolves claims brought against ByteDance's social media platform in 2024 for its handling of children's personal data.

Policy & LegalCyberScoop·2 days ago

Lawmakers seek watchdog review of federal hacking of Americans

Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.

Policy & LegalHelp Net Security·2 days ago

Nearly half of enterprises have no one leading PQC migration

Nearly half of enterprises lack designated leadership for post-quantum cryptography migration efforts, despite believing they are adequately prepared for quantum computing threats, according to research from Axiad. The study reveals significant gaps in organizational readiness, including deficiencies in ownership structure, testing capabilities, and visibility into cryptographic assets—areas critical to successfully transitioning to PQC implementations. While 75% of respondents reported maintaining updated inventories of certificates and cryptographic keys, the absence of clear migration leadership suggests many organizations may struggle to execute their transition strategies effectively.

Policy & LegalCyberScoop·3 days ago

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

Policy & LegalCyberScoop·3 days ago

The push to designate AI as the next critical infrastructure sector

The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.

Policy & LegalMalwarebytes Labs·3 days ago

Twitch wants your content for Amazon AI training. Here’s how to opt out

Twitch has enabled content creators to opt out of having their streams and videos used for Amazon's AI model training, following a two-year delay since the platform initially confirmed it was already conducting such training. This move provides creators with control over their intellectual property but raises questions about why the opt-out mechanism was not offered from the start of the AI training program.

Policy & LegalBishop Fox·3 days ago

CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes to move from a reactive pile of findings to a continuous, prioritized risk reduction program.

Policy & LegalSANS Internet Storm Center·3 days ago

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

Microsoft Graph is an increasingly adopted API that enables querying and modifying information across M365, Entra users, and managed machines, presenting opportunities for both legitimate administration and reconnaissance activities. Security teams should be aware that PowerShell-based approaches using Microsoft Graph can identify organizational vulnerabilities such as stale accounts and unused licenses that may pose security risks if left unmanaged.

Policy & LegalInfosecurity Magazine·3 days ago

NCSC Urges Stronger Controls for Agentic AI Systems

The UK's National Cyber Security Centre has issued guidance recommending sandboxing, oversight mechanisms, and strict access controls as essential safeguards for autonomous AI agents. These recommendations aim to mitigate security risks inherent in agentic AI systems that operate with limited human intervention.

Load more