Policy & LegalThe Hacker News·3 days ago

Why "Shady AI" is Security's Next Big Governance Problem

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee

Policy & LegalSchneier on Security·3 days ago

Police Are Hiding Their Use of Flock Surveillance Cameras

Law enforcement in Wapello County, Iowa is operating under a usage policy that explicitly directs officers not to disclose their use of Flock automated license plate reader cameras to vehicle occupants or in official reports unless absolutely necessary. This practice of concealing surveillance technology deployment mirrors historical patterns seen with IMSI-catchers like Stingray devices, which police similarly went to great lengths to keep hidden from the public and legal proceedings.

Policy & LegalCyberScoop·4 days ago

A California county wants to hire Tina Peters to help run its elections

After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.

Policy & LegalSchneier on Security·4 days ago

ICE Collecting DNA Samples

ICE collected nearly a million DNA samples last year.

Policy & LegalWired Security·5 days ago

The Cop Who Took On Flock

A police officer who publicly criticized his department's use of Flock surveillance cameras faced retaliation through multiple internal affairs investigations within a short timeframe. The case highlights potential tensions between law enforcement accountability and the adoption of surveillance technology in policing.

Policy & LegalInfosecurity Magazine·5 days ago

UK Legal Regulator Raises AI Misuse Concerns

The UK's Solicitors Regulation Authority has flagged risks posed by artificial intelligence within the legal sector, specifically warning about AI hallucinations that could compromise case accuracy and data leaks that threaten client confidentiality. These concerns highlight regulatory scrutiny of AI adoption in professional services where errors and data breaches carry significant liability and compliance implications.

Policy & LegalInfosecurity Magazine·6 days ago

ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

The European Telecommunications Standards Institute has initiated an approval process for 17 cybersecurity standards that vendors must comply with under the Cyber Resilience Act. These standards are designed to establish baseline security requirements for organizations operating within the European regulatory framework. The move aims to strengthen cyber resilience across the region by creating consistent security benchmarks for vendor compliance.

Policy & LegalRapid7 Blog·6 days ago

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

African organizations across Egypt, Nigeria, South Africa, and Kenya are rapidly expanding their use of cloud infrastructure, AI, and digital services, but face a cybersecurity challenge that goes beyond technology access—security teams lack the time, context, and specialized capacity to effectively manage their expanding environments. Rapid7 and StarLink are partnering to address this gap by providing regional partners with technical enablement and expertise to help local organizations connect exposure management, threat detection, and response capabilities into cohesive security operations tailored to their specific needs.

Policy & LegalWired Security·1 week ago

New York City Lawmakers Push to ‘Ban the Scan’ at MSG

New York City lawmakers and privacy advocates are pushing for stricter regulations on biometric surveillance systems used at public venues like Madison Square Garden, with the effort dubbed "Ban the Scan." The coalition, which includes politicians and musicians, is calling for tighter restrictions on how such facial recognition and scanning technologies can be deployed at entertainment and gathering spaces.

Policy & LegalDark Reading·1 week ago

Cyera's Oasis Security Buy Is All About AI Agent Control

Cyera's $1 billion acquisition of Oasis Security seeks to unify data security and identity management into a consolidated control plane designed specifically for AI agents. The deal reframes privileged access management by shifting from traditional static role-based controls to a context-aware model grounded in business requirements.

Policy & LegalInfosecurity Magazine·1 week ago

Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone

Google Cloud has established 2027 as a key milestone to address store-now-decrypt-later threats through its post-quantum cryptography initiative, reflecting the industry's growing concern about adversaries harvesting encrypted data today for future decryption. The company's broader migration to post-quantum cryptographic standards is expected to extend through 2028, indicating a multi-year commitment to transitioning its infrastructure ahead of quantum computing threats.

Policy & LegalInfosecurity Magazine·1 week ago

Trump Authorizes Private Sector Participation in Offensive Cyber Operations

The White House has authorized private sector participation in government-directed offensive cyber operations targeting transnational groups, marking a significant shift in cyber warfare approach. Security experts have raised concerns about potential escalation and the difficulty of attributing attacks when private companies are involved in such operations.

Load more