Policy & LegalWired Security·1 week ago

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

U.S. Customs and Border Protection workers have allegedly exploited government databases to conduct unauthorized surveillance of personal contacts, including romantic interests and colleagues, according to records reviewed by WIRED. The documented cases reveal a pattern of internal tool misuse affecting hundreds of individuals, highlighting significant insider threat vulnerabilities within the agency's data access controls.

Policy & LegalRapid7 Blog·1 week ago

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

AI has moved from experimental pilot programs to embedded production systems in security operations centers, with 97% of SOC teams reporting positive outcomes—yet security executives are notably more concerned than frontline staff about data governance, accountability, and risk management. The confidence gap reflects a maturity shift: operational teams validated that AI works, while leaders now grapple with harder questions about governance, oversight, and what happens when AI systems fail. The organizations pulling ahead aren't choosing between AI and human expertise; they're building models where AI handles volume and pattern matching while analysts retain decision authority, and buyers increasingly expect transparency into how AI decisions are made rather than simply faster automation.

Policy & LegalDark Reading·1 week ago

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert has developed a five-point framework to address gaps in global cybercrime legislation that currently expose ethical hackers and security researchers to legal risk. The analysis maps existing cybercrime laws across jurisdictions to identify how outdated regulations fail to adequately protect good-faith security research activities. This framework aims to guide policymakers in updating laws to better distinguish between malicious hacking and legitimate security work.

Policy & LegalKrebs on Security·1 month ago

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics USA plans to ban residential proxy apps from its smart TV platform following researcher findings that over 42 percent of apps in its webOS store permit unknown third parties to route internet traffic through users' televisions. The suspension addresses security and privacy concerns around devices being weaponized as always-on proxy nodes without explicit user awareness. This action represents a significant step in addressing how consumer IoT devices can be exploited in proxy networks.

Policy & LegalCloudflare Blog·1 month ago

Why we cannot wait for better post-quantum signature algorithms

NIST is advancing nine new post-quantum signature algorithms toward standardization, but their timeline remains uncertain. Cloudflare argues that organizations should adopt ML-DSA immediately rather than wait for future candidates, as it represents the most mature and practical option currently available for post-quantum cryptography deployment.