In the security news this week: FCC router bans and the hidden firmware update problem, Why extending support timelines actually improves security, Github supply chain concerns and the evolving SBOM ecosystem, CRA and NIS2 compliance deadlines are getting very real, The EU Cyber Resilience Act’s 24-hour vulnerability disclosure requirement, Securit...
The Take It Down Act mandates that online platforms remove nonconsensual intimate imagery and AI-generated "digital forgeries" within 48 hours of a victim's report.
The cyberattack on South Staffordshire Water Plc was initiated through a phishing attempt that allowed attackers to install undetected malware for nearly two years.
CISA is warning that state-sponsored hackers, specifically Chinese groups known as Salt Typhoon and Volt Typhoon, pose a continuous threat to vital sectors such as electricity, water, and internet services.
The FTC's complaint detailed how Kochava collected and sold geolocation data from hundreds of millions of mobile devices, enabling clients to track users' movements to and from sensitive locations such as health clinics and places of worship.
The FCC's unanimous vote on April 30, 2026, extends a prior ban on state-affiliated Chinese labs to encompass all laboratories within China and Hong Kong.