Policy & Regulation — Page 15

Weekly Recap: Old Tricks, New Victims — Poisoned Packages, a Chatbot Bypass, and a GitHub Worm
A week of loud incidents masked quieter intrusions. The common thread: failures that should have been caught at code review.

AI-Generated Phishing Is Drowning SOC Queues. The Policy Response Is Lagging.
Tier 1 analysts face a volume problem that existing disclosure and reporting regimes were not built to absorb.

Anthropic Pushes for Verified AI Pause Mechanism Among Leading Labs
The company wants coordinated verification protocols that could let frontier AI developers confirm rivals have genuinely halted or slowed development if safety risks cross certain thresholds.

Voluntary AI Security Rules: The Industry Already Knows What That Means
Trump's AI cybersecurity executive order drew polite applause from vendors and quiet skepticism from practitioners. The gap between those two reactions is where the real story lives.

Inspector General Pins NVD Backlog on NIST Mismanagement — But the Real Problem Runs Deeper
A Commerce Department IG report calls out strategic failures, duplicated work, and severity scores that matched only 12% of the time. Budget cuts and genAI-driven vuln volume tell the rest of the story.

Webinar Highlights Gaps in Third-Party Risk Management
A critical look at third-party risk programs and their practical failures.

HD Moore's Pitch to Defenders: Stop Racing Patches, Reshape the Network
The Metasploit creator argues blast-radius control, not patch velocity, is what regulators and boards should be measuring.

Trump Signs AI Cybersecurity Order, Reviving the Pre-Release Review Provisions His Team Killed Two Weeks Ago
The new directive creates a voluntary framework for government review of frontier AI models and spins up a Treasury-led vulnerability clearinghouse — while going out of its way to say none of this is mandatory.

Executive Order Mandates AI Security Vetting
Federal directive requires AI models to undergo national security risk assessments before release.

Nominations Open for CSO30 ASEAN & Hong Kong Awards 2026
Recognizing leaders transforming cybersecurity into a business capability across ASEAN and Hong Kong.

Weekly Recap: Linux Privilege Flaw, PAN-OS Exploitation, and OAuth Phishing Surge
A patchy Monday across auth paths, repos, and dev tooling — with regulators watching the disclosure clock.

CSO30 ASEAN & Hong Kong Awards Opens Nominations for 2026 Cycle
Now in its sixth edition, the regional awards programme accepts submissions across three pathways through July 31.

India Sets a 12-Hour Clock on Exploited Vulnerabilities. Can Enterprises Actually Do It?
CERT-In's new AI-threat framework resets expectations around patch velocity — but the real test is whether organizations even know what's exposed.

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach
AG Rob Bonta is going after Chrome Holding Co. — the shell 23andMe rebranded into after its bankruptcy — arguing the company failed to adequately protect the genetic and personal data of millions of users.

What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity
A fresh read of 2024–2025 10-K Section 1.C filings shows NIST CSF dominance, audit committee capture, and a suspicious abundance of 'no material impact' disclosures.