Policy & Regulation — Page 16

GDPR Fines and the Looming AI Regulation Battle
As AI tech faces scrutiny, GDPR's enforcement lessons underline the coming regulatory challenges.

Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days
Redmond is invoking CVD principles after a researcher publicly posted unpatched flaws, raising fresh questions about the boundary between disclosure ethics and platform enforcement.

Shadow AI Is Now a Compliance Problem, Not Just an IT One
Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.

CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours
India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules
Machine-learning-driven flood attacks are reshaping volumetric thresholds faster than current incident-reporting frameworks anticipated.

AI-Driven OT Security Is Only as Good as the Telemetry Feeding It
Fewer than 10 percent of OT networks have meaningful monitoring in place, according to the 2026 Dragos OT Cybersecurity Year in Review. Until that changes, layering machine-learning tools on top of industrial control systems may create more risk than it resolves.

Authorities Shut Down First VPN Over Criminal Ties
A European crackdown takes out a VPN aiding crime, but raises wider privacy concerns.

Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet
Federal prosecutors say Jacob Butler, 23, developed and rented out a variant of the AISURU botnet for paid denial-of-service attacks.

Dutch Investigators Seize 800 Servers, Arrest Two Tied to Stark Industries Successor
FIOD raids in Enschede, Almere, Dronten and Schiphol-Rijk target MIRhosting and WorkTitans BV over alleged sanctions breaches linked to Russian influence operations.

npm Introduces Staged Publishing With Mandatory 2FA Gate for Maintainer Approval
GitHub's package registry now requires a human maintainer to clear a two-factor challenge before a release leaves a staging area, a control aimed at the supply chain attacks that have repeatedly compromised the JavaScript ecosystem.

Agentic AI Quietly Rewrites the NDR Pitch, But Procurement Rules Have Not Caught Up
Network detection vendors say autonomous triage is thinning the alert queue. Buyers are now asking what regulators will let those agents actually do.

Twelve Hours, or Else: India's New Patch Clock Starts Ticking
CERT-In tells operators of internet-facing systems to close critical flaws within half a day, citing AI-assisted exploit chains that compress the attacker's runway to minutes.

Dutch Authorities Arrest Two Bulletproof Hosting Administrators Linked to Russia-Aligned Threat Actors
The two suspects owned Dutch-registered companies that allegedly supplied infrastructure used to support Russia-aligned cybercriminal operations.