Policy & Regulation — Page 4

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Contractor Jailed Two Years After $2.5M Extortion Attempt Against Brightly Software
Cameron Curry stole payroll data on his way out the door, then threatened to report his ex-employer to the SEC unless it paid up.

White House Enlists Security Firms to Combat International Cybercrime
The U.S. government plans to work with security companies to target foreign cybercriminals. Firms may face penalties if they don't meet requirements.

America's Drinking Water Networks Are Getting a Long-Overdue Security Upgrade
A new Senate bill and a first-of-its-kind monitoring centre launched at DEF CON aim to plug gaping security holes in the water systems that supply millions of American homes.

UK Children Report Surge in Explicit Deepfake Images of Themselves
A service that helps young people remove intimate photos from the internet says digitally faked images are rising fast. Regulators warn AI tools are making the problem worse.

New Zealand Sanctions 33 Russia-Linked Cyber Operators and Child Abduction Networks
Wellington's latest penalties name hackers and individuals tied to the forced removal of Ukrainian children, signalling that digital warfare now sits alongside human-rights abuses on the sanctions list.

Train companies target 'donutters' and last-minute digital ticket fraud
A simple double-tap on a smartphone is costing UK rail operators millions. Here is how the schemes work and what operators plan to do about it.

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

Smart Glasses With Hidden Cameras Are Getting Popular. Privacy Experts Are Alarmed.
Ordinary-looking eyewear that secretly records video is moving from novelty to mainstream, and the rules haven't kept up.

Apple Takes UK Government Back to Court Over Demand to Read Encrypted User Data
Apple has filed a second legal challenge against a British government order requiring access to data so heavily protected that even Apple cannot read it. The case could decide whether end-to-end encryption survives as a meaningful privacy tool in the UK.

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.
At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack
Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract
A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here is what is changing and why it matters.

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means, and why it matters to everyone.