Policy & Regulation — Page 8

Security Executives Push Back on Anthropic Export Restrictions
A coalition of cybersecurity leaders argues that blocking foreign nationals from accessing Anthropic's latest models hands adversaries a strategic gift.

Feds Pull the Plug on CFAKE and SOCFAKE in First TAKE IT DOWN Act Domain Grab
DOJ seizes two deepfake nude sites that pulled tens of millions of visits a month, marking the first public test of the new federal statute.

US Orders Anthropic to Geofence Fable 5 and Mythos 5; Models Pulled Globally
Washington cites a jailbreak risk. Anthropic disagrees but complies, suspending both models worldwide rather than build a foreign-national access wall.

Anthropic Pulls Two AI Models Offline After Trump Administration Export Control Directive
Fable 5 and Mythos 5 go dark as the White House moves to block foreign-national access to frontier AI systems.

Google Takes Lighthouse PhaaS Operators to Court Over Gemini-Powered Smishing
Civil complaint targets a China-linked network behind the 'Outsider' phishing kit, alleging misuse of Gemini to scale text-message fraud against U.S. consumers.

US Surveillance Capabilities Temporarily Halted by Congressional Inaction
Congressional impasse leaves Section 702 in limbo, halting some warrantless surveillance.

MDR's AI Reckoning: When the Old Service Model Stops Keeping Up
Managed detection and response solved a staffing problem. It is not, by itself, an answer to adversaries who automate reconnaissance and intrusion at machine speed.

Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

CISA's New Directive: Agencies Must Prioritize High-Risk Security Patches
Federal agencies get their marching orders: focus on Known Exploited Vulnerabilities.

South Korea Fines Coupang ₩624.6 Billion Over 37M-Record Breach
The PIPC's record penalty under PIPA cites failures in access control and insider-threat monitoring tied to a 2024 intrusion attributed to a former contractor.

GitHub's npm Overhaul: No More Automatic Install Scripts
GitHub reshapes npm with default script blocking, aiming to tighten software supply chain security.

CISA's New Patching Directive Drops CVSS as the North Star
BOD 26-04 introduces a four-factor framework that prioritizes internet exposure, active exploitation, and attacker automation over raw severity scores — and gives agencies three days to act on the worst cases.

CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV
Three vulnerabilities added to the Known Exploited Vulnerabilities catalog activate BOD 22-01 remediation deadlines for civilian agencies.

Starmer's Device-Scan Mandate Puts Enterprise Encryption in the Crosshairs
The UK Prime Minister gave tech firms three months to build image-filtering controls into every device. Security leaders say the architecture required would gut encryption protections, create fresh exfiltration paths, and hand future governments a surveillance tool the current one insists it doesn't want.

Meta Expands Off-Platform Data Use to Feed Ranking and AI Chatbot Replies
Activity shared by third-party businesses — already feeding ad targeting — will now shape what users see in their feeds and how Meta AI answers their questions.