Policy & Regulation — Page 9

Policy & Regulation

Executive Order Mandates AI Security Vetting

Federal directive requires AI models to undergo national security risk assessments before release.

2 min read
Policy & Regulation

Nominations Open for CSO30 ASEAN & Hong Kong Awards 2026

Recognizing leaders transforming cybersecurity into a business capability across ASEAN and Hong Kong.

2 min read
Policy & Regulation

Weekly Recap: Linux Privilege Flaw, PAN-OS Exploitation, and OAuth Phishing Surge

A patchy Monday across auth paths, repos, and dev tooling — with regulators watching the disclosure clock.

3 min read
Policy & Regulation

CSO30 ASEAN & Hong Kong Awards Opens Nominations for 2026 Cycle

Now in its sixth edition, the regional awards programme accepts submissions across three pathways through July 31.

2 min read
Policy & Regulation

India Sets a 12-Hour Clock on Exploited Vulnerabilities. Can Enterprises Actually Do It?

CERT-In's new AI-threat framework resets expectations around patch velocity — but the real test is whether organizations even know what's exposed.

3 min read
Policy & Regulation

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach

AG Rob Bonta is going after Chrome Holding Co. — the shell 23andMe rebranded into after its bankruptcy — arguing the company failed to adequately protect the genetic and personal data of millions of users.

2 min read
Policy & Regulation

What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity

A fresh read of 2024–2025 10-K Section 1.C filings shows NIST CSF dominance, audit committee capture, and a suspicious abundance of 'no material impact' disclosures.

3 min read
Policy & Regulation

GDPR Fines and the Looming AI Regulation Battle

As AI tech faces scrutiny, GDPR's enforcement lessons underline the coming regulatory challenges.

2 min read
Policy & Regulation

Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days

Redmond is invoking CVD principles after a researcher publicly posted unpatched flaws, raising fresh questions about the boundary between disclosure ethics and platform enforcement.

2 min read
Policy & Regulation

Shadow AI Is Now a Compliance Problem, Not Just an IT One

Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.

3 min read
Policy & Regulation

CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours

India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

3 min read
Policy & Regulation

Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules

Machine-learning-driven flood attacks are reshaping volumetric thresholds faster than current incident-reporting frameworks anticipated.

3 min read
Policy & Regulation

AI-Driven OT Security Is Only as Good as the Telemetry Feeding It

Fewer than 10 percent of OT networks have meaningful monitoring in place, according to the 2026 Dragos OT Cybersecurity Year in Review. Until that changes, layering machine-learning tools on top of industrial control systems may create more risk than it resolves.

5 min read
Policy & Regulation

Authorities Shut Down First VPN Over Criminal Ties

A European crackdown takes out a VPN aiding crime, but raises wider privacy concerns.

2 min read
Policy & Regulation

Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet

Federal prosecutors say Jacob Butler, 23, developed and rented out a variant of the AISURU botnet for paid denial-of-service attacks.

2 min read
© 2026 Threat Vectr