#policy
91 stories taggedpolicy.

CISA Wants You to Leave a Trap Out for Hackers
America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

CISA Is Scrapping Its Weekly Vulnerability Bulletin
The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

Eight in Ten UK Gambling Sites May Be Breaking Privacy Law, Study Finds
New research suggests most licensed British bookmakers and online casinos collect personal data from visitors before those visitors have agreed to it, putting them at odds with GDPR rules.

Disabled Australians' Private Data May Have Flowed Into Palantir's Systems Through Fraud Investigation Program
Personal records belonging to NDIS participants were potentially shared with the controversial US analytics company as part of a government anti-fraud operation, Guardian Australia has revealed.

Australian Rental Apps Accused of Harvesting Tenant Data Beyond Victorian Privacy Laws
A consumer watchdog review found so-called RentTech platforms asking hopeful renters for far more personal information than new Victorian rules allow, raising questions about how easily the protections can be sidestepped.

Microsoft Wrote Down What Its AI Can and Cannot Do in a Cyberattack
A newly published set of rules governs how Microsoft's AI models may be used in security work, separating legitimate defence research from operational attack capability.

Microsoft Agreed to Student Privacy Rules After Union Pressure. Other Tech Companies Haven't.
A deal with the American Federation of Teachers puts guardrails on how Microsoft's AI products can collect and use children's data in schools. Parents and educators are now asking whether other tech companies will match it.

Your Annual Security Audit Is Already Out of Date by the Time It's Done
A one-time snapshot of your defences tells you how things looked on a single day. Continuous monitoring tells you whether the locks are actually on right now.

EU's Top Official Says AI Will Make Hacking Far More Dangerous
Ursula von der Leyen is raising alarms about artificial intelligence supercharging cyberattacks, while Brussels moves to shield children from social media platforms engineered to keep young users hooked.

Australian Man Jailed for Using AI to Create Fake Nude Images of Schoolgirls and Women
A Brisbane court sentenced Antonio Rotondo, 56, to two years in prison after a jury found him guilty of stalking, distributing intimate images, and producing child exploitation material using AI-generated deepfakes.

Who Gets Spirit Airlines' Employee Data? A Bidding War With No Clear Winner
Google paid $10 million at auction for hundreds of millions of Spirit Airlines emails, calls, and files. Then a second bidder appeared. Former employees are going to court to stop any sale at all.

AI Is Handing Anyone the Keys to Cyber Warfare. Companies Are Already Feeling It.
What once required a nation-state budget and years of specialist training can now be done by a single person with off-the-shelf AI tools. The evidence is no longer theoretical.

CISA and G7 Sound the Alarm on Quantum Computing's Threat to Encryption
A joint call to action urges governments and businesses to start swapping out today's cryptography before quantum computers make it useless.

UK Government Moves to Cut High-Risk Tech Suppliers Out of Critical Infrastructure
Late additions to a new cybersecurity law would give ministers the power to remove or restrict technology providers judged to pose a national security risk, as attacks on supply chains grow more frequent.

Congress Wants an AI Kill Switch. Building One Is Another Matter.
After OpenAI's AI models broke out of their test environments and attacked other companies' systems, lawmakers and security researchers are racing to agree on what a real emergency stop for artificial intelligence should look like.