Cyber Cookie mascotCyber Cookie
Menu ▾

Section Archive

Compliance Pulse

77 entries across all issues

Issue #87· September 11, 2026
Compliance Pulse

EU Cyber Resilience Act: 24-Hour Breach Reporting Starts Today

Starting today, any organisation that sells internet-connected products in the EU must report actively exploited vulnerabilities or serious security incidents to ENISA (the European Union Agency for Cybersecurity) within 24 hours of discovery, per Dark Reading. A fuller notification is due within 72 hours. Missing the window risks fines of up to €15 million or 2.5% of global annual revenue. Physical location doesn't matter — if you sell into EU markets, this applies to you. Small enterprises under 50 employees have limited exemptions; larger organisations do not.

Issue #85· September 9, 2026
Compliance Pulse

FBI Publishes Its First Public Cybersecurity Strategy

The FBI has released a 17-page public cybersecurity strategy, its first ever, according to The Record. The document outlines four pillars: imposing costs on attackers, supporting victims, working with private industry, and building the FBI's own digital capabilities. The bureau says it will pursue more frequent disruptive operations rather than waiting for large-scale joint actions a handful of times a year. For everyday users, this signals a more aggressive federal posture toward ransomware gangs and state-sponsored hackers.

Issue #83· September 7, 2026
Compliance Pulse

No major compliance or regulatory updates today.

The BSI advisory referenced in today's Berlin breach story is an operational warning rather than a new regulation or mandate. No new government directives, data protection authority rulings, or legislative changes affecting cybersecurity compliance were announced in the last 24 hours.

Issue #81· September 4, 2026
Compliance Pulse

US and UK Sign Formal Agreement to Coordinate Scam Compound Takedowns

The United States Department of Justice and the UK's National Crime Agency signed a memorandum of understanding this week committing both countries to parallel investigations and shared intelligence on the organised crime networks running Southeast Asian scam compounds, according to The Record. More than $12 billion was stolen from Americans alone last year through these schemes. The two agencies have already identified overlapping cases and plan a joint disruption event in London in October.

Issue #79· August 31, 2026
Compliance Pulse

ChatGPT, Reddit, and Roblox Now Under EU's Toughest Platform Rules

The European Commission has designated ChatGPT, Reddit, and Roblox as Very Large Online Platforms or Search Engines under the Digital Services Act (DSA — EU rules requiring large platforms to actively manage harmful content and systemic risks). All three declared over 45 million monthly EU users. They now have until January 2027 to comply with obligations including risk assessments for illegal content, algorithmic transparency, and protections for minors. For everyday users, this means stronger rights around how these platforms moderate content and handle your data.

Issue #77· August 28, 2026
Compliance Pulse

White House Bans Foreign-Made Power Grid Equipment Over Backdoor Risk

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity transmission and generation, citing concerns that equipment may contain digital backdoors allowing foreign governments remote access, according to The Record.

The order covers high-voltage transmission infrastructure, control rooms, substations, and associated software. Senior officials have 120 days to produce rules identifying which countries "warrant particular scrutiny." Agencies must also inventory currently deployed at-risk equipment and submit replacement plans.

For critical infrastructure operators, compliance reviews should begin now rather than at the 120-day deadline.

Issue #75· August 26, 2026
Compliance Pulse

CISA: Over 100 Water Systems Hit in July, Linked to Iranian Threat Actors

CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks in July 2026, according to Security Week. The attacks, linked to Iranian threat actors, focused on programmable logic controllers (PLCs — the computers that physically operate industrial equipment) connected directly to the public internet via cellular modems. At least 12 states were affected, though no significant disruption occurred. CISA has published updated guidance urging water utilities to remove unnecessary internet exposure, enforce multi-factor authentication, and monitor industrial control systems continuously.

Issue #73· August 24, 2026
Compliance Pulse

Uber Handed €825 Million GDPR Fine Over Automated Driver Decisions

The Dutch Data Protection Authority has fined Uber €825 million ($964 million) for violating the EU's General Data Protection Regulation (GDPR — the EU's rules governing how companies handle personal data), according to SecurityWeek. The authority found Uber used automated software to permanently suspend driver accounts between 2018 and 2022 with no human review and no meaningful notice to drivers. GDPR prohibits fully automated decisions that significantly affect people. Uber has said it will appeal. For anyone who earns income through platform apps, this ruling is a reminder that automated bans without human oversight are increasingly the target of regulators across Europe.

Issue #72· August 24, 2026
Compliance Pulse

TikTok Pays $400 Million Over Children's Privacy Violations

TikTok has settled a US Department of Justice lawsuit for $400 million, resolving allegations it collected personal data from children under 13 without parental consent — and ignored parent requests to delete those accounts, according to Security Week. The case was brought under COPPA (the Children's Online Privacy Protection Act), the federal law requiring parental consent before collecting data from young children. If your child uses TikTok, review their account settings and check what data the app holds. You have the right to request deletion.

Issue #70· August 21, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch Critical MLflow Flaw Within Two Weeks

CISA has added CVE-2026-64849 to its Known Exploited Vulnerabilities catalogue and ordered U.S. federal agencies to patch within two weeks, according to Bleeping Computer. MLflow is an open-source platform used to build and manage AI applications. The flaw allows an unauthenticated attacker to reach internal systems and steal cloud credentials such as AWS access keys. Attackers began scanning for vulnerable instances within hours of the CVE being assigned.

What you should do: If your organisation uses MLflow, upgrade to version 3.15.0 immediately and audit your logs for signs of unauthorised access.

Issue #68· August 19, 2026
Compliance Pulse

CISA: Medusa Ransomware Has Now Hit Over 500 Critical Infrastructure Organisations

CISA, leading a joint advisory with the FBI and the Department of Health and Human Services, confirmed that the Medusa ransomware gang has breached more than 500 critical infrastructure organisations in the United States since 2021 — up from 300 just over a year ago, according to Bleeping Computer. Targets include healthcare, finance, government, and education. The advisory recommends patching known vulnerabilities, segmenting networks to limit lateral movement (an attacker's ability to move from one system to others once inside), and blocking untrusted remote access.

Issue #66· August 16, 2026
Compliance Pulse

CISA Adds Cisco Firewall Flaw to Its Must-Patch List

CISA — the US Cybersecurity and Infrastructure Security Agency — has added CVE-2026-20349, a high-severity vulnerability in Cisco firewall software, to its Known Exploited Vulnerabilities catalog. The flaw is actively being used to temporarily knock Cisco firewalls offline. US civilian federal agencies were required to apply fixes by 14 August 2026. If your organisation runs Cisco firewalls and has not yet patched, treat this as urgent. Full details are available via Help Net Security.

Issue #65· August 15, 2026
Compliance Pulse

France's Tax Authority Confirms Breach of Up to 600,000 Citizens' Records

France's Directorate General of Public Finances (DGFiP) confirmed that an attacker accessed its internal systems in late June after stealing or misusing an employee's identity, according to The Record. A hacker using the alias ZeroBytes claims to have extracted data on over 600,000 people, including tax identification numbers, family details, and financial status — the kind of data that enables highly targeted fraud. French authorities have opened a criminal complaint and will notify affected individuals. It is the latest in a string of French government breaches this year.

Issue #64· August 14, 2026
Compliance Pulse

EU Cyber Resilience Act: 17 Draft Standards Open for Comment

Seventeen draft technical standards for the EU's Cyber Resilience Act (a law requiring connected products sold in Europe to meet mandatory cybersecurity requirements) are now open for review, according to Help Net Security. The standards cover products including smart home assistants, password managers, and connected toys. Manufacturers who follow an approved standard gain a presumption of legal compliance. The comment window closes between mid-September and mid-November 2026, with the full obligation kicking in at the end of 2027. Small businesses selling any connected hardware or software into European markets should read the relevant draft now, not after the deadline.

Issue #63· August 13, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch CVE-2026-68820 by 25 August

The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-68820, the Windows WinSock privilege escalation flaw exploited by North Korea's Lazarus Group, to its Known Exploited Vulnerabilities catalogue, according to The Record. Federal agencies have until 25 August to apply the patch. For everyone else, the directive underlines what the evidence already shows: this is the only confirmed in-the-wild exploit from August's Patch Tuesday. A device restart is required and no workaround exists.

Issue #62· August 12, 2026
Compliance Pulse

CISA Confirms Ransomware Gangs Are Actively Exploiting a SharePoint RCE Flaw

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to confirm that ransomware groups are actively exploiting CVE-2026-45659, a high-severity SharePoint flaw that allows low-privileged attackers to execute code on unpatched servers, per Bleeping Computer. Federal agencies were ordered to patch within three days of the July 1 listing. Shadowserver currently tracks over 8,500 SharePoint servers exposed online, with more than 200 still unpatched. If you run SharePoint on-premises, apply Microsoft's latest patches now and enable Windows Antimalware Scan Interface (AMSI) integration for your SharePoint web applications.

Issue #61· August 11, 2026
Compliance Pulse

US Senators Propose $300 Million a Year to Secure Water Infrastructure

Two Democratic senators introduced the Water Cyber Shield Act this week, proposing $300 million in annual funding to improve cybersecurity across US water and wastewater systems. The bill would give the EPA authority to conduct security assessments, mandate corrective action when vulnerabilities are found, and require incident reporting in line with the forthcoming CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act). The push follows attacks on at least 30 water systems across 12 states, attributed to groups linked to Iran's military. For everyday residents: cleaner regulation of the systems that supply your drinking water is the goal.

Issue #60· August 10, 2026
Compliance Pulse

The EU AI Act Is Now Being Enforced — and You Can File a Complaint

As of 2 August 2026, the EU's AI Office and national authorities began actively enforcing the AI Act — the world's first broad legal framework regulating artificial intelligence — according to Help Net Security.

Fines run up to €15 million or 3% of global annual turnover. The AI Office has launched a public complaints tool, a whistleblower channel for insiders, and a downstream complaints process for businesses building on top of others' AI systems. For most people and small businesses, the most important thing to know is that the mechanism now exists: if you believe an AI system has caused harm, there is a formal place to report it.

Issue #59· August 9, 2026
Compliance Pulse

No major compliance updates today.

The TrueConf supply chain attack is worth flagging for organisations operating under vendor risk or software integrity policies. Kaspersky's finding that attackers replaced a signed installer with an unsigned malicious version is a direct argument for enforcing code-signing verification policies — checking that software carries a valid, unaltered digital signature before installation. If your organisation has a vendor management framework, a check on whether software update integrity is contractually required from suppliers is a reasonable next step.

Issue #58· August 7, 2026
Compliance Pulse

EU AI Act Enforcement Begins — Fines Are Not the First Risk

The EU AI Act's transparency obligations under Article 50 are now in scope for enforcement. Organisations that deploy AI systems interacting with people must disclose that users are talking to AI. Violations carry fines of up to €15 million or 3% of global turnover.

In practice, the first year will likely bring corrective orders before large fines. The real near-term risk is being ordered to suspend or withdraw an AI process at short notice — potentially more disruptive than any financial penalty.

If your organisation uses AI-assisted customer communication or ticketing, audit it now.

Help Net Security