Data breaches and website tracking technologies may seem like distinct privacy risks, but the California Supreme Court’s recent decision in J.M. v. Illuminate Education could affect litigation involving both. Businesses that collect sensitive information should review how they characterize, protect, and share that information, as plaintiffs will likely rely on the decision to challenge both cybersecurity practices and disclosures involving website tracking technologies. The case arose from a cyberattack on a K-12 education software provider that stored student health-related information. A student filed a putative class action alleging violations of California’s Confidentiality of Medical Information Act (CMIA) and Customer Records Act (CRA). Although the California Supreme Court ultimately held that Illuminate was neither a covered health care provider under the CMIA nor subject to liability under the CRA because the plaintiff was not a “customer,” it adopted a broader standard for CMIA confidentiality claims. The Court held that actual viewing or misuse of compromised information is not required where a breach creates a significant risk of unauthorized access or use. The broader significance of Illuminate is the Court’s focus on exposure to unauthorized access or use rather than proof that someone actually viewed the data. Plaintiffs will likely seek to extend that reasoning beyond CMIA claims and into litigation involving the California Consumer Privacy Act (CCPA), California Invasion of Privacy Act (CIPA), and website tracking technologies. In particular, plaintiffs may argue that liability can arise from the transmission of information through cookies and pixels without proof that anyone actually viewed the data, so long as the disclosure created a significant risk of unauthorized access or use. Therefore, Illuminate should not be viewed as a case affecting only healthcare organizations or victims of data breaches. Its reasoning could ultimately affect virtually every California employer that maintains employee data and every website
Jun 16, 2026 · via procopio.com
Brussels to the Bay: Securing the hyperconnected EU-US perspectives on cybersecurity EU The livestream of this event is now available by clicking here. Cybercrime cost the global economy over $10 trillion last year, with public services, transport, digital infrastructure, finance, and manufacturing among the hardest hit sectors. Ransomware attacks are projected to occur every two seconds by 2031. As digital systems become increasingly central to economic and societal functioning, cyber threats are expected to intensify, prompting both the EU and the United States to refine their approaches through regulation, public-private partnerships, and international cooperation. Against this backdrop, the Brussels to the Bay session, “Securing the hyperconnected EU-US perspectives on cybersecurity,” organized by the EU Office in San Francisco, convened Andrew Grotto (Stanford scholar and former White House Senior Director for Cybersecurity Policy under the Obama and first Trump administrations), Despina Spanou (Deputy Director-General at the European Commission, DG CNECT), Christiane Kirketerp de Viron (Director for Cyber at DG CNECT), and Edvardas Šileris (Head of European Cybercrime Centre, EUROPOL). The discussion took place amid new policy initiatives on both sides of the Atlantic. The EU recently introduced measures to strengthen EU cybersecurity resilience and capabilities while fostering market development through harmonised standards. In parallel, the White House published the “Cyber strategy for America,” signalling a shift toward a more proactive, technology-driven approach to securing digital infrastructure. While these models differ, both prioritise resilience and emerging technologies: the EU focuses on building a trusted marketplace through regulatory clarity, whereas the United States emphasises proactive defence and technological leadership. The panel explored how these approaches can complement one another to strengthen the global cybersecurity ecosystem, gathering panellists’ views and perspectives around key questions: - In what ways can these two different approaches complement each other to foster a more robust global ecosystem for
Jun 16, 2026 · via eeas.europa.eu
The Trump administration released a long-anticipated executive order this month aimed at exercising oversight of cybersecurity risks posed by the most advanced artificial intelligence models. The order attempts to thread the needle between the administration’s anti-regulatory posture and the recognition that it cannot remain on the sidelines in the face of AI’s serious risks to national security. Last week’s chaotic federal ban on foreigners from using Anthropic’s new Claude Fable 5, however, may have provided a preview of how the administration’s regulation of AI will play out, and many questions remain. Fable 5 is the publicly accessible version of Claude Mythos 5, a large language model the company released in April 2026 that is capable of identifying security flaws in software systems. The model can help governments, banks, utilities, hospitals, and other providers of essential services detect and patch the holes. But bad actors could also use this capability to exploit these weaknesses to freeze payment networks, shut down hospitals, and take telecommunications and internet services offline. The release of Mythos was part of the motivation behind President Trump’s order, which establishes a voluntary process for AI developers to submit their models to the government for classified testing for a period of up to 30 days, after which they can release the model to other trusted partners. The order also creates an “AI security clearinghouse” that fosters collaboration between AI developers and operators of critical infrastructure to identify and patch software vulnerabilities. The administration’s newfound openness to AI safeguards will not by itself undo the evisceration and politicization of regulatory agencies that are now expected to shoulder the responsibility of testing, mitigating, and overseeing a rapidly evolving threat landscape. Testing and threat sharing alone will not head off a cybersecurity catastrophe. Achieving that will also depend on how the administration
Jun 16, 2026 · via brennancenter.org
Julie Devoll, HBR Hello, my name is Julie Devoll, editor of special projects and webinars at Harvard Business Review. I recently had the pleasure of attending Zero Trust World and sitting down with Sami Jenkins, [chief operating officer] and cofounder of ThreatLocker. Sami discussed the challenges of building high-performing cybersecurity teams and addressing the industry’s talent shortage and why organizations must stay actively engaged in managing their security. Sami, thank you so much for joining us today. Sami Jenkins, Threatlocker Thank you for having me. Julie Devoll, HBR So ThreatLocker brings together developers, security engineers, researchers, and operations teams. What challenges come with structuring an organization that brings together so many specialized disciplines? Sami Jenkins, Threatlocker And the biggest challenge is getting everybody to work together at times. And we have a phenomenal team, and we do work at a rapid pace. And then finding the right talent, especially local to Orlando—we are office-based here and it is just finding the skill set at times. Our teams do work very, very closely together, and they build a product, obviously. And so with ThreatLocker works, we have our developers who together. And then we’ve got our infrastructure push to build, and then we’ve got a help desk for customers as well. And the biggest challenge from day one, in a sense, is just structuring teams, in a sense. So I’m responsible for building the teams. I still personally hire quite a lot of the people on the team. So as we grow, we always find different areas that need different skill sets. So currently, we’re working on building the solutions engineering team because, hey, we just released a new product. So I need more people to onboard that new product. Julie Devoll, HBR Got it. So cybersecurity is facing a significant
Jun 16, 2026 · via hbr.org
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF). The following versions of Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP are affected: - CompactLogix 5370 <=34.016 (CVE-2026-11317) - Compact GuardLogix 5370 <=35.015 (CVE-2026-11317) - ControlLogix 5570 <=35.015 (CVE-2026-11317) - GuardLogix 5570 36.012 (CVE-2026-11317) | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 7.5 | Rockwell Automation | Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP | Improper Resource Shutdown or Release | Background - Critical Infrastructure Sectors: Critical Manufacturing - Countries/Areas Deployed: Worldwide - Company Headquarters Location: United States Vulnerabilities CVE-2026-11317 A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover. Affected Products Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Rockwell Automation Rockwell Automation CompactLogix 5370: <=34.016, Rockwell Automation Compact GuardLogix 5370: <=35.015, Rockwell Automation ControlLogix 5570: <=35.015, Rockwell Automation GuardLogix 5570: 36.012 known_affected Remediations Vendor fix Rockwell Automation recommends users to update to the following versions: CompactLogix 5370: Versions 34.016 and later Vendor fix Compact GuardLogix 5370: Versions 35.015 and later Vendor fix ControlLogix 5570: Versions 36.012 and later Vendor fix GuardLogix 5570: Versions 37.011 and later Mitigation For more information, see Rockwell Automation Security Advisory SD1772 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1772.html) https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1772.html Relevant CWE: CWE-404 Improper Resource Shutdown or Release Metrics | CVSS Version | Base Score | Base Severity | Vector
Jun 16, 2026 · via cisa.gov
President Donald Trump has signed a new National Security Presidential Memorandum aimed at strengthening the cybersecurity of the federal government’s most sensitive military and intelligence networks. The June 12 memo, issued at a time of growing concern about cyber threats from China and other adversaries, re-constitutes the Committee on National Security Systems (CNSS) to oversee the cybersecurity of National Security Systems (NSS) across federal agencies. It puts the director of the National Security Agency (NSA) in a strengthened role as National Manager for National Security Systems, empowering the director “to leverage the full technical power of the National Security Agency to provide advanced defenses and assistance in order to bolster the security of NSS across the U.S. government,” according to a White House fact sheet. The memo establishes National Institute of Standards and Technology (NIST) cybersecurity standards as a baseline for NSS, saying the systems must meet or exceed NIST protection levels. It also requires each national security agency to “maintain and annually update” an inventory of its national security systems, while adding that the CNSS will request secure configuration baselines from cloud service providers accredited to host NSS within120 days. “It is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions,” Trump said in the memo. “It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable.” Bob Ackerman, co-founder and managing partner at DataTribe and founder and chairman of the Global Cyber Innovation Summit (GCIS), offered praise for the memo. “This action is a pragmatic acknowledgement of the cyber threats targeting our country and calls for a long overdue, holistic cyber defense
Jun 16, 2026 · via meritalk.com
SoftBank to Launch Cybersecurity Service in Japan
Newsfrom Japan
Economy Technology- English
- 日本語
- 简体字
- 繁體字
- Français
- Español
- العربية
- Русский
Tokyo, June 16 (Jiji Press)--Japan's SoftBank Group Corp. said Tuesday that it will launch a domestic cybersecurity service to help companies detect vulnerabilities and take countermeasures.
The service uses advanced artificial intelligence technologies developed by OpenAI, the U.S. developer of ChatGPT.
SoftBank Group aims to support companies in strengthening their digital defense capabilities amid growing concerns over the misuse of advanced AI models, such as Claude Mythos, developed by U.S. startup Anthropic.
The service will identify vulnerabilities in security systems, support companies in drawing up guidelines for applying patches and propose methods for implementing those countermeasures.
SoftBank Group will initially offer the service to about 100 firms, including operators of important social infrastructure, such as finance and telecommunications.
[Copyright The Jiji Press, Ltd.]
Jun 16, 2026 · via nippon.com
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP, and WebSocket protocols." Like its Linux counterpart, the Windows versions support more than 30 commands to facilitate system information collection, process enumeration, service management, and file system operations. WIN_DRV has also been found to utilize kernel drivers to conceal the malware's network connections, processes, files, and registry keys. In addition, the variant enables TCP traffic diversion that allows the malware operators to send commands to the backdoor through a random TCP port on the victim's device without exposing the backdoor's actual listening port in the network traffic. SprySOCKS was first publicly documented by Trend Micro in September 2023, attributing its use to a China-nexus state-sponsored threat actor known as Earth Lusca, which is also tracked by the cybersecurity community under the monikers Aquatic Panda, Bronze University, Charcoal Typhoon, and RedHotel. The adversary is assessed to be active since at least 2021 and operated by a Chinese contractor named i-Soon. The Slovakian cybersecurity vendor, which has assigned the name FishMonger to the threat cluster, has described it as a cyber espionage group that falls under the broader Winnti umbrella. In a report published in March 2025, the company linked the hacking group to a global campaign dubbed Operation FishMedley targeting seven organizations in Taiwan, Hungary, Turkey, Thailand, France, and the U.S. between January and October 2022. SprySOCKS is based on a Windows remote access trojan called Trochilus, and shares several common traits with RedLeaves, a backdoor that also exhibits extensive source code overlaps with Trochilus. What's
Jun 16, 2026 · via thehackernews.com
Leading the Development of a Cybersecurity and AI Ecosystem in Puerto Rico Yarice Hidalgo (GBEL 2025, Puerto Rico) shares her reflections on leadership as a collaborative and human-centered practice, the values that guide it, and the role of innovation, cybersecurity, and artificial intelligence (AI) in building inclusive and sustainable development in Puerto Rico. By Guadalupe Ramirez In the following interview, Yarice shares some of the experiences and perspectives that have shaped her professional journey. As a professional with an outstanding career across the private and social sectors, as well as valuable experience serving on executive committees, how do you define leadership and what values do you consider essential to the way you practice it? From my perspective, a good leader is the key element a team needs at any given moment to bring out the best in each person. Sometimes, a leader acts as an observer and provides an external perspective that enriches the analysis; other times, they guide the team’s reflection process to encourage creative solutions. One of the greatest misconceptions about leadership is the belief that a leader must always be the one directing. On the contrary, many times a leader must allow themselves to be guided by the team in order to create spaces for critical thinking and collective creativity. It is precisely in those spaces that solutions and conclusions emerge—ones that, individually, I may have never imagined. Georgetown’s comprehensive approach to education, critical thinking, and commitment to social justice guide our mission. In your case, what values guide you personally and professionally? Humility, transparency, and humanity guide my work. I consider myself fortunate to have built a career dedicated to strengthening historically underrepresented communities, recognizing their potential from a perspective of abundance. My experience as an intern at ABC Boston’s first Hispanic program taught me to
Jun 16, 2026 · via lalp.georgetown.edu
Venza Named 2026 “TravelTech Cybersecurity Solution of the Year” By TravelTech Breakthrough Venza Named 2026 “TravelTech Cybersecurity Solution of the Year” By TravelTech Breakthrough Venza, a leading provider of cybersecurity, data protection, and compliance solutions for the hospitality industry, announced it has been awarded “TravelTech Cybersecurity Solution of the Year” in the 4th annual Travel Tech Breakthrough Awards program conducted by TravelTech Breakthrough, a leading independent market intelligence organization that evaluates and recognizes standout travel technology companies, products and services around the globe. The Venza Cybersecurity & Threat Protection system offers hotels that operate across distributed locations, shared technology environments and high-volume payment and guest data workflows full coverage protection. The platform provides end-to-end visibility into cybersecurity risk and compliance across properties and portfolios, enabling hotel executives to clearly understand exposure, prioritize action and measure progress. Venza brings together risk management, PCI compliance and human-centric security awareness into a single integrated system. This includes expert-led PCI guidance, continuous vulnerability scanning, penetration testing and hospitality-specific training and social engineering simulations designed around real-world hotel threats. “We’re proud to receive ‘TravelTech Cybersecurity Solution of the Year’ from TravelTech Breakthrough. We believe our core innovation is reframing cybersecurity and compliance as a business-critical operational discipline rather than a purely technical function. Uncovering exposures early and turning those findings into action, before they can be used against you, is essential,” said James Filsinger, CEO of Venza. “Through deep hospitality expertise and a technology-first approach to cybersecurity, we will continue to deliver technology that addresses the industry’s most persistent and complex security challenges, setting the standard for how travel and hospitality organizations protect sensitive data in an increasingly complex threat landscape.” The mission of the annual TravelTech Breakthrough Awards program is to recognize the innovators transforming the global travel landscape through technology. The program conducts
Jun 16, 2026 · via hospitalityupgrade.com
"These tools are moving so fast, do we really have the ability to actually maintain and keep up with where this stuff is at?" said Alan Webber. Interview transcript Terry Gerton As countries race to adopt artificial intelligence, the challenge is building capability they actually control without falling behind or over relying on outside providers. You saw some of that in the Anthropic and Fable 5 conversation over the weekend. Alan Weber, Program Vice President for National Security, Defense and Intelligence at IDC, tells us what it takes to get that right. Mr. Weber, thank you so much for joining me today. Alan Webber Thank you for having me. I appreciate it. Terry Gerton We have been talking a lot about AI in terms of pilots and experimentation, but this new research suggests that something is changing. Where do you see governments now on the AI development and deployment curve? Alan Webber Wow, they’re really finally beginning now. Let me start with the fact that it’s highly dependent upon levels of government, maturity of the government organization, civilian versus defense, things like that. So overall, if I had to say generally, it’s really towards the fact that it is moving from pilot to actual implementation in certain places. I would still call it spotty, is how I might refer to it. I wouldn’t say it’s broad. I think there’s still a lot of experimentation going on. There’s still a lot of issues with data that we’re dealing with, what the actual models produce, things like that within government, how we actually tune what it is we’re using model-wise and data-wise to the actual needs of government. So I think we’re at a great starting point generally, but we still have a long ways to go. We still have maturity around
Jun 16, 2026 · via federalnewsnetwork.com
Overview
David Saunders spoke at Practising Law Institute’s 27th Annual Institute on Privacy and Cybersecurity Law on the panel, “Courting Trouble: Insights on the Latest Privacy and Data Security Litigation.” The session examined the evolving landscape of privacy and data security litigation and mass arbitration, including claims stemming from data breaches, statutory laws such as state wiretap and biometric statutes, and common law theories. Panelists addressed recent enforcement actions, key procedural hurdles, and strategic considerations for defendants, as well as emerging trends and practical approaches for mitigating risk and defending against future litigation.
The Annual Institute on Privacy and Cybersecurity Law’s program provided a comprehensive overview of critical developments in privacy and cybersecurity law, equipping practitioners with strategies to navigate evolving legal and regulatory challenges. To learn more, visit the conference website.
Jun 16, 2026 · via mcdermottlaw.com
Assume You Will Be Hacked AI is enabling a deluge of cyberattacks the likes of which we’ve never seen before. Late last month, I began to consider withdrawing some money from my savings account to buy gold. It’s the first time I’ve ever thought about panic-buying. For all of the firewalls and two-factor-authentication codes, the safety of the internet is starting to falter. Hackers are gaining the upper hand over organizations around the world—hospitals, energy grids, government agencies, and, yes, banks. As AI tools have become extremely good at writing code, they’ve also become extremely good at pulling off cyberattacks. (Malware, after all, is still software.) The result has been a change in the scale, speed, and sophistication of hacks that is difficult to overstate: Among its tens of thousands of clients, the cybersecurity firm Palo Alto Networks identified a fourfold increase in daily attacks from 2024 to 2025. Hackers are developing AI-enhanced computer viruses that adapt on the fly to avoid detection. They are automating cyber-espionage campaigns on foreign governments. They are stealing data in minutes instead of hours. “There’s a crazy amount of offensive activity happening right now,” Alex Stamos, a former chief security officer of Yahoo and Facebook, told me. “Companies are getting hacked every single day.” If the NSA is perturbed by the rise in cyberattacks, which it apparently is, then surely my savings are vulnerable. There could be any number of weaknesses in my bank’s IT systems to directly hack. Or perhaps an AI-written phishing email targeted at an employee, personalized to sound like a family member or manager, could let hackers into the back end to empty my coffers. Even if the bank has great cybersecurity, an attack on another business—a medical clinic I visited, a car-rental company, a newsletter subscription—could steal my payment
Jun 16, 2026 · via theatlantic.com
🚀 CloudSEK becomes first Indian origin cybersecurity company to receive investment from US state fund Read more The UAE’s digital economy is expanding at a pace few markets can match. Banks, fintech firms, exchange houses, payment service providers, retailers, government entities and technology companies are rapidly moving customer journeys, payments, onboarding, support and enterprise operations online. But as organisations digitise, regulators are also raising expectations around cybersecurity, data protection, consumer protection, operational resilience and digital fraud prevention. For UAE financial institutions, the compliance clock is now ticking. Under the Central Bank of the UAE’s guidance on brand protection, digital impersonation monitoring and takedown controls, licensed financial institutions are expected to conduct their first digital impersonation risk assessment before 30 June 2026. This means banks, exchange houses, finance companies, payment service providers, stored value facilities and other regulated financial entities have limited time to assess how their brand, domains, apps, social media presence, customer support channels and digital assets may be misused by fraudsters. This is not a routine paperwork exercise. It is a direct response to the growing use of fake domains, phishing pages, fraudulent ads, social media impersonation, malicious apps and brand abuse campaigns that exploit consumer trust in financial institutions. Cybersecurity compliance in the UAE is no longer limited to having firewalls, antivirus tools and IT policies. It now requires organisations to understand where they are exposed, how attackers may exploit those exposures, how customer data is protected, how incidents are reported, how third parties are monitored and how digital impersonation risks are detected before customers are harmed. For enterprises operating in the UAE, the compliance question is changing from “Do we have security controls?” to “Can we prove that we are continuously identifying and disrupting the attack paths that can lead to customer harm, data exposure or
Jun 16, 2026 · via cloudsek.com
The SoftBank Group Announces “Patching as a Service” Cybersecurity Solution Powered by OpenAI to Secure Critical Infrastructure in Japan Solution supports enterprises with vulnerability assessments through remediation, planning and implementation advisory SoftBank Corp. SB OAI Japan GK The SoftBank Group (SoftBank Group Corp., SoftBank Corp. and SB OAI Japan GK) announced the launch of “Patching as a Service,” a cybersecurity solution that applies OpenAI’s advanced AI capabilities designed to support enterprise cybersecurity vulnerability assessment and remediation planning. Combining OpenAI’s technologies provided by SB OAI Japan with SoftBank Corp.’s operational knowhow, Patching as a Service is a solution that supports clients with vulnerability assessments through remediation planning and implementation advisory, and will be offered in Japan through SB OAI Japan GK. SoftBank Corp. will progressively begin outreach to selected eligible companies supporting Japan's critical infrastructure to accept applications for vulnerability assessments. As malicious actors increasingly use AI to automate and scale cyberattacks, the threats facing systems that support critical infrastructure have become more severe than ever. As cyberattack methods get increasingly sophisticated and automated, vulnerabilities can be exploited to launch attacks that may result in system outages, data breaches and service interruptions, posing substantial risks to both business continuity and society. While AI models support a range of cybersecurity workflows, expert cybersecurity teams play a critical role in vulnerability assessment, prioritization and remediation planning. Accordingly, in today’s market environment, where AI model capabilities continue to evolve rapidly, organizations face the growing challenge of continuously identifying potential vulnerabilities and considering appropriate remedial measures. The difficulty associated with these security tasks has become greater than ever. SoftBank Corp. carried out a large-scale internal vulnerability assessment across its internal systems using OpenAI's cybersecurity technologies and observed promising results in identifying potential vulnerabilities. SoftBank Corp.’s cybersecurity team also gained operational experience through this internal initiative
Jun 16, 2026 · via group.softbank
An AFS Licensee First: Receiving an Order to Pay AU$2.5 Million for Cybersecurity Failures By: Cameron Abbott, Daniel Knight, Rob Pulham, Alex Parker, Madison Jeffreys, Emre Cakmakcioglu and Annaliese Filippis In a key decision against an Australian financial services licence (AFSL) holder, the Federal Court of Australia has ordered the AFSL holder to pay AU$2.5 million in penalties for inadequate cybersecurity measures. The Australian Securities and Investments Commission (ASIC) took action following a cyberattack on the AFSL holder’s IT systems, resulting in approximately 385GB of data being downloaded from its servers. This is the first time civil penalties have been imposed for cybersecurity failures pursuant to general AFSL obligations. The Court found the AFSL holder failed to comply with the following obligations under the Corporations Act 2001 (Cth): - Efficient, honest, and fair financial services (s 912A(1)(a)): the AFSL holder lacked an adequate incident response plan such as monitoring threat alerts or providing mandatory cybersecurity awareness training. - Adequate resources (s 912A(1)(d)): the AFSL holder delegated responsibility for its IT security measures to staff without adequate skills or knowledge and did not dedicate sufficient financial resources towards adequate cybersecurity measures. - Adequate risk management systems (s 912A(1)(h)): the AFSL holder failed to implement, maintain and monitor controls outlined in its risk management system, including under its IT Information Security Policy, Cyber and Information Security Policy, and its annual audits of custodial services. In addition to the AU$2.5 million penalty and $500,000 in costs awarded to ASIC, the AFSL holder must undertake a compliance programme which involves engaging an independent expert to ensure its cybersecurity and cyber resilience systems are reasonably managed. Importantly, the court found the penalties and remediation costs far exceeded what it would have cost the AFSL holder to implement adequate controls in the first place. Key Takeaways:
Jun 16, 2026 · via klgates.com
EU Cybersecurity Act 2.0: When good regulation goes bad Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter. The problem with CSA 2.0 The original EU Cybersecurity Act, which came into force in 2019, was a solid foundation. CSA 2.0 was supposed to be a measured evolution to deal with the current threat landscape. What has emerged instead is something more ambitious and more troubling: For the first time, the European Commission would gain the power to designate certain countries as “high-risk,” with vendors from those countries automatically inheriting that label and facing strict restrictions across the EU. The consequences of this are potentially enormous and could cause more harm than good. The old saying “the road to hell is paved with good intentions” is starting to ring true for CSA 2.0. The Irish Business and Employers Confederation (IBEC) has warned that the proposed changes could threaten stability across 18 critical sectors in Ireland alone, and land the Irish telecoms industry with a bill of approximately €730 million for ripping out and replacing equipment. Research prepared by my firm, BH Consulting, for Digital Business Ireland, found that companies well outside the direct regulatory scope of CSA 2.0 will still be hit hard through tighter supply-chain requirements, procurement rules, and investor caution. But the question I think too few people are asking publicly is “who exactly ends up on that “high-risk” list, and how?” The honest answer is that nobody knows yet. The current framing ties
Jun 16, 2026 · via helpnetsecurity.com
Cybersecurity jobs available right now: June 16, 2026 Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Environment (TEE). You will reverse engineer native binaries and mobile software, identify vulnerabilities through code review, fuzzing, and static and dynamic analysis, and develop proof-of-concept exploits to validate findings. Application Security Engineer Millennium | Ireland | On-site – View job details As an Application Security Engineer, you will design and implement security controls for applications, AI systems, and cloud-native environments. The role includes conducting threat modeling, risk assessments, code reviews, penetration testing, and AI security evaluations to identify and mitigate vulnerabilities throughout the software development lifecycle. Cyber Security Lead Nava | India | On-site – View job details As a Cyber Security Lead, you will oversee cybersecurity strategy, risk management, and security operations, including threat modeling, vulnerability management, incident response, and compliance activities. You will implement security controls across cloud and on-premises environments, integrate security into DevOps processes, manage third-party risk, and mentor security team members while driving continuous improvements to the organization’s security posture. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Specialist for Vulnerability Management Siemens Energy | Germany | On-site – View job details As a Cybersecurity Specialist for Vulnerability Management, you will identify, assess, and manage security vulnerabilities across IT environments through vulnerability scanning and risk analysis. The role involves analyzing findings, supporting remediation efforts with IT teams and service providers, prioritizing critical risks, and tracking resolution activities to ensure compliance with security and governance requirements. Dev Sec Ops Engineer – Level 2 (TS/SCI) Lockheed Martin | USA | On-site – View job details As a Dev Sec Ops
Jun 16, 2026 · via helpnetsecurity.com
Connected Living with C Spire: Cybersecurity
GULFPORT, Miss. (WXXV)- As cyber threats continue to evolve, cybersecurity is becoming even more critical for businesses.
On this edition of Connected Living with C Spire, we learn about the solutions and services C Spire offers for businesses and consumers.
WXXV News 25’s Aubrey Spears speaks with Conrad Bell, C Spire’s Senior Vice President and Chief Information Security Officer, about cybersecurity.
Jun 16, 2026 · via wxxv25.com
What EY can do for you
Organizations face frontier AI-driven cyber threats that outpace traditional security, patching and detection models. Adversaries are discovering more vulnerabilities and exploiting them faster than ever before, while legacy technology, limited visibility and complex dependencies make it difficult to identify and remediate risk at machine speed.
Boards and executives must manage cyber risk as a threat to enterprise resilience, not just a technical concern.
EY teams combine strategic cyber, risk, resilience, AI governance, and transformation capabilities with AI-native accelerators and alliance-enabled delivery, helping organizations move faster from assessment to remediation and enterprise-wide resilience. We work with alliance partners to accelerate delivery, strengthen solution capabilities and support scalable implementation. These relationships improve asset visibility, detection, remediation and resilience outcomes across complex enterprise environments.
Jun 16, 2026 · via ey.com