<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: GRC Briefing</title><link>https://cybersecuritytracker.ai/?persona=grc</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open</title><link>https://databreaches.net/2026/07/26/developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open?pk_campaign=feed&amp;pk_kwd=developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open</link><guid isPermaLink="false">cst-3229</guid><description>AnMed Health System, which operates four hospitals in Upstate South Carolina and northeast Georgia, experienced a phone and internet outage affecting all locations. Emergency rooms remained operational during the incident despite the connectivity disruption.</description><pubDate>Sun, 26 Jul 2026 14:10:29 GMT</pubDate></item><item><title>A-list directors, actors and celebrities exposed in Tribeca film festival data leak</title><link>https://databreaches.net/2026/07/26/a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak?pk_campaign=feed&amp;pk_kwd=a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak</link><guid isPermaLink="false">cst-3230</guid><description>A security researcher discovered four publicly accessible, unencrypted databases connected to the Tribeca Film Festival, including a development database containing over 203,000 records. The databases lacked password protection and exposed sensitive information about festival-associated individuals.</description><pubDate>Sun, 26 Jul 2026 13:06:14 GMT</pubDate></item><item><title>Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached</title><link>https://helpnetsecurity.com/2026/07/26/week-in-review-servicenow-pre-auth-rce-exploited-in-the-wild-hugging-face-breached</link><guid isPermaLink="false">cst-3226</guid><description>A weekly news roundup covered multiple security topics, including active exploitation of a ServiceNow pre-authentication remote code execution vulnerability and a breach of Hugging Face. The piece also discussed how organizations increasingly run multiple AI platforms simultaneously across different vendors and departments.</description><pubDate>Sun, 26 Jul 2026 08:00:34 GMT</pubDate></item><item><title>US House Votes to Extend Cyber Sharing Law for 10 Years</title><link>https://databreaches.net/2026/07/25/us-house-votes-to-extend-cyber-sharing-law-for-10-years?pk_campaign=feed&amp;pk_kwd=us-house-votes-to-extend-cyber-sharing-law-for-10-years</link><guid isPermaLink="false">cst-3218</guid><description>The U.S. House of Representatives voted to extend a key cyberthreat sharing law for 10 years by including the reauthorization in the fiscal year 2027 national defense authorization act. The measure passed narrowly on a 216-212 vote Wednesday and was attached to the $1.15 trillion defense policy bill after the reauthorization had been stalled.</description><pubDate>Sat, 25 Jul 2026 14:25:16 GMT</pubDate></item><item><title>AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’</title><link>https://databreaches.net/2026/07/25/au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust?pk_campaign=feed&amp;pk_kwd=au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust</link><guid isPermaLink="false">cst-3219</guid><description>A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorization. NSW Police launched an investigation following a report to the agency and subsequently searched a home in Frenchs Forest as part of the inquiry.</description><pubDate>Sat, 25 Jul 2026 14:24:50 GMT</pubDate></item><item><title>No Need to Hack When It’s Leaking: Click to Pray edition</title><link>https://databreaches.net/2026/07/25/no-need-to-hack-when-its-leaking-click-to-pray-edition?pk_campaign=feed&amp;pk_kwd=no-need-to-hack-when-its-leaking-click-to-pray-edition</link><guid isPermaLink="false">cst-3220</guid><description>The Click To Pray app, a prayer application endorsed by the Pope with hundreds of thousands of users, exposed users' names and email addresses through a data leak. An ethical hacker discovered the exposure, which had persisted for months or longer.</description><pubDate>Sat, 25 Jul 2026 14:24:35 GMT</pubDate></item><item><title>OpenAI confirms ChatGPT is down worldwide</title><link>https://bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-worldwide</link><guid isPermaLink="false">cst-3208</guid><description>OpenAI confirmed that ChatGPT experienced a worldwide outage affecting access to the artificial intelligence chatbot. The company did not provide details on the cause or expected resolution timeline in the initial report.</description><pubDate>Sat, 25 Jul 2026 09:31:09 GMT</pubDate></item><item><title>CISOs vs. Boards: Myth or Misunderstanding?</title><link>https://darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-</link><guid isPermaLink="false">cst-3196</guid><description>Boards are increasing focus on security due to rising threats, yet communication gaps remain between board members and chief information security officers (CISOs). Both groups report needing additional resources and better dialogue to close the divide.</description><pubDate>Fri, 24 Jul 2026 21:31:53 GMT</pubDate></item><item><title>Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks</title><link>https://cyberscoop.com/cisa-circia-cyber-incident-reporting-rule-feedback</link><guid isPermaLink="false">cst-3198</guid><description>Industry groups told CISA during town halls on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that they want the rule to cover fewer companies, require fewer incident reports, and demand less detailed information when reporting does occur. The rule, which Congress designed to require critical infrastructure owners to report major cyberattacks within 72 hours and ransomware payments within 24 hours, has missed multiple finalization deadlines, with CISA now targeting September for completion. Industry representatives expressed concerns about the scope affecting over 300,000 entities, the burden of reporting minor intrusion attempts, and the sensitivity of sharing security measure details.</description><pubDate>Fri, 24 Jul 2026 20:58:35 GMT</pubDate></item><item><title>OnTrac notifies customers of data breach after network hack</title><link>https://bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack</link><guid isPermaLink="false">cst-3195</guid><description>OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. The company is notifying affected customers of the incident.</description><pubDate>Fri, 24 Jul 2026 19:55:01 GMT</pubDate></item><item><title>US accuses American of allegedly wiping his phone using a ‘duress’ password during border search</title><link>https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search</link><guid isPermaLink="false">cst-3194</guid><description>A U.S. citizen is challenging a government claim in court that he provided border authorities with a passcode that erased his phone's data. The case raises constitutional questions about privacy protections and what individuals must disclose during border searches.</description><pubDate>Fri, 24 Jul 2026 17:53:30 GMT</pubDate></item><item><title>Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry</title><link>https://therecord.media/andy-burnham-liz-lloyd-cyber-policy-uk</link><guid isPermaLink="false">cst-3193</guid><description>The new UK Prime Minister Keir Starmer retained Liz Lloyd in a cyber policy role, maintaining her position despite broader government restructuring. Lloyd remains one of the few Starmer allies continuing in the administration.</description><pubDate>Fri, 24 Jul 2026 17:14:00 GMT</pubDate></item><item><title>Microsoft, tech companies throw weight behind spread of open-source AI</title><link>https://cyberscoop.com/tech-leaders-open-source-ai-cybersecurity</link><guid isPermaLink="false">cst-3185</guid><description>Microsoft and more than two dozen technology companies released an open letter urging policymakers to support open-source AI systems, comparing the potential ecosystem benefits to the open-source software movement of the 1980s. The signatories argue that open-weight models enable startups, universities, and research institutions to innovate efficiently and strengthen cybersecurity defenses, though critics warn that unrestricted access could lower barriers to entry for malicious actors and enable creation of deepfakes and child sexual abuse material.</description><pubDate>Fri, 24 Jul 2026 15:22:15 GMT</pubDate></item><item><title>Chick-fil-A data breach affects more than 13,000 customers</title><link>https://bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers</link><guid isPermaLink="false">cst-3178</guid><description>Chick-fil-A confirmed that attackers using credential stuffing tactics compromised more than 13,000 customer accounts on its website and mobile app during a three-day period in mid-June. The breach involved unauthorized access to customer data through reused or weak credentials rather than a direct compromise of the company's systems.</description><pubDate>Fri, 24 Jul 2026 14:04:29 GMT</pubDate></item><item><title>Suspect arrested in investigation into sadistic “764” group</title><link>https://databreaches.net/2026/07/24/suspect-arrested-in-investigation-into-sadistic-764-group?pk_campaign=feed&amp;pk_kwd=suspect-arrested-in-investigation-into-sadistic-764-group</link><guid isPermaLink="false">cst-3187</guid><description>A suspect from North Holland was arrested on July 20 in connection with an online sadistic network called '764'. The individual allegedly coerced minors to engage in self-harm and create 'bloodsigns' bearing his username as evidence of compliance.</description><pubDate>Fri, 24 Jul 2026 13:47:04 GMT</pubDate></item><item><title>Vatican's Official Prayer App Leaks 700K+ Global Users' PII</title><link>https://darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii</link><guid isPermaLink="false">cst-3167</guid><description>Vatican's official prayer application contained a vulnerable API endpoint that exposed personal information for over 700,000 users worldwide. The exposed data included names, email addresses, location information, and site status that could be accessed without authentication through a standard web browser.</description><pubDate>Fri, 24 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.</title><link>https://databreaches.net/2026/07/24/crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked?pk_campaign=feed&amp;pk_kwd=crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked</link><guid isPermaLink="false">cst-3188</guid><description>A breach of Navigate360's systems exposed more than one million tips submitted to Crime Stoppers and law enforcement programs that relied on the company's software for anonymous reporting. The incident undermines trust in anonymous tip submission channels that promised confidentiality to sources.</description><pubDate>Fri, 24 Jul 2026 12:49:59 GMT</pubDate></item><item><title>The SOCI Act, explained: obligations, recent reforms, and where preemptive cyber defense fits</title><link>https://silentpush.com/blog/the-soci-act-obligations</link><guid isPermaLink="false">cst-3176</guid><description>Australia's Security of Critical Infrastructure Act 2018 (SOCI Act) imposes cyber risk management, incident reporting, and asset registration requirements on organizations operating in eleven critical sectors including energy, finance, healthcare, and transport. The framework has evolved significantly over the past two years, with additional changes currently under consultation, and increasingly emphasizes proactive threat visibility and defense rather than reactive incident response.</description><pubDate>Fri, 24 Jul 2026 12:49:17 GMT</pubDate></item><item><title>Origin silent on settlement as alleged fired employee breach detail emerges</title><link>https://databreaches.net/2026/07/24/origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges?pk_campaign=feed&amp;pk_kwd=origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges</link><guid isPermaLink="false">cst-3170</guid><description>Origin Energy has declined to publicly comment on a reported private settlement of a cyber extortion threat. The alleged breach involved unauthorized access through a former employee's credentials, creating concurrent disclosure obligations to regulators, the ASX, and insurers.</description><pubDate>Fri, 24 Jul 2026 12:08:15 GMT</pubDate></item><item><title>T-Mobile violated WA data breach notification law, judge rules</title><link>https://databreaches.net/2026/07/24/t-mobile-violated-wa-data-breach-notification-law-judge-rules?pk_campaign=feed&amp;pk_kwd=t-mobile-violated-wa-data-breach-notification-law-judge-rules</link><guid isPermaLink="false">cst-3171</guid><description>A King County Superior Court judge ruled that T-Mobile violated Washington state data breach notification law by failing to properly notify customers of a 2024 breach affecting 40 million people whose sensitive personal information was stolen and sold on the dark web. The Washington attorney general's office filed the civil lawsuit against T-Mobile in January 2025. The ruling establishes that T-Mobile's notification practices did not meet the state's legal requirements.</description><pubDate>Fri, 24 Jul 2026 12:08:06 GMT</pubDate></item><item><title>Furious KPMG boss expels senior partner over confidential documents in locker</title><link>https://databreaches.net/2026/07/24/furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker?pk_campaign=feed&amp;pk_kwd=furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker</link><guid isPermaLink="false">cst-3172</guid><description>KPMG's chief operating officer, Eileen Hoggett, was expelled after an investigation confirmed she and other senior partners illegally accessed sensitive Lendlease board documents and stored them in a work locker. The expulsion followed a whistleblower claim regarding the unauthorized possession of confidential materials.</description><pubDate>Fri, 24 Jul 2026 12:07:56 GMT</pubDate></item><item><title>Millions of California-bought cars can be hijacked via Bluetooth</title><link>https://databreaches.net/2026/07/24/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth?pk_campaign=feed&amp;pk_kwd=millions-of-california-bought-cars-can-be-hijacked-via-bluetooth</link><guid isPermaLink="false">cst-3174</guid><description>Researchers at UC San Diego identified Bluetooth vulnerabilities affecting at least 2.2 million vehicles equipped with dealer-installed KARR and SWDS security systems. The flaws allow nearby attackers to unlock doors or disable vehicle ignition through wireless attacks. The full research details are forthcoming.</description><pubDate>Fri, 24 Jul 2026 12:06:56 GMT</pubDate></item><item><title>Man gets six years for hacking 750 women's Snapchat accounts</title><link>https://bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts</link><guid isPermaLink="false">cst-3159</guid><description>An Illinois man received a 76-month prison sentence and three years of supervised release for hacking over 750 women's Snapchat accounts to obtain their nude photos. The case illustrates criminal liability for unauthorized account access and theft of intimate images.</description><pubDate>Fri, 24 Jul 2026 11:17:19 GMT</pubDate></item><item><title>New infosec products of the week: July 24, 2026</title><link>https://helpnetsecurity.com/2026/07/24/new-infosec-products-of-the-week-july-24-2026</link><guid isPermaLink="false">cst-3141</guid><description>A weekly roundup covers new security products from vendors including Druva, which launched AI Resilience to add backup, recovery, and governance capabilities for AI workloads with support for Microsoft Copilot and Claude Code.</description><pubDate>Fri, 24 Jul 2026 04:00:36 GMT</pubDate></item><item><title>State Department imposes visa restrictions on foreign cyber scammers</title><link>https://therecord.media/visa-restrictions-cyber-scammers</link><guid isPermaLink="false">cst-3112</guid><description>The U.S. State Department, under Secretary of State Marco Rubio, announced visa restrictions targeting individuals involved in transnational cyber-scam operations. The policy aims to limit entry to the United States for those connected to international fraud schemes conducted through digital channels.</description><pubDate>Thu, 23 Jul 2026 16:29:00 GMT</pubDate></item><item><title>Microsoft 365 outage affects Teams, SharePoint and other services</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services</link><guid isPermaLink="false">cst-3100</guid><description>Microsoft experienced a widespread outage affecting Teams, SharePoint, and other Microsoft 365 services, with impact concentrated in North America. The disruption impacted collaboration and productivity tools relied upon by thousands of organizations.</description><pubDate>Thu, 23 Jul 2026 15:34:43 GMT</pubDate></item><item><title>Chick-fil-A Accounts Get Fried in Credential Stuffing Attack</title><link>https://securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack</link><guid isPermaLink="false">cst-3109</guid><description>Threat actors used credentials from previous breaches to gain unauthorized access to Chick-fil-A One customer accounts through credential stuffing. The attack relied on reused passwords rather than exploiting a vulnerability in the restaurant chain's systems.</description><pubDate>Thu, 23 Jul 2026 14:55:19 GMT</pubDate></item><item><title>FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires</title><link>https://bleepingcomputer.com/news/security/fedramp-rev5-is-ending-what-the-20x-transition-really-requires</link><guid isPermaLink="false">cst-3101</guid><description>FedRAMP 20X replaces the current Rev5 model by shifting from periodic security assessments to continuous, machine-readable evidence that validates control effectiveness. Organizations must transition to this evidence-based assurance approach to maintain compliance with the updated federal security framework.</description><pubDate>Thu, 23 Jul 2026 14:00:10 GMT</pubDate></item><item><title>Abstract Raises $25 Million to Expand Composable Security Operations Platform</title><link>https://securityweek.com/abstract-raises-25-million-to-expand-composable-security-operations-platform</link><guid isPermaLink="false">cst-3110</guid><description>Abstract, a security operations platform company, has raised $25 million in its latest funding round, bringing total capital raised to approximately $50 million. The company plans to use the investment to expand its composable security operations platform.</description><pubDate>Thu, 23 Jul 2026 13:54:56 GMT</pubDate></item><item><title>Major Australian energy supplier confirms customer data compromised</title><link>https://therecord.media/australia-origin-energy-data-breach</link><guid isPermaLink="false">cst-3113</guid><description>Origin Energy, a major Australian energy supplier, confirmed that customer data was compromised in a recent breach and is investigating the scope of the incident to determine how many Australians were affected.</description><pubDate>Thu, 23 Jul 2026 13:20:00 GMT</pubDate></item><item><title>EU fines Google $1 billion for search, app store antitrust violations</title><link>https://bleepingcomputer.com/news/google/eu-fines-google-1-billion-for-digital-markets-act-breaches-in-search-and-play-store</link><guid isPermaLink="false">cst-3083</guid><description>The European Commission issued a €890 million fine to Google for violating the Digital Markets Act, which regulates fair competition in digital markets. The penalty addresses breaches related to the company's search and app store practices.</description><pubDate>Thu, 23 Jul 2026 12:33:19 GMT</pubDate></item><item><title>End-to-End Encryption and “Going Dark”</title><link>https://schneier.com/blog/archives/2026/07/end-to-end-encryption-and-going-dark.html</link><guid isPermaLink="false">cst-3097</guid><description>A new academic paper analyzes the third round of the 'Going Dark' debate, tracing encryption policy from the 1990s Crypto Wars through current end-to-end encryption (E2EE) controversies. The authors identify five distinct E2EE technical scenarios and demonstrate that E2EE is embedded throughout modern infrastructure including Transport Layer Security, Secure Shell, Virtual Private Networks, and Zero Trust Architecture, arguing that broad restrictions would harm cybersecurity and government operations.</description><pubDate>Thu, 23 Jul 2026 11:03:50 GMT</pubDate></item><item><title>ANCHOR-CI could fix 20 years of broken government-industry collaboration</title><link>https://cyberscoop.com/cisa-anchor-ci-critical-infrastructure-framework-op-ed</link><guid isPermaLink="false">cst-3076</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) published a notice on July 1 establishing ANCHOR-CI, a new framework for government-industry collaboration on critical infrastructure protection that replaces the 20-year-old Critical Infrastructure Partnership Advisory Council (CIPAC). The new structure introduces cross-sector councils alongside traditional sector-specific councils to address threats that span multiple industries, moving beyond the siloed approach that characterized the previous model. CISA director approval of council members and streamlined advisory mechanisms aim to improve the speed and effectiveness of government-private sector coordination on emerging cyber and resilience issues.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Assaf Keren Appointed New CISO of Meta</title><link>https://securityweek.com/assaf-keren-appointed-new-ciso-of-meta</link><guid isPermaLink="false">cst-3073</guid><description>Assaf Keren has been appointed Chief Information Security Officer (CISO) at Meta, succeeding Guy Rosen who retired after 13 years with the company.</description><pubDate>Thu, 23 Jul 2026 09:53:51 GMT</pubDate></item><item><title>Microsoft working to fix Exchange Online mailbox quarantine issue</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-exchange-online-mailbox-quarantine-issue</link><guid isPermaLink="false">cst-3069</guid><description>Microsoft is addressing an issue with Exchange Online that has been incorrectly quarantining customer mailboxes since Sunday. The company is working to resolve the problem and restore normal service for affected users.</description><pubDate>Thu, 23 Jul 2026 09:20:10 GMT</pubDate></item><item><title>Srsly Risky Biz: Knives Are Out For Open-Weight AI Models</title><link>https://risky.biz/srsly-risky-biz-knives-are-out-for-open-weight-ai-models</link><guid isPermaLink="false">cst-3080</guid><description>The Trump administration and Chinese government are both signaling plans to restrict open-weight artificial intelligence (AI) models, with the US considering adding Chinese AI companies to its Entity List and China exploring export controls on its own AI technology. White House officials including Michael Kratsios publicly accused Chinese company Moonshot AI of conducting large-scale model distillation against US AI systems to steal proprietary technology.</description><pubDate>Thu, 23 Jul 2026 07:41:22 GMT</pubDate></item><item><title>ID: Kootenai County notifies residents of data breach</title><link>https://databreaches.net/2026/07/22/id-kootenai-county-notifies-residents-of-data-breach?pk_campaign=feed&amp;pk_kwd=id-kootenai-county-notifies-residents-of-data-breach</link><guid isPermaLink="false">cst-3057</guid><description>Kootenai County is notifying residents of a ransomware attack discovered on March 30, 2026, that compromised personal information on its computer network. The county took immediate action to secure and restore its systems following the detection.</description><pubDate>Thu, 23 Jul 2026 00:45:56 GMT</pubDate></item><item><title>TN: Data breach delays start of Sumner County school year</title><link>https://databreaches.net/2026/07/22/tn-data-breach-delays-start-of-sumner-county-school-year?pk_campaign=feed&amp;pk_kwd=tn-data-breach-delays-start-of-sumner-county-school-year</link><guid isPermaLink="false">cst-3058</guid><description>Sumner County Schools in Tennessee discovered a data breach in its computer network and postponed the start of the school year to resolve the incident before students return. The breach was identified earlier in the week, prompting district officials to revise the calendar.</description><pubDate>Thu, 23 Jul 2026 00:25:52 GMT</pubDate></item><item><title>Instructure Incident Driving 58 Percent of Breach Notices in 2026</title><link>https://databreaches.net/2026/07/22/instructure-incident-driving-58-percent-of-breach-notices-in-2026?pk_campaign=feed&amp;pk_kwd=instructure-incident-driving-58-percent-of-breach-notices-in-2026</link><guid isPermaLink="false">cst-3059</guid><description>A single Instructure incident generated 471 million breach notices in the first half of 2026, accounting for 58 percent of all breach notifications despite 1,029 total compromises being reported during that period. The Identity Theft Resource Center documented this concentration of impact from one major breach event among organizations handling large datasets.</description><pubDate>Wed, 22 Jul 2026 23:12:10 GMT</pubDate></item><item><title>Upbound says hack caused $13 million in fraudulent Acima leases</title><link>https://bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases</link><guid isPermaLink="false">cst-3047</guid><description>Threat actors who compromised Upbound Group's systems used stolen data to fraudulently originate approximately $13 million in Acima leases. The breach highlighted the exposure of customer information and the downstream financial impact when stolen credentials are weaponized for unauthorized transactions.</description><pubDate>Wed, 22 Jul 2026 21:43:39 GMT</pubDate></item><item><title>Most federal cybersecurity reporting rules are duplicative, study finds</title><link>https://cyberscoop.com/gao-report-duplicate-cybersecurity-regulations-harmonization</link><guid isPermaLink="false">cst-3053</guid><description>A Government Accountability Office report found that 80 of 117 federal cybersecurity regulations contain duplicate reporting requirements, with seven out of 10 rules requiring written reports to agencies overlapping elsewhere. Harmonization efforts under the Biden administration have stalled under Trump, with a March 2024 executive order pausing work while the administration conducts a review. The fragmentation affects critical infrastructure sectors, which may face multiple conflicting reporting obligations depending on regulatory jurisdiction.</description><pubDate>Wed, 22 Jul 2026 21:04:43 GMT</pubDate></item><item><title>Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill</title><link>https://therecord.media/cisa-2015-extension-passes-house-ndaa</link><guid isPermaLink="false">cst-3052</guid><description>The House included a 10-year extension of the Cybersecurity Information Sharing Act (CISA) of 2015 in its fiscal 2027 defense authorization bill. The renewal maintains legal protections for organizations that voluntarily share cybersecurity threat information with government agencies and each other.</description><pubDate>Wed, 22 Jul 2026 20:39:35 GMT</pubDate></item><item><title>South Korea discloses data breach impacting diplomats worldwide</title><link>https://bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide</link><guid isPermaLink="false">cst-3048</guid><description>South Korea's National Diplomatic Academy suffered a ten-month breach of its online education system, exposing personal information of current and former Ministry of Foreign Affairs employees and diplomats stationed abroad. The incident remained undetected for an extended period before disclosure.</description><pubDate>Wed, 22 Jul 2026 20:06:54 GMT</pubDate></item><item><title>French Parliament greenlights social media ban for under-15s</title><link>https://therecord.media/france-social-media-ban-parliament</link><guid isPermaLink="false">cst-3036</guid><description>France's Parliament has passed legislation to ban social media access for children under 15 years old, establishing France as the first European nation to implement such a restriction on platform use by minors. The vote reflects growing international momentum toward regulating social media use among younger users.</description><pubDate>Wed, 22 Jul 2026 18:00:00 GMT</pubDate></item><item><title>White House accuses Chinese company of distilling Anthropic’s Fable</title><link>https://cyberscoop.com/white-house-accuses-moonshot-ai-anthropic-model-distillation</link><guid isPermaLink="false">cst-3039</guid><description>A White House official accused Chinese company Moonshot AI of using large-scale distillation to reverse-engineer Anthropic's Fable model and create its own K3 product, leveraging sophisticated internal platforms and GB300 servers sourced through Thailand or newly acquired. The accusation highlights ongoing tensions over AI intellectual property protection, with U.S. frontier AI companies pushing for stronger safeguards against what they characterize as covert industrial model theft. Congressional committees are investigating a broader pattern of Chinese AI firms allegedly stealing proprietary U.S. frontier model capabilities and redistributing them as open-weight models globally.</description><pubDate>Wed, 22 Jul 2026 16:45:37 GMT</pubDate></item><item><title>Real world incident response: Microsoft and AXA XL strengthen cyber resilience</title><link>https://microsoft.com/en-us/security/blog/2026/07/22/real-world-incident-response-microsoft-and-axa-xl-strengthen-cyber-resilience</link><guid isPermaLink="false">cst-3041</guid><description>Microsoft and AXA XL have established a partnership to integrate Microsoft Defender Experts Cybersecurity Incident Response services into AXA XL's cyber insurance offerings for policyholders. The collaboration aims to coordinate technical response, business decisions, and insurance coverage in parallel during incidents rather than sequentially, reducing response delays and risk. The model emphasizes pre-crisis alignment among security, executive, legal, and insurance teams to streamline decision-making when incidents occur.</description><pubDate>Wed, 22 Jul 2026 16:00:00 GMT</pubDate></item><item><title>Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts</title><link>https://securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts</link><guid isPermaLink="false">cst-3015</guid><description>Data breaches at Suno and Paidwork exposed personally identifiable information and financial data from tens of millions of accounts. Attackers leaked names, email addresses, phone numbers, passwords, and financial information from both platforms.</description><pubDate>Wed, 22 Jul 2026 15:02:11 GMT</pubDate></item><item><title>Palo Alto Networks to Acquire Observability Platform Provider Embrace</title><link>https://securityweek.com/palo-alto-networks-to-acquire-observability-platform-provider-embrace</link><guid isPermaLink="false">cst-3016</guid><description>Palo Alto Networks announced an acquisition of Embrace, an observability platform provider, extending its expansion into monitoring and observability tools beyond traditional security offerings. This follows the company's January acquisition of Chronosphere, signaling a strategic shift toward broader infrastructure visibility capabilities.</description><pubDate>Wed, 22 Jul 2026 14:58:53 GMT</pubDate></item><item><title>Swimlane AI SOC automates security operations for MSSPs</title><link>https://helpnetsecurity.com/2026/07/22/swimlane-ai-soc-mssps</link><guid isPermaLink="false">cst-3025</guid><description>Swimlane announced Swimlane AI SOC for MSSPs, a platform designed to enable managed security service providers to automate security operations using agentic AI. Rather than competing for customers, Swimlane positions the offering to allow MSSPs to retain their client relationships while building AI-driven SOC capabilities on the Swimlane Turbine platform.</description><pubDate>Wed, 22 Jul 2026 13:29:27 GMT</pubDate></item><item><title>What’s New in Rapid7 Products and Services: Q2 2026 in Review</title><link>https://rapid7.com/blog/post/pt-new-products-services-q2-2026-mdr</link><guid isPermaLink="false">cst-3026</guid><description>Rapid7 released Q2 2026 product updates across detection, response, compliance, and exposure management, including bidirectional Microsoft Defender integration, Detection as Code capabilities using Terraform workflows, and ransomware prevention features for Incident Command. The company also launched updated compliance solution pages mapping platform capabilities to NIS2, NIST CSF 2.0, DORA, HIPAA, HITRUST, and GovRAMP requirements, and improved its Remediation Hub with asset-level context and reporting tools. Additional enhancements include AI pre-triaging for application security findings to reduce false positives in vulnerability scanning.</description><pubDate>Wed, 22 Jul 2026 13:28:02 GMT</pubDate></item></channel></rss>