America Declared a Power-Grid Emergency Over Hardware It Does Not Trust

A US national-emergency order treats power-grid security as a hardware, firmware, maintenance and remote-access supply-chain problem.

A US national-emergency order treats power-grid security as a hardware, firmware, maintenance and remote-access supply-chain problem.

Alabama has subpoenaed OpenAI over the Hugging Face agent intrusion, testing whether weak AI evaluation controls can also violate consumer-protection law.

A €824.99 million Dutch GDPR fine against Uber turns meaningful human review from an AI-governance slogan into an operational control.

Alabama has subpoenaed OpenAI over the Hugging Face agent incident, testing whether an AI containment failure can become a consumer-protection case.

The EU e-Evidence Regulation makes cross-border data orders an eight-hour operational challenge for service providers, not merely a legal process.

China’s new rules for network-data security risk assessments took effect on 20 August 2026. For organisations that process data in China, the important change is not simply another assessment obligation. The result may now have to leave the security team,…

A new White House programme will let vetted U.S. security companies conduct surveillance and disruptive operations against foreign cybercrime groups under federal direction. It is a significant expansion of private-sector offensive capability, but the memorandum’s legal guardrails leave difficult questions about attribution, accountability and escalation.

The Cyber Resilience Act (CRA) comes into effect on 11 September 2026, mandating manufacturers to report exploited vulnerabilities and severe product-security incidents within specified timeframes. Initial obligations begin immediately, despite broader compliance deadlines in December 2027. Companies must establish effective reporting processes to ensure timely and accurate notifications regarding product security.

The European Union delayed major requirements for high-risk AI systems. It did not delay the transparency rules that already determine whether a chatbot must identify itself, whether synthetic output needs a machine-readable mark, and whether deepfakes or certain public-interest text…

The usbliter8 exploit exposed an immutable Apple SecureROM flaw. A court order removed the original research, but it could not remove the vulnerability or copies already distributed.