#cyberpolicy — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberpolicy, aggregated by home.social.
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-15
US greenlights private companies to conduct offensive 'hack back' cyberattacks against criminal gangs — a historic policy reversal.
https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks/
#CyberPolicy #InfoSec #Cybersecurity #HackBack -
With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.
Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.
Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.
The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:
- Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?
- Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?
- Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?
- Why would a European buyer accept "we cannot comment" as a tender answer?
- Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?
- Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?
- Why would an allied service share access with a partner whose contractors may be on the same box?
- How does a US prosecutor explain the next indictment of a Chinese contractor hacker?
- What does Washington say when Beijing runs the same program and calls it law enforcement?
Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.
https://postquantum.com/cyber-kinetic-security/cyber-privateers-what-breaks/
#Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC
-
Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.
This week's Policy Pulse: https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
-
Just attended CyberNext Brussels, Belgium (in the neighborhood of the Royal Palace) : bringing together policymakers, institutions, and industry voices to discuss the future of cybersecurity globally. #Cybersecurity #CyberPolicy #Brussels #CyberNext #EU https://www.cybernextconference.org/
-
@inex ❌ In Russia, the classifieds platform Avito has blocked a woman’s account after she used it for messaging during internet outages.
The service explained that the listing titled “Strict cat for friends” violated its rules because it did not offer a real product or service. The woman created it solely as a chat workaround, since Avito is included in the “whitelisted” resources accessible during shutdowns.
ℹ️ Residents of St. Petersburg and the Leningrad region have been reporting for the third consecutive day a lack of mobile internet and problems accessing websites and banking services, according to “Current Time.” The “whitelists” have been tested since summer 2025, but even they remain unstable.
❤️ Radio Liberty. Subscribe
#Russia #Avito #InternetShutdown #Censorship #DigitalRights #FreedomOfSpeech #Runet #Whitelist #TechNews #StPetersburg #LeningradRegion #InternetAccess #CyberPolicy #OnlineFreedom #MediaFreedom
-
Vom "Wheel of Distortion" zum "Wheel of Motion": Nachdem das #BSI anlässlich der #MSC die Herausforderungen in einer Welt zunehmender digitaler Unordnung präsentierte, folgte Ende letzter Woche mit einem "Wheel of Motion" der Blick auf einen strategischen Perspektivwechsel nationaler #Cyberpolicy.
Gegen #Cybercrime setzt das BSI auf mehr Automatisierung, gegen Cyber Conflict auf staatliche #Cyberabwehr, und gegen „Cyber Dominance“ auf mehr #Digitalsouveränität:
https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Blog/Wheel_of_Motion_260306.html
-
Non-consensual synthetic imagery is scaling faster than platform controls.
Recent reporting details how AI tools were used to fabricate explicit deepfakes of a public content creator - then monetize them via impersonation accounts.
Researchers documented millions of sexualized AI-generated images in a short timeframe, prompting regulatory investigations across jurisdictions.
From a security and governance standpoint:
• Identity verification failures
• Monetization platform abuse
• Content moderation lag
• Cross-platform amplification
• Enforcement complexityThis is not only a policy issue - it’s an abuse-of-technology issue.
How should AI providers implement friction without crippling innovation?
Soure: https://www.404media.co/grok-nudify-ai-images-impersonation-onlyfans/?ref=daily-stories-newsletter
Follow @technadu for threat-informed AI and cybersecurity reporting.
#Infosec #ThreatModeling #AIAbuse #PlatformSecurity #CyberPolicy #DigitalForensics #OnlineHarms #TechNadu
-
California’s privacy authority has restricted a data broker from selling Californians’ personal and health data due to registration and compliance failures.
The case underscores:
• Sensitivity of health-related datasets
• Importance of broker registration frameworks
• Enforcement trends under consumer privacy lawsWhat impact do you see this having on data brokerage practices?
Follow TechNadu for objective analysis across privacy, regulation, and InfoSec.
#DataProtection #HealthPrivacy #PrivacyCompliance #CyberPolicy #InfoSec #RegulatoryEnforcement
-
Australia now mandates age verification for logged-in search engine users.
Ends anonymous logged-in searches and expands identity checks - with fines up to ~$50M for non-compliance by 2026.
🔗 https://www.technadu.com/australia-enforces-age-verification-for-search-engine-users/617352/
Thoughts from a privacy perspective?
-
China has issued draft regulatory measures for public comment addressing AI systems designed for human-like and emotional interaction.
The proposal emphasizes lifecycle responsibility, algorithm governance, data security, personal information protection, and mitigation of psychological risks.
From an information security perspective, this reflects growing attention to how AI design, data handling, and user interaction intersect with digital safety.
What implications could this have for global AI governance standards?
Engage in the discussion and follow @technadu for factual InfoSec and AI policy updates.
#InfoSec #AIGovernance #DataProtection #ResponsibleAI #CyberPolicy #TechNadu
-
Acting CISA Director reportedly took a polygraph tied to an intelligence access request, prompting a DHS internal review.
At least 6 career staff placed on paid leave amid the investigation.Thoughts on the implications for agency leadership?
-
Denmark explores VPN limits to address illegal streaming.
https://www.technadu.com/denmark-proposes-vpn-limits-to-tackle-illegal-streaming/615849/• Proposal targets piracy-related access
• Government denies full VPN ban
• Tech-neutral language raises enforcement questions
• Privacy advocates warn of censorship risks -
Two major U.S. cyber laws — the CISA Act and State & Local Cybersecurity Grant Program — are temporarily back through Jan 30 following the shutdown’s end.
-
Want to shape cybersecurity policy? 🛡️ This interactive workshop deepens your understanding of foundational concepts, hard problems, and practical solutions by having you step into the shoes of industry, government, and academia stakeholders to debate and craft policy recommendations. #CyberPolicy #GovTech
Workshop: https://bsidesnova-2025.sessionize.com/session/999817
-
🚨 Speaker Spotlight: Deputy Minister Herming Chiueh
We’re honored to welcome Herming Chiueh of Taiwan’s MODA back to @defcon 33 and the Maritime Hacking Village!
Join us for his panel: “Fighting the Digital Blockade: A View from Taiwan” — exploring cyber resilience, secure comms & infrastructure defense.
#DEFCON #DC33 #MaritimeHackingVillage #CyberPolicy #NationalSecurity #DEFCONSpeakers #Taiwan #CyberDefense
-
🚨 Speaker Spotlight: Michael Sulmeyer, former Asst. Secretary of Defense for Cyber Policy, joins the Maritime Hacking Village at @defcon 33!
With top cyber roles at DoD, Cyber Command & NSC, Michael offers deep expertise on cyber conflict, military readiness & infrastructure resilience.
⚓ Catch him live on the "Threat Dynamics on the Seas" policy panel.
#DEFCON #DC33 #MaritimeHackingVillage #CyberDefense #CyberPolicy #MaritimeSecurity #DEFCONTalks
-
Trump Signs Executive Order that Ends Punitive Measures Against Domestic Hackers
#Cybersecurity #USPolitics #Trump #CISA #NationalSecurity #DOGE #ExecutiveOrder #InfoSec #WhiteHouse #CyberPolicy #GovTech
-
📢 A coalition of 52 industry organizations is urging Congress to reauthorize CISA before it’s too late 🛡️📅
📝 The joint letter includes voices from critical sectors — energy, telecom, finance, healthcare, transportation, retail, and tech
📉 Without immediate reauthorization, programs supporting vulnerability coordination, incident response, and threat sharing will stall out.
⚠️ The current authorization expires September 30 😱
🏛️ The call: long-term, stable support for the U.S. government’s lead civilian cyber agencyWhen 52 business and infrastructure groups align on cyber policy, that’s not noise — it’s a warning flare.
#CyberSecurity #CISA #ThreatIntel #CyberPolicy #PublicPrivatePartnership #security #privacy #cloud #infosec
https://www.ciodive.com/news/cisa-reauthorization-congress-industry-letter/748356/ -
Two Top CISA Officials Resign Amid Agency Turmoil Caused by US Government
#Cybersecurity #CISA #SecureByDesign #GovTech #NationalSecurity #DOGE #USGov #CyberPolicy #FederalGovernment #InfoSec #TrumpAdmin
-
With Chinese diplomats reportedly admitting to targeting US Critical Infrastructure as a "warning to the U.S. about Taiwan" and some in the industry war-gaming the possibility of Cyber Effects being used to sway the Trade dispute between the US and China, now seemed a good time to do a reality check on how - if at all - China would do so.
The bottom line - expect a surge in cyber espionage and signaling campaigns targeting US telcos and leadership to provide the CCP a competitive advantage in negotiations and their backdoor dealings.🕵️
Cyber Security doesn't operate in a vacuum - here's a good example of where geopolitics starts to seep in at the edges: https://opalsec.io/is-cyber-a-legitimate-weapon-in-a-tariff-war/
#CyberSecurity #InfoSec #ThreatIntel #China #USChinaTradeWar #Geopolitics #CyberWarfare #CriticalInfrastructure #VoltTyphoon #SaltTyphoon #NationalSecurity #CyberThreats #RiskManagement #GeopoliticalRisk #CyberPolicy #CISA
-
Back in 2018 I got to interview the inagural Cybersecurity Ambassador for Australia and this year, in Melbourne, we got to meet and interview Brendan Dowling, Australia’s Ambassador for Cyber Affairs and Critical Technology.
You do not want to miss this conversation, trust me 😬
🎙️✨Australia's Global Opportunity and Responsibility: Shaping a More Secure Region and a Safer Digital World
On Location Coverage with Sean Martin and Marco Ciappelli on ITSPmagazine Podcasts
An Australian Cyber Conference 2024 in Melbourne Conversation with Ambassador Brendan Dowling
Australian Information Security Association (AISA)
At the Australian Cyber Conference Melbourne 2024, On Location with Sean Martin and Marco Ciappelli welcomed Brendan Dowling, Australia’s Ambassador for Cyber Affairs and Critical Technology. In this thought-provoking conversation, Dowling shared his insights on the evolving role of cyber diplomacy, the ethical implications of #AI, and the importance of international collaboration in securing the digital world.
📺 Watch the episode video on YouTube & subscribe to ITSPmagazine Channel here 👇
📻 If you prefer to listen to the audio podcast, enjoy it here 👉 https://on-location-with-sean-martin-and-marco-ciappelli.simplecast.com/episodes/australias-global-opportunity-and-responsibility-shaping-a-more-secure-region-and-a-safer-digital-world-an-australian-cyber-conference-2024-in-melbourne-conversation-with-ambassador-brendan-dowling-on-location-coverage
🖥️ More about our Australian Cyber Conference 2024 Coverage👇
🌟Sponsor of ITSPmagazine's Australian Cyber Conference 2024 Coverage at the time of publishing: ThreatLocker 👉 https://itspm.ag/threatlocker-r974
#AustralianCyberConference2024
#CyeberCon2024
#CyberSecurity
#infosecurity
#infosec #cyberpolicy
#technology #politicalscience #internatinalrelationship #cyber #cyberdiplomacy