Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • New Zealand Targets Russian Cyber Actors With Fresh Sanctions Samiksha Jain
    New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreadi
     

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

11 de Agosto de 2026, 03:18

New Zealand Sanctions

New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreading anti-Ukraine propaganda, as well as actors from the Democratic People’s Republic of Korea (DPRK) and Iran providing support to Moscow. “Children should never be used as instruments of war,” Peters said, expressing concern over efforts to abduct and re-educate Ukrainian children through state-directed programmes.

New Zealand Sanctions Target Russian Cyber Actors

The latest Russia sanctions include several individuals previously accused by the United States and other Western governments of malicious cyber activity. Among them are Yuliya Pankratova and Denis Degtyarenko, members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR). The U.S. Treasury sanctioned both individuals in 2024 over alleged cyber operations targeting U.S. critical infrastructure. U.S. officials identified Pankratova, who uses the alias “YUliYA,” as the group’s leader, while Degtyarenko, known as “Dena,” was described as one of its primary hackers. American officials alleged that Degtyarenko was responsible for compromising an industrial control system at a U.S. energy company and had developed training materials for compromising supervisory control and data acquisition (SCADA) systems. Pankratova has also allegedly been associated with Z-Pentest, another pro-Russian hacking group accused of targeting critical infrastructure. New Zealand has also sanctioned Aleksandr Volosovik, known online as “Yalishanda.” U.S. prosecutors have accused him of helping operate Media Land, a Russian bulletproof hosting provider allegedly used by cybercriminals to target organizations including hospitals, schools and banks. In July, the U.S. Justice Department unsealed charges against Volosovik and two other Russian nationals, alleging activities that caused more than $62 million in losses to victims in the United States and other countries.

GRU-linked Official Among Sanctioned Individuals

Another individual included in the latest New Zealand sanctions against Russia is Andrey Averyanov, a senior Russian military intelligence officer who previously commanded GRU Unit 29155. Western governments have linked the unit to cyberattacks, sabotage and other covert operations. Its cyber division has been accused of targeting governments, defense organizations, think tanks and other entities in Ukraine and NATO countries. New Zealand had previously sanctioned members of the unit over alleged malicious cyber activity targeting Ukraine and other countries.

Russia Propaganda and Technology Entities Targeted

The new sanctions also target Russia’s Internet Development Institute (IRI), a Kremlin-backed organization that finances digital media and content promoting Russian state narratives. IRI director Alexey Goreslavsky has also been designated. The British government has previously said the institute was established by Russia’s presidential administration and received hundreds of millions of dollars in government funding. Its projects have included films and video games promoting narratives associated with the Kremlin. Russian information technology company LANIT has also been added to the sanctions list. The company has provided services to Russia’s Defense Ministry and sanctioned defense-industry companies, including state-owned conglomerate Rostec. LANIT had previously been sanctioned by the United States, Canada and Ukraine.

New Zealand Reaches 36th Russia Sanctions Round

The latest package represents New Zealand’s 36th round of Russia sanctions since the Russia Sanctions Act came into force in March 2022. New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. The measures generally include asset freezes and travel bans and prohibit New Zealanders from making funds or other assets available to designated individuals and entities. Peters said cyber activity can have real-world consequences, noting that cyber actors are increasingly being used to gather intelligence, enable sanctions evasion and disrupt those opposing Russia’s aggression.
  • ✇Firewall Daily – The Cyber Express
  • Suisun City Declares Emergency After Cyberattack Disrupts Systems Ashish Khaitan
    The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack comprom
     

Suisun City Declares Emergency After Cyberattack Disrupts Systems

10 de Agosto de 2026, 06:19

Suisun City Emergency

The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack compromised the city's computer systems. Officials said the network shutdown was necessary to contain the threat and preserve potential evidence for a federal investigation into the incident.  Although the Suisun City cyberattack affected communications operations involving both the fire and police departments, city officials said there was no imminent danger to the public. They also emphasized that public safety services continued to operate despite the disruption.  One of the most significant effects involved the handling of emergency communications, including the routing of 911 calls. Suisun City dispatchers began receiving emergency police and fire calls through the Solano County dispatch center as officials worked around the damaged municipal network. 

Suisun City Emergency Response Shifts Dispatch Operations 

The Suisun City emergency response required officials to temporarily move some communications functions outside the city's own computer infrastructure. By Sunday morning, online city services and internal municipal operations remained unavailable while cybersecurity specialists investigated the attack.  Those experts were also working to restore the affected systems. The decision to take the network offline was intended not only to stop the cyberattack from spreading but also to protect evidence that could assist federal investigators in determining how the intrusion occurred and who was responsible.  City officials described the attack as apparently the first incident of its kind to affect Suisun City. The municipality is located about 55 miles north of San Francisco and has a population of approximately 30,000. 

California City Attack Highlights Broader Cyber Threats 

The California city incident also comes amid federal investigations into a separate wave of cyberattacks involving municipal water systems in a dozen states.  Late last month, the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency warned that cyberattackers had remotely accessed online infrastructure used by water and wastewater systems in at least seven states. Federal agencies said the hackers believed to be affiliated with Iran were targeting internet-connected industrial controllers with the goal of “to cause disruptive effects within the United States.”  The risks became apparent in Minnesota, where 30 water systems were affected by a cyberattack. Officials reported dramatic declines in water levels before backup systems were activated to prevent further disruption.  While the water-system attacks are separate from the Suisun City cyberattack, the incidents illustrate the expanding range of public infrastructure that can be exposed when essential services depend on connected computer networks.

Suisun City Cyberattack Comes Amid Funding Concerns 

The recent attacks have also prompted calls for greater federal support for cybersecurity efforts. Last week, a bipartisan group of lawmakers urged the restoration of federal funding for Department of Homeland Security programs intended to coordinate cybersecurity efforts across multiple states.  The lawmakers' concerns reflect the increasingly interconnected nature of cyber threats. An attack may occur within one municipality or state, but the technology and infrastructure involved can be linked to broader systems and networks that cross jurisdictional boundaries.  Gov. Gavin Newsom's office, in a statement to The Times, said there was no evidence that California water systems were among those targeted in the recent series of attacks. The governor's office nevertheless argued that cybersecurity efforts conducted independently by individual states are less effective than a coordinated federal approach.  “Cyber threats do not stop at state lines, and no state can defend against them alone,” the governor's office said.  The statement also pointed to reductions in the federal cybersecurity workforce and cuts affecting critical programs. According to the governor's office, those changes have weakened partnerships, threat intelligence capabilities and technical assistance intended to protect essential services nationwide.  “Federal cuts to the nation’s cybersecurity workforce and critical programs have weakened the partnerships, threat intelligence and technical support that help protect essential services across the country,” the governor's office said. “Reducing these capabilities while cyber threats continue to grow leaves every state, and the nation, less prepared for the next attack.” 
  • ✇Firewall Daily – The Cyber Express
  • Origin Energy Data Breach Affects 900,000 Current and Former Customers Ashish Khaitan
    The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses
     

Origin Energy Data Breach Affects 900,000 Current and Former Customers

Origin Energy data breach

The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses, dates of birth, phone numbers and account details, along with the last four digits of a credit card or the last three digits of a bank account.  The company said incomplete credit card and bank account details cannot be used to make purchases or access customer accounts.  Origin provides electricity, fossil gas, LPG and internet services to households and businesses across Australia and has approximately 4.8 million customer accounts. 

Frank Calabria Apologizes After Origin Energy Data Breach 

Origin Chief Executive Frank Calabria apologized to customers following confirmation of the breach and warned that affected individuals should remain alert to suspicious activity and a heightened risk of scams.  "We are sorry," Calabria said. "We don't take for granted the trust customers place in Origin, and we're here to support them."  Calabria said Origin first received emails on 2 July from an individual claiming to have accessed customer records. However, the company did not initially consider the threat credible because there was no evidence confirming customer data had been accessed.  The company received proof of customer data access on 22 July, after which Origin announced the incident publicly.  Calabria said the information accessed appeared to be historical customer data obtained "on an unauthorised basis". He said Origin had taken steps to secure its systems and prevent further unauthorised access, adding that the company did not believe any customer information had been published on the dark web. 

Timeline of the Data Breach at Origin Energy 

Origin said it had been reviewing a potential security threat since early July and had worked to assess its credibility and possible impact.  In its update, the company said the threat was not considered credible based on the information available at the time.  "On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution," Calabria said.  The Origin Energy data breach remains under investigation by relevant authorities. Calabria said the company could not provide further details about the incident because it was a criminal matter.  "It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time," he said.  Calabria declined to comment on several issues, including when the breach occurred, whether any employees were involved, whether a ransom had been demanded or paid, and whether there remained an active risk of further data leaks. 

Origin Confirms Investigation into Customer Data Breach 

In its first statement on 23 July 2026, Origin announced it was investigating a potential security incident involving unauthorized access to some customer data.  The company said it did not believe the affected information included customer credit card or bank account details.  "We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers," Origin said.  The company confirmed it had notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.  A later update confirmed there had been unauthorised access and disclosure of customer information. Origin said it was working to identify all affected customers and would contact those whose information had been compromised. 

Around 900,000 Customers Affected by Origin Energy Data Breach 

Following an initial review, Origin confirmed that approximately 900,000 current and former customers had been affected by the breach.  "We have now completed the initial phase of our review into Origin's customer data security incident," Frank Calabria said.  "At this point in time, we believe the information of approximately 900,000 current and former customers was accessed."  Calabria again apologized to customers and said protecting affected individuals remained the company's priority.  "To our customers, I am sorry. We don't take for granted the trust customers place in Origin and our safeguarding of their information," he said.  "We are contacting those customers whose information has been accessed and are providing support to them."  Origin said it had extended customer support hours, established a dedicated contact number and was working with cybersecurity and forensic specialists to contain the incident.  The company also confirmed ongoing cooperation with government agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner. 

Customers Warned about Scams Following Data Breach at Origin Energy 

Origin has made specialist identity and cybersecurity support services available to affected customers.  Customers with concerns can contact Origin through its dedicated support line on +61 8 9922 7000 or email hello@origin.com.au.  The company advised customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts. It recommended avoiding links in unsolicited messages, independently verifying callers through official channels, never sharing passwords, and not providing personal or financial information unless the recipient's identity is confirmed.  Origin also encouraged customers to use two-step authentication, such as authentication applications, for personal email accounts and other online services where available.  We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity," Calabria said.  "We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams." 
  • ✇Firewall Daily – The Cyber Express
  • India Tightens Social Media Rules to Protect Children Online Samiksha Jain
    India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities. The Information Technology Act, 2000, and the
     

India Tightens Social Media Rules to Protect Children Online

India online safety rules

India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities.

The Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, form the core legal framework governing online safety and intermediary responsibilities in India. The government has also highlighted the Digital Personal Data Protection Act, 2023, and recent amendments to the IT Rules as part of its broader approach to digital safety.

India Online Safety Rules Tighten Platform Responsibilities

Under the IT Rules, intermediaries are required to observe due diligence and inform users that they must not host, display, upload, modify, publish, transmit, update or share content that is harmful to children or violates applicable laws.

Recent amendments require social media platforms and other intermediaries to remove unlawful content within three hours of receiving an order from a competent court or a reasoned intimation from the appropriate government or its agency.

The government has also outlined specific obligations related to content involving nudity, impersonation and other sensitive material. In cases involving certain complaints about content featuring full or partial nudity, exposed private areas or artificially morphed images, intermediaries must take reasonable and practicable measures to remove or disable access within two hours.

Government Targets Harmful Content and OTT Platforms

The government said it has taken action against online platforms and OTT services over unlawful and obscene content. In the last two years, 50 OTT platforms have been disabled for public access in India for displaying obscene content and violating provisions including Sections 67 and 67A of the IT Act, Section 294 of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act, 1986.

The government also said it has taken note of reports alleging the dissemination of advertisements linked to child sexual abuse material (CSAM) on social media platforms and sought a detailed report from the concerned intermediary. The National Commission for Protection of Child Rights has also issued notices to the concerned platforms.

India Strengthens AI-Generated Content Safeguards

The government has also expanded its regulatory focus to address risks associated with AI-generated content and synthetically generated information. Amendments to the IT Rules introduce requirements for clear labelling and traceable metadata for permissible AI-generated content, allowing users to identify synthetically generated material.

The framework also strengthens platform accountability and requires greater user awareness about the legal consequences of unlawful AI-generated content. The rules specifically cover harmful material including CSAM, non-consensual intimate imagery and impersonation.

Platforms are required to deploy reasonable and appropriate technical measures, including automated tools or other mechanisms, to prevent users from creating, modifying, publishing or sharing synthetically generated information that violates applicable laws.

Significant Social Media Intermediaries are also required to make reasonable efforts to deploy technical measures to proactively identify content depicting rape, child sexual abuse or conduct, as well as content identical to information previously removed.

Child Privacy and Digital Addiction Remain Key Concerns

The Digital Personal Data Protection Act, 2023, provides a framework for protecting children's privacy online. It mandates parental consent for processing children's personal data and prohibits practices considered detrimental to children's well-being, including tracking, behavioural monitoring and targeted advertising directed at children.

The government has also highlighted digital addiction as a serious challenge affecting children and young people. The Economic Survey 2025-26 noted potential impacts on cognitive development, academic performance, workplace productivity, social connectedness and mental health, alongside risks linked to cyberbullying, compulsive gaming, social media and online gambling.

Cyber Awareness Reaches 11.37 Lakh Participants

Alongside regulatory measures, the government is expanding cyber awareness initiatives through the Information Security Education and Awareness project. So far, 6,650 awareness workshops have been conducted nationwide, reaching more than 11.37 lakh participants, including students, teachers, law enforcement officials, government personnel and members of the public.

The government has also highlighted digital safety initiatives in education. The PRAGYATA Guidelines provide a framework for safe online learning and responsible use of social media and electronic devices. CBSE has introduced digital etiquette and cybersecurity training initiatives, while NCERT has incorporated cyber safety into its curriculum.

The measures were outlined by Union Minister for Electronics and Information Technology Ashwini Vaishnaw in the Lok Sabha on July 22, 2026, as the government continues to strengthen its approach to c child protection and accountability across India's digital ecosystem.

  • ✇Firewall Daily – The Cyber Express
  • Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability Ashish Khaitan
    Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.  The legal action follows a report from 404 Media that revealed a reported vuln
     

Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability

Hide My Email

Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.  The legal action follows a report from 404 Media that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix. 

Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit 

Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email vulnerability had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.  The complaint states that security researchers first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable. 

How Apple’s Hide My Email Feature Works 

Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address. Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication. The lawsuit argues that millions of Apple users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.

Anthony Alvarez Claims Apple Misled Customers Over Privacy 

The complaint argues that Apple built much of its brand identity around privacy, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”  According to the lawsuit, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.  The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a privacy protection tool. 

Lawsuit Seeks Damages and Changes From Apple 

Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.  The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of fraud, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.  The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger privacy features. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue. 
  • ✇Firewall Daily – The Cyber Express
  • Dubai Police Warns Against Online Scams Promising Work and Visit Visas Samiksha Jain
    The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fra
     

Dubai Police Warns Against Online Scams Promising Work and Visit Visas

Dubai Police fraudulent visa ads

The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fraud campaign, which aims to raise awareness about online scams and help residents identify fraudulent schemes.

Dubai Police Fraudulent Visa Ads Circulating on Social Media

According to Dubai Police, scammers are promoting visa services through advertisements and messages that claim to offer work, residency, or visit visas for a fee. The Anti Fraud Centre said these advertisements are designed to convince victims to transfer money by falsely claiming to represent government authorities or licensed visa service providers. Some also use the names of unlicensed companies or offices to appear legitimate. Dubai Police urged the public not to rely on such offers and reminded residents that all visa procedures should be completed only through competent authorities or legally approved offices.

Authorities Urge Public to Verify Visa Offers

The Anti Fraud Centre said verifying the source of a visa service is the first step in avoiding visa fraud. Residents have been advised to confirm the authenticity of any visa offer or application process through official channels before making payments or sharing personal information. The centre also warned against dealing with intermediaries or unknown individuals claiming they can arrange visas through unofficial means. Dubai Police said people should not be misled by promises of guaranteed visas or job opportunities that are offered outside the legal process.

How to Report Fraud Attempts

Dubai Police has asked members of the public to report any fraud or attempted fraud immediately. Reports can be submitted through the Dubai Police Smart App, the eCrime platform for cybercrime reports, or by calling 901. The Anti Fraud Centre reiterated that staying informed and verifying service providers through official channels remain the most effective ways to avoid falling victim to fraudulent visa schemes.
  • ✇Firewall Daily – The Cyber Express
  • EU to Review Social Media Age Limits After Child Safety Report Samiksha Jain
    The European Commission is moving closer to introducing new measures on Child Safety Online after President Ursula von der Leyen received recommendations from a Special Panel examining the impact of social media on children. The report, released Monday, calls for stronger safeguards, greater platform accountability, and age-appropriate restrictions as the EU prepares to review the findings and present legislative proposals after the summer. Speaking alongside the panel's co-chairs, von der Leye
     

EU to Review Social Media Age Limits After Child Safety Report

Child Safety Online

The European Commission is moving closer to introducing new measures on Child Safety Online after President Ursula von der Leyen received recommendations from a Special Panel examining the impact of social media on children. The report, released Monday, calls for stronger safeguards, greater platform accountability, and age-appropriate restrictions as the EU prepares to review the findings and present legislative proposals after the summer.

Speaking alongside the panel's co-chairs, von der Leyen said protecting children online has become one of the most pressing challenges facing governments. She stressed that parents, not algorithms, should shape children's development and warned that the current digital environment is exposing young users to growing risks.

Child Safety Online Becomes a Priority for the EU

Von der Leyen said the Special Panel examined both the opportunities and harms created by social media algorithms and their effects on children. According to the findings highlighted in her statement, young people across Europe now spend between four and six hours each day on screens, while nearly 60% of young children have experienced emotional or psychosocial problems online.

She said these challenges include loss of sleep, anxiety, depression, cyberbullying, exposure to harmful content, and unwanted online interactions, all occurring while children's brains are still developing.

"We believe that parents bring up our kids, and not predatory algorithms," von der Leyen said, adding that social media platforms should no longer have unrestricted access to children.

Digital Services Act Places Responsibility on Platforms

A key recommendation focuses on holding technology companies accountable for the safety of their services. Von der Leyen said platforms that build online systems should also be responsible for ensuring they do not harm users, particularly children.

She pointed to the Digital Services Act (DSA) as the EU's framework for requiring providers to remove harmful features, including addictive algorithms, dark patterns, harmful content, and unwanted contacts.

According to the Commission President, the EU has already taken action under the Digital Services Act against TikTok over its addictive design and recently against Meta. She said platforms have a duty of care toward users and must respond quickly when children report harmful experiences.

EU Considers Social Media Age Restrictions

The report also strengthens the case for introducing social media age restrictions, with von der Leyen arguing that the debate is no longer about whether children use social media but when platforms should be allowed to reach them.

She said the European Union's age verification app is designed to help parents by providing an easy-to-use, privacy-preserving, and open-source tool to verify age before accessing online platforms.

Von der Leyen also suggested that Europe should consider establishing a "social media start date," comparing it to existing age limits for driving and purchasing alcohol.

Panel Calls for Age-Appropriate Digital Access

According to the statement, children under the age of three should have no exposure to screens or digital platforms. Older children should only access social media under parental, caregiver, or teacher supervision and within limited time periods.

Von der Leyen said childhood is a critical stage of brain development and argued that children need opportunities to play, build real-world friendships, and develop their identities before algorithms begin shaping their online experiences.

She added that policymakers should first identify platforms with age-inappropriate and addictive features, describing the category as "social media plus," before considering phased access for different age groups.

EU to Review Recommendations Before New Proposal

The European Commission said the report comes after consultations with parents, educators, experts, young people, EU member states, and international partners, including Australia.

Von der Leyen confirmed that the Commission will now review the recommendations before presenting a formal proposal after the summer.

While no legislative measures have yet been announced, the report signals the EU's intent to strengthen Child Safety Online protections by expanding platform accountability, improving age verification, and evaluating new rules governing children's access to social media.

  • ✇Firewall Daily – The Cyber Express
  • Why India Temporarily Blocked Telegram Ahead of NEET UG 2026 Samiksha Jain
    India has temporarily enforced a Telegram Ban in India ahead of the NEET UG 2026 Re-examination, citing concerns that the platform could be used by organized cheating networks to target candidates. The restriction, recommended by the National Testing Agency (NTA) and implemented through directions issued by the Ministry of Electronics and Information Technology (MeitY), will remain in effect until June 22, 2026. According to the NTA, the measure is intended to support the safe and secure cond
     

Why India Temporarily Blocked Telegram Ahead of NEET UG 2026

Telegram Ban in India

India has temporarily enforced a Telegram Ban in India ahead of the NEET UG 2026 Re-examination, citing concerns that the platform could be used by organized cheating networks to target candidates. The restriction, recommended by the National Testing Agency (NTA) and implemented through directions issued by the Ministry of Electronics and Information Technology (MeitY), will remain in effect until June 22, 2026. According to the NTA, the measure is intended to support the safe and secure conduct of the NEET re-examination scheduled for June 21, 2026, and prevent the spread of fraudulent claims related to exam papers.

Telegram Ban in India Limited to Examination Period

The temporary Telegram Ban in India has been imposed under Section 69A of the Information Technology Act, 2000. The restriction is limited to a defined period covering the examination day and its immediate aftermath. In addition to restricting access to the platform, authorities have directed Telegram to disable its Telegram Message Editing Feature in India until June 30, 2026. The NTA stated that the feature has been misused in the past to create misleading claims of Paper Leak incidents after examinations had already taken place. The agency noted that the temporary measures were adopted after other enforcement actions had already been pursued and were intended to address concerns during the examination window with the minimum restriction considered necessary. Telegram Ban in India Ahead of NEET UG 2026

Coordinated Action Against NEET UG 2026 Exam Fraud Networks

The NTA credited the Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, for coordinating action against channels and groups allegedly involved in Exam Fraud targeting NEET candidates. According to the agency, I4C worked with state law enforcement agencies and MeitY to identify and remove numerous Telegram channels, groups, and bots that openly advertised access to examination papers or related services. Authorities said several channels used names such as "PAPER LEAKED NEET," "Re-NEET 2026," and similar variations while demanding payments from candidates and their families in exchange for purported access to examination material. The NTA reiterated that no examination paper was available outside the secured examination process and described such offers as fraudulent.

Why the Message Editing Feature Was Restricted

The direction related to the Telegram Message Editing Feature addresses concerns about fabricated evidence of examination leaks. According to the NTA, Telegram administrators can edit previously published messages while retaining the original posting timestamp. Authorities stated that this capability has been used in multiple examinations to replace earlier content with actual question papers after an exam had concluded, creating the appearance that the material had been shared before the test. The temporary restriction on editing existing messages is intended to prevent the creation and circulation of such misleading content during the post-examination period.

Law Enforcement Investigations Continue

Authorities also pointed to ongoing enforcement actions in several states. The Bihar Police Economic Offences Unit issued a public advisory on June 9, warning candidates against fraudulent claims of pre-examination paper access circulating through Telegram and other online platforms. Separately, the Ahmedabad City Cyber Crime Branch arrested members of an alleged inter-state cyber fraud network accused of operating multiple Telegram channels linked to the same scheme. Investigators reported documented transactions worth approximately ₹1.5 crore and outreach to nearly 1,000 mobile numbers within a month.

NTA Reassures Candidates

The NTA acknowledged that the restriction affects users who rely on Telegram for educational, professional, and personal communication. However, the agency emphasized that the measure is temporary and focused on protecting the integrity of the NEET UG 2026 Re-examination. The examination will proceed as scheduled on June 21. The agency urged candidates to ignore unverified information circulating online and rely only on official NTA communication channels for updates. Officials also encouraged students and parents to report suspicious activities through the national cybercrime reporting mechanisms and remain cautious of claims related to examination papers circulating on any platform.
  • ✇Firewall Daily – The Cyber Express
  • Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests Ashish Khaitan
    A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism. According to Tempo's technology team, the attacks generated an extraordinary
     

Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests

cyberattacks on Tempo

A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism. According to Tempo's technology team, the attacks generated an extraordinary volume of fake internet traffic, placing significant pressure on the organization's servers and temporarily affecting the availability of the website for readers in Indonesia and elsewhere.

24.9 Million Requests Recorded During Cyberattacks on Tempo 

Tempo Digital Chief Technology Officer Heru Tjatur Tjahja said the cyberattacks on Tempo had reached an unprecedented scale. By Monday, June 8, 2026, the company's monitoring systems had logged a total of 24.9 million requests aimed at its servers.  “The total attacks flooding our website as of June 8 reached 24.9 million requests,” Tjahja said on Monday, June 8, 2026.  The Tempo cyberattack relied on bot-generated traffic, a common tactic used in DDoS incidents. Such attacks typically involve networks of compromised devices sending enormous numbers of requests simultaneously, overwhelming targeted systems and making websites difficult or impossible to access.  Tjahja explained that preliminary findings indicated the attacks occurred intermittently but intensified dramatically during certain periods. 

Largest Wave Hit During Evening Hours 

The investigation into the cyberattacks on Tempo revealed a pattern in the timing of the attacks. According to Tjahja, the attackers frequently launched their operations during evening and early morning hours, when activity surged sharply.  One of the most significant attack waves occurred between 8:30 p.m. and midnight. During that period alone, Tempo recorded 12.97 million attack requests within a span of just two hours.  “For example, the first major wave consisted of 12.97 million attacks in only two hours. From 8:30 p.m. until midnight, the attackers carried out a digital assault,” he said.  The intensity of the attack highlighted the scale of resources being used against the Indonesian media organization. 

Attack Traffic Traced Beyond Indonesia 

Early analysis conducted by Tempo's technology team suggested that the sources of the malicious traffic extended well beyond Indonesia's borders.  While the exact identities of those responsible remain unclear, investigators traced attack activity to multiple countries. According to Tempo, traffic associated with the cyberattacks on Tempo originated from Colombia, the United States, the Philippines, Bangladesh, Mexico, and Indonesia.  The international nature of the attack traffic reflects the complexity of modern DDoS operations, which often use distributed networks of compromised devices globally to conceal the origin of an attack. 

Possible Link to Earlier CMS Breach Attempt 

Tjahja believes the Tempo cyberattack may be connected to an earlier security incident that targeted the organization's content management system (CMS) at the end of May 2026.  During that earlier intrusion attempt, attackers managed to unpublish several articles that had already been published on the website. According to Tjahja, the content affected by the breach involved corruption-related reporting.  However, the CMS architecture limited the level of access available to unauthorized users. As a result, the attackers were unable to permanently remove the articles and could only temporarily unpublish them.  According to Tjahja, the sequence of events suggests a possible connection between the two incidents.  “It appears that those behind the attacks were unhappy and then proceeded with the DDoS attack,” he said. 
  • ✇Firewall Daily – The Cyber Express
  • Austria Blocks Eurovision Cyberattack During Contest Week Ashish Khaitan
    Authorities in Austria said they successfully blocked the Eurovision cyberattack, targeting the Song Contest during the competition week in Vienna.  According to Austrian authorities, nearly 500 cyberattack attempts were recorded during Eurovision activities in the capital. The cyberattack on Eurovision targeted both the official Eurovision website and access control systems used at the venue, raising concerns about possible disruption to one of Europe’s largest live entertainment broadcasts.
     

Austria Blocks Eurovision Cyberattack During Contest Week

Eurovision cyberattack

Authorities in Austria said they successfully blocked the Eurovision cyberattack, targeting the Song Contest during the competition week in Vienna.  According to Austrian authorities, nearly 500 cyberattack attempts were recorded during Eurovision activities in the capital. The cyberattack on Eurovision targeted both the official Eurovision website and access control systems used at the venue, raising concerns about possible disruption to one of Europe’s largest live entertainment broadcasts.  Michael Takàcs, head of Austria’s federal police, said the attempted cyber sabotage operations were detected and prevented before they could cause serious damage. Speaking at a press conference, Takàcs explained that the attackers attempted to slow down systems, interfere with operations, and potentially disable critical infrastructure connected to the contest.  “The perpetrators sought to disrupt, slow down, or disable systems,” Takàcs said, adding that investigators have not yet identified those responsible for the Eurovision cyberattack attempts or determined their motives. 

Eurovision Cyberattack Prompts Major Security Operation in Austria 

In response to the heightened threat environment, Austrian authorities implemented extensive security measures throughout the final week of the Eurovision Song Contest. Around 3,500 Austrian police officers were deployed across Vienna, while special police units from Bavaria, Germany, assisted local law enforcement teams.  Security agencies also increased monitoring of online activity during the event. Officials from Austria’s Interior Ministry said authorities observed rising levels of polarization and radicalization on social media platforms in the lead-up to the contest. Intelligence and domestic security services reportedly paid close attention to extremist threats and groups linked to Iran, although officials did not directly connect them to the cyberattack on Eurovision systems.  Austrian Interior Minister Gerhard Karner said the primary objective was to guarantee public safety during the event and prevent major incidents during live broadcasts and public gatherings. “The goal had been to ensure a safe and peaceful event. We succeeded,” Karner stated, noting that no serious disruptions occurred during the Eurovision Song Contest despite the cybersecurity threats and demonstrations. 

Eurovision Song Contest in Vienna Marked by Protests and Arrests 

Alongside the Eurovision cyberattack attempts, the contest also faced political demonstrations linked to Israel’s participation in this year’s competition. Several protests were held in Vienna during the event week, reflecting broader political tensions that have increasingly surrounded the Eurovision Song Contest in recent years.  Shortly before Saturday’s grand final, Austrian police detained 14 masked pro-Palestinian activists after they refused to end an unauthorized but peaceful protest despite repeated police instructions. Authorities said the demonstrators failed to comply with orders to disperse from the area surrounding the venue.  In total, 16 detentions were made during the Eurovision Song Contest. One individual was also detained after attempting to climb over a security barrier near the event site.  Officials maintained that, despite the tense atmosphere, the event proceeded without any major security failures. Austrian authorities credited the coordinated efforts of police forces, cybersecurity teams, and intelligence agencies for ensuring the competition continued safely and without interruption. 
  • ✇Firewall Daily – The Cyber Express
  • Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation Ashish Khaitan
    Security researchers have disclosed a newly identified local privilege escalation vulnerability in the Linux Kernel, dubbed “Fragnesia,” which belongs to the broader Dirty Frag family of flaws. The issue, officially tracked as CVE-2026-46300, affects the Linux Kernel’s XFRM ESP-in-TCP subsystem and allows unprivileged local attackers to escalate privileges to root by corrupting page-cache memory.  The discovery of Fragnesia highlights how fixes for previous Linux Kernel vulnerabilities can un
     

Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation

Fragnesia

Security researchers have disclosed a newly identified local privilege escalation vulnerability in the Linux Kernel, dubbed “Fragnesia,” which belongs to the broader Dirty Frag family of flaws. The issue, officially tracked as CVE-2026-46300, affects the Linux Kernel’s XFRM ESP-in-TCP subsystem and allows unprivileged local attackers to escalate privileges to root by corrupting page-cache memory.  The discovery of Fragnesia highlights how fixes for previous Linux Kernel vulnerabilities can unintentionally introduce new attack surfaces. According to researcher Hyunwoo Kim, who previously identified Dirty Frag, Fragnesia emerged as an unintended consequence of patches created to mitigate the original Dirty Frag vulnerabilities.  The vulnerability impacts a wide range of Linux distributions, many of which have already begun rolling out security updates. While a proof-of-concept exploit for Fragnesia is publicly available, researchers have stated that there is currently no confirmed evidence of active exploitation in real-world attacks. 

How Fragnesia Targets the Linux Kernel 

Fragnesia exploits a logic flaw within the Linux Kernel’s XFRM ESP-in-TCP implementation. Specifically, the vulnerability stems from improper handling of shared page fragments during socket buffer (skb) coalescing operations.  The attack abuses a condition where file-backed pages are inserted into a TCP receive queue before the socket transitions into ESP-in-TCP ultra-light protocol (ULP) mode. Once ESP processing is activated, the kernel decrypts queued data in-place. This process creates controlled corruption within the underlying page cache through manipulation of the AES-GCM keystream.  Researchers explained that the exploit leverages user and network namespaces to gain CAP_NET_ADMIN privileges inside an isolated namespace. Attackers can then install a specially crafted ESP security association using NETLINK_XFRM and repeatedly trigger controlled single-byte writes into cached file pages.  Using this approach, researchers successfully demonstrated overwriting the opening bytes of /usr/bin/su with a compact ELF payload. The payload executes setresuid(0,0,0) before launching /bin/sh, ultimately providing attackers with a root shell.  Importantly, the modified data exists only within page-cache memory and does not permanently alter the binary stored on disk. However, researchers warned that exploitation is not limited to /usr/bin/su. Any file readable by the user could potentially be modified, including highly sensitive files such as /etc/passwd. 

Relationship Between Fragnesia and Dirty Frag 

Fragnesia shares several characteristics with Dirty Frag and other recently disclosed Linux Kernel privilege escalation flaws, including Copy Fail. All of these vulnerabilities rely on corruption primitives that enable attackers to tamper with protected memory structures.  Microsoft’s threat intelligence team noted the similarities between Fragnesia and Dirty Frag in its analysis of the vulnerability.  “Similar to Dirty Frag, Fragnesia exploits a vulnerability in the XFRM ESP-in-TCP subsystem to achieve a memory write primitive in the kernel,” Microsoft stated.  The company further explained:  “The primitive is then used to corrupt the page cache memory of the /usr/bin/su binary, which in turn leads to launching a shell with root privilege. Note that exploitation is not constrained to use the /usr/bin/su binary; it can modify any file readable by the user, including /etc/passwd.”  Microsoft also warned that Copy Fail has already been exploited in the wild. Shortly after Dirty Frag was disclosed, the company indicated that it may also have been leveraged in malicious attacks.  On May 8, Microsoft reported that telemetry from its Defender platform had identified limited activity that could indicate attempted exploitation involving either Dirty Frag or Copy Fail. At the time of publication, however, there were no additional public reports confirming exploitation of Dirty Frag or Fragnesia in active campaigns. 

Why XFRM ESP-in-TCP Matters 

The XFRM ESP-in-TCP subsystem plays a key role in enabling Encapsulating Security Payload (ESP) traffic over TCP connections within the Linux Kernel. Because ESP-in-TCP is used in certain VPN and encrypted networking scenarios, vulnerabilities affecting this component can expose critical systems to local privilege escalation attacks.  Fragnesia demonstrates how flaws in low-level networking components can lead to deterministic page-cache corruption, giving attackers powerful primitives capable of bypassing standard file protections.  Unlike some earlier Linux Kernel privilege escalation flaws, Fragnesia does not require host-level privileges before exploitation. This significantly lowers the barrier for local attackers operating within constrained environments.  Researchers also pointed out that AppArmor restrictions on unprivileged user namespaces, which are enabled by default on Ubuntu systems, may provide partial mitigation. However, additional bypasses could still allow successful exploitation under certain conditions. 

Mitigation and Security Recommendations 

Security experts strongly recommend that organizations apply vendor-provided Linux Kernel patches addressing Fragnesia and the underlying XFRM ESP-in-TCP vulnerability as soon as updates become available.  Until patches are fully deployed, administrators are advised to disable vulnerable modules associated with both Fragnesia and Dirty Frag if they are not required. Recommended commands include:  rmmod esp4 esp6 rxrpc  Administrators can also prevent the modules from loading by creating the following configuration:  printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/fragnesia.conf  Researchers additionally recommend restricting or disabling unprivileged user namespaces wherever operationally feasible. Monitoring systems for suspicious namespace creation, abnormal AF_ALG usage, or unauthorized XFRM manipulation may also help detect exploitation attempts.  If compromise is suspected, administrators should reboot affected systems or clear page-cache contents to remove modified in-memory binaries:  echo 1 | tee /proc/sys/vm/drop_caches  As Linux Kernel developers continue addressing Dirty Frag-related vulnerabilities, Fragnesia serves as another example of how security patches can unintentionally introduce new weaknesses into complex subsystems such as XFRM ESP-in-TCP. 
  • ✇Firewall Daily – The Cyber Express
  • California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement Samiksha Jain
    California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimizat
     

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.
  • ✇Firewall Daily – The Cyber Express
  • UIDAI, NFSU Sign 5-Year Pact to Boost Cybersecurity and Digital Forensics Ashish Khaitan
    The collaboration between the Unique Identification Authority of India and the National Forensic Sciences University marks a significant development in India's security landscape and digital forensics. In a move aimed at strengthening the country’s digital infrastructure, UIDAI and NFSU have formalized a five-year partnership to advance research, training, and operational capabilities in cybersecurity and digital forensics.  According to an official statement, UIDAI and NFSU have established a
     

UIDAI, NFSU Sign 5-Year Pact to Boost Cybersecurity and Digital Forensics

UIDAI and NFSU

The collaboration between the Unique Identification Authority of India and the National Forensic Sciences University marks a significant development in India's security landscape and digital forensics. In a move aimed at strengthening the country’s digital infrastructure, UIDAI and NFSU have formalized a five-year partnership to advance research, training, and operational capabilities in cybersecurity and digital forensics. 

According to an official statement, UIDAI and NFSU have established a structured collaboration designed to address emerging challenges in cybersecurity and digital forensics.

UIDAI and NFSU Join Forces on Cybersecurity and Digital Forensics

The agreement, announced on May 5 in Ahmedabad, provides a comprehensive framework to bring together expertise from both institutions. It is intended to reinforce cyber resilience across UIDAI’s systems, which form the backbone of India’s digital identity ecosystem.  The Ministry of Electronics and Information Technology highlighted that this partnership creates an umbrella structure for coordinated efforts in research, technical development, and capacity building. The initiative underscores the growing importance of cybersecurity and digital forensics as critical components of national digital infrastructure. 

Six Strategic Pillars Driving UIDAI and NFSU Collaboration 

The UIDAI and NFSU partnership is structured around six key pillars, each targeting specific aspects of cybersecurity and digital forensics. These include academic and professional development, aimed at building skilled talent in the field, as well as strengthening information security and system integrity within UIDAI’s ecosystem.  Another major focus area is the development of advanced forensic infrastructure and laboratory capabilities. This will support deeper investigation and analysis of cyber incidents. Additionally, the agreement outlines provisions for technical support in cybersecurity operations, ensuring that UIDAI benefits from NFSU’s specialized expertise.  The collaboration also emphasizes joint research and technical advisory in emerging technologies. Areas such as artificial intelligence, blockchain, cryptography, and deepfake detection are expected to play a central role. The sixth pillar focuses on strategic placement and outreach, creating pathways for NFSU students to gain hands-on experience and career opportunities within UIDAI-related projects. 

Strengthening India’s Digital Backbone

India’s digital identity framework, powered by UIDAI, requires continuous upgrades to counter evolving cyber threats. The UIDAI and NFSU partnership aims to address this need by integrating advanced cybersecurity and digital forensics practices into the system’s core operations. UIDAI Chief Executive Officer Vivek Chandra Verma described the agreement as a crucial step toward enhancing the security architecture of India’s digital public infrastructure. He stated that the collaboration will significantly improve forensic readiness and resilience, ensuring stronger protection against cyber risks. The signing ceremony was attended by senior officials from both institutions, including Deputy Director General Abhishek Kumar Singh and NFSU Gujarat Campus Director S. O. Junare. Their presence highlighted the institutional commitment to advancing cybersecurity and digital forensics through sustained collaboration. 

Expanding Access While Enhancing Security 

Alongside this partnership, UIDAI has also taken steps to improve accessibility to its services. Collaborations with digital platforms like MapmyIndia and Google now allow users to locate authorized Aadhaar centers more easily. These platforms provide information on available services, operating hours, and accessibility features. While these initiatives focus on user convenience, they also align with the broader objective of strengthening the integrity of India’s digital identity system. By combining improved accessibility with robust cybersecurity and digital forensics measures, UIDAI aims to maintain trust in its infrastructure.

Australia Forms Cyber Incident Review Board to Strengthen Defences After Major Breaches

Cyber Incident Review Board

Australia has announced the creation of a Cyber Incident Review Board, a move aimed at strengthening the country’s ability to respond to and learn from major cyberattacks. The initiative places Australia among a small group of jurisdictions globally that have formalised independent review mechanisms to assess significant cyber incidents and improve long-term resilience. The Cyber Incident Review Board will conduct no-fault, post-incident reviews of major cybersecurity events affecting both government and private sector organisations. Rather than assigning blame, the board’s mandate is to identify systemic gaps and generate actionable recommendations to improve how Australia prevents, detects and responds to cyber threats. Established under the Cyber Security Act 2024, the board is a central element of the government’s 2023-2030 Australian Cyber Security Strategy. The broader goal is to position Australia as one of the most cyber secure nations by the end of the decade, supported by resilient infrastructure, prepared communities and stronger industry practices. Officials said the Cyber Incident Review Board will focus on extracting lessons from incidents and translating them into practical steps that can reduce the likelihood and impact of future attacks.

Cyber Incident Review Board Brings Leaders From Cross-Sector 

The government has appointed a panel of senior cybersecurity and industry leaders to the Cyber Incident Review Board. The board will be chaired by Narelle Devine, Global Chief Information Security Officer at Telstra. Other members include Debi Ashenden of the University of New South Wales, Valeska Bloch from Allens, Jessica Burleigh of Boeing Australia, Darren Kane from NBN Co, Berin Lautenbach of Toll Group and Nathan Morelli from SA Power Networks. The group brings experience across cybersecurity operations, legal frameworks, governance, national security and critical infrastructure. Authorities said this mix is designed to ensure independent, credible advice that reflects both technical and policy realities.

Government Emphasises Learning Over Blame

Australia’s Minister for Cyber Security Tony Burke said the Cyber Incident Review Board will play a key role in ensuring continuous improvement in national cyber defence. “We know that cyber attacks are constant. This guarantees we learn from every attack and keep increasing our resilience,” Burke said in a statement. He added that the board will examine major cybersecurity incidents, develop findings and provide recommendations that can be applied across sectors. The no-fault model is intended to encourage cooperation from affected organisations, while still producing insights that can benefit the wider ecosystem.

Response Shaped by Recent High-Profile Cyberattacks

The creation of the Cyber Incident Review Board follows a series of major cyber incidents in Australia, including breaches involving health insurer Medibank and telecom provider Optus. These events exposed sensitive customer data and triggered widespread public concern, increasing pressure on the government to strengthen cybersecurity oversight. By introducing structured post-incident reviews, authorities aim to ensure that lessons from such breaches are not lost and can inform future preparedness efforts.

How Australia’s Approach Compares Globally

Australia’s Cyber Incident Review Board aligns with similar efforts internationally but includes some distinct features. The European Union has established a comparable mechanism under its Cyber Solidarity Act, tasking the EU Agency for Cybersecurity with reviewing significant cross-border incidents. However, that framework has yet to be tested in practice. In the United States, a cyber safety review board has already examined several incidents, including a high-profile breach involving Microsoft. That report pointed to avoidable security failures and called for cultural and leadership changes within the company, prompting CEO Satya Nadella to prioritise security across operations. However, earlier U.S. reviews, such as those into the Log4j vulnerability and the Lapsus$ group, were criticised for lacking focus and impact. Analysts noted that broader, less targeted reviews made it harder to drive accountability or meaningful change.

Stronger Powers to Ensure Participation

One notable difference in Australia’s model is its ability to compel organisations to provide information if they decline to participate voluntarily. This marks a shift from the U.S. approach, which relied on cooperation from affected entities. Experts have argued that such powers could improve the depth and accuracy of findings, ensuring that the Cyber Incident Review Board has access to critical data when analysing incidents. At the same time, the framework stops short of allowing flexible expansion of board membership for specialised cases, an idea that has been suggested in international policy discussions.

Focus on Long-Term Cyber Preparedness

The Cyber Incident Review Board is expected to become a key mechanism in shaping Australia’s cybersecurity posture over the coming years. By systematically reviewing incidents and sharing lessons across sectors, the government hopes to build a more coordinated and resilient defence against evolving cyber threats. With cyberattacks continuing to target critical infrastructure, businesses and public services, the success of the Cyber Incident Review Board will likely depend on its ability to translate insights into measurable improvements across the national ecosystem.
  • ✇Firewall Daily – The Cyber Express
  • Global Rights Event Scrapped in Zambia Amid Sudden Government Decision Samiksha Jain
    The global digital rights conference RightsCon 2026 has been cancelled just days before its scheduled start in Lusaka, after Zambia’s government intervened, citing concerns over the event’s themes and participation. The decision has left thousands of attendees stranded or forced to change plans, marking a major disruption for one of the world’s largest gatherings focused on digital rights. The conference, hosted by Access Now, was set to begin on May 5 and expected to bring together more than
     

Global Rights Event Scrapped in Zambia Amid Sudden Government Decision

RightsCon 2026

The global digital rights conference RightsCon 2026 has been cancelled just days before its scheduled start in Lusaka, after Zambia’s government intervened, citing concerns over the event’s themes and participation. The decision has left thousands of attendees stranded or forced to change plans, marking a major disruption for one of the world’s largest gatherings focused on digital rights. The conference, hosted by Access Now, was set to begin on May 5 and expected to bring together more than 2,600 in-person participants and 1,100 online attendees from over 150 countries. However, organisers confirmed that RightsCon 2026 will not proceed either in Zambia or virtually.

Sudden Cancellation of RightsCon 2026

The first indication of trouble emerged when Zambia’s Minister of Technology and Science raised concerns about incomplete security clearances and the nature of the conference’s discussions. Soon after, state-owned media announced that the government had “postponed” the event. Organisers say the move came without formal consultation. In a detailed statement, Access Now described the situation as unprecedented and deeply disruptive. “To our community, We are devastated to be writing to you instead of gathering together as planned and we know we’re not alone. The frustration and disappointment stemming from the loss of RightsCon 2026 is felt deeply by all of us, especially our partners in the region who worked tirelessly alongside our team.” The organisation added that the scale of the event made postponement impractical, noting that planning had been underway for more than a year with over 500 sessions scheduled.

Allegations of Foreign Interference

A key issue highlighted by organisers was alleged external pressure linked to participation from Taiwanese civil society groups. According to Access Now, concerns were raised after communication from Zambian officials regarding diplomatic pressure. “We believe foreign interference is the reason RightsCon 2026 won’t proceed in Zambia or online.” The organisers said they were informally told that for the conference to go ahead, certain topics would need to be moderated and some communities excluded, including Taiwanese participants. This, they said, crossed a fundamental line. “This was our red line. Not because we were unwilling to engage, but because the conditions set before us were unacceptable and counter to what RightsCon is and what Access Now stands for.”

Breakdown in Communication

Access Now detailed a breakdown in communication with Zambian authorities in the final days leading up to the event. Despite prior agreements, including a signed memorandum of understanding and coordination on visa processes, organisers said they received no clear explanation before the cancellation was publicly announced. At 9:33 pm local time on April 28, the postponement was reported in the media before organisers received official confirmation. A formal letter followed later, stating that the decision was “necessitated by the need for comprehensive disclosure of critical information relating to key thematic issues proposed for discussion.” Organisers said the explanation lacked clarity and did not specify actionable concerns.

Impact on Global Digital Rights Community

The cancellation of RightsCon 2026 has had immediate consequences for the global digital rights community. Thousands of participants were already travelling to Lusaka when the announcement was made. “It is with heavy hearts that we share: RightsCon will not proceed in Zambia or online.” “We do not recommend registered participants travel to Lusaka for RightsCon.” The event has long been considered a key platform for discussions on internet governance, privacy, cybersecurity, and freedom of expression. Its cancellation raises broader concerns about shrinking civic space and restrictions on global dialogue. Access Now described the situation as part of a wider challenge facing civil society. “We see this unilateral decision, and the way it was taken, as evidence of the far reach of transnational repression targeting civil society, and effectively shrinking the spaces in which we operate.”

What Comes Next After RightsCon 2026 Cancellation

Despite the setback, organisers reaffirmed their commitment to the event’s mission and the broader digital rights movement. “RightsCon may not happen in Zambia, but we will come together again; how and where we do so will be informed by you, our community.” Access Now also acknowledged the support received from partners, governments, and participants in the aftermath of the cancellation. The abrupt halt of RightsCon 2026 highlights the challenges facing international forums that address sensitive issues such as digital freedoms.
  • ✇Firewall Daily – The Cyber Express
  • Australia’s APRA Issues AI Risk Warning to Banks and Insurers Samiksha Jain
    The APRA AI risk warning has placed banks, insurers, and superannuation trustees on alert as Australia’s financial regulator calls for a significant uplift in how artificial intelligence is governed across the sector. The Australian Prudential Regulation Authority has stated that current governance, risk management, and operational resilience practices are not keeping pace with the rapid adoption of AI. In a letter to regulated entities, APRA said the APRA AI risk warning follows a targete
     

Australia’s APRA Issues AI Risk Warning to Banks and Insurers

APRA AI risk warning

The APRA AI risk warning has placed banks, insurers, and superannuation trustees on alert as Australia’s financial regulator calls for a significant uplift in how artificial intelligence is governed across the sector. The Australian Prudential Regulation Authority has stated that current governance, risk management, and operational resilience practices are not keeping pace with the rapid adoption of AI. In a letter to regulated entities, APRA said the APRA AI risk warning follows a targeted supervisory review conducted late last year across major financial institutions. The review assessed how AI is being deployed and governed across the industry and found widening gaps between technology adoption and risk control frameworks.

APRA AI Risk Warning on Governance and Operational Gaps

The APRA AI risk warning highlights that AI is increasingly being embedded into operational systems, customer services, and decision-making tools across regulated entities. While adoption is accelerating, APRA observed that governance structures have not matured at the same speed. According to the regulator, assurance practices remain fragmented, particularly in areas involving cyber security, data protection, procurement, and operational resilience. The APRA AI risk warning notes that many organisations are still relying on traditional risk management approaches that are not designed for AI-driven systems. Another key concern raised in the APRA AI risk warning is the limited visibility over how AI models are trained, updated, or modified when embedded within third-party platforms. This lack of transparency, APRA said, reduces the ability of institutions to fully assess risks linked to model behaviour and system dependencies.

Board Oversight Gaps Highlighted in APRA Warning

The APRA AI risk warning also draws attention to board-level oversight challenges. While boards show strong interest in AI-driven productivity and customer service improvements, many still lack sufficient technical understanding to effectively challenge management decisions. APRA observed that some boards are heavily reliant on vendor summaries and presentations rather than detailed internal assessments of AI risk exposure. The APRA AI risk warning stresses that this creates blind spots in governance, particularly when dealing with unpredictable model outputs and operational risks.

AI Risk Warning Flags Cyber and Concentration Risks

Cybersecurity is a major focus of the APRA AI risk warning, with APRA noting that advanced AI models could significantly increase the speed and scale of cyberattacks. The regulator specifically referenced frontier AI models that may assist malicious actors in identifying system vulnerabilities more efficiently. The APRA AI risk warning also highlights growing concentration risk, where institutions depend heavily on single AI providers across multiple use cases. APRA cautioned that insufficient contingency planning in such scenarios could create operational vulnerabilities if service disruptions occur.

Fragmented Risk Management Systems

A key theme in the APRA AI risk warning is the fragmented nature of current risk management frameworks. AI-related risks often cut across multiple domains, including cyber security, privacy, procurement, and operational risk. However, APRA found that existing systems are not always integrated enough to manage these overlaps effectively. The regulator said this fragmentation limits the ability of financial institutions to gain a complete view of AI-related exposure and weakens overall assurance mechanisms.

Expectations for Stronger Controls

APRA Member Therese McCarthy Hockey stated that financial institutions must adapt quickly to manage emerging risks while continuing to leverage AI for efficiency and service improvements. She noted that while AI presents significant opportunities, organisations must ensure their systems are capable of identifying and responding to vulnerabilities at a pace matching AI-driven threats. The APRA AI risk warning outlines expectations for boards to maintain sufficient understanding of AI systems, set clear risk appetite frameworks, and ensure stronger oversight of third-party dependencies. APRA also expects clearer triggers for intervention when systems do not operate as intended.

Ongoing Supervisory Focus

The APRA AI risk warning confirms that while no new regulatory requirements are being introduced at this stage, APRA expects immediate improvements in how institutions manage AI-related risks. The regulator has indicated that it will continue to monitor AI adoption closely and may consider further policy action if necessary. APRA also stated it will continue engaging with domestic and international regulators to assess emerging risks linked to AI technologies and their impact on financial system stability.
❌
❌