Visualização de leitura

Hugging Face Deepfake Tests Raise New Risks for AI Procurement

Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls.

The post Hugging Face Deepfake Tests Raise New Risks for AI Procurement appeared first on TechRepublic.

8 pilares de um programa de compliance com a LGPD

EM CONFORMIDADE

framework · compliance & lgpd

Mural de conformidade: programa de proteção de dados

Estrutura em 8 pilares para construir (ou auditar) um programa de compliance com a LGPD, do mapeamento de dados até a cultura contínua. Marque o progresso por área ou processo avaliado.

⚠ Isto não é aconselhamento jurídico

Este framework organiza a metodologia de um programa de compliance com a LGPD, mas não substitui a avaliação de um advogado ou DPO qualificado para o seu caso concreto — cada setor e modelo de negócio tem nuances específicas.

  • Decisões sobre base legal aplicável, contratos com operadores e resposta a incidentes devem passar por validação jurídica formal.
  • A ANPD publica regulamentações e guias orientativos que podem alterar obrigações específicas — acompanhe as atualizações oficiais.
  • Trate dados pessoais de titulares (clientes, funcionários) com a mesma seriedade que trataria dados financeiros da empresa.
  • Documentar decisões e justificativas é tão importante quanto tomá-las — isso é o que demonstra conformidade em caso de fiscalização.

Contrate um profissional de segurança da informação e mantenha sua empresa à prova de golpes digitais

 


🧠 Entenda o risco

Antes de se proteger, é essencial saber que golpes digitais exploram pressa, distração e confiança. Criminosos usam mensagens falsas, sites clonados e engenharia social para roubar dados e dinheiro.

🔍 Verifique links e remetentes

  • Passe o mouse sobre o link antes de clicar — veja se o endereço parece legítimo.

  • Desconfie de e-mails com erros de ortografia ou domínios estranhos.

  • Nunca baixe anexos de remetentes desconhecidos.

🔐 Ative autenticação em dois fatores

  • Habilite o 2FA em redes sociais, bancos e e-mails.

  • Prefira aplicativos autenticadores (como Microsoft Authenticator ou Google Authenticator) em vez de SMS.

  • Isso bloqueia invasões mesmo que alguém descubra sua senha.

💸 Desconfie de pedidos urgentes de Pix

  • Golpistas simulam familiares ou empresas pedindo transferências imediatas.

  • Confirme por telefone ou outro canal antes de enviar dinheiro.

  • Lembre-se: urgência é sinal de golpe.

🧰 Mantenha antivírus e sistemas atualizados

  • Atualizações corrigem falhas que hackers exploram.

  • Use antivírus confiável e mantenha o firewall ativo.

  • Evite instalar programas de fontes desconhecidas.

🚫 Nunca compartilhe códigos recebidos por SMS

  • Códigos de verificação são pessoais e temporários.

  • Nenhum suporte técnico legítimo pedirá esse código.

  • Compartilhar pode permitir que o golpista acesse sua conta.

🧩 Dica extra: educação digital contínua

  • Leia blogs confiáveis como osintbrasil.blogspot.com.

  • Participe de cursos gratuitos sobre segurança cibernética.

  • Ensine familiares e colegas — proteção é coletiva.

Em um cenário cada vez mais vulnerável a ataques digitais, proteger dados e sistemas deixou de ser opcional — é uma necessidade estratégica. Contratar um profissional de segurança da informação garante que sua empresa esteja preparada para prevenir, detectar e responder a ameaças cibernéticas com eficiência. Esse especialista implementa políticas de proteção, monitora vulnerabilidades e assegura conformidade com normas como LGPD e ISO 27001. Investir em segurança é investir na continuidade e credibilidade do seu negócio.






 


Transformando riscos em decisões estratégicas

Checklist para Compliance — RDS Intelligence Group
RDS Intelligence Group
Doc. CL-COMP / 2026
Auditoria & Governança

Checklist para Compliance

Compliance não é possuir políticas. É conseguir provar que elas funcionam.

Itens comprovados
0/12
O dossiê

12 pontos que uma auditoria vai cobrar de você

Marque cada item já formalizado na sua empresa. Ao lado de cada ponto, a evidência que um auditor, investidor ou regulador vai pedir para acreditar em você.

Se sobrou mais quadrado vazio do que marcado, sua empresa tem política — não tem prova.

Solicitar diagnóstico de compliance
RDS Intelligence Group
Transformando riscos em decisões estratégicas.
Investigação Defensiva · Inteligência Corporativa
Due Diligence · Compliance · Perícia Digital
© 2026 RDS Intelligence Group — Documento confidencial de uso consultivo.

AI Chatbot Warnings May Not Stop Hallucinations, Researchers Say

A June 2026 research review found that AI chatbot warning labels may be a weak safeguard for organization-backed AI advisors, raising new audit questions for IT, security, and compliance teams.

The post AI Chatbot Warnings May Not Stop Hallucinations, Researchers Say appeared first on TechRepublic.

UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

U.S. Government Sues TikTok, TikTok

When governments introduced stricter online age checks under the UK’s Online Safety Act, the goal was to keep children away from harmful content. But in practice, the system is already showing cracks—and the most telling insight comes from the very users it’s meant to protect.

Children aren’t just countering age checks, they’re actively bypassing them—and often with surprising ease.

According to a new report from Internet Matters foundation, nearly half of children (46%) believe age verification systems are easy to get around, while only 17% think they are difficult. That perception isn’t theoretical. It’s grounded in real behavior, shared knowledge, and increasingly creative workarounds.

From simply entering a fake birthdate to using someone else’s ID, children have developed a toolkit to bypass techniques. Some methods are almost trivial—changing a date of birth or borrowing a parent’s login—while others reflect a growing sophistication. Kids reported submitting altered images, using AI-generated faces, or even drawing facial hair on themselves to trick facial recognition systems.

In one striking example, a parent described catching their child using makeup to appear older—successfully fooling the system.

I did catch my son using an eyebrow pencil to draw a moustache on his face, and it verified him as 15 years old. – Mum of boy, 12

But the problem goes deeper than perception. It’s systemic.

Also read: UK Regulator Ofcom Launches Probe into Telegram, Teen Chat Platforms

Bypassing Is the Norm, Not the Exception

The report reveals that nearly one in three children (32%) admitted to bypassing age restrictions in just the past two months. Older children are even more likely to do so, which shows how digital literacy often translates into evasion capability.

The most common methods?

  • Entering a fake birthdate (13%)
  • Using someone else’s login credentials (9%)
  • Accessing platforms via another person’s device (8%)

Despite widespread concerns about VPNs, they play a relatively minor role. Only 7% of children reported using them to bypass restrictions, suggesting that simpler, low-effort tactics remain the preferred route.

In other words, the barrier to entry is not just low—it’s practically optional.

Europe Threat Landscape Q1 2026, Online Age Check Europe’s cyber threat landscape Q1 2026 shows a sharp acceleration in cyber threats across the region. Do you know what's contributing to it?

Check Cyble's full analysis report here!

Even When It Works, It Doesn’t Work

Ironically, even when children attempt to follow the rules, the technology doesn’t always cooperate.

Some reported being incorrectly identified as older—or younger—by facial recognition systems. In cases where they were flagged as underage, enforcement was often inconsistent or temporary. One child described being blocked from going live on a platform for just 10 minutes before being allowed to try again.

This inconsistency creates a loophole where persistence pays. If at first you’re denied, simply try again.

A Risky Side Effect

Perhaps the most concerning finding isn’t that children can bypass age checks—it’s that adults can too.

The report states fears that adults may exploit these same weaknesses to access spaces intended for younger users. In some cases, this involves using images or videos of children to trick verification systems. There are even reports of adults acquiring child-registered accounts to blend into youth platforms.

This flips the entire premise of age verification on its head. Instead of protecting children, flawed systems may inadvertently expose them to greater risk.

Parents, Part of the Problem—or the Solution?

Adding another layer of complexity, parents themselves are sometimes complicit.

About 26% of parents admitted to allowing their children to bypass age checks, with 17% actively helping them do so. The reasoning is often pragmatic. Parents feel they understand the risks and trust their child’s judgment.

I have helped my son get around them. It was to play a game, and I knew the game, and I was happy and confident that I was fine with him playing it. – Mum of non-binary child, 13

But this undermines the consistency of enforcement. If rules vary from household to household, platform-level protections lose their impact.

Interestingly, the data also suggests that communication matters. Children who regularly discuss their online activity with parents are less likely to bypass restrictions than those who don’t.

Why Kids Are Bypassing in the First Place

The motivations aren’t always malicious. In many cases, children are simply trying to access social media (34%), gaming communities (30%), or messaging apps (29%) that their peers are already using.

What this resonate is a fundamental tension where age verification systems are trying to enforce boundaries in environments where social participation is the norm.

Age verification is often positioned as a cornerstone of online safety. But in practice, it’s proving to be more of a speed bump than a safeguard.

Children understand the systems. They share methods. They adapt quickly. And until the technology—and its enforcement—becomes significantly more robust, age checks may offer more reassurance than real protection.

RBI Cybersecurity Compliance Checklist for Fintech Organizations

The financial services ecosystem in India is undergoing rapid digital transformation, and fintech organizations sit at the center of this evolution. With increasing cyber threats targeting digital payments, lending platforms, and financial data, regulatory oversight has intensified. The Reserve Bank of India mandates a strong RBI cybersecurity framework that fintechs must follow to ensure resilience, […]

The post RBI Cybersecurity Compliance Checklist for Fintech Organizations appeared first on Kratikal Blogs.

The post RBI Cybersecurity Compliance Checklist for Fintech Organizations appeared first on Security Boulevard.

NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover

NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover The NIST Cybersecurity Framework is a useful way to organise cybersecurity work around business risk. For UK SMEs, that matters because most teams do not have the time or budget to do everything at once. A framework gives you […]

The post NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover appeared first on Clear Path Security Ltd.

The post NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover appeared first on Security Boulevard.

Protective Security in the NCSC CAF: A Practical Guide for UK SMEs

Protective security is one of those topics that can sound broader and more complex than it needs to be. For UK SMEs, the practical question is simple: what do you need to protect, how much protection is enough, and how do you make it work without creating unnecessary overhead? Within the NCSC Cyber Assessment Framework, […]

The post Protective Security in the NCSC CAF: A Practical Guide for UK SMEs appeared first on Clear Path Security Ltd.

The post Protective Security in the NCSC CAF: A Practical Guide for UK SMEs appeared first on Security Boulevard.

The $700 million question: How cyber risk became a market cap problem

Cyber risk used to be the kind of problem you could delegate. Something for the CISO, the IT team, and maybe an external auditor to worry about once a year. That comfort zone is gone. In the last decade, a new reality has set in: a single cyber incident can erase hundreds of millions of […]

The post The $700 million question: How cyber risk became a market cap problem first appeared on TrustCloud.

The post The $700 million question: How cyber risk became a market cap problem appeared first on Security Boulevard.

IRDAI 2026 Cybersecurity Guidelines for Insurance Companies

The Insurance Regulatory and Development Authority of India (IRDAI) has introduced significant amendments to its cybersecurity guidelines in 2026, marking a shift from static compliance to continuous cyber resilience. For insurers, IRDAI compliance is no longer just about implementing baseline controls. The updated framework demands stronger governance, tighter oversight, real-time monitoring, and accountability across business […]

The post IRDAI 2026 Cybersecurity Guidelines for Insurance Companies appeared first on Kratikal Blogs.

The post IRDAI 2026 Cybersecurity Guidelines for Insurance Companies appeared first on Security Boulevard.

❌