Visualização de leitura

EU Classifies ChatGPT as Search Engine

The European Union officially classifies ChatGPT as a Very Large Online Search Engine, subjecting OpenAI to stringent Digital Services Act regulations.

Related Posts:

The post EU Classifies ChatGPT as Search Engine appeared first on Daily CyberSecurity.

EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions

Russia cyberattack

The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.

According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted cyber sabotage against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader cyber operations against governments and critical infrastructure across Europe.

Russia Cyberattack Linked to FSB's Center 16 Operations

The European Union said Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.

The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.

British authorities described last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.

Poland Attack Nearly Triggered Major Blackout

The cyber incident targeting Poland's energy infrastructure last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.

However, Poland's national cybersecurity agency, CERT Polska, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.

Separately, Poland's domestic intelligence service warned in May that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.

EU and UK Expand Cyber Sanctions

In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.

The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer malware, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.

EU foreign policy chief Kaja Kallas said Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.

She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.

France Details FSB Activities

France also announced additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.

A technical report from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.

French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of data from a research institute working with the French defense industry in February 2025.

France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games.

Allied Advisory Warns of Ongoing Threats

Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a joint cybersecurity advisory warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.

The United Kingdom separately sanctioned individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the malware have been used to support Russian espionage operations globally. According to the UK's National Crime Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.

British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.

The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has dismissed European allegations of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.

European Parliament Revives Controversial Chat Scanning Law

Chat Control

The Chat Control 1.0 framework has been revived after the European Parliament voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for Child Sexual Abuse Material (CSAM). The decision, taken on July 9, comes months after the temporary regulation expired in April and has reignited debate over privacy, surveillance, and the future of online safety laws in the European Union.

The vote was held on the final sitting day before the Parliament's summer recess. Under an urgent legislative procedure, rejecting the proposal required an absolute majority of all Members of the European Parliament rather than a simple majority of those present. As a result, the proposal passed despite more lawmakers present voting against it than in favor.

Chat Control 1.0 Restores Voluntary CSAM Scanning

The revived regulation, formally known as Regulation (EU) 2021/1232, provides the legal basis for online platforms to voluntarily scan private communications for known and new Child Sexual Abuse Material (CSAM) as well as the solicitation of children.

The original regulation was introduced in 2021 as a temporary derogation from the ePrivacy Directive. It expired in April after lawmakers failed to agree on a long-term replacement amid widespread concerns over user privacy.

Although several technology companies continued voluntary scanning after the regulation lapsed, European authorities had warned that doing so without a legal basis could expose platforms to legal uncertainty. The restored framework does not authorize scanning on end-to-end encrypted messaging services such as Signal.

Urgent Procedure Draws Criticism

The renewed proposal followed an urgent legislative process that critics described as highly unusual. According to CDT Europe, the Parliament had previously rejected a similar proposal in March, but the issue returned through a fast-tracked second-reading procedure supported by European Parliament President Roberta Metsola.

Because the proposal was treated as a second reading, opponents needed at least 361 votes to block it. While a simple majority supported rejecting the measure during voting, it did not reach the higher threshold required under the urgent procedure. Reduced attendance before the summer recess also affected the outcome.

Only two amendments were adopted during the process, both aimed at preserving protections for end-to-end encryption.

Debate Continues Over Permanent CSAM Framework

The revival of Chat Control 1.0 comes shortly after negotiations on the proposed Child Sexual Abuse Material Regulation (CSAR) ended without agreement on June 29. Discussions on the permanent framework are expected to resume after the summer break.

CDT Europe argued that restoring the temporary regulation could complicate ongoing negotiations over the long-term legislative framework. The organization said questions surrounding voluntary or mandatory scanning require careful legal and technical assessment before permanent rules are introduced.

Questions Raised Over the Need for Urgency

Supporters of the urgent procedure argued that allowing the temporary regulation to expire would create an immediate regulatory gap for online platforms investigating child sexual abuse content.

However, CDT Europe challenged that justification, pointing to statements from the German Federal Police, which reportedly acknowledged there was no direct connection between the expiration of the temporary regulation and the number of CSAM reports received.

The organization also noted that several legal mechanisms remain available even without the temporary derogation. These include targeted telecommunications surveillance with judicial authorization, electronic evidence preservation under the EU's e-evidence framework, existing content removal and reporting processes under the Digital Services Act, and hash-matching technology that identifies previously verified CSAM for human review.

Privacy Concerns Remain

Following the vote, CDT Europe said it opposed both the outcome and the legislative process used to restore the regulation. The organization stated it would continue advocating for a future Child Sexual Abuse Material Regulation (CSAR) that rejects indiscriminate mass scanning while protecting end-to-end encryption and fundamental rights.

The renewed Chat Control 1.0 regulation restores the legal framework for voluntary scanning by online platforms, but the broader debate over balancing child protection, privacy, and digital rights in the European Union remains unresolved.

Europe Confirms Record €4.1B Penalty Against Google for Android Practices

EU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices.

The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brought by Google and its parent company Alphabet against an earlier judgment from the General Court, confirming a fine of €4,125,000,000. Alphabet is jointly and severally liable for €1,520,605,895 of that amount.

The case goes back to 2018, when the European Commission concluded that Google had abused its dominant market position through three categories of restrictions built into its Android licensing arrangements. Device manufacturers who wanted access to Google’s Play Store had to pre-install Google Search and Chrome. To get the licences needed for those apps, they also had to agree not to sell devices running Android versions that Google hadn’t approved. And Google paid manufacturers and mobile operators a share of its advertising revenue on the condition that they didn’t pre-install a competing search engine on a defined set of devices. The Commission concluded all three formed a single, coordinated strategy to protect Google’s search dominance, and fined the company €4,342,865,000.

The General Court reviewed the case in 2022 and agreed that the conduct was a single and continuous infringement. It annulled one piece of the Commission’s decision: the part dealing with revenue share agreements tied to the exclusive pre-installation of Google Search on a predefined device portfolio. That partial annulment led the court to recalculate the fine downward to €4.125 billion. Everything else held.

Google and Alphabet then appealed to the Court of Justice, the EU’s highest court, arguing the General Court had made legal errors in its analysis. The Court of Justice went through those arguments and rejected them all.

“The appeal brought by Google and its parent company Alphabet against the judgment of the General Court is dismissed, thereby confirming the penalty imposed for Google Search’s abuse of a dominant position in the context of the Android operating system.” the court’s press release states. “In 2018, the European Commission adopted a decision in which it concluded 1 that Google had abused its dominant position by requiring, in particular through pre-installation agreements and licensing conditions for certain apps, that its search engine, Google Search, and its Chrome browser be promoted on mobile devices running the Android operating system, which is also provided by Google. 2 It therefore found a single and continuous infringement covering the whole of that conduct and imposed an overall fine on Google of €4 342 865 000, with Alphabet jointly and severally liable as to €1 921 666 000.”

Google’s first argument was that the General Court assessed the anticompetitive effects of the pre-installation conditions incorrectly, in particular, that it should have run a counterfactual analysis to show what the market would have looked like without those conditions. However, the Court of Justice disagreed and confirmed the General Court was entitled to look at the full economic context, including the revenue share agreements, without needing to run a formal counterfactual test. The court also confirmed the finding that pre-installed apps enjoy a status quo bias, meaning users are less likely to switch away from them, and that Google hadn’t shown that user preferences or the quality of its services alone explained its market position.

On the pre-installation conditions specifically, Google argued that proving abuse of a dominant position requires showing the conduct could exclude competitors that are equally efficient. The Court of Justice rejected that too.

“Second, the General Court did not err in law by confirming the Commission’s assessment of the pre-installation conditions laid down by the Android agreements. Demonstrating an abuse of a dominant position is not conditional in any case on proof of a capability to foreclose only as-efficient competitors.” continues the press release. “Given the particular characteristics of the digital markets concerned, the General Court was entitled to conclude that those practices were liable to restrict competition and strengthen barriers to entry without applying that test.”

On the anti-fragmentation agreements, which required manufacturers to avoid selling devices running unapproved Android forks, the Court of Justice again sided with the General Court. Those agreements limited the commercial space for Android versions Google hadn’t blessed, which reinforced its dominant position. A counterfactual analysis wasn’t necessary because the anticompetitive effects were already sufficiently established on the facts.

Google also challenged how the fine was calculated, invoking procedural arguments including rights of defence. The Court of Justice endorsed the General Court’s use of its unlimited jurisdiction to set the penalty amount, ruling that the reasoning was sufficient and the procedural principles were respected.

“The Court of Justice endorses the exercise by the General Court of its unlimited jurisdiction to set the amount of the fine, ruling that its reasons were sufficient and that the procedural principles invoked by Google and Alphabet, including rights of defence, were adhered to.” states the report.

Google is disappointed with the ruling.

“We are disappointed with the ruling. Android has given people more choice, not less, enabling thousands of device makers to build affordable smartphones and giving billions of people access to a wide range of apps and services. We will review the judgment carefully.” the company said in a statement.

This is the end of the road for this particular case. The Court of Justice is the EU’s highest court on points of law. There’s no further appeal. The €4.1 billion fine stands, and the legal framework the Commission used to reach that conclusion has now been validated at every level of the EU court system.

The case also sets a precedent for how digital markets get treated under EU competition law. The court confirmed that the standard test used in traditional markets, whether conduct excludes equally efficient competitors, doesn’t automatically apply in digital contexts. That has implications well beyond Google. Any company with a dominant platform position in the EU now knows that structuring licensing arrangements to steer users toward its own products carries real legal risk, even if it can argue its products are genuinely better.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

EU-US Data Privacy Framework Under Threat After Supreme Court Ruling

EU-US Data Privacy Framework

The EU-US Data Privacy Framework is facing renewed legal scrutiny after privacy advocacy group noyb announced plans to challenge the agreement following a recent U.S. Supreme Court decision involving the Federal Trade Commission.

In a letter sent to the European Commission on June 30, noyb founder Max Schrems argued that the Supreme Court's ruling in Trump v. Slaughter undermines a central requirement of the EU-US Data Privacy Framework: independent oversight of personal data transfers between the European Union and the United States.

The case concerns the U.S. Supreme Court's interpretation of presidential authority over independent executive agencies. According to noyb, the decision means that agencies such as the FTC can no longer be considered constitutionally independent, a status the European Commission relied upon when adopting the framework in 2023.

Why the FTC Matters to the Framework

The EU-US Data Privacy Framework, formally adopted through Commission Implementing Decision EU 2023/1795, allows certified U.S. companies to receive personal data from the EU under a system deemed to provide adequate privacy protections.

EU law requires that data protection oversight be carried out by an independent authority. The FTC has been the primary U.S. regulator fulfilling that role under the framework.

In its letter, noyb said the European Commission's adequacy decision references the FTC hundreds of times and treats the agency as the key enforcement body for privacy obligations.

Schrems argued that if the FTC's independence is no longer guaranteed, the legal foundation supporting the adequacy decision may no longer satisfy EU constitutional requirements.

Potential Impact on Data Transfers

The challenge does not immediately suspend transatlantic data flows. The European Commission's adequacy decision remains in force unless it is repealed by the Commission or annulled by the Court of Justice of the European Union.

However, the development could create uncertainty for companies that rely on the framework to transfer customer and employee data between Europe and the United States.

noyb is also questioning other oversight mechanisms tied to the agreement, including the Data Protection Review Court created under Executive Order 14086 and the Privacy and Civil Liberties Oversight Board.

The organization argues that these bodies may also be affected by the Supreme Court's reasoning because their independence depends on executive or statutory arrangements that could now face constitutional challenges.

Background: A Long-Running Dispute

The EU-US Data Privacy Framework is the third major attempt to create a legal basis for EU-U.S. data transfers.

Earlier arrangements, Safe Harbor and Privacy Shield, were both struck down by the Court of Justice of the European Union in the Schrems I and Schrems II judgments.

Those rulings focused on U.S. surveillance laws and the lack of effective judicial remedies for EU citizens.

The current framework was introduced in 2023 after negotiations between the European Commission and the Biden administration.

What Happens Next?

noyb has urged the European Commission to begin planning an orderly transition away from the current arrangement rather than waiting for a court ruling.

The group says it intends to file a formal lawsuit challenging the adequacy decision if the Commission does not act.

Legal experts expect any court challenge to take several years before reaching a final judgment.

For now, the EU-US Data Privacy Framework remains valid, but the Supreme Court's decision has reopened a debate that many businesses hoped had been settled.

Europe Moves to Tighten AI Rules While Easing Compliance Burden

EU AI Act

The European Union has reached a provisional agreement to amend parts of the EU AI Act, introducing simplification measures for businesses while also expanding restrictions on harmful AI applications, including so-called “nudifier” apps and AI-generated child sexual abuse material. The agreement, reached early Thursday by negotiators from the European Parliament and the Council, forms part of the EU’s broader “digital omnibus” package aimed at refining the implementation of the bloc’s landmark AI legislation. The updated proposal seeks to reduce compliance burdens and legal uncertainty for AI providers while maintaining the AI Act’s core risk-based framework. Lawmakers said the changes are designed to make the rules more practical without weakening safeguards tied to safety, privacy, and fundamental rights.

EU AI Act Deadlines Pushed to Reduce Legal Uncertainty

One of the biggest changes under the proposed amendments is the postponement of several obligations linked to high-risk AI systems. Under the revised timeline, rules for AI systems classified as high-risk due to their use cases will now apply from 2 December 2027. These systems include AI deployed in biometric identification, critical infrastructure, education, employment, law enforcement, and border management. Meanwhile, AI systems used as safety components under sector-specific EU product safety laws will face compliance obligations from 2 August 2028. The agreement also delays watermarking obligations for AI-generated content until 2 December 2026. The European Commission had earlier proposed a February 2027 implementation date. Watermarking tools are intended to help identify and trace AI-generated images, audio, and video content. Lawmakers said the postponements are necessary to ensure technical standards and implementation guidance are fully in place before the rules become enforceable.

EU Bans Nudifier Apps and AI-Generated Abuse Content

A major part of the agreement focuses on tightening restrictions around harmful AI-generated sexual content. Negotiators agreed to ban AI systems designed to create child sexual abuse material or generate explicit deepfake content involving identifiable individuals without consent. The restriction covers images, video, and audio content. The EU AI Act ban specifically applies to companies placing such AI systems on the EU market, providers failing to include reasonable safeguards against misuse, and users deploying the systems to create illegal or non-consensual explicit material. The decision directly targets “nudifier” apps, which use AI to digitally remove clothing or generate fake explicit imagery of individuals. Companies operating such systems will have until 2 December 2026 to comply with the new requirements. Michael McNamara, co-rapporteur for the Civil Liberties, Justice and Home Affairs committee, said the agreement strengthens the EU’s ability to act against AI systems that threaten human dignity and fundamental rights. “I’m pleased that this morning we reached an agreement on the AI Omnibus,” McNamara said. “Alongside simplification measures, we are banning nudification apps, a key part of the Parliament’s mandate, and, of course, the creation of child sexual abuse material using AI systems.”

Simplification Measures for AI Providers and SMEs

The amendments also introduce several simplification measures intended to reduce overlapping compliance requirements for companies developing AI technologies. Under the new framework, machinery products with AI features will no longer need to comply separately with both the EU AI Act and sector-specific safety laws if existing safety rules already provide equivalent protection. Lawmakers also narrowed the definition of “safety component” within the EU AI Act. This means AI functions designed only to assist users or improve product performance will not automatically be classified as high-risk unless their failure creates health or safety risks. Another change allows companies to process personal data where strictly necessary to detect and correct bias in AI systems, provided appropriate safeguards are in place. The agreement further extends certain exemptions previously available only to small and medium-sized enterprises (SMEs) to small mid-cap companies. EU officials said the move is intended to help startups and growing technology firms scale AI innovation more easily within Europe. Arba Kokalari, co-rapporteur for the Internal Market and Consumer Protection committee, said the revised rules strike a balance between innovation and regulation. “With this agreement, we show that politics can move just as quickly as technology,” Kokalari said. “We now make the AI rules more workable in practice, remove overlaps and pause the high-risk requirements.”

Next Steps for the EU AI Act Amendments

The provisional agreement still requires formal approval from both the European Parliament and the Council before it can become law. EU lawmakers are aiming to finalize adoption before 2 August 2026, which marks the scheduled start date for existing high-risk AI system rules under the original AI Act framework. The negotiations are part of the EU’s continuing effort to shape global standards around artificial intelligence governance while addressing concerns related to safety, transparency, and misuse of generative AI technologies.

Crossbench MPs pressure Labor over gas export tax – as it happened

This blog is now closed

The pollies have been asked this morning whether people should consider working from home to save fuel, as conflict escalates in the Middle East.

Tehran has said it will “irreversibly destroy” essential infrastructure across the Middle East, including vital water systems, if the US follows through on Donald Trump’s threat to “obliterate” Iran’s power plants unless the strait of Hormuz is fully opened within two days.

This is like Covid style restrictions I think that are potentially being floated. I would not support that in any way, and I don’t think businesses would do so either …

If people can work from home and they want to and it works for their employers, fine, I think that’s terrific, but it doesn’t help small businesses. It certainly doesn’t help the truckers and the fishers and the farmers and the manufacturers and the miners that are relying on fuel supply.

Continue reading...

© Photograph: Mick Tsikas/AAP

© Photograph: Mick Tsikas/AAP

© Photograph: Mick Tsikas/AAP

❌