New proposed bill on anti-encryption law requires a backdoor to be placed in nearly every electronic device that has at least 1 GB of memory and all encrypted services.
California is now leading the charge to beef up the cyber security features of connected devices by banning weak passwords, forcing device manufacturers to supply a unique password or force a password change on startup.
The Delete Act (SB 362) expands an existing right under California state law to have personal data deleted, but streamlines the process so that one request will be sent to all data brokers.
A new draft China cybersecurity law could restrict certain U.S. companies from doing business in the country which clearly represent a tit-for-tat in the escalating trade and cyber war between U.S. and China.
A new joint alert from CISA and the FBI seeks to assist private sector software developers in removing XSS vulnerabilities from their products, with a basic overview of best practices aimed primarily at executives and business leaders.
CISA notified 93 critical infrastructure organizations of the presence of a vulnerability that could lead to ransomware attacks, and plans to scale up the program and provide more warnings in the coming months.
Unit 29155's actions since 2020 include cyber attacks on a number of federal agencies and critical infrastructure companies in a variety of countries. But the group seems to have switched most of its focus to Ukraine in the weeks prior to the 2022 military invasion.
A new CISA-NSA joint report follows many calls by both members of the cybersecurity industry and government agencies for a transition to memory-safe languages like Rust, Ruby, Java and C# due to their inherent minimization of memory-related classes of vulnerabilities.
One key finding from CNCERT report shows most cyber attacks are using U.S. servers to implant viruses and carry out botnet attacks against Chinese computer assets.
A nearly unanimous vote in the Connecticut House made the CTDPA official, with its terms set to go into effect on July 1, 2023. As with the other state privacy laws, only businesses that meet certain thresholds of personal information handling will be regulated.










