Privacy & Data Security

Over 30 individual Minnesota water and wastewater treatment facilities were simultaneously hit with a cyber-attack from an unknown source on July 26 and 27, 2026. The coordinated attack targeted the utilities’ operational technology systems and caused some affected communities to request that residents minimize water use due to limited stored water. Other communities experienced equipment

Major League Baseball’s (MLB) move to restrict dugout iPad functionality is a reminder that AI governance is showing up everywhere, including in the middle of professional baseball games. According to reports, MLB disabled custom tablet tabs after concerns that teams were using AI-powered tools to support real-time decisions on substitutions, pitch calling, and other in-game

California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request

California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers,

On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule

Threat actors are spoofing big brand logos in recruiting scams to dupe individuals into believing they are working with real companies and to divulge their Google credentials.

The scam was first identified by a Team Cymru researcher, who discovered that threat actors were impersonating recruiters from big brands to target marketing professionals. The fraudulent emails

On July 8, 2026, the Federal Communications Commission (FCC) Enforcement Bureau entered into a consent decree with Voximplant, Inc., a voice and video call platform, to resolve an investigation into whether the company failed to comply with the FCC’s robocall mitigation rules. The FCC’s robocall mitigation framework is designed to make the voice calling ecosystem