Over 30 individual Minnesota water and wastewater treatment facilities were simultaneously hit with a cyber-attack from an unknown source on July 26 and 27, 2026. The coordinated attack targeted the utilities’ operational technology systems and caused some affected communities to request that residents minimize water use due to limited stored water. Other communities experienced equipment
Privacy & Data Security
AI Agents A Top 2026 Cybersecurity Threat
Cybersecurity firm Forrester recently issued its annual report, Top Cybersecurity Threats in 2026, which outlines “the most critical risks organizations need to plan for.”
The report predicts the top threats that organizations will face in 2026 based on recent trends and observations. The top five threats expected in 2026 include:
…
Privacy Tip #500 – Wow—500 Privacy Tips! Here’s a Recap
It’s hard to believe that today’s post marks the publication of our 500th Privacy Tip. What a milestone!
We started publishing Tips because readers kept asking me about ways to protect themselves from scams, how to keep up with the latest threats, and how to stay informed about emerging technology. Feedback has been overwhelmingly positive,…
Frontier Model Evaluations Show They “Cheat”
A new study by the AI Security Institute (AISI), Cheating Behaviour in Frontier Model Evaluation, found “cheating behaviour in all of our capability evaluations,” and outlines “the implications as models grow more capable.”
AISI defined “cheating” as “taking an action that is out of scope for the task or explicitly disallowed by the rules,…
AI In the Dugout: MLB’s AI Crackdown Shows Why Guardrails Matter
Major League Baseball’s (MLB) move to restrict dugout iPad functionality is a reminder that AI governance is showing up everywhere, including in the middle of professional baseball games. According to reports, MLB disabled custom tablet tabs after concerns that teams were using AI-powered tools to support real-time decisions on substitutions, pitch calling, and other in-game…
New DROP Requirements Raise the Stakes for Data Brokers Handling Californians’ Personal Information
California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request…
California Privacy Regulator Puts Delivery and Transportation Apps Under the Microscope
California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers,…
CMMC Phase 2: A Pause, Not a Pass
On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule…
Privacy Tip #499 – Scammers Using Big Brand Logos to Launch Fake Recruiting Schemes
Threat actors are spoofing big brand logos in recruiting scams to dupe individuals into believing they are working with real companies and to divulge their Google credentials.
The scam was first identified by a Team Cymru researcher, who discovered that threat actors were impersonating recruiters from big brands to target marketing professionals. The fraudulent emails…
FCC and 49 State Attorneys General Dial Up Attention on Robocall Compliance
On July 8, 2026, the Federal Communications Commission (FCC) Enforcement Bureau entered into a consent decree with Voximplant, Inc., a voice and video call platform, to resolve an investigation into whether the company failed to comply with the FCC’s robocall mitigation rules. The FCC’s robocall mitigation framework is designed to make the voice calling ecosystem…