6019 events
AI Regulation 2

EU AI Act GPAI Obligations Full Deadline

The EU AI Act's obligations for General-Purpose AI model providers become fully applicable, with GPAI providers required to maintain technical documentation, comply with EU copyright law, publish summaries of training data, and implement systemic-risk mitigation measures for the most capable models. The EU AI Office begins formal oversight of GPAI compliance across all member states.

eu-ai-act gpai deadline compliance foundation-models
Ransomware & Malware

Microsoft and DOJ Disrupt Lumma Stealer Malware Infrastructure

Microsoft's Digital Crimes Unit and the US Department of Justice, in coordination with Europol and international law enforcement, seized infrastructure supporting the Lumma Stealer malware-as-a-service operation. Lumma had infected hundreds of thousands of devices globally to steal credentials, cryptocurrency wallets, and sensitive files. The operation dismantled over 2,300 malicious domains used by the threat actor.

lumma-stealer malware takedown microsoft doj europol infosteal maas
AI Regulation 3

US Releases National AI Strategy Under Trump Administration

The Trump White House releases an updated National AI Strategy emphasising US AI dominance, removing regulatory barriers to AI deployment, and prioritising AI applications for economic competitiveness and national security. The strategy includes a National AI Infrastructure Initiative to build sovereign US AI compute capacity and directs agencies to accelerate AI procurement.

us national-ai-strategy trump ai-competitiveness deregulation national-security compute
Security Breaches

Wyoming County, New York Listed by ThreeAM Ransomware

ThreeAM ransomware listed Wyoming County, New York — a county government providing job opportunities, economic development, and community services in western New York State — on its extortion site in May 2026. ThreeAM is a known ransomware operation associated with former Conti/Ryuk infrastructure, targeting primarily US government and business entities.

ransomware threeam county-government New-York US
Security Breaches

Winona County, Minnesota Breached by Interlock

Interlock ransomware listed Winona County, Minnesota — located in the Mississippi River blufflands of south-eastern Minnesota — on its leak site in May 2026, claiming to have exfiltrated confidential data held by the county. Interlock has maintained consistent targeting of US county and municipal governments throughout 2025–2026. The listing appeared on 1 May 2026.

ransomware interlock county-government Minnesota US
AI Regulation 2

EU AI Act High-Risk AI Obligations Approaching — August 2026 Deadline

With the EU AI Act's high-risk AI system obligations set to apply from 2 August 2026, the EU AI Office and national market surveillance authorities intensified compliance readiness activities in April 2026. Providers of high-risk AI systems in areas including employment screening, credit scoring, biometric identification, and critical infrastructure management began conformity assessment procedures.

EU AI Act high-risk AI conformity assessment market surveillance compliance August 2026 employment AI credit scoring
Cybersecurity Law & Policy 1

NIST Publishes Cybersecurity Framework Version 3.0

NIST released version 3.0 of the Cybersecurity Framework (CSF), significantly expanding the Govern function, incorporating AI and supply chain security considerations, and adding new implementation tiers reflecting the increasing maturity of organisational cybersecurity practices. The updated framework included sector-specific profiles for healthcare, financial services, and critical manufacturing.

nist csf framework regulation ai supply-chain governance standard
AI Regulation 2

EU AI Act Employment AI Rules Enter Preparatory Phase

The EU AI Office releases preparatory guidance for AI systems used in employment contexts (recruitment, performance monitoring, task allocation), which will be regulated as high-risk systems from August 2026. Guidance covers worker information rights, algorithmic management transparency, and workers' representative consultation requirements. Several trade unions file formal complaints regarding existing AI-enabled workforce monitoring systems.

eu-ai-act employment algorithmic-management worker-rights high-risk-ai trade-unions
Security Breaches

Bayou Title Louisiana Breached by Aurora, 70,000-100,000+ SSNs Exfiltrated

Bayou Title, Inc., the largest title insurance agent and closing/settlement services provider in Louisiana with 19 full-service locations statewide, was claimed by the Aurora ransomware group.

ransomware aurora title-insurance louisiana ssn data-theft
AI Regulation 2

UK Introduces AI Regulation Bill to Parliament

The UK government introduces the AI Regulation Bill to Parliament, establishing a statutory framework for AI oversight that empowers existing sector regulators (FCA, ICO, CMA, MHRA) to apply AI-specific requirements within their domains. The bill establishes a cross-sectoral AI Authority with coordinating and standards-setting powers.

uk ai-regulation-bill ai-authority sector-regulator fca ico cma
Privacy & Data Protection 1

Spanish AEPD Fines Meta €2.5M for WhatsApp Data Sharing Violations

Spain's Agencia Española de Protección de Datos fined Meta €2.5 million for sharing WhatsApp user data with Facebook for advertising personalisation without adequately informing Spanish users or obtaining valid consent.

AEPD Spain Meta WhatsApp GDPR €2.5 million data sharing consent fine
Surveillance & Intelligence 2

EU Parliament Votes Down Proposal to Expand Law Enforcement AI Surveillance

The European Parliament voted down a proposal from several member states to create an exemption allowing broader use of real-time AI facial recognition by law enforcement in counterterrorism operations, beyond the narrow exceptions permitted under the EU AI Act.

EU facial-recognition surveillance AI-Act biometrics law-enforcement civil-liberties
Security Breaches

Rural Municipality of Gimli, Manitoba Attacked by Payload Ransomware

Payload ransomware listed the Rural Municipality of Gimli, Manitoba, Canada — a local government district on the western shore of Lake Winnipeg known for its Icelandic heritage and recreational tourism — on its extortion site in April 2026. The municipality administers residential and lakefront communities and holds resident and administrative data.

ransomware payload municipal-government Canada Manitoba
Policy & Regulation 2

Deepfake Election Content Incidents Prompt Regulatory Action

A series of AI-generated deepfake videos targeting candidates in the 2026 US midterm elections prompt the FEC to issue emergency guidance and Congressional hearings on AI in political advertising. Multiple states introduce or accelerate legislation requiring disclosure of AI-generated political content.

deepfakes elections midterms fec political-ai disinformation synthetic-media
Nation-State & APT 1

US Military Infrastructure in Guam Targeted by Volt Typhoon

The NSA and CISA issued a classified advisory (later declassified in summary form) revealing that Volt Typhoon had maintained persistent access to US military-adjacent telecommunications and logistics infrastructure in Guam. The disclosure intensified congressional debate over the security of US military assets in the Indo-Pacific region and accelerated defensive cyber operations targeting Volt Typhoon infrastructure.

volt-typhoon china guam military critical-infrastructure apt indo-pacific
Privacy & Data Protection 1

Irish DPC Fines Google €350M for RTB Real-Time Bidding GDPR Violations

Ireland's Data Protection Commission fined Google €350 million for GDPR violations in its real-time bidding (RTB) online advertising system, finding that Google's Authorised Buyers programme broadcast detailed personal profiles of EU internet users to hundreds of advertising partners without adequate safeguards or data processing agreements.

Google DPC Ireland GDPR €350 million real-time bidding adtech RTB fine
Artificial Intelligence 2

Baidu Releases ERNIE 5.0 Foundational Model

Baidu releases ERNIE 5.0, its latest flagship large language model with enhanced multimodal capabilities in Chinese and English. The model shows improved performance on Chinese-language benchmarks and is integrated into Baidu's search engine, enterprise platform, and autonomous driving stack. Baidu positions ERNIE 5.0 as competitive with international frontier models for Chinese enterprise customers.

baidu ernie china llm multimodal chinese-ai foundation-model
Privacy & Data Protection 2

eBay Fined €30 Million by Irish DPC for Transparency Violations

Ireland's Data Protection Commission fined eBay €30 million for failing to provide adequate privacy information to users regarding data processing activities and for unlawful retention of user data beyond stated retention periods. The fine followed a complaint-based investigation and required eBay to undertake compliance measures within six months.

gdpr ebay dpc ireland fine transparency data-retention
Privacy & Data Protection 2

Irish DPC Fines eBay €27M for GDPR Profiling and Transparency Violations

Ireland's Data Protection Commission fined eBay €27 million for GDPR violations related to its behavioural profiling of users for targeted advertising without adequate legal bases, and for providing insufficient transparency about how eBay profiles users across its marketplace and advertising ecosystem.

eBay DPC Ireland GDPR €27 million profiling targeted advertising transparency fine
Science Breakthroughs 1

Commonwealth Fusion Systems Demonstrates High-Field Magnet in Full-Scale Prototype

Commonwealth Fusion Systems announced successful operation of its SPARC high-temperature superconducting magnet technology at full design parameters in a prototype configuration, a key milestone toward its planned SPARC fusion reactor.

fusion-energy CFS SPARC high-temperature-superconductor magnets clean-energy private-fusion
Cybercrime & Hacking

Magecart Campaign Targets E-Commerce Platforms with Updated Skimmer

Security researchers identified a large-scale Magecart digital skimming campaign targeting e-commerce websites running WooCommerce and Magento platforms. The skimmer used advanced obfuscation and injected into third-party payment widgets to avoid detection. Hundreds of online retailers were compromised, with payment card data for over 200,000 customers exfiltrated to attacker-controlled servers.

magecart skimmer ecommerce payment-card woocommerce magento javascript
Financial Breaches

Frost Bank Texas Listed by Everest Ransomware Group

Frost Bank, a major Texas-based financial institution and subsidiary of Cullen/Frost Bankers, Inc. founded in 1868 and headquartered in San Antonio, was listed by the Everest ransomware group. Frost Bank operates across major Texas cities offering personal and commercial banking, wealth management, insurance, and investment services to a large customer base.

ransomware everest commercial-bank texas wealth-management
Financial Breaches

Citizens Bank Listed as Victim by Everest Ransomware Group

Citizens Bank, a major American retail and commercial bank headquartered in Providence, Rhode Island, was listed by the Everest ransomware group. Citizens Financial Group is one of the largest bank holding companies in the United States, serving millions of personal and business banking customers. The Everest group threatened publication of corporate and customer financial data.

ransomware everest retail-bank rhode-island major-bank
Internet Culture 1

AI-Generated Political Disinformation Surges Ahead of European Elections

European election monitoring bodies documented a significant surge in AI-generated disinformation content including synthetic candidate videos, fabricated audio clips, and coordinated inauthentic social media campaigns ahead of multiple national elections in 2026.

AI-disinformation deepfake elections EU DSA political-manipulation synthetic-media
AI Regulation 2

EU AI Office Issues First Fine Under AI Act to GPAI Provider

The EU AI Office imposed the first fine under the EU Artificial Intelligence Act, fining a large GPAI model provider approximately €10 million for failing to publish required technical documentation and capability evaluation results within the deadlines set under the GPAI transparency obligations that entered force in August 2025.

EU AI Act EU AI Office GPAI fine transparency technical documentation enforcement model provider
AI Regulation 2

G7 Issues AI Governance Communique Under Canadian Presidency

The G7, meeting under Canada's 2026 presidency, issues a joint communique on AI governance endorsing the Hiroshima AI Process principles and committing member states to mutual recognition of AI safety evaluation results.

g7 ai-governance hiroshima-ai-process military-ai laws international multilateral
Cybercrime & Hacking

Pakistan Government Websites Defaced Following India-Pakistan Tensions

Multiple Pakistani government websites were defaced and temporarily taken offline following an escalation of India-Pakistan regional tensions. Indian hacktivist groups claimed responsibility for the disruptions, while Pakistani state-linked threat actors reportedly conducted retaliatory intrusion attempts against Indian government and financial sector targets. Both governments denied state involvement in the attacks.

hacktivism pakistan india government defacement geopolitics cyberwarfare
AI Regulation 2

EU AI Liability Directive Adopted

The European Parliament formally adopts the AI Liability Directive, which harmonises national tort law rules for AI-related damage claims across the EU. The directive introduces a rebuttable presumption of causality for high-risk AI systems and requires that providers disclose evidence about AI systems involved in harm claims.

eu ai-liability directive tort-law high-risk-ai causality regulation
Policy & Regulation

SEC Charges Multiple Public Companies for Delayed Cyber Incident Disclosure

The Securities and Exchange Commission charged four publicly traded companies for failing to timely disclose material cybersecurity incidents under the SEC's 2023 cybersecurity disclosure rules. The companies failed to report significant breaches within the required four-business-day window and provided misleading characterisations of incident severity. Fines totalling $18 million were assessed.

sec disclosure cybersecurity regulation enforcement public-company fine
Big Tech & Antitrust 2

Apple Unveils iPhone 17 With Advanced Apple Intelligence Features

Apple previewed the iPhone 17 lineup at a spring event, highlighting significant improvements to Apple Intelligence including a fully redesigned Siri with multi-app reasoning, personalised on-device AI models, and enhanced Private Cloud Compute capabilities. The devices featured Apple's A19 chip with substantially increased Neural Engine performance.

apple iphone17 apple-intelligence siri A19 consumer-AI on-device