nicfab
127 subscribers
15 photos
16 files
2.43K links
Canale di aggiornamento su Privacy, Data Protection, IA e Cybersecurity
Channel for updates on Privacy, Data Protection, AI, and Cybersecurity
Download Telegram
Daily Digest | 23 March 2026

EDPB-EDPS Joint Opinion on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive
EDPS News Feed
https://www.edps.europa.eu/press-publications/press-news/news/2026/edpb-edps-joint-opinion-cybersecurity-act-2-and-amendments-nis-2-directive

High-Level Debate: “From Omnibus to Opportunity: Driving Data Protection and Innovation”
EDPS News Feed
https://www.edps.europa.eu/press-publications/press-news/news/2026/high-level-debate-omnibus-opportunity-driving-data-protection-and-innovation_en

PODCAST - A proposito di privacy - Sesto episodio - DOSSIER SANITARIO
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10148225

VoidStealer malware steals Chrome master key via debugger trick
BleepingComputer
https://www.bleepingcomputer.com/news/security/voidstealer-malware-steals-chrome-master-key-via-debugger-trick/

A Novel Solution for Zero-Day Attack Detection in IDS using Self-Attention and Jensen-Shannon Divergence in WGAN-GP
cs.LG updates on arXiv.org
https://arxiv.org/abs/2603.19350

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 24 March 2026

CONSIL:ST_7470_2026_INIT: Proposal for a COUNCIL RECOMMENDATION on a European Union framework for science diplomacy -...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CONSIL:ST_7470_2026_INIT

North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware
The Hacker News
https://thehackernews.com/2026/03/north-korean-hackers-abuse-vs-code-auto.html

FBI says Iranian hackers are using Telegram to steal data in malware attacks
TechCrunch
https://techcrunch.com/2026/03/23/fbi-says-iranian-hackers-are-using-telegram-to-steal-data-in-malware-attacks/

Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack
SecurityWeek RSS Feed
https://www.securityweek.com/aquas-trivy-vulnerability-scanner-hit-by-supply-chain-attack/

Rule-State Inference (RSI): A Bayesian Framework for Compliance Monitoring in Rule-Governed Domains
cs.LG updates on arXiv.org
https://arxiv.org/abs/2603.21610

#Privacy #AI #Cybersecurity #DailyDigest
📩 NicFab Newsletter #13 — 24 marzo 2026

È disponibile il numero 13 della newsletter bilingue (IT/EN) su privacy, protezione dei dati, regolazione AI e cybersecurity.

Questa settimana:
🔹 Tribunale di Roma annulla la sanzione da €15M a OpenAI
🔹 EDPB lancia il CEF 2026 sulla trasparenza (25 autorità)
🔹 Chat Control — nessuna intesa tra Parlamento e Consiglio
🔹 Parere congiunto EDPB-EDPS su Cybersecurity Act 2 e NIS2
🔹 Approvato il rinvio di alcune norme AI Act
🔹 Sanzioni UE contro entità cinesi e iraniane per cyberattacchi

🎙️ NOVITÀ: Debutta il Podcast — Legal Prompting, Episodio #1
🔖 AI Act in Pillole – Parte 13: Articolo 17

📖 https://www.nicfab.eu/it/newsletter-issues/2026-03-24-issue-13/
📩 Iscriviti → https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity #EDPB #NicFab #LegalPrompting #Podcast
📩 NicFab Newsletter #13 — March 24, 2026

Issue #13 of the bilingual (IT/EN) newsletter on privacy, data protection, AI regulation and cybersecurity is now available.

This week:
🔹 Rome Court annuls the €15M fine against OpenAI
🔹 EDPB launches CEF 2026 on transparency (25 DPAs)
🔹 Chat Control — no deal between Parliament and Council
🔹 EDPB-EDPS Joint Opinion on Cybersecurity Act 2 & NIS2
🔹 EU AI Act delay approved
🔹 EU sanctions Chinese and Iranian entities for cyberattacks

🎙️ NEW: Podcast launches today — Legal Prompting, Episode #1
🔖 AI Act in a Nutshell – Part 13: Article 17

📖 https://www.nicfab.eu/en/newsletter-issues/2026-03-24-issue-13/
📩 Subscribe → https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity #EDPB #NicFab #LegalPrompting #Podcast
Daily Digest | 25 March 2026

Crunchyroll confirms data breach after hacker claims unauthorized access
TechCrunch
https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/

Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
BleepingComputer
https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/

Yanluowang ransomware access broker gets 81 months in prison
BleepingComputer
https://www.bleepingcomputer.com/news/security/yanluowang-ransomware-access-broker-gets-81-months-in-prison/

3.1 Million Impacted by QualDerm Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/3-1-million-impacted-by-qualderm-data-breach/

Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn
SecurityWeek RSS Feed
https://www.securityweek.com/critical-citrix-netscaler-vulnerability-poised-for-exploitation-security-firms-warn/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 26 March 2026

Delve did the security compliance on LiteLLM, an AI project hit by malware
TechCrunch
https://techcrunch.com/2026/03/25/delve-did-the-security-compliance-on-litellm-an-ai-project-hit-by-malware/

Vie privée des enfants : les résultats de l’audit du Global Privacy Enforcement Network
CNIL France
https://www.cnil.fr/fr/vie-privee-des-enfants-les-resultats-de-laudit-du-global-privacy-enforcement-network

G7 meets in France to narrow transatlantic Iran split
Euractiv
https://www.euractiv.com/news/g7-meets-in-france-to-narrow-transatlantic-iran-split/

Press release - Future EU Customs Authority to be headquartered in Lille, France
Press releases - Committees - European Parliament
https://www.europarl.europa.eu/news/en/press-room/20260323IPR38814/

Briefing - Artificial Intelligence in Classrooms: Ethical Dimensions - 25-03-2026
Documents - Think Tank - European Parliament
https://www.europarl.europa.eu/thinktank/en/document/IUST_BRI(2026)784573

#Privacy #AI #Cybersecurity #DailyDigest
The European Parliament has published a briefing on the ethical dimensions of AI in classrooms (PE 784.573, March 2026), authored by Prof. Wayne Holmes for the CULT Committee.

The document is strong on the ethical-philosophical plane. But the real challenge lies elsewhere: we don't need more principles — we need operational connections between the principles already formulated, binding rules (GDPR, AI Act) and European competence frameworks (DigComp 3.0, eCF 4.0).

In my latest article, I analyse the briefing from the perspective of a data protection lawyer, focusing on:

— The false dichotomy between ethics and law
— Children as rights-bearing subjects, not objects of optimisation
— The "flipped AI divide" as a matter of substantive equality
— The CEN-CENELEC JTC 21 standard on professional AI ethicists
— The role of DigComp 3.0 and eCF 4.0 in bridging the principles-to-practice gap

Full article: https://www.nicfab.eu/en/posts/ai-ethics-classrooms-ep/

Stay updated on AI, privacy and digital rights — subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#AIAct #GDPR #AIethics #Education #DigComp #eCF #EuropeanParliament #DigitalRights #Privacy #ArtificialIntelligence
Il Parlamento Europeo ha pubblicato un briefing sulle dimensioni etiche dell'IA nelle aule scolastiche (PE 784.573, marzo 2026), redatto dal Prof. Wayne Holmes per la commissione CULT.

Il documento è solido sul piano etico-filosofico. Ma il vero nodo è un altro: non servono nuovi principi — servono connessioni operative tra i principi già formulati, le norme vincolanti (GDPR, AI Act) e i framework europei di competenze (DigComp 3.0, eCF 4.0).

Nel mio ultimo articolo analizzo il briefing dalla prospettiva del giurista specializzato in protezione dei dati, con un focus su:

— La falsa dicotomia tra etica e diritto
— I minori come soggetti di diritto, non oggetti di ottimizzazione
— Il "flipped AI divide" come questione di uguaglianza sostanziale
— Lo standard CEN-CENELEC JTC 21 sugli eticisti professionali dell'IA
— Il ruolo di DigComp 3.0 e eCF 4.0 nel colmare il divario principi-prassi

Articolo completo: https://www.nicfab.eu/it/posts/ai-ethics-classrooms-ep/

Per restare aggiornati sui temi di AI, privacy e diritti digitali, iscrivetevi alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#AIAct #GDPR #EticaIA #Istruzione #DigComp #eCF #ParlamentoEuropeo #DigitalRights #Privacy #ArtificialIntelligence
Daily Digest | 27 March 2026

EDPB conference on cross-regulatory cooperation: what we learned
EDPB News
https://www.edpb.europa.eu/news/news/2026/edpb-conference-cross-regulatory-cooperation-what-we-learned_en

NEWSLETTER del 26 marzo 2026 - Telemarketing, il Garante privacy sanziona Enel Energia per oltre 500mila euro - Annun...
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10233427

Press release - Artificial Intelligence Act: delayed application, ban on nudifier apps
Press releases - Plenary sessions - European Parliament
https://www.europarl.europa.eu/news/en/press-room/20260323IPR38829/

PI_COM:Ares(2026)3247482: COMMISSION DELEGATED REGULATION (EU) …/… supplementing Directive (EU) 2023/1791 of the Euro...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=PI_COM:Ares(2026)3247482

Automotive Cybersecurity Threats Grow in Era of Connected, Autonomous Vehicles
Dark Reading
https://www.darkreading.com/vulnerabilities-threats/automotive-cybersecurity-threats-grow-connected-autonomous-vehicles

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 30 March 2026

COM:2026:135:FIN: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on establishing the Program...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=COM:2026:135:FIN

OJ:L_202600705: Commission Implementing Regulation (EU) 2026/705 of 20 March 2026 establishing model identification d...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=OJ:L_202600705

CELEX:52026PC0135: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on establishing the Progra...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026PC0135

CONSIL:ST_7716_2026_INIT: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on establishing the...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CONSIL:ST_7716_2026_INIT

Press release - Returns regulation: MEPs ready to start negotiations
Press releases - Plenary sessions - European Parliament
https://www.europarl.europa.eu/news/en/press-room/20260324IPR38908/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 31 March 2026

COMUNICATO STAMPA - Data breach, Garante privacy sanziona Intesa Sanpaolo per 31,8 milioni di euro. Accessi indebiti ...
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10235001

COMUNICATO STAMPA - Ddl tutela minori sui social, precisazione Garante privacy
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10235032

European Commission confirms data breach after Europa.eu hack
BleepingComputer
https://www.bleepingcomputer.com/news/security/european-commission-confirms-data-breach-after-europaeu-hack/

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
The Hacker News
https://thehackernews.com/2026/03/openai-patches-chatgpt-data.html

A Regression Framework for Understanding Prompt Component Impact on LLM Performance
cs.LG updates on arXiv.org
https://arxiv.org/abs/2603.26830

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 1 April 2026

CELEX:02005R0396-20260307: Regulation (EC) No 396/2005 of the European Parliament and of the Council of 23 February 2...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02005R0396-20260307

CONSIL:ST_7842_2026_INIT: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on establishing a f...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CONSIL:ST_7842_2026_INIT

Human rights in Iran: Council extends sanctions regime until April 2027
Council of the EU Press Releases
https://www.consilium.europa.eu/en/press/press-releases/2026/03/30/human-rights-in-iran-council-extends-sanctions-regime-until-april-2027/

Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project
TechCrunch
https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise 
SecurityWeek RSS Feed
https://www.securityweek.com/critical-vulnerability-in-openai-codex-allowed-github-token-compromise/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 2 April 2026

New CrystalRAT malware adds RAT, stealer and prankware features
BleepingComputer
https://www.bleepingcomputer.com/news/security/new-crystalrat-malware-adds-rat-stealer-and-prankware-features/

CELEX:02011L0061-20260416: Directive 2011/61/EU of the European Parliament and of the Council of 8 June 2011 on Alter...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02011L0061-20260416

CELEX:02013R0575-20260626: Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 ...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02013R0575-20260626

CELEX:02024R2642-20260316: Council Regulation (EU) 2024/2642 of 8 October 2024 concerning restrictive measures in vie...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02024R2642-20260316

Study - The human rights dimension of EU-Latin America relations in the context of the EU-CELAC summit - 31-03-2026
Documents - Think Tank - European Parliament
https://www.europarl.europa.eu/thinktank/en/document/EXAS_STU(2026)783607

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 3 April 2026

CELEX:32025M11936: Commission Decision of 11/08/2025 declaring a concentration to be compatible with the common marke...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:32025M11936

Gestion des ressources humaines : la CNIL publie un référentiel de durées de conservation
CNIL France
https://www.cnil.fr/fr/referentiel-durees-conservation-donnees-rh

Claude Code leak used to push infostealer malware on GitHub
BleepingComputer
https://www.bleepingcomputer.com/news/security/claude-code-leak-used-to-push-infostealer-malware-on-github/

EU blames major cybercrime group for cloud infrastructure breach
POLITICO
https://www.politico.eu/article/eu-blames-major-cybercrime-group-for-cloud-infrastructure-breach/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

Do LLMs Know What Is Private Internally? Probing and Steering Contextual Privacy Norms in Large Language Model Repres...
cs.CL updates on arXiv.org
https://arxiv.org/abs/2604.00209

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 6 April 2026

Les webinaires de la CNIL
CNIL France
https://www.cnil.fr/fr/les-webinaires-de-la-cnil

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
Krebs on Security
https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/

Traffic violation scams switch to QR codes in new phishing texts
BleepingComputer
https://www.bleepingcomputer.com/news/security/traffic-violation-scams-switch-to-qr-codes-in-new-phishing-texts/

Privacy-Accuracy Trade-offs in High-Dimensional LASSO under Perturbation Mechanisms
cs.LG updates on arXiv.org
https://arxiv.org/abs/2603.26227

Communication-Efficient Distributed Learning with Differential Privacy
cs.LG updates on arXiv.org
https://arxiv.org/abs/2604.02558

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 7 April 2026

German authorities identify REvil and GandCrab ransomware bosses
BleepingComputer
https://www.bleepingcomputer.com/news/security/german-authorities-identify-revil-and-gangcrab-ransomware-bosses/

Microsoft links Medusa ransomware affiliate to zero-day attacks
BleepingComputer
https://www.bleepingcomputer.com/news/security/microsoft-links-medusa-ransomware-affiliate-to-zero-day-attacks/

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
The Hacker News
https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html

Fortinet Rushes Emergency Fixes for Exploited Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/fortinet-rushes-emergency-fixes-for-exploited-zero-day/

Stable and Privacy-Preserving Synthetic Educational Data with Empirical Marginals: A Copula-Based Approach
cs.LG updates on arXiv.org
https://arxiv.org/abs/2604.04195

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 8 April 2026

COM:2026:152:FIN: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the European Union Space...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=COM:2026:152:FIN

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
The Hacker News
https://thehackernews.com/2026/04/china-linked-storm-1175-exploits-zero.html

RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever
Dark Reading
https://www.darkreading.com/cybersecurity-operations/rsac-2026-how-ai-is-reshaping-cybersecurity-faster-than-ever

Human vs AI: Debates Shape RSAC 2026 Cybersecurity Trends
Dark Reading
https://www.darkreading.com/cybersecurity-operations/human-vs-ai-debates-shape-rsac-2026-cybersecurity-trends

Lies, Damned Lies, and Cybersecurity Metrics
Dark Reading
https://www.darkreading.com/cyber-risk/lies-damned-lies-cybersecurity-metrics

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 10 April 2026

Municipales 2026 : le bilan de l’observatoire des élections de la CNIL
CNIL France
https://www.cnil.fr/fr/municipales-2026-bilan-observatoire

CELEX:32026R0771: Commission Implementing Regulation (EU) 2026/771 of 7 April 2026 laying down the necessary measures...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:32026R0771

Accompagnement des professionnels : le programme de travail de la CNIL pour 2026
CNIL France
https://www.cnil.fr/fr/accompagnement-des-professionnels-le-programme-de-travail-de-la-cnil-pour-2026

Eurail says December data breach impacts 300,000 individuals
BleepingComputer
https://www.bleepingcomputer.com/news/security/eurail-says-december-data-breach-impacts-300-000-individuals/

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
The Hacker News
https://thehackernews.com/2026/04/adobe-reader-zero-day-exploited-via.html

#Privacy #AI #Cybersecurity #DailyDigest