nicfab
120 subscribers
15 photos
16 files
2.55K links
Canale di aggiornamento su Privacy, Data Protection, IA e Cybersecurity
Channel for updates on Privacy, Data Protection, AI, and Cybersecurity
Download Telegram
Daily Digest | 4 August 2026

EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter
EDPB publications
https://www.edpb.europa.eu/documents/edpb-correspondence/edpb-letter-to-the-european-commission-on-us-supreme-court-judgment_en

CELEX:02024R1689-20260727: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 la...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02024R1689-20260727

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The Hacker News
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
SecurityWeek RSS Feed
https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News
https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 5 August 2026

OJ:C_202603690: P10_TA(2026)0014 – Human rights and democracy in the world and the European Union’s policy on the mat...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=OJ:C_202603690

OJ:C_202603697: P10_TA(2026)0022 – European technological sovereignty and digital infrastructure – European Parliamen...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=OJ:C_202603697

Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest
EDPB News
https://www.edpb.europa.eu/news/stakeholder-event-on-guidelines-on-the-interplay-between-data-protection-and-competition-law-0_en

150,000 Impacted by Madera Community Hospital Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
SecurityWeek RSS Feed
https://www.securityweek.com/decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 6 August 2026

Collège de la CNIL : 5 nouveaux membres nommés le 2 août 2026
CNIL France
https://www.cnil.fr/fr/college-de-la-cnil-5-nouveaux-membres-nommes-le-2-aout-2026

CELEX:52026IP0022: P10_TA(2026)0022 – European technological sovereignty and digital infrastructure – European Parlia...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026IP0022

Ransom Cartel ransomware creator sentenced to 16 years in prison
BleepingComputer
https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/

311,000 Impacted by Brown Health Medical Group-MA Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/311000-impacted-by-brown-health-medical-group-ma-data-breach/

Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data 
SecurityWeek RSS Feed
https://www.securityweek.com/cybersecurity-alliance-drafts-safe-guidelines-for-sharing-ai-incident-data/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 7 August 2026

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
BleepingComputer
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-rolls-out-a-major-chatgpt-upgrade-even-if-you-dont-pay-for-it/

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
The Hacker News
https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html

CELEX:52026SC0616: COMMISSION STAFF WORKING DOCUMENT IMPACT ASSESSMENT REPORT Accompanying the documents Proposal for...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026SC0616

CELEX:02024X0211-20240112: UN Regulation No 168 – Uniform provisions concerning the approval of light duty passenger ...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02024X0211-20240112

CELEX:02023R1230-20260727: Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:02023R1230-20260727

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 10 August 2026

COMUNICATO STAMPA - Dal Garante privacy stop ai deepfake satirici su Enrico Mentana. Ammonita R.T.I. per alcuni video...
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10281135

CELEX:52026IP0014: P10_TA(2026)0014 – Human rights and democracy in the world and the European Union’s policy on the ...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026IP0014

3.8 Million Impacted by Unlimited Technology Systems Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
SecurityWeek RSS Feed
https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
The Hacker News
https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 11 August 2026

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/

A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
TechCrunch
https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
The Hacker News
https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
SecurityWeek RSS Feed
https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
The Hacker News
https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html

#Privacy #AI #Cybersecurity #DailyDigest
📧 NicFab Newsletter #33 — 11 August 2026

The Italian Garante reprimands R.T.I. over AI-manipulated deepfakes of Enrico Mentana: satire is no free pass, and a disclaimer counts only if the average viewer perceives it.

The EDPB asks the Commission to reassess the Data Privacy Framework after Trump v. Slaughter.

Also in this issue: the Ninth Circuit on AI agents and the CFAA, the EES switched off when queues grow, the SAFE guidelines on agentic incident reporting, and AI Act in a Nutshell on Article 37.

👉 https://www.nicfab.eu/en/newsletter-issues/2026-08-11-issue-33/
📧 NicFab Newsletter #33 — 11 agosto 2026

Il Garante ammonisce R.T.I. per i deepfake di Enrico Mentana generati con l'IA: la satira non è un lasciapassare, e il disclaimer conta solo se il telespettatore medio lo percepisce.

L'EDPB chiede alla Commissione di riesaminare il Data Privacy Framework dopo Trump v. Slaughter.

Nel numero anche: il Nono Circuito su agenti AI e CFAA, il sistema EES spento quando le code crescono, le linee guida SAFE sugli incidenti dei sistemi agentici, e l'AI Act in Pillole sull'articolo 37.

👉 https://www.nicfab.eu/it/newsletter-issues/2026-08-11-issue-33/
Daily Digest | 12 August 2026

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
The Hacker News
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/

US and South Korea warn of Gunra ransomware targeting govt agencies
BleepingComputer
https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
The Hacker News
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html

Zoom Patches Zero-Click Code Execution Vulnerability
SecurityWeek RSS Feed
https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 13 August 2026

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition

Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer
https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa

SharePoint Vulnerability Exploited Shortly After PoC Release
SecurityWeek RSS Feed
https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
The Hacker News
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 14 August 2026

Privacy watchdog warns of ‘serious risks’ over EU police agency surveillance
POLITICO
https://www.politico.eu/article/europol-data-processing-reform-privacy-risks-edps-warning/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

Hackers breach govt webmail while running parallel crypto fraud
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/

Trezor discloses data breach affecting nearly 14,000 customers
BleepingComputer
https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The Hacker News
https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
SecurityWeek RSS Feed
https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 17 August 2026

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office

Hackers arrested over €30M bank fraud exploiting service provider flaw
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/

RingCentral data breach exposed info of 1.6 million accounts
BleepingComputer
https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/

Hackers Exploiting Unpatched GeoServer Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
SecurityWeek RSS Feed
https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/

#Privacy #AI #Cybersecurity #DailyDigest
📬 NicFab Newsletter #34 | 18 agosto 2026

Privacy, Data Protection, AI e Cybersecurity — la rassegna settimanale.

In questo numero:

🏛️ D-TECT: la Commissione europea apre il forum industriale su droni e contro-droni, tra sovranità tecnologica e minacce ibride

🟢 La CNIL pubblica una guida operativa su DPO e conflitti di interesse: le funzioni incompatibili e il caso DPO-RSSI

📊 Australia, le restrizioni social per i minori fanno scuola, ma eSafety rileva che i divieti restano largamente inefficaci

🔍 Apple Intelligence in Cina con Alibaba e registrazione presso la CAC, mentre nell'UE resta aperto lo scontro sul DMA

🏛️ New Jersey: firmato l'Age-Appropriate Design Code, con la soglia di processing più bassa fra i design code USA

⚠️ Prompt injection nascosto in un atto giudiziario, Ghostjacking via log di sicurezza e il problema strutturale della delega vaga agli agenti IA

🔴 Operation Klonen: 30 milioni sottratti a Commerzbank sfruttando un fornitore, RingCentral con 1,6 milioni di account esposti e CVE-2026-65400 su macOS sfruttata attivamente

📖 AI Act in Pillole – Parte 34: l'articolo 38 e il coordinamento degli organismi notificati

👉 Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

📩 Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity
📬 NicFab Newsletter #34 | August 18, 2026

Privacy, Data Protection, AI & Cybersecurity — weekly review.

In this issue:

🏛️ The European Commission launches D-TECT, the EU industrial forum on drone and counter-drone technology: expressions of interest open, inaugural meeting on 11 November 2026

🟢 CNIL publishes operational guidance on DPO conflicts of interest: senior management and HR roles incompatible as a rule, and the DPO-CISO combination put under scrutiny

📊 Australia's under-16 social media ban becomes an exported regulatory model, but eSafety finds most 10-15 year-olds still online due to inadequate age verification

📈 Apple Intelligence registered by China's CAC with an Alibaba-built model, while the DMA standoff in Europe delays Siri AI — same company, two very different strategies

⚠️ Prompt injection hidden in a court filing, Ghostjacking via security logs, and OpenAI's GPT-5.6-Cyber lowering safeguards on exploit development: agentic AI risks are becoming concrete

🔴 Operation Klonen siphons €30 million from Commerzbank through a supplier, while ShinyHunters expose 1.6 million RingCentral accounts and SafePal data goes up for sale

🔍 Coordinated attacks on U.S. water utilities with Iranian attribution suspicions, and a Polish combined heat and power plant breached through a private APN

📖 AI Act Explained – Part 34: Article 38 and the coordination of notified bodies, the sectoral group, and the exchange of knowledge between notifying authorities

👉 Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

📩 Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity