nicfab
119 subscribers
15 photos
16 files
2.58K links
Canale di aggiornamento su Privacy, Data Protection, IA e Cybersecurity
Channel for updates on Privacy, Data Protection, AI, and Cybersecurity
Download Telegram
πŸ“§ NicFab Newsletter #33 β€” 11 August 2026

The Italian Garante reprimands R.T.I. over AI-manipulated deepfakes of Enrico Mentana: satire is no free pass, and a disclaimer counts only if the average viewer perceives it.

The EDPB asks the Commission to reassess the Data Privacy Framework after Trump v. Slaughter.

Also in this issue: the Ninth Circuit on AI agents and the CFAA, the EES switched off when queues grow, the SAFE guidelines on agentic incident reporting, and AI Act in a Nutshell on Article 37.

πŸ‘‰ https://www.nicfab.eu/en/newsletter-issues/2026-08-11-issue-33/
πŸ“§ NicFab Newsletter #33 β€” 11 agosto 2026

Il Garante ammonisce R.T.I. per i deepfake di Enrico Mentana generati con l'IA: la satira non Γ¨ un lasciapassare, e il disclaimer conta solo se il telespettatore medio lo percepisce.

L'EDPB chiede alla Commissione di riesaminare il Data Privacy Framework dopo Trump v. Slaughter.

Nel numero anche: il Nono Circuito su agenti AI e CFAA, il sistema EES spento quando le code crescono, le linee guida SAFE sugli incidenti dei sistemi agentici, e l'AI Act in Pillole sull'articolo 37.

πŸ‘‰ https://www.nicfab.eu/it/newsletter-issues/2026-08-11-issue-33/
Daily Digest | 12 August 2026

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
The Hacker News
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/

US and South Korea warn of Gunra ransomware targeting govt agencies
BleepingComputer
https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
The Hacker News
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html

Zoom Patches Zero-Click Code Execution Vulnerability
SecurityWeek RSS Feed
https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 13 August 2026

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition

Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer
https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa

SharePoint Vulnerability Exploited Shortly After PoC Release
SecurityWeek RSS Feed
https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
The Hacker News
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 14 August 2026

Privacy watchdog warns of β€˜serious risks’ over EU police agency surveillance
POLITICO
https://www.politico.eu/article/europol-data-processing-reform-privacy-risks-edps-warning/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

Hackers breach govt webmail while running parallel crypto fraud
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/

Trezor discloses data breach affecting nearly 14,000 customers
BleepingComputer
https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The Hacker News
https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
SecurityWeek RSS Feed
https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 17 August 2026

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office

Hackers arrested over €30M bank fraud exploiting service provider flaw
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/

RingCentral data breach exposed info of 1.6 million accounts
BleepingComputer
https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/

Hackers Exploiting Unpatched GeoServer Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
SecurityWeek RSS Feed
https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/

#Privacy #AI #Cybersecurity #DailyDigest
πŸ“¬ NicFab Newsletter #34 | 18 agosto 2026

Privacy, Data Protection, AI e Cybersecurity β€” la rassegna settimanale.

In questo numero:

πŸ›οΈ D-TECT: la Commissione europea apre il forum industriale su droni e contro-droni, tra sovranitΓ  tecnologica e minacce ibride

🟒 La CNIL pubblica una guida operativa su DPO e conflitti di interesse: le funzioni incompatibili e il caso DPO-RSSI

πŸ“Š Australia, le restrizioni social per i minori fanno scuola, ma eSafety rileva che i divieti restano largamente inefficaci

πŸ” Apple Intelligence in Cina con Alibaba e registrazione presso la CAC, mentre nell'UE resta aperto lo scontro sul DMA

πŸ›οΈ New Jersey: firmato l'Age-Appropriate Design Code, con la soglia di processing piΓΉ bassa fra i design code USA

⚠️ Prompt injection nascosto in un atto giudiziario, Ghostjacking via log di sicurezza e il problema strutturale della delega vaga agli agenti IA

πŸ”΄ Operation Klonen: 30 milioni sottratti a Commerzbank sfruttando un fornitore, RingCentral con 1,6 milioni di account esposti e CVE-2026-65400 su macOS sfruttata attivamente

πŸ“– AI Act in Pillole – Parte 34: l'articolo 38 e il coordinamento degli organismi notificati

πŸ‘‰ Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

πŸ“© Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity
πŸ“¬ NicFab Newsletter #34 | August 18, 2026

Privacy, Data Protection, AI & Cybersecurity β€” weekly review.

In this issue:

πŸ›οΈ The European Commission launches D-TECT, the EU industrial forum on drone and counter-drone technology: expressions of interest open, inaugural meeting on 11 November 2026

🟒 CNIL publishes operational guidance on DPO conflicts of interest: senior management and HR roles incompatible as a rule, and the DPO-CISO combination put under scrutiny

πŸ“Š Australia's under-16 social media ban becomes an exported regulatory model, but eSafety finds most 10-15 year-olds still online due to inadequate age verification

πŸ“ˆ Apple Intelligence registered by China's CAC with an Alibaba-built model, while the DMA standoff in Europe delays Siri AI β€” same company, two very different strategies

⚠️ Prompt injection hidden in a court filing, Ghostjacking via security logs, and OpenAI's GPT-5.6-Cyber lowering safeguards on exploit development: agentic AI risks are becoming concrete

πŸ”΄ Operation Klonen siphons €30 million from Commerzbank through a supplier, while ShinyHunters expose 1.6 million RingCentral accounts and SafePal data goes up for sale

πŸ” Coordinated attacks on U.S. water utilities with Iranian attribution suspicions, and a Polish combined heat and power plant breached through a private APN

πŸ“– AI Act Explained – Part 34: Article 38 and the coordination of notified bodies, the sectoral group, and the exchange of knowledge between notifying authorities

πŸ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

πŸ“© Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
Daily Digest | 18 August 2026

680,000 Impacted by French Tax Authority Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/680000-impacted-by-french-tax-authority-data-breach/

Philips and GE investigating Clop ransomware data theft claims
BleepingComputer
https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/

Microsoft working on Defender patch for ShieldBreak zero-day
BleepingComputer
https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
SecurityWeek RSS Feed
https://www.securityweek.com/critical-sap-commerce-cloud-vulnerability-exploited-3-days-after-disclosure/

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
The Hacker News
https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 19 August 2026

Statement by the High Representative on behalf of the EU on the alignment of certain countries concerning restrictiv...
Council of the EU Press Releases
https://www.consilium.europa.eu/en/press/press-releases/2026/08/18/statement-by-the-high-representative-on-behalf-of-the-eu-on-the-alignment-of-certain-countries-concerning-restrictive-measures-against-serious-human-rights-violations-and-abuses/

French tax authority data breach affects 678,000 individuals
BleepingComputer
https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/

CISA: Windows Task Host flaw now exploited by ransomware gangs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
SecurityWeek RSS Feed
https://www.securityweek.com/heights-finance-data-breach-impacts-at-least-1-2-million-individuals/

France probes disinfo campaigns targeting 2027 election candidates
POLITICO
https://www.politico.eu/article/france-probe-russia-disinformation-campaigns-2027-election/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 20 August 2026

OpenAI confirms ChatGPT is down as logins and signups fail
BleepingComputer
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-as-logins-and-signups-fail/

OpenAI seeks to one-up Anthropic with new customer privacy protections
TechCrunch
https://techcrunch.com/2026/08/19/openai-seeks-to-one-up-anthropic-with-new-customer-privacy-protections/

Rogue ransomware affiliate poses as data recovery firm to steal payments
BleepingComputer
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/

Rogue ransomware affiliate poses as recovery firm to steal payments
BleepingComputer
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/

Healthtech firm CareCloud data breach impacts 3.7 million patients
BleepingComputer
https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 21 August 2026

CISA: Medusa ransomware hit over 500 critical infrastructure orgs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Hacker News
https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
SecurityWeek RSS Feed
https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/

MLflow Vulnerability Exploited for Cloud Credential Theft
SecurityWeek RSS Feed
https://www.securityweek.com/mlflow-vulnerability-exploited-for-cloud-credential-theft/

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The Hacker News
https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 24 August 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The Hacker News
https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html

Microsoft Patches Exploited Entra ID Vulnerability
SecurityWeek RSS Feed
https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/

Brussels changes gear on Big Tech enforcement
Politico EU Technology
https://www.politico.eu/article/brussels-changes-gear-on-big-tech-enforcement-as-first-wave-of-cases-wraps-up/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

SickKids data breach exposes employee and job applicant info
BleepingComputer
https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
SecurityWeek RSS Feed
https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/

#Privacy #AI #Cybersecurity #DailyDigest
πŸ“¬ NicFab Newsletter #35 | 25 agosto 2026

Privacy, Data Protection, AI e Cybersecurity β€” la rassegna settimanale.

In questo numero:

πŸ›οΈ La Commissione europea mette a gara uno studio empirico da 400.000 euro sul design dei marketplace e sull'effettivitΓ  dei meccanismi DSA (artt. 16, 30.7 e 31)

πŸ“– Parere EDPS 17/2026 sulla revisione del Regolamento 2018/1725 trasmesso alle delegazioni del Consiglio, con riunione del Working Party on Data Protection il 4 settembre

🟒 La CNIL pubblica una guida per i cittadini sul rifiuto del credito: scoring, FICP, trasparenza degli algoritmi e diritto a conoscere le ragioni del diniego

πŸ”΄ DMA: 890 milioni di euro a Google per self-preferencing su Search e restrizioni allo steering su Play, mentre Bruxelles cambia marcia sull'enforcement Big Tech

πŸ“ˆ Apple e Commissione trovano l'intesa sui termini App Store UE: commissione IAP dal 30 al 26 percento dal 1Β° ottobre 2026

⚠️ Grok esfiltra dati utente tramite istruzioni cifrate, "mind virus" tra agenti AI via file di prompt persistenti e Copilot rivela da sé il parametro segreto per attaccarlo

πŸ” Cybersecurity: GitLab CVE-2026-19478 sfruttata in poche ore, Zimbra RCE non autenticato giΓ  in KEV e 14 pacchetti npm trojanizzati distribuiscono RedC2 4.0

πŸ“Š TikTok paga 400 milioni per violazioni COPPA, la FTC prepara limiti al surveillance pricing e Aylo chiude con 120 milioni le class action su CSAM

πŸ“– AI Act in Pillole - Parte 35: l'articolo 39 e gli organismi di valutazione della conformitΓ  di paesi terzi

πŸ‘‰ Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-08-25-issue-35/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-35

πŸ“© Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity
πŸ“¬ NicFab Newsletter #35 | August 25, 2026

Privacy, Data Protection, AI & Cybersecurity β€” weekly review.

In this issue:

πŸ›οΈ The European Commission tenders a EUR 400,000 empirical study on how marketplace design shapes user behaviour under DSA Articles 16, 30(7) and 31

πŸ“– EDPS Opinion 17/2026 on the revision of Regulation 2018/1725 sent to Council delegations, ahead of the Working Party meeting on 4 September

🟒 CNIL publishes a citizens' guide on credit refusals: no "right to credit", but transparency, bias mitigation and explainability duties apply to AI scoring models

πŸ”΄ Brussels changes gear on Big Tech: EUR 890 million in DMA fines against Google for self-preferencing and Play Store restrictions, bringing total DMA penalties to EUR 1.6 billion

πŸ“ˆ Apple reshapes App Store terms for EU developers from 1 October 2026: commission down to 26%, Core Technology Fee replaced by a 5% Core Technology Commission

⚠️ Cybersecurity week: GitLab CVE-2026-19478 exploited within hours, unauthenticated RCE in Zimbra already in KEV, and 14 trojanized npm packages delivering RedC2 4.0

πŸ” AI security under pressure: Grok exfiltrating user data via encrypted instructions, Copilot disclosing the secret parameter used to attack it, and OpenAI pausing frontier RL training

πŸ“Š TikTok pays USD 400 million for COPPA violations while the FTC prepares limits on surveillance pricing

πŸ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-25-issue-35/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-35

πŸ“© Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
Daily Digest | 25 August 2026

Foul Language: WordlistLoader Disguises Malware as Ordinary Text
Dark Reading
https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text

Alabama launches investigation into OpenAI’s hack of Hugging Face
TechCrunch
https://techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/

Instinct’s powerful AI assistant is raising privacy and security concerns
TechCrunch
https://techcrunch.com/2026/08/24/instincts-powerful-ai-assistant-is-raising-privacy-and-security-concerns/

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
The Hacker News
https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html

Tricky 'SynkLoader' Multitool May Herald Ransomware
Dark Reading
https://www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware

#Privacy #AI #Cybersecurity #DailyDigest