Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]
The European Commission’s DG CONNECT disclosed nine documents in response to an access-to-documents request, but all were already publicly available resources. No Data Protection Impact Assessment (DPIA), internal privacy-by-design documentation, threat models, or controller-role assessments were released. DG CONNECT stated it does not hold a DPIA, arguing that responsibility lies with the future publisher of […]
The UK’s communications regulator, Ofcom, is demanding stronger age verification measures from social media platforms ahead of a proposed social media age ban. The regulator has launched an investigation into TikTok, questioning whether its current age assurance methods effectively protect minors. Ofcom is also investigating dozens of adult websites and working with Google and Bing […]
AI has evolved from a technology initiative into a board-level strategic and enterprise risk that demands continuous oversight, not periodic reviews. Boards must establish clear governance, accountability, and AI risk appetite while ensuring innovation is balanced with responsible use. Traditional cybersecurity alone is no longer sufficient, organizations must protect AI-driven decision-making, data, identities, and autonomous […]
A new US Supreme Court ruling questions the independence of the FTC, undermining a key legal pillar of the EU-US Data Privacy Framework (DPF) according to privacy group noyb. Max Schrems argues that the European Commission relied on the FTC’s independence hundreds of times, meaning the legal basis for unrestricted EU-US personal data transfers has […]
The World Bank argues that digital wallets represent a fundamental shift from siloed digital identity, data-sharing, and payment systems toward a unified, user-centric trust ecosystem. Digital wallets enable individuals to securely store and control verifiable credentials issued by trusted organizations. Users can selectively share only the data required, improving privacy and reducing unnecessary data exposure. […]
AI agents are rapidly moving from experiments to core business systems, but governance is struggling to keep pace. 65% of organizations experienced at least one AI agent-related security incident in the past year, making incidents a mainstream operational reality. The biggest impact was exposure or mishandling of sensitive data (61%), followed by operational disruption (43%) […]
French and Spanish police, supported by Europol, dismantled a large-scale fake document factory in Alicante and arrested one suspect. Authorities seized around 800 forged European identity and residence documents, along with production equipment, digital devices, and other evidence. The suspect allegedly operated an online marketplace supplying counterfeit IDs to criminal networks involved in migrant smuggling […]
Google warns quantum computing could soon break today’s encryption, threatening global digital security. Quantum machines aren’t powerful enough yet, but progress is accelerating faster than expected. A major risk is “store now, decrypt later,” where hackers collect data today to crack it in the future. Google plans to shift to post-quantum cryptography by 2029, urging […]
Indirect prompt injection is the most widespread and serious vulnerability in AI agents today, not just a theoretical risk. Research shows attacks can transfer across models and behaviors, revealing a fundamental weakness in how agents interpret context. More capable models aren’t safer, high performance often comes with equally high vulnerability. Attacks are especially dangerous because […]

