Data Breaches Incident Response Social engineering

Levi Strauss hit by social engineering cyberattack

Apparel giant Levi Strauss & Co. recently disclosed a cybersecurity incident after attackers used targeted social engineering tactics to compromise three employees’ company computers. This initial breach allowed the attackers to gain access to internal files and successfully exfiltrate specific corporate information. Thanks to a rapid incident response, Levi’s managed to contain the intrusion effectively. […]

AI Compliance Information Security Risk management

Open-Source AI tools are strong on security, but Governance remains human

A new study maps 21 open-source AI risk tools against 32 risk categories, including Promptfoo, Garak, PyRIT, NeMo Guardrails and Langfuse. The ecosystem performs particularly well in AI testing, red teaming, content safety, data governance and post-deployment monitoring. But major gaps remain in board oversight, regulatory compliance, legal remedies and financial/market controls, areas software alone […]

Data Protection Data Rights Encryption Privacy Privacy Procedures and Policy

Apple vs. UK where encryption showdown enters a new chapter

Apple is challenging the UK government’s renewed demand for access to encrypted iCloud backups of British users through the Investigatory Powers Tribunal. The tech giant reiterates it will never build a backdoor into its products, arguing it would weaken security for everyone. The UK says lawful access is essential for tackling terrorism, serious crime, and […]

AI Cybersecurity Risk management

Africa’s cyber threat surge: where AI supercharges digital crime

Cybercrime across Africa is evolving into a highly organized, AI-enabled ecosystem, with ransomware, business email compromise (BEC), online scams, data breaches, and digital sextortion driving unprecedented financial and societal damage. AI is accelerating phishing, deepfakes, identity fraud, and cybercrime-as-a-service, while weak legislation, limited cyber capabilities, and fragmented cross-border cooperation continue to benefit criminals. Financial services, […]

Cybersecurity Information Security Risk management Vulnerability

ENISA’s new CRA Maturity Model is a practical roadmap for SME Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]

Cybersecurity Hack Information Security Risk management Vulnerability

Autonomous AI agent breach signals a new era of cyber threats

Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]

GDPR Information Security Personal data Privacy

EU Age Verification under scrutiny as transparency questions remain

The European Commission’s DG CONNECT disclosed nine documents in response to an access-to-documents request, but all were already publicly available resources. No Data Protection Impact Assessment (DPIA), internal privacy-by-design documentation, threat models, or controller-role assessments were released. DG CONNECT stated it does not hold a DPIA, arguing that responsibility lies with the future publisher of […]

Cybersecurity Personal data Privacy

UK pushes for tougher age checks as TikTok faces investigation

The UK’s communications regulator, Ofcom, is demanding stronger age verification measures from social media platforms ahead of a proposed social media age ban. The regulator has launched an investigation into TikTok, questioning whether its current age assurance methods effectively protect minors. Ofcom is also investigating dozens of adult websites and working with Google and Bing […]

AI Cybersecurity Information Security Risk management

Why AI governance will define tomorrow’s winners in the board room

AI has evolved from a technology initiative into a board-level strategic and enterprise risk that demands continuous oversight, not periodic reviews. Boards must establish clear governance, accountability, and AI risk appetite while ensuring innovation is balanced with responsible use. Traditional cybersecurity alone is no longer sufficient, organizations must protect AI-driven decision-making, data, identities, and autonomous […]