
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Anthropic just dropped a bombshell, revealing major gaps in AI agent governance with its new Compliance API - and it's a game-changer for cloud security. By introducing local session transcripts, Anthropic is shining a light on what really happens when AI agents interact with your systems.

Meta is shelling out a whopping $18 billion to settle allegations that its platforms contributed to a mental health crisis among youth - and as part of the deal, it's making significant changes to its platforms to promote safer online experiences. This massive settlement could be a game-changer for social media, pushing other platforms to follow suit.

The UK's Information Commissioner's Office has fined Nuisance Call Blocker, operating as Elderly Aids Ltd, a whopping £190k for making over 758,000 unsolicited calls to vulnerable people who'd specifically asked not to be contacted. This hefty penalty sends a strong warning to businesses that think they can flout the law with impunity.
Meta's proposed $18 billion settlement aims to revolutionize teen safety online, introducing industry-leading protections that will safeguard young users across Facebook, Instagram, and beyond. The agreement includes game-changing defaults like a two-hour daily usage limit, nighttime app blocks, and muted notifications, all designed to shield teens from potential harm.
In a shocking expose, researchers uncover a cunning tactic used by Silicon Valley entrepreneurs to deceive investors: "façading," a deliberate process of creating and maintaining illusory growth stories to mask operational failure. By analyzing court records, they reveal a repeatable pattern of deception that has fooled even the most discerning eyes.

The NSA's nondisclosure agreements are leaving employees in the dark about their whistleblower rights, with most failing to include crucial language that would inform them of their statutory protections. This oversight could silence employees who want to speak out about wrongdoing, undermining their ability to hold the agency accountable.

TikTok is coughing up $400 million to settle allegations that it violated children's online privacy laws, with $300 million changing hands immediately and another $100 million pending a court ruling. The hefty fine sends a clear message: companies must play by the rules when collecting kids' personal info.

The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
TikTok is paying a whopping $400 million to settle a lawsuit alleging it broke US child privacy laws, in a major win for American kids and parents. The deal, secured by the US Department of Justice, marks one of the largest recoveries ever under the Children's Online Privacy Protection Act.

The UK's Information Commissioner's Office warns that police use of facial recognition technology poses significant risks to privacy and individual rights if not governed properly. A recent audit of five police forces revealed inconsistent compliance with data protection laws, highlighting an urgent need for improved data governance.

A staggering 220,000 fraud cases were filed with the UK's National Fraud Database in just the first half of 2026, marking a record high for the period and highlighting a disturbing surge in identity-related crime. This represents a 9% year-on-year spike in identity fraud alone, with nearly 130,000 cases reported.

The UK's Solicitors Regulation Authority is warning lawyers to be vigilant about the risks of AI misuse, citing concerns that some may not be meeting their obligations to courts, clients, and third parties. AI-generated "hallucinations" in legal work and court submissions have already led to reports of poor client outcomes, delayed cases, and damage to public trust.

Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

The European Telecommunications Standards Institute (ETSI) is pushing forward with 17 crucial cybersecurity standards to help vendors and buyers across the continent meet the EU's Cyber Resilience Act requirements. These draft standards cover 17 major product categories, setting a vital baseline for manufacturers to ensure their products are secure and compliant.

To truly achieve IAM compliance, it's not enough to just have policies in place - you need to prove that they're being enforced. The real challenge lies in bridging the gap between policy intent and actual runtime execution, where compliance failures and unmanaged access often hide.

The Department of Defense's sudden pause on CMMC Phase 2 has created an urgent need for gap assessments, especially for small and non-traditional businesses struggling to meet compliance requirements. This 60-day review aims to ease the burden, but existing obligations, including Phase 1 self-assessment requirements, remain in force.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Industry leaders are pushing back on a proposed cyber incident reporting rule, arguing it casts too wide a net, with one critic saying it would ensnare far too many companies. The rule, aimed at bolstering national security, has sparked concerns about its broad scope and reporting requirements.

The Government Accountability Office has uncovered a staggering truth: nearly 7 in 10 federal cybersecurity reporting rules are duplicated, with 80 out of 117 rules at 37 agencies requiring redundant written reports. This revelation raises critical questions about the efficiency and effectiveness of current federal cybersecurity regulations.

FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

After cracking down on 23andMe's lax security measures, a coalition of 42 US attorneys general, led by New York Attorney General Letitia James, has secured an $18 million settlement and binding data-protection commitments to safeguard customer information. This move comes after a 2023 data breach put millions of 23andMe customers at risk of having their personal info exposed.

For nearly two years, Zhuoying Chen and Haojie Zhang allegedly masterminded a brazen $43 million investment fraud laundering scheme, preying on innocent victims and funneling their life savings into bank accounts in China. The sophisticated network, involving over a dozen people, was recently dismantled by US authorities.

The Department of Defense is shaking things up in the world of cybersecurity certification, suspending Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day review to explore a more streamlined approach. This move aims to ease compliance burdens, especially for small and medium-sized businesses.

The Pentagon has hit pause on its cybersecurity certification requirements, citing prohibitive compliance costs and bureaucratic burdens that could stifle innovation in the US defense industrial base. This 60-day suspension sparks a review that may reshape enforcement and acquisition rules for defense contractors.

In a massive global sting operation, authorities arrested 5,811 suspects and seized $293 million in illicit assets, dealing a significant blow to social engineering fraud and money laundering. The sweeping crackdown, dubbed Operation First Light 2026, spanned 97 countries and identified over 142,000 victims.