Avsnitt

  • This week on Cyber Matters, Tanner Wilburn, Katherine Kennelly, and Zach Smith begin with Google's decision to end its plans to ban third-party cookies, discussing the implications for user privacy and online advertising.

    They then explore recent developments in the cybersecurity industry, including Google's failed acquisition of Israeli cybersecurity company Wiz and Mimecast's successful acquisition of Code 42. They also discuss Apple's warnings to Indian iPhone users about potential "mercenary spyware" attacks and the legal brief filed by major tech firms supporting a journalist targeted by NSO Group's spyware.

    They cover KnowBe4's inadvertent hiring of a North Korean hacker and the potential reporting obligations for companies following the recent Crowdstrike outages. The podcast also touches on the FTC's not-so-new guidance on hashing and anonymization, as well as their investigation into "surveillance pricing" practices.

    State privacy laws are discussed, with a focus on Colorado's universal opt-out shortlist and a recent BIPA decision regarding Samsung's face-scanning feature. The hosts also cover recent fines and settlements involving Meta, Oracle, and TracFone related to various privacy and data protection violations.

    If you enjoy the show, share and leave us 5 stars!

    Links from the show:

    https://www.linkedin.com/company/cyber-matters-podcast/

    https://www.cooley.com/news/insight/2024/2024-07-22-sec-reporting-implications-for-publicly-traded-companies-impacted-by-crowdstrike-defective-software-update

    https://www.techtarget.com/whatis/feature/AI-lawsuits-explained-Whos-getting-sued

    https://www.lawfaremedia.org/article/lawfare-podcast-orin-kerr-and-asaf-lubin-apple-v-nso-group

  • This week on Cyber Matters, Tanner Wilburn and Katherine Kennelly begin with the widespread outages caused by a CrowdStrike update, discussing the implications for IT practices and the importance of testing updates before deployment.

    They then explore the dismissal of most of the SEC's lawsuit against SolarWinds and its former CISO, Timothy Brown. They provide background on the SolarWinds Orion software compromise and analyze the court's decision, particularly highlighting the setback for the SEC's authority in cybersecurity regulation.

    In data breach news, they discuss the arrest of a suspected Scattered Spider hacker in the UK and the ongoing costs of the Change Healthcare ransomware attack for UnitedHealth. They also cover a class-action lawsuit against a law firm related to a data breach.

    The podcast touches on allegations that AWS leased infrastructure to NSO Group, known for its controversial spyware. They also discuss a lawsuit against Patagonia for alleged violations of California privacy law from 1967 and explore the broader trend of CIPA litigation.

    In AI news, the hosts cover updated USPTO guidance for AI-related patent applications and Meta's decision not to offer future multimodal AI models in the EU. The episode concludes with a brief mention of Google's potential $23 billion acquisition of cybersecurity startup Wiz.

    Linkedin: https://www.linkedin.com/company/cyber-matters-podcast/

    A breakdown of USPTO Guidance: https://www.intellectualpropertylawblog.com/archives/uspto-issues-ai-subject-matter-eligibility-guidance/

  • Saknas det avsnitt?

    Klicka här för att uppdatera flödet manuellt.

  • This week on Cyber Matters, host Tanner Wilburn and guests Katherine Kennelly and Zach Smith cover a wide range of cybersecurity, privacy, and technology law topics. They begin with a discussion of AT&T's massive data breach disclosure, highlighting the company's use of SEC guidance on cybersecurity incident reporting and the involvement of the Department of Justice in delaying public disclosure.

    The hosts then explore the ongoing fallout from the MOVEit breach one year later, using it as a case study to anticipate potential consequences for Snowflake's recent data breach. They discuss the legal and financial implications for Progress Software, the company behind MOVEit.

    CISA Director Jen Easterly's recent comments on ransomware payments are examined, along with the broader debate on whether to ban such payments. The hosts also delve into CISA's proposed Cyber Incident Reporting for Critical Infrastructure Act regulations and industry reactions.

    In regulatory news, they cover the 6th Circuit's stay on the FCC's net neutrality rules and provide historical context for the ongoing debate over internet regulation. The podcast touches on several Big Tech stories, including OpenAI's "Strawberry" project, Microsoft's board seat changes at OpenAI, and Apple's antitrust maneuvers in the EU.

    The hosts discuss Meta's relaxation of restrictions on former President Trump's social media accounts and the potential implications of the Supreme Court's SEC v. Jarkesy decision on Meta's dispute with the FTC. They also cover the official publication of the EU AI Act and its significance for businesses operating in Europe.

    National security topics include expanded U.S. Treasury reviews of foreign real estate purchases near military bases, Microsoft's potential investment in UAE's G42 AI firm, and updates on TikTok-related legislation. The hosts also discuss a new software supply chain security bill and Germany's decision to phase out Huawei and ZTE components in 5G infrastructure.

    The episode concludes with updates on Pennsylvania's amended data breach notification law and a local ransomware attack affecting Monroe County, Indiana.

    LinkedIn Page:

    https://www.linkedin.com/company/cyber-matters-podcast

    Ransomware Resources:

    https://www.lawfaremedia.org/article/ofac-the-ransomware-gangs#:~:text=In%20a%20nutshell%2C%20OFAC%20can,in%20other%20words%2C%20ransomware%20gangs.

    https://securityandtechnology.org/virtual-library/memo/roadmap-to-potential-prohibition-of-ransomware-payments/

  • This week on Cyber Matters, hosts Tanner and Katherine cover a wide range of topics in cybersecurity, privacy, and technology law. They begin by discussing the ELVIS Act, a new Tennessee law effective July 1, 2024. Katherine explains how this act expands protections for individuals' voices and likenesses, particularly regarding AI-generated deepfakes. While both hosts praise the act's intentions, they also point out several ambiguities in its language that could lead to implementation challenges.

    Tanner then provides an update on the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program. He details the revised CMMC rules submitted to the Office of Information and Regulatory Affairs, incorporating changes based on public feedback. These revisions include a new 2.5-year rollout plan, allowances for self-attestation in some cases, and increased focus on third-party risk management.

    In SEC news, Tanner discusses a recent 8-K filing by Affirm Holdings, noting how it aligns with new SEC guidance on cybersecurity incident disclosures. The hosts also delve into the Supreme Court's decision in Moody v. NetChoice, which vacates lower court rulings on social media platform regulation laws in Florida and Texas. They explore the nuances of the majority opinion, concurrences, and the implications for future as-applied challenges to these laws.

    Katherine highlights international privacy enforcement actions, including the European Commission's preliminary findings that Meta's "pay or consent" model for Facebook and Instagram users in Europe may violate the Digital Markets Act. She also mentions an order for Meta to stop training its AI on Brazilian personal data.

    In the healthcare sector, Tanner covers a $950,000 settlement between the Office for Civil Rights and Heritage Valley Health System for potential HIPAA violations. He emphasizes the importance of basic security measures like risk assessments and access policies, noting that this case took nearly seven years to resolve.

    The hosts then turn their attention to emerging technologies and their privacy implications. They address concerns about OpenAI's ChatGPT application for Mac storing conversation history in plaintext, debating whether this constitutes a breach of trust. Tanner and Katherine also explore the potential risks and considerations surrounding Morgan Stanley's new AI-powered tool for recording and summarizing client calls.

  • This week on Cyber Matters, Tanner Wilburn and Katherine Kennelly cover a wide range of cybersecurity, privacy, and regulatory news. The episode begins with a discussion of the Department of Commerce's final determination prohibiting Kaspersky Lab from providing antivirus software and cybersecurity services in the United States.

    Tanner then delves into the ongoing challenges with the SEC's cyber disclosure rules that went into effect in December 2023. Many companies have been using cautious language in their Form 8-K filings, often stating that they have not yet determined the materiality of cyber incidents. The SEC has issued further clarifications, including guidance on how companies should assess and disclose ransomware attacks.

    Katherine discusses the American Privacy Rights Act, which was unexpectedly pulled from a congressional hearing. The pair then covers the Protecting Americans' Data from Foreign Adversaries Act (PADFA), which took effect on June 23. This act establishes new restrictions on data brokers transferring sensitive personal data to foreign adversary countries, enforced by the Federal Trade Commission (FTC).

    Tanner and Katherine cover several significant court decisions. These include a ruling from the Northern District of Texas in American Hospital Association v. Becerra, which challenged the Department of Health and Human Services' definition of individually identifiable health information. The Supreme Court's decision in Murthy v. Missouri, addressing government involvement in social media content moderation, is also discussed. Additionally, they touch on the landmark Supreme Court decision overturning the Chevron deference doctrine and its potential effect on the administrative state. (More to come on future episodes).

    State-level privacy legislation is a major focus of this episode, with Tanner highlighting three new state privacy laws taking effect on July 1: the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, and the Florida Digital Bill of Rights Act. He discusses unique aspects of each law and notes Texas's aggressive approach to enforcement. The podcast also covers other state-level developments, including Florida Governor Ron DeSantis's veto of a cybersecurity safe harbor bill, Vermont's failure to pass a privacy bill, and Rhode Island's enactment of comprehensive privacy legislation.

    Katherine examines New York's newly enacted child and teen online safety bills, the New York Child Data Protection Act and the Stop Addictive Feeds Exploitation (SAFE) for Kids Act. Tanner then discusses California's third CCPA settlement, involving Tilting Point Media and its mobile gaming app.

    International cooperation in privacy regulation is touched upon, with Tanner noting the California Privacy Protection Agency (CPPA) signing a partnership agreement with France's data protection authority (CNIL) for joint research and information sharing.

    The episode concludes with discussions on several other topics, including a lawsuit by the Arkansas Attorney General against Temu, Project Veritas challenging an Oregon privacy law before the Ninth Circuit Court of Appeals, Microsoft's blog post on "skeleton key" AI jailbreak techniques, and a brief mention of a Neiman Marcus hack.

    __________________________

    Questions, comments, and feedback can go to [email protected], and dont forget to subscribe to the podcast and share with your network.

    Thanks for joining us, and we'll see you next week!

    _______________________


    Links Mentioned in the show:
    https://www.bakerlaw.com/insights/northern-district-of-texas-flashes-the-blue-lights-on-ocrs-pixel-guidance/