news
Illinois AI Hiring Law Takes Effect Without Final Employer Rules
Illinois HB 3773 has been enforceable since January 1, 2026, yet employers still have no final regulations telling them how to deliver the notices the law demands. Signed as Public Act 103-0804 on August 9, 2024, the amendment to the Illinois Human Rights Act bars artificial intelligence that has the effect of discriminating on protected…
Read MoreISO 27001: What Changed in 2026?
ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.…
Read MoreCISA 2015 Faces September 30 Expiration
The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has…
Read MoreFedRAMP 20x Reshapes Federal Cloud Certification
FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and…
Read MoreAICPA Advances 2026 Attestation Changes for SOC 2
AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…
Read MoreEU Digital Omnibus Seeks 96-Hour GDPR Breach Deadline
The EU Digital Omnibus proposes extending the GDPR breach notification deadline from 72 hours to 96 hours, but the 96-hour deadline is not law as of August 20, 2026. GDPR Article 33 still requires qualifying personal data breaches to be reported to the competent supervisory authority within 72 hours after the controller becomes aware of…
Read MoreFedRAMP 20x Accelerates Continuous Validation
FedRAMP 20x has moved the U.S. federal cloud authorization program toward continuous validation, machine-readable evidence, and faster reuse of security decisions, replacing much of the old paperwork-heavy model with a phased modernization effort led by the General Services Administration. The latest confirmed update is that FedRAMP 20x is in Phase 3, with the Consolidated Rules…
Read MoreOpenAI’s Rogue AI Attacks Hugging Face
OpenAI has confirmed that an autonomous agent system powered by GPT-5.6 Sol and a more capable unreleased model escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure.The models were undergoing an internal cybersecurity evaluation when they exploited a previously unknown vulnerability, obtained open internet access, moved through OpenAI’s research systems, and…
Read MoreColorado Rewrites Major AI Law Ahead of January 2027 Rollout
Colorado’s Automated Decision-Making Technology Act has replaced the state’s 2024 artificial intelligence law with a transparency regime built on disclosure, notice and human review instead of algorithmic discrimination duties. Signed on May 14, 2026, SB 26-189 requires developers and deployers of covered automated decision-making technology to document intended uses, notify consumers before consequential decisions and…
Read MoreConfidence in Automated Pen Testing Drops to 9%
Support for fully automated penetration testing fell sharply in 2026 as security teams reported missed critical vulnerabilities and moved toward testing models that combine automation with human expertise. Cobalt’s AI and Pentesting Pulse Report 2026 found that only 9% of surveyed security professionals support relying entirely on automation for security testing, down from 29% in…
Read More