ZeroHour

Source: The Register · Security

3 stories in the last 3d

Ofcom discovers issuing Online Safety Act fines is easier than collecting them

Ofcom says most Online Safety Act fines totaling over £7 million remain unpaid as platforms structure businesses to evade collection.

Ofcom director of enforcement Suzanne Cater told the House of Lords that the majority of fines issued under the UK Online Safety Act remain uncollected despite over £7 million in penalties on 11 providers. The regulator's largest fine was £1.4 million against 8579 LLC in February. Ofcom is running six enforcement programs and 40 formal investigations covering more than 100 services, including Telegram, TikTok and X, and is working with the UK government to strengthen its enforcement powers.

CISA decides weekly vulnerability bulletin isn't necessary anymore

CISA will discontinue its weekly vulnerability bulletin on September 28, pushing users toward KEV, alerts, and CVE data under risk-based prioritization.

CISA announced its weekly vulnerability bulletin will stop on Monday, September 28, as part of a shift from static CVSS severity scores to a modern, risk-based approach detailed in a June Binding Operational Directive. The directive prioritizes federal remediation based on exposure, exploitation evidence, control granted by exploitation, and whether exploitation can be automated. CISA directs bulletin subscribers to rely instead on its Known Exploited Vulnerabilities catalog, cybersecurity alerts and advisories, and the CVE catalog, requiring users to enable those subscriptions in GovDelivery or Granicus to avoid missing critical notices.

The Register · Security · 17h agoPolicy & legal

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Zurich court sentences Ukrainian ransomware developer to 12 years, 9 months for LockerGoga, MegaCortex and Nefilim attacks including Stadler Rail.

Zurich District Court sentenced a 52-year-old Ukrainian to 12 years and 9 months for developing LockerGoga, MegaCortex, and Nefilim ransomware, plus a 10-year ban from Switzerland; the verdict can be appealed. The operations hit over 1,800 victims across 71 countries with losses of several hundred million Swiss francs, including Stadler Rail (2020, $6 million Nefilim demand), Meier Tobler, and Crealogix. Alleged mastermind Volodymyr Tymoshchuk, indicted in the US and tied to at least 250 companies including Norsk Hydro, remains at large with an $11 million FBI bounty.

The Register · Security · 2d agoPolicy & legal