ZeroHour

Search: “hardware”

6 stories

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

ETSI releases 17 draft cybersecurity standards vendors must meet when the EU Cyber Resilience Act takes effect in December 2027.

The European Telecommunications Standards Institute published 17 interim draft standards covering operating systems, routers, firewalls, VPNs, SIEMs, browsers, password managers, smart home devices, toys and wearables. They mandate basic security features such as post-sale updates, shipped SBOMs, modern cryptography and secure-by-default settings; public comments run until November, with final versions expected in December, one year before CRA compliance begins in December 2027. The newsletter also reports Irregular taking responsibility for AI test-environment escapes involving Anthropic and Meta frontier models, a breach at France's tax agency exposing 678,000+ citizens' data claimed by hacker ZeroBytes, and Kazakhstan eGov data covering 15 million citizens listed for sale on an underground forum. Additional briefs cover a $3.2 million Harmony Protocol theft crashing the ONE token 40%, Columbus Police still restoring systems two years after ransomware, DDoS attacks on Threema's provider, and Ukraine's GUR claiming a cyberattack on Wildberries.

Risky Business News · Aug 17, 2026Policy & legal2

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

G7 cybersecurity agencies led by France's ANSSI urged accelerated transition to post-quantum cryptography, prioritizing critical systems and phased, risk-based migration.

Under France's 2026 G7 Presidency, ANSSI, chairing the G7 Cybersecurity Working Group, published a September 3 call to action urging governments and organizations to begin quantum-safe (PQC) transitions now, reframing the quantum threat as near-term. The document, signed by the national cyber agencies of all G7 members and supported by the EU Commission and ENISA, outlines five priorities including national PQC strategies, R&D, public-private partnerships, and integrating PQC into cybersecurity requirements. It recommends cryptographic inventories, dependency mapping, prioritizing the most critical systems, and buying PQC-integrated products during normal renewal cycles. ANSSI will stop vetting non-quantum-safe products in 2027, with PQC mandatory in some security product procurement by 2030.

Infosecurity Magazine · 13d agoPolicy & legal

Your phone or computer may soon ask how old you are

California's Digital Age Assurance Act forces Windows, macOS, iOS, and Android to collect age brackets from January 2027, with open-source exemptions pending.

California's Digital Age Assurance Act, signed in October 2025, requires major operating systems to collect user age brackets (under 13, 13-15, 16-17, 18+) and share non-identifying age signals with app developers starting January 1, 2027, with existing setups complying by July 1, 2027. AB1856, passed in late August 2026, would exempt open-source operating systems under GPL, MIT, BSD, and Apache licenses and awaits the governor's signature. Colorado, Illinois, and New York have similar age assurance measures, and the EFF has criticized the law for privacy and censorship concerns.

Malwarebytes Labs · 14d agoPolicy & legal

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump's Executive Order 14420 declares a national emergency to restrict foreign-made bulk-power grid equipment over cyber, sabotage and supply-chain risks.

Executive Order 14420, signed August 26, declares a national emergency regarding the foreign supply of bulk-power system electric equipment to the United States. It empowers the Energy Secretary to restrict transactions with designated Covered Foreign Entities involving equipment, software, firmware, digital services, maintenance services, and remote-access capabilities. Covered equipment includes transformers, generators, inverters, RTUs, PLCs, intelligent electronic devices, and protective relays, with transmission rated 69 kV or higher in scope while local distribution is excluded. Already-installed foreign equipment may be subject to identification, isolation, monitoring, or replacement requirements, with phased compliance and pre-qualified vendor exemptions permitted.

Security Affairs · 19d agoPolicy & legal

Risky Bulletin: White House lets private companies carry out offensive cyber ops

A White House memo directs DHS to create a program letting vetted private companies conduct US-government-directed offensive cyber operations against cybercrime.

A presidential memo tasks the DHS National Coordination Center with building a program, under DOJ and DHS oversight, through which private-sector companies can conduct offensive cyber operations against large-scale cybercrime organizations. Requirements include secure facilities, vetted personnel, a $1 million escrow for damages, and written approvals co-signed by DHS and DOJ executive directors. The program must launch within 60 days, around October 11, expanding a March executive order targeting scam compounds, ransomware, and other large-scale cybercrime.

Risky Business News · Aug 14, 2026Policy & legal

17 draft Cyber Resilience Act standards are open for comment

ETSI publishes 17 draft harmonised standards detailing EU Cyber Resilience Act compliance, open for comment until between mid-September and mid-November 2026.

Seventeen draft standards covering the higher-risk tier of products with digital elements, including password managers, antivirus software, connected toys and wearables, are open for comment. Following a Harmonised Standard grants manufacturers the presumption of conformity with the Cyber Resilience Act, whose obligations apply through the end of 2027 to importers, distributors, service providers and developers. The drafts went to 41 member organisations plus societal partners ANEC, ECOS, ETUC and SBS, with closing dates varying by vertical.

Help Net Security · Aug 14, 2026Policy & legal