Cybersecurity

27 briefs · 1 new

JFSA ·

Japan's FSA asks financial institutions to take nine short-term cyber measures against the frontier-AI threat

Financial institutions in Japan should implement the FSA's nine short-term cyber measures against the frontier-AI threat, with direct senior-management involvement and a roughly one-month guideline

CISA ·

CISA issues BOD 26-04, replacing KEV remediation rules with risk-based timelines for federal civilian agencies

Federal civilian agency security teams must migrate from the prior KEV remediation regime to BOD 26-04's risk-based timelines, with policy updates due immediately and remediation timelines enforceable within 180 days

IFSCA ·

IFSCA imposes binding cyber controls on IFSC regulated entities for frontier-AI attack risks

IFSC regulated entities must adopt binding cyber controls against frontier-AI attack risks — including treating critical vulnerabilities as exploitable within hours, adding frontier AI as a defined risk-assessment scenario reviewed by the Board, maintaining an SBOM and API inventory, and imposing preparedness requirements on critical service providers — with immediate effect.

EUR-Lex ·

European Commission amends vehicle OBD and repair-information access rules (Delegated Regulation 2026/699)

Vehicle manufacturers must implement the Appendix X procedures for secure, standardised OBD and RMI access (authentication, pseudonymised traceability, API provision, server availability and cybersecurity checks) so independent operators obtain non‑discriminatory, machine‑readable diagnostic and repair data