CISA says hackers targeted more than 100 US water systems
CISA confirms attacks on over 100 internet-exposed US water and wastewater systems in July 2026, which US officials believe were likely Iranian.
Insights for North, Central, and South America, and the Caribbean.
CISA confirms attacks on over 100 internet-exposed US water and wastewater systems in July 2026, which US officials believe were likely Iranian.
Registered California data brokers must now retrieve and act on consumer deletion requests submitted through the state’s DROP platform.
Canada’s Critical Cyber Systems Protection Act creates mandatory cyber security programmes and incident reporting for federally regulated critical sectors.
Covered platforms must now remove reported non-consensual intimate imagery, including AI deepfakes, within 48 hours of a valid request.
ShinyHunters claims a breach of Instructure’s Canvas platform, affecting nearly 9,000 schools and universities, then defaces login pages during exams.
Online services directed at US children under 13 must now comply with the amended COPPA Rule, including written security programmes and retention policies.
A pro-Iran group claims a destructive attack on Stryker that wiped tens of thousands of company devices and disrupted operations worldwide.
US rules on substance use disorder treatment records now align more closely with HIPAA, adding breach notification and civil penalties.
New CCPA regulations on cybersecurity audits, risk assessments and automated decision-making technology come into force in California.
The Texas Responsible AI Governance Act and Illinois’ AI-in-employment law both come into force, adding to US state AI regulation.
Larger US broker-dealers, investment advisers and funds must now have incident response programmes and notify affected customers within 30 days.
The DFARS rule implementing CMMC takes effect, allowing US Department of Defense contracts to require CMMC status as a condition of award.