Policy
-
Researchers find 131 Chrome extensions cloned to automate WhatsApp spam in Brazil
Researchers say 131 rebranded Chrome extensions, sharing a common codebase, were used to automate bulk WhatsApp Web messaging aimed at Brazilian users, a campaign that appears designed to evade platform anti-spam controls and contravene Chrome Web Store rules.
-
German authorities seize 1,406 fraudulent crypto trading domains in Operation Heracles
German authorities seized 1,406 fraudulent cryptocurrency trading domains on Oct. 3, 2025 under Operation Heracles, BaFin said, recording about 866,000 access attempts in ten days and warning that professional-looking sites, call centres and possibly AI were used to target German-speaking victims.
-
CISA adds Adobe AEM flaw to Known Exploited Vulnerabilities list
CISA added CVE-2025-54253, a critical Adobe Experience Manager Forms misconfiguration that can allow remote code execution, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; Adobe has released a patch and federal agencies were told to apply fixes by Nov. 5, 2025.
-
U.S. seizes $15 billion in Bitcoin, sanctions Southeast Asia cybercrime network tied to alleged Cambodian leader
U.S. authorities announced the seizure of 127,271 Bitcoin (about $15 billion) tied to Chen Zhi and unsealed an indictment alleging he ran the Prince Group, a Cambodia-based network of scam compounds linked to human trafficking and global fraud; coordinated U.S. and U.K. sanctions targeted people, businesses and the Huione Group.
-
Council of Europe authorises EU to sign UN cybercrime convention
The Council of Europe authorised the European Commission and member states to sign the UN Convention against Cybercrime, a treaty adopted by the UN General Assembly in December 2024 that sets common rules for criminalising cyber offences and exchanging electronic evidence, with safeguards to protect human rights.
-
Netherlands places Nexperia under special administrative measures over governance concerns
The Netherlands has placed Chinese-owned Nexperia under special administrative measures under the Goods Availability Act, citing governance failures and risks to European chip capabilities; the company’s owner Wingtech has disputed the move and said it will effectively freeze operations.
-
CISA to end cooperative agreement and federal funding for Center for Internet Security
CISA said it will end its cooperative agreement with the Center for Internet Security on Sept. 30, 2025, ceasing federal funding for programs such as the MS-ISAC. CIS said it will shift MS-ISAC to a fee-based model after federal cuts, and officials warned the move could affect threat-sharing and election security.
-
Senate Democrats flag DOGE program for privacy, cybersecurity risks across three federal agencies
A Senate Democratic report accuses the DOGE program of violating federal law and exposing Americans’ personal data across three agencies, urging immediate safeguards and compliance measures amid warnings of heightened identity theft risk.
-
GitHub Tightens npm Publishing Security with 2FA, Short-Lived Tokens and Trusted Publishing
GitHub announced a sweeping set of security measures for npm publishing, including deprecating legacy tokens, migrating to FIDO-based 2FA, and introducing seven-day, short-lived granular tokens plus trusted publishing that uses OpenID Connect and cryptographic provenance attestations to bolster npm’s supply-chain security.










