On August 18, 2026, the Cybersecurity & Infrastructure Security Agency, Federal Bureau of Investigation, and U.S. Department of Health & Human Services issued an update to a previous advisory to the health care industry warning against Medusa ransomware. The advisory provided tactics, techniques, and procedures as well as the indicators of compromise gathered to assist with response and remediation.

Medusa ransomware has been hitting the healthcare space particularly hard, but it’s also affecting the defense industry, critical manufacturing information technology, and financial services.

The advisory outlines how Medusa is a ransomware-as-a-service (RaaS) variant that was first identified in June 2021. Since its inception, Medusa developers and affiliates have hit over 500 victims, including “medical, education, legal, insurance, technology, and manufacturing.”

Although Medusa originally operated as a closed organization, since 2023 it has developed into an affiliate model, selling RaaS to affiliates that are paid different amounts depending on their experience and how effective they are in extorting victims. Medusa is a double extortion program, where they deploy ransomware to decrypt data, then extort victims for payment to decrypt and suppress publication of the data.

Medusa recruits access brokers in cybercriminal forums and marketplaces. The access brokers are the ones who attack the company through phishing campaigns, or exploit unpatched software vulnerabilities, including ScreenConnect, Fortinet, Fortra, and BeyondTrust. They pay the access brokers between $100 and $1 million to break into the company and sell that access to Medusa operators. They leverage new vulnerabilities within 24 hours and sometimes before they are announced. Once in, the access brokers use legitimate tools to cover their tracks to give them time to sell their wares to Medusa (and other ransomware gangs). Medusa then uses legitimate remote monitoring software to evade detection to exfiltrate data, deploy the ransomware, and extort the victim.

The advisory lists the indicators of compromise that companies should review and block. It also provides common remediation, including eviction countermeasures, and mitigations, which should be applied as soon as possible.

The advisory reinforces how important it is to continue internal phishing tests, employee training, and patching programs as priorities to help avoid becoming a victim.

On August 17, 2026, the Federal Trade Commission (FTC) announced a $2.1 million settlement with online bill-payment company Doxo over allegations that the company, and its two co-founders, deceived consumers through search ads, fees, and subscription practices. The case shows that consumer protection risk can begin at the first click, especially when ads or landing pages make a third-party service look like an official payment channel.

The FTC alleged that Doxo used search ads and other advertising to make consumers believe they were paying utilities, car loans, and other bills through their billers’ official channels. The FTC also alleged that Doxo landing pages often displayed biller names and sometimes logos, even though Doxo had no relationship with the many companies it claimed were in its payment network.

The proposed settlement order starts with the core problem: Doxo allegedly made its payment pages look more official than they were. The order prohibits Doxo from suggesting that a customer paying through a Doxo-controlled site is paying the biller directly or using a service authorized by the biller. It also restricts Doxo from using biller website addresses, names, and logos in search ads, URLs, webpages, and other payment-related advertising in ways that falsely imply sponsorship or approval.

That focus reflects a broader point about consumer perception. A disclaimer may not cure an overall impression created by the rest of the page. If a landing page uses a biller’s name in the headline, places a familiar logo near the payment button, or shows a display URL that looks official, consumers may reasonably think they are dealing with the biller itself. The FTC’s position is that companies need to evaluate the full context, not isolate each word or design choice.

The order also addresses how Doxo presented fees. The FTC alleged that Doxo charged “delivery fees” without clear disclosure and did not adequately explain that those fees were waived only for certain payment methods. Under the order, Doxo cannot misrepresent what consumers will pay, why a fee applies, its total cost, or important limits and conditions. Essentially, fees that matter to the purchase decision need to appear before the consumer enters payment information or commits to the transaction.

The subscription allegations also raise a related issue: consent. The FTC alleged that Doxo enrolled consumers in a recurring subscription program without clearly disclosing the subscription price. Recurring subscriptions often involve a “negative option” feature, where the consumer’s silence or failure to cancel is treated as acceptance. For those features, the order requires Doxo to disclose the key terms before collecting billing information, obtain express informed consent before charging consumers, and provide cancellation methods that are easy to find and use.

The settlement is a reminder that compliance review should follow the customer’s experience from the first search result through cancellation. The question is not only whether each disclosure is technically present, but what the overall flow communicates. If a payment page uses another company’s name, offers a fee waiver, or includes a recurring charge, those terms should be clear before the customer pays. Companies should also be able to show that customers affirmatively agreed to the terms and can cancel without unnecessary steps or confusion. Overall, the checkout flow should make the relationship, cost, and commitment clear before the consumer clicks to pay.

AI governance is often treated as a policy problem: define approved uses, create an oversight framework, publish acceptable use rules, and document compliance. These steps matter, especially as increasingly more regulations are introduced that raise expectations for accountability, transparency, data governance, and lifecycle risk management. However, the harder question for many organizations is no longer whether they have AI rules in place, but whether those rules can keep pace with how AI is being adopted across the business. Public AI tools, embedded platform features, developer copilots, automated workflows, and AI agents are often introduced faster than security, legal, compliance, and risk teams can map what they access, what they influence, and what new exposures they create.

This is why AI governance must become operational. AI risk does not sit neatly inside a single model or use case. It changes depending on the data the system can reach, the identities and permissions it inherits, the applications it connects to, and the business processes it can affect. A tool that appears low risk in one context can become much more sensitive when it is connected to confidential information, privileged accounts, payment approvals, procurement workflows, or critical infrastructure. As AI agents begin acting across enterprise environments, organizations are no longer managing only human users, devices, and applications. They are also managing non-human actors that can retrieve information, make decisions, and initiate actions at machine speed.

The organizations best positioned for responsible AI adoption will be those that treat governance as a living operating model, not a static compliance document. That means identifying AI capabilities across the enterprise, classifying them by business risk, reviewing their access rights, limiting unnecessary permissions, monitoring how they interact with systems and data, and adjusting controls as use cases evolve. Regulation may define the destination, but operational governance builds the road. The objective is not to put the brakes on AI adoption; it is to give organizations the visibility, control, and confidence to innovate safely as AI becomes part of everyday work. The real test of AI governance will be whether organizations can move from written rules to practical controls that support innovation while keeping risk within clear, defensible boundaries.

This week, Apple notified customers in 110 countries around the world (150 countries to date) that they “may have been targeted with spyware capable of hacking into their devices.” Apple notifies users “directly on their iPhone lock screen with a push notification that urges the person to take action.” The threat alert will read “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” Apple will send notifications to users via email as well.

If you receive this notification from Apple, take it seriously and follow it urgently.

Why?

Spyware is “software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge” and is a type of malicious code. The spyware then passes the information to another entity without consent or asserts control over the device without the user’s knowledge. Spyware includes password stealers, banking trojans, and keyloggers.

On mobile devices, spyware steals information including “SMS messages, incoming/outgoing call logs, contact lists, emails, browser history, and photos. Mobile spyware can even log keystrokes, activate and record from any connected microphones or cameras, take screenshots of the phone’s background and track the device using GPS.” The ways threat actors can install spyware on mobile devices is through unsecured free wi-fi, operating system flaws, and malicious apps.

Spyware allows the controller to literally take over your phone without your knowledge or consent.

Spyware is also known as stalkerware, which can be applied to a device for an abusive partner or ex-partner to secretly track an individual’s device and online activity. The FTC has provided guidance on how to detect whether you have become the victim of spyware and how to protect yourself.

How to Detect and Protect Yourself from Spyware

First, if you get an alert from Apple or another manufacturer, take it seriously and follow their instructions.

It is difficult to detect spyware. The signs may be minimal, but be aware of changes to your device’s behavior including: overheating, battery drainage, old messages and pop-ups, excessive data usage, and the presence of new apps on your phone.

To protect yourself against spyware, Guardian Digital suggests the following tips:

CISA also has tips to consider:

  • Use lock-down mode on your phone;
  • Reboot your device weekly;
  • Implement user account control;
  • Routinely update your OS and apps;
  • Install antivirus and anti-malware software;
  • Manage your application permissions;
  • Vet apps before you install them;
  • Keep physical control of your devices;
  • Use secure messaging apps; and
  • Only visit websites beginning with HTTPS://

These tips include basic cybersecurity hygiene to protect your device from compromise, but more importantly, from spyware, which apparently is becoming a bigger problem than in the past. Be aware of the burgeoning problem and implement the above tips to best protect yourself.

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”

Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:

• Healthcare and public health;

• Financial services and insurance;

• Critical manufacturing and construction;

• Transportation systems and logistics;

• Government services and facilities;

• Utilities;

• Academia;

• Media and communications;

• Retail; and

• Professional and nonprofit services.

Organizations in these sectors are urged to implement the recommendations for mitigation including:

• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;

• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and

• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.

The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.

A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration of files containing names, dates of birth, Social Security numbers, driver’s license and passport information, and bank account information used for direct deposits.

The complaint alleged that Cicada3301, a ransomware group, stole about 2.561 terabytes of data and later published the stolen data on the dark web. Several plaintiffs alleged post-breach activity, including attempted account access, increased spam and phishing communications, and fraudulent credit inquiries.

The judge allowed the negligence claim to proceed. The court relied on Dittman v. UPMC,  196 A.3d 1036 (Pa. 2018), for the point that an entity who collects and stores sensitive personal information owes a duty to exercise reasonable care in protecting it from foreseeable breach risks. On causation, the court found it significant that plaintiffs alleged misuse of the same categories of information Rivers allegedly failed to protect, not merely suspicious activity that happened sometime after the breach. On damages, the court held that time spent monitoring accounts, changing passwords, placing fraud alerts or freezes, communicating with financial institutions, buying credit monitoring, and actual misuse were sufficiently alleged at the early pleading stage.

However, most other theories did not survive. Negligence per se was dismissed because the judge concluded that Pennsylvania does not treat it as a standalone cause of action. The implied-contract claim failed because the complaint alleged an expectation of data security, not mutual assent to a contractual promise, and the privacy policy disclaimed any guarantee that personal information would always remain private or secure. The court also dismissed claims of breached fiduciary duty, breach of confidence, invasion of privacy, and unjust enrichment, emphasizing that ordinary data collection, a failure to prevent third-party theft, and general payment-for-services allegations did not supply the missing elements of those claims. The order suggests that a negligence claim may survive where plaintiffs allege specific compromised data, later misuse of the same types of information, and concrete response costs.

However, the court was not willing to let the same breach allegations support every adjacent theory. Expectations about data security did not create an implied contract, ordinary data collection did not create fiduciary duties, and a third-party hack was not treated as an affirmative disclosure by the company.

California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering as one. The CPPA also alleged that LocateSmarter made it too difficult for consumers to opt out of the sale of their personal information by requiring them to provide the last four digits of their Social Security numbers before submitting an opt-out request. According to the CPPA, LocateSmarter collected sensitive and high-risk data, including names, driver’s license information, dates of birth, and information about employment, bankruptcy, and litigation. The CPPA’s order emphasized that requiring consumers to provide more personal information than necessary, particularly sensitive information, can violate California’s data minimization requirements and discourage the exercise of privacy rights.

The takeaway for companies that are data brokers, or those that may fall within California’s broad data broker definition, is practical and immediate. First, companies should reassess whether they are required to register in California, especially if they buy, sell, license, trade, or otherwise share personal information about consumers with whom they do not have a direct relationship. Second, opt-out and deletion-rights workflows should be simple, low-friction, and limited to information reasonably necessary to process the request; asking for sensitive identifiers “just in case” may create enforcement risk. Third, low opt-out volumes should not be viewed as a compliance success story if the request process is confusing, intimidating, or overly burdensome. The CPPA’s comments also suggest that California regulators are increasingly looking at privacy practices through multiple legal lenses at once, meaning companies should treat CCPA compliance, data broker registration, data minimization, and consumer rights operations as connected parts of the same compliance program, not separate boxes to check.

The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will be the first recurring, regulator-visible audit cycle that ties cybersecurity governance, privacy compliance, executive accountability, and legal defensibility together. Businesses that meet the applicable revenue and data-processing thresholds, including those processing large volumes of Californians’ personal information or sensitive personal information, should be preparing now, because the first audit period is quickly approaching.

These audits will require more than a technical controls review. Covered businesses will need to define audit scope, identify relevant systems and data flows, assess third-party and vendor access, document control performance, and support scoping decisions with clear evidence. Legal teams, privacy leaders, security, technology, compliance, and business stakeholders should be aligned early on what is in scope, what evidence will be used, who will own remediation, and how decisions will be documented. Chief legal officers and legal departments have an important role to play here: helping the business interpret regulatory expectations, pressure-test assumptions, assess whether auditor independence requirements are met, and frame the organization’s risk posture in a way that can withstand external scrutiny.

Companies can start by revisiting their data maps, identifying systems that collect, store, transmit, or provide access to California residents’ personal information, and comparing existing cybersecurity frameworks against the CCPA’s required audit domains. Organizations with mature compliance programs may have a head start, but even well-resourced companies should expect meaningful work around documentation, evidence standards, remediation tracking, and executive certification. The key is to move from “we have a program” to “we can prove the program works.” By 2027, the CCPA cybersecurity audit requirement will not be just another compliance milestone, it will be a credibility test for how well companies understand, govern, and protect the personal information they hold.

The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your medical information with a generative AI tool, like ChatGPT, Gemini or Claude, please read this first.

Earlier this year, OpenAI announced the launch of a version of the chatbot dedicated to assist individuals with navigating their health records. Whether you are contemplating sharing your medical information with ChatGPT, or another chatbot, there are risks of doing so that have been outlined in the article “When Patients Share Everything With an AI Chatbot – Risks and Opportunities of Large Language Models” published in the Journal of the American Medical Association.

The article outlines the “potential benefits and discuss the attendant risks of privacy violations, discrimination, and the exacerbation of health disparities that may accompany the unfiltered upload of EHRs” into large language models. These risks include the fact that once the health information is shared with a commercial company, it is not protected by HIPAA, the federal law that protects health information that is created or maintained by medical providers. In addition, the shared information could be disclosed as output for other prompts by other people. Further, the results could be inaccurate, biased, or discriminatory. Finally, the information can be shared with other third parties as outlined in the company’s privacy policy.

It is imperative that prior to uploading any medical information, you read the company’s privacy policy thoroughly, understand the risks, minimize uploading the actual medical records, and be cautious about relying too heavily on the results.

There are studies that show that caution should be used when receiving diagnosis or treatment information from an AI tool. Several individuals have sued AI developers for misdiagnosis that allegedly caused them harm. One individual is suing ChatGPT and its CEO alleging that “ChatGPT’s medical advice nearly killed him.” OpenAI’s terms state that individuals should not rely on it for medical advice. Unfortunately, it is well-known that it is rare for individuals to read privacy policies in depth.

The takeaway? As we have said before, it is really important to read privacy policies before you share your information, even if they are long. Take the time, as that is the only way you will find out how companies are using and disclosing your most sensitive information.

It is similarly important to understand that your medical information is not protected when you share it with a third party. Protect your most sensitive information, and know the risks before you share it with a commercial entity or rely on the results of an AI bot.

Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI) confirmed that at least seven states were affected and issued an alert detailing the hackers’ actions and their impact on water and wastewater systems.

Shortly thereafter, both Georgia and Michigan confirmed that they were targeted and experienced “hostile cyber activity,” including nine systems in Michigan, though both states reported no operational disruption or public health concern.

As of today, it is being reported that “at least 12 states have been hit.” In addition to Minnesota, Michigan, and Georgia, a water system in South Dakota reported a cyberattack “that appears to be part of the same campaign.”

In addition to alerts issued by the FBI and the Cybersecurity and Infrastructure Security Agency, Infracritical published a detailed report on the Minnesota attack and—to  a lesser extent—Michigan, including the attack overview and vector, threat actor profile, and the public health risk to residents as a result of the attack happening during a regional heat event. The report notes that, for the first time confirmed in U.S. water sector history, “at least one utility experienced flooding as a direct result of PLC manipulation — the first cyber-caused flooding event documented in U.S. water infrastructure. This indicates adversary willingness to cause physical infrastructure damage, not merely access loss or service interruption.”

The report provides a statewide hardening roadmap that state utility operators should consider in the face of this ongoing threat by foreign adversaries.

The fact that the hackers of 12 statewide water systems did not think twice about damaging physical infrastructure is a wake-up call that our water, electrical, and financial systems must be hardened against these new cyber warfare threats for national security.