Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Chinese State Actors Linked to Expanding Botnet Activity and AI Data Center Security Concerns

Recent intelligence indicates that Chinese state linked operators are actively rebuilding botnets and engaging in discussions around AI data center security implications. This activity includes the expansion of the JDY botnet, specifically targeting US military networks. The dual focus on sustained cyber operations and shaping discourse on critical AI infrastructure highlights a sophisticated, multifaceted approach to intelligence gathering and strategic influence.

Today's question

Article 13(1) GDPR requires the controller to provide which of the following information at the time of collection?

  1. Only the purpose of processing, subject to the applicable communication standards, with corresponding procedural safeguards
  2. The controller's identity/contact details, DPO contact, purposes and legal basis, legitimate interests (if applicable), recipients, and information on transfers
  3. Only the controller's name, under the transparency and fairness framework, with corresponding procedural safeguards
  4. Only the data subject's rights, in accordance with the information provision framework, particularly for cross-border operations

Answer this question on the site

Worth knowing

  1. WhatsApp Alleges NSO Group Violates Court Order with New Spyware Attacks

    WhatsApp has reported new spyware attacks linked to the NSO Group, alleging these activities violate a standing court order. This development suggests a continued use of sophisticated surveillance tools by the NSO Group against individuals, despite legal interventions. The ongoing nature of these attacks highlights the challenges in regulating powerful cyber surveillance technologies.

  2. Signal Condemns UK's Device Scanning Proposal as a Threat to Privacy

    Signal has issued a strong condemnation of a UK government proposal to scan user devices for illicit content, arguing that such measures endanger fundamental privacy and security for all users. The encryption service states that this approach, while ostensibly aimed at child protection, would undermine end to end encryption and create severe vulnerabilities. This debate highlights the tension between security goals and privacy rights in digital communications.

  3. European Data Protection Board Adopts Common Data Breach Notification Model

    The European Data Protection Board (EDPB) has met with Commissioner McGrath and adopted a common model for data breach notifications. This initiative aims to streamline and standardize the process for reporting data breaches across the European Union, enhancing efficiency and consistency for both data controllers and supervisory authorities. This harmonized approach is expected to improve enforcement and clarity under the GDPR.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.