<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spoiledlunch</title><link>https://d63efb54.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 13:45:25 +0000</lastBuildDate><atom:link href="https://d63efb54.spoiledlunch.pages.dev/news/" rel="self" type="application/rss+xml"/><item><title>SEC Announces Departure of Principal Deputy Director of Enforcement Sam Waldon</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-sec-announces-departure-of-principal-deputy-director-of-enforcement-sam-waldon/</link><pubDate>Wed, 22 Jul 2026 13:45:25 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-sec-announces-departure-of-principal-deputy-director-of-enforcement-sam-waldon/</guid><description>News Brief • July 22, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today announced that Sam Waldon, Principal Deputy Director of the Division of Enforcement, will depart …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission today announced that Sam Waldon, Principal Deputy Director of the Division of Enforcement, will depart the agency on July 31, 2026, after more than 14 years at the SEC.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-68-sec-announces-departure-principal-deputy-director-enforcement-sam-waldon">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</link><pubDate>Wed, 22 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</guid><description>News Brief • July 22, 2026 | Topics: AI | Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
Why it …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting ...</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-cisa-fbi-epa-and-u-s-government-partners-update-warning-of-iran-affiliated-threat-actors-targeting/</link><pubDate>Wed, 22 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-cisa-fbi-epa-and-u-s-government-partners-update-warning-of-iran-affiliated-threat-actors-targeting/</guid><description>News Brief • July 22, 2026 | Topics: AI | Summary: CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting …
Why it matters: This matters …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting &hellip;</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting">[Critical Advisories] CISA News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-news</category></item><item><title>NTT DATA Group cuts incident analysis to 30 minutes with Codex</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-ntt-data-group-cuts-incident-analysis-to-30-minutes-with-codex/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-22-ntt-data-group-cuts-incident-analysis-to-30-minutes-with-codex/</guid><description>News Brief • July 22, 2026 | Topics: AI | Summary: NTT DATA Group uses ChatGPT Enterprise and Codex to help 9,000 employees automate work, cut incident analysis to 30 minutes, and scale secure …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> NTT DATA Group uses ChatGPT Enterprise and Codex to help 9,000 employees automate work, cut incident analysis to 30 minutes, and scale secure AI adoption.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://openai.com/index/ntt-data">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>ai-governance-openai-news</category></item><item><title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-cisa-adds-four-known-exploited-vulnerabilities-to-catalog/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-cisa-adds-four-known-exploited-vulnerabilities-to-catalog/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
Why …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Rockwell Automation 1718-AENTR/1719-AENTR</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-1718-aentr-1719-aentr/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-1718-aentr-1719-aentr/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Rockwell Automation 1734 POINT I/O</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-1734-point-i-o/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-1734-point-i-o/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Rockwell Automation FactoryTalk Services Platform</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-factorytalk-services-platform/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-factorytalk-services-platform/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Rockwell Automation Studio 5000 Logix Designer</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-studio-5000-logix-designer/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-rockwell-automation-studio-5000-logix-designer/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens CADRA</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-cadra/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-cadra/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities.
Why it matters: This matters if it changes how teams think …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens IAM Client</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-iam-client/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-iam-client/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client.
Why it matters: This matters if …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens Opcenter X</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-opcenter-x/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-opcenter-x/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-ruggedcom-ape1808-with-palo-alto-networks-virtual-ngfw/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-ruggedcom-ape1808-with-palo-alto-networks-virtual-ngfw/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS.
Why it matters: This matters if it changes …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens SIDIS Secured SmartPlug</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-sidis-secured-smartplug/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-siemens-sidis-secured-smartplug/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Tycon Systems TPDIN-Monitor-WEB2</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-tycon-systems-tpdin-monitor-web2/</link><pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-tycon-systems-tpdin-monitor-web2/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>OpenAI and Hugging Face partner to address security incident during model evaluation</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-openai-and-hugging-face-partner-to-address-security-incident-during-model-evaluation/</link><pubDate>Tue, 21 Jul 2026 07:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-21-openai-and-hugging-face-partner-to-address-security-incident-during-model-evaluation/</guid><description>News Brief • July 21, 2026 | Topics: AI | Summary: OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>security</category></item><item><title>Founders of Celsius Network Ordered to Pay $16.5 Million to Resolve FTC Charges</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-20-founders-of-celsius-network-ordered-to-pay-16-5-million-to-resolve-ftc-charges/</link><pubDate>Mon, 20 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-20-founders-of-celsius-network-ordered-to-pay-16-5-million-to-resolve-ftc-charges/</guid><description>News Brief • July 20, 2026 | Topics: AI | Summary: Alexander Mashinsky, the former CEO of cryptocurrency platform Celsius Network Inc.
Why it matters: This matters if it changes how teams …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Alexander Mashinsky, the former CEO of cryptocurrency platform Celsius Network Inc.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/07/founders-celsius-network-ordered-pay-165-million-resolve-ftc-charges">[Executive Risk] FTC Consumer Protection Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-ftc-consumer-protection-press-releases</category></item><item><title>Safety and alignment in an era of long-horizon models</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-20-safety-and-alignment-in-an-era-of-long-horizon-models/</link><pubDate>Mon, 20 Jul 2026 10:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-20-safety-and-alignment-in-an-era-of-long-horizon-models/</guid><description>News Brief • July 20, 2026 | Topics: AI | Summary: OpenAI shares lessons from deploying long-running AI models, highlighting new safety risks, observed failures, and improved safeguards …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> OpenAI shares lessons from deploying long-running AI models, highlighting new safety risks, observed failures, and improved safeguards through iterative deployment.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://openai.com/index/safety-alignment-long-horizon-models">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>safety</category></item><item><title>EDPB calls for legal basis for cross-regulatory information sharing</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-17-edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing/</link><pubDate>Fri, 17 Jul 2026 12:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-17-edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing/</guid><description>News Brief • July 17, 2026 | Topics: GRC | Summary: Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en">EDPB News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-news</category></item><item><title>A scorecard for the AI age</title><link>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-17-a-scorecard-for-the-ai-age/</link><pubDate>Fri, 17 Jul 2026 10:00:00 +0000</pubDate><guid>https://d63efb54.spoiledlunch.pages.dev/news/2026-07-17-a-scorecard-for-the-ai-age/</guid><description>News Brief • July 17, 2026 | Topics: AI | Summary: Sarah Friar, CFO of OpenAI, introduces a practical AI scorecard to measure ROI through useful work, cost per successful task, dependability, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Sarah Friar, CFO of OpenAI, introduces a practical AI scorecard to measure ROI through useful work, cost per successful task, dependability, and return on compute.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://openai.com/index/a-scorecard-for-the-ai-age">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>company</category></item></channel></rss>