Legacy Core

Official sources · Human review

Legacy Core Intelligence Center

Focused updates that affect trust readiness and responsible data practices — not a general cybersecurity news feed. Nothing appears here until a human reviewer approves the source, lifecycle, summary, and recommended action.

Clear filters
Enforcement Action

FTC settles impersonation and hidden-fee case against bill-payment firm Doxo

On August 17, 2026 the FTC announced a $2.1 million proposed settlement with Doxo over allegations that it used misleading search ads to impersonate billers and failed to disclose add-on fees. A federal court found Doxo violated the Restore Online Shoppers' Confidence Act. The stipulated order takes effect when signed by the district court.

Published:
Aug 17, 2026
Reviewed:
Aug 17, 2026
Final Rule

FinCEN finalizes narrower beneficial-ownership reporting rule

FinCEN published a final rule on August 14, 2026 adopting, with limited changes, its March 2025 interim rule narrowing beneficial ownership information reporting under the Corporate Transparency Act. The rule is effective August 14, 2026. It continues to exempt reporting of U.S. person beneficial owners and also exempts U.S. person company-applicant reporting and FinCEN-identifier updates by U.S. persons.

Published:
Aug 14, 2026
Reviewed:
Aug 17, 2026
Passed One Chamber — Not final law

California bill would limit website-tracking lawsuits under the Invasion of Privacy Act

This is a bill, not current law. SB 690 would limit private lawsuits for alleged pen-register or trap-and-trace violations arising from conduct on a website or app, leaving those actions to the Attorney General. On August 13, 2026 it passed Assembly Appropriations and was ordered to third reading after earlier Senate passage.

Published:
Aug 13, 2026
Reviewed:
Aug 17, 2026
Passed One Chamber — Not final law

California bill would rewrite privacy rules for insurance licensees and their vendors

This is a bill, not current law. SB 354 would revise California's Insurance Information and Privacy Protection Act for insurance licensees and third-party service providers. On August 13, 2026 Assembly Appropriations passed it as amended, so the operative text is the amended version.

Published:
Aug 13, 2026
Reviewed:
Aug 17, 2026
Official Guidance

CISA adds Cisco Secure Firewall vulnerability to the KEV Catalog

CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.

Published:
Aug 11, 2026
Reviewed:
Aug 17, 2026
Official Guidance

CISA adds Apache Tomcat vulnerability to the KEV Catalog

CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.

Published:
Aug 4, 2026
Reviewed:
Aug 17, 2026
Effective

California CCPA regulations on automated decisions, risk assessments, and cybersecurity audits are in force

The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.

Published:
Sep 22, 2025
Reviewed:
Aug 17, 2026
Legacy Core Intelligence Center | Legacy Core