Enforcement Action
On August 17, 2026 the FTC announced a $2.1 million proposed settlement with Doxo over allegations that it used misleading search ads to impersonate billers and failed to disclose add-on fees. A federal court found Doxo violated the Restore Online Shoppers' Confidence Act. The stipulated order takes effect when signed by the district court.
- Published:
- Aug 17, 2026
- Reviewed:
- Aug 17, 2026
Final Rule
FinCEN published a final rule on August 14, 2026 adopting, with limited changes, its March 2025 interim rule narrowing beneficial ownership information reporting under the Corporate Transparency Act. The rule is effective August 14, 2026. It continues to exempt reporting of U.S. person beneficial owners and also exempts U.S. person company-applicant reporting and FinCEN-identifier updates by U.S. persons.
- Published:
- Aug 14, 2026
- Reviewed:
- Aug 17, 2026
Passed One Chamber — Not final law
This is a bill, not current law. SB 690 would limit private lawsuits for alleged pen-register or trap-and-trace violations arising from conduct on a website or app, leaving those actions to the Attorney General. On August 13, 2026 it passed Assembly Appropriations and was ordered to third reading after earlier Senate passage.
- Published:
- Aug 13, 2026
- Reviewed:
- Aug 17, 2026
Passed One Chamber — Not final law
This is a bill, not current law. AB 1542 would amend the CCPA's sensitive-personal-information provisions. On August 13, 2026 it passed Senate Appropriations and was ordered to third reading after earlier Assembly passage.
- Published:
- Aug 13, 2026
- Reviewed:
- Aug 17, 2026
Passed One Chamber — Not final law
This is a bill, not current law. SB 354 would revise California's Insurance Information and Privacy Protection Act for insurance licensees and third-party service providers. On August 13, 2026 Assembly Appropriations passed it as amended, so the operative text is the amended version.
- Published:
- Aug 13, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
CISA added CVE-2026-68820, a Microsoft Windows Ancillary Function Driver for WinSock use-after-free vulnerability, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 25, 2026 applies to federal agencies, not to private businesses.
- Published:
- Aug 11, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.
- Published:
- Aug 11, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
On August 4, 2026, the IRS and Security Summit partners issued IR-2026-85 describing phishing, spear phishing, clone phishing, whaling, and fake new-client emails used against tax preparers. This is official guidance, not a new rule.
- Published:
- Aug 4, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
NIST updated its event listing on August 4, 2026 for a free August 20, 2026 webinar with CISA, FBI, and NIST speakers on common small-business cyber risks and practical safeguards. This is an awareness session, not a new framework, rule, or legal requirement.
- Published:
- Aug 4, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.
- Published:
- Aug 4, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.
- Published:
- Aug 4, 2026
- Reviewed:
- Aug 17, 2026
Official Guidance
CISA added CVE-2026-18577, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 3, 2026.
- Published:
- Aug 3, 2026
- Reviewed:
- Aug 17, 2026
Effective
The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.
- Published:
- Sep 22, 2025
- Reviewed:
- Aug 17, 2026
SupersededSuperseded
This record is retained as an archived reference and is not presented as the latest California privacy update.
- Published:
- Sep 1, 2025
- Reviewed:
- Aug 17, 2026
Proposed Rule — Not final law
HHS published a proposed rule that would revise HIPAA Security Rule requirements for electronic protected health information.
- Published:
- Jan 6, 2025
- Reviewed:
- Aug 17, 2026
Compliance Deadline
The June 3, 2026 compliance date for smaller entities covered by the SEC's amended Regulation S-P has passed.
- Published:
- May 16, 2024
- Reviewed:
- Aug 17, 2026