Governance, Legislation, Regulation
Tasmania proposes data centre expectations on renewables, network costs and water
(DigWatch) Tasmania has proposed new data centre expectations for major digital infrastructure projects, covering renewable energy, electricity-network costs, water use, community benefits, and transparency. The draft applies to new and expanded data centres and AI infrastructure, including hyperscale, co-location, large-scale AI computing facilities, and multi-site developments. It excludes small edge and on-site enterprise facilities. The data centre expectations are non-statutory and would not create a new approval or regulatory process. Instead, they provide government guidance on the outcomes developers should pursue through Tasmania’s existing planning, connection, infrastructure, and commercial processes. Energy is central to the proposal. Tasmania expects new data centre and AI infrastructure developers to support additional renewable generation and enter commercial arrangements that can help bring forward new wind and solar projects. Developers would also be expected to explain how they source electricity and demonstrate that renewable-energy commitments are genuine and independently verifiable. – https://dig.watch/updates/tasmania-data-centre-expectations
Spain opens consultation on data centre rules
(DigWatch) Spain has opened consultation on new data centre rules that would make access to electricity networks conditional on requirements covering energy and water efficiency, renewable power, resilience, and digital sovereignty. The draft Royal Decree responds to a rapid increase in proposed computing infrastructure. Spain says more than 6 GW of grid-access capacity has been granted to data centres through the transmission network since late 2023, alongside around another 6 GW through electricity-distribution networks since 2020. Those figures already exceed the government’s 2030 estimate of 3.5–4 GW of electricity demand associated with 2.5 GW of computing capacity. The main requirements would apply to data centres with electricity-grid access capacity of 1 MW or more. Before beginning operations, covered facilities would have to demonstrate compliance with digital-sovereignty requirements and must remain compliant to retain their grid-access and connection permits. – https://dig.watch/updates/spain-data-centre-rules-consultation
India and Luxembourg deepen cooperation in emerging technologies
(DigWatch) India and Luxembourg are looking to broaden their cooperation beyond their established space partnership, with discussions focusing on AI, quantum technologies, advanced materials, and life sciences. Luxembourg’s Minister of Economy, SME, Energy and Tourism, Lex Delles, met India’s Minister of State for Science and Technology and Space, Dr Jitendra Singh, in New Delhi to explore concrete areas for collaboration. Space remains a central pillar of the relationship. The countries already have an agreement on peaceful cooperation in outer space, while Luxembourg companies have already worked with Indian partners on satellite capacity and related technologies. Both sides discussed further opportunities involving Earth observation, communications, satellite systems, launch services, ground stations and mission support, alongside greater engagement between their private space industries. – https://dig.watch/updates/india-and-luxembourg-emerging-technologies
China outlines digital and data-driven logistics network under 15th Five-Year Plan
(DigWatch) China’s National Development and Reform Commission (NDRC) and Ministry of Transport have released a new Logistics Network Construction Implementation Plan, setting out measures to develop a more interconnected, digital, and automated national logistics network by 2030. The plan, approved by the State Council, covers physical infrastructure as well as rules, standards and information and data systems. Under the plan, China aims to improve the interconnection of logistics hubs and transport corridors, expand the use of smart and green infrastructure and equipment, and strengthen interoperability of logistics information and rules. It also sets a target of reducing total social logistics costs to 13.1% of GDP by 2030. The NDRC and Ministry of Transport identified digitalisation, data-sharing, and technical standards among the areas where further development is needed. – https://dig.watch/updates/china-logistics-data-interconnection-plan
ILO dialogue examines how AI is reshaping labour markets in Asia
(DigWatch) Governments, workers, and employers across South-East Asia and China have called for stronger reskilling, social dialogue, and inclusive AI policies as artificial intelligence changes labour markets across the region, according to the International Labour Organization (ILO). The recommendations emerged from the Regional Policy Dialogue 2026 in Bangkok, which examined how AI is affecting employment and how governments can integrate the technology into public employment services and skills-development systems. Participants stressed that human judgement and social dialogue should remain central as AI adoption expands. – https://dig.watch/updates/ilo-policies-ai-asian-labour
OECD finds how students use AI matters for learning outcomes
(DigWatch) Students who use AI and digital tools for clearly defined learning purposes can benefit from the technology, while excessive or poorly guided use is associated with weaker educational outcomes, according to new findings from the OECD’s Programme for International Student Assessment (PISA) 2025 assessment. The study, which involved 760,000 students across 91 countries and economies, found that students who reported not using AI to draft text for writing assignments performed better than those who did. Among frequent AI users, however, students who used the technology to support learning and had been taught how to assess the quality of AI-generated information tended to perform better than those who had received no such guidance. – https://dig.watch/updates/oecd-finds-students-ai-learning-outcomes
Digital payments and technology emerge as drivers of BRICS trade
(DigWatch) BRICS+ countries should accelerate the development of digital payments, technology sharing, and simplified trade mechanisms to strengthen economic cooperation, according to Sameep Shastri, Chairman of the BRICS Chamber of Commerce and Industry. Speaking to news agency ANI, Shastri said India’s fourth BRICS presidency has raised expectations among businesses, with this year’s focus on resilience, innovation, cooperation and sustainability. He said BRICS+ nations should create larger markets for innovators and startups, allowing businesses to expand across member and partner economies. – https://dig.watch/updates/digital-payments-technology-drivers-of-brics
Singapore proposes new licensing rules for data centres and cloud services
(DigWatch) Singapore has introduced a Digital Infrastructure Bill that would create new licensing regimes for major data centres and cloud service providers, covering both operational resilience and environmental sustainability. Under the proposed framework, major co-location and cloud data centres with a critical IT load of at least 10 MW would be subject to security and resilience requirements. Major cloud providers would also be covered where their Infrastructure-as-a-Service and Platform-as-a-Service activities generate at least S$100 million in average annual revenue from users in Singapore over the previous three years. Licensed operators would have to implement risk-management measures, business continuity and disaster recovery plans, and report specified disruptions to the Infocomm Media Development Authority. – https://dig.watch/updates/singapore-licensing-data-centres-cloud-services
An AI agenda for the India-Australia partnership
(Nidhi Singh – The Interpreter) Australia is building data centre capacity at a pace it cannot absorb, while India’s AI expansion requires computing power on a scale it cannot build fast enough – creating a natural complementarity both countries can take advantage of. The Australian National AI Plan, released in December 2025, presents Australia as the Indo-Pacific’s home for trusted digital infrastructure, citing more than A$100 billion in forecast data centre investment alongside an abundant renewable resource. It also instructs Austrade to market the country as a regional AI hub, including a mandate to find demand in other regions. India offers a suitable destination. Indian businesses are adopting AI at some of the highest rates and demand is outrunning what can be built domestically. This offers a chance to outsource the infrastructure – training a large model is a kind of workload where the physical distance is immaterial. Other governments are bidding for the same business. India and the United Arab Emirates agreed terms in May 2026 for a cluster involving G42 and the Centre for Development of Advanced Computing. However, this was a single transaction with no standing framework behind it. – https://www.lowyinstitute.org/the-interpreter/an-ai-agenda-for-the-india-australia-partnership
Terrorism/Counter-Terrorism
From Al-Qaeda To Lone Wolves And AI: How Terrorism Has Changed Since 9/11
(Ray Furlong – RFE/RL) Farhad N. was just a few months old when hijacked airliners were deliberately piloted into the twin towers of the World Trade Center in New York on September 11, 2001, part of attacks on the United States that killed thousands of people. Twenty-five years later, he was sentenced to life imprisonment for plowing a Mini Cooper car into a crowd of people in Munich, killing two people and injuring dozens. The 25-year-old Afghan’s story underlines how the world has been shaped since 9/11, with both the terror threat and counterterrorism operations continually in flux. The 9/11 attacks were plotted by Al-Qaeda, a group led by Saudi millionaire Osama bin-Laden and sheltered by the Taliban authorities in Kabul who were subsequently driven from power. After this, Farhad N. – whose surname is abbreviated in line with German privacy rules — began to grow up in a country where US-led international forces fought for 20 years to keep the Taliban at bay. Later, he was among hundreds of thousands of Afghans who left their country to seek peace and prosperity in Europe — only to become radicalized by online propaganda posted by imams in his native country. He had no affiliation or links to any specific group and appeared to have acted entirely on his own initiative. “In the old days, we would call these lone actors or lone wolves. This is the future,” a former US diplomat with decades of experience in counterterrorism told RFE/RL. “Nobody needs to be a part of a group…They can be inspired by a group, they can be inspired by multiple groups,” the ex-diplomat, who did not wish to be named, said, adding that advances in Artificial Intelligence were exacerbating an “inflection point” in the development of terror threats. RFE/RL spoke to multiple experts about how technological means that did not exist 25 years ago, including drones, AI, and social media — are creating a completely new and more dangerous environment. “We’re beginning to see a lot more online presence. We’re beginning to see a lot more use of influencers…in addition to the standardized actors that we have become used to in the terrorist scene, we also have lone actors, those who are influenced,” retired US General Joseph Votel told RFE/RL. Votel led a parachute assault by US troops on Taliban positions in Kandahar in October 2001, just weeks after the 9/11 attacks on New York and Washington. He went on to play a key role in what was dubbed the War on Terror, serving also in Iraq and commanding operations against Islamic State (IS) militants. “These terrorist organizations have survived. They’ve continued to adapt as much as they can…they’ve become more sophisticated,” he said. “The environment is much more complex now for security experts.” – https://www.rferl.org/a/al-qaeda-terrorism-counterterrorism-25-years/33846520.html
Security and Surveillance
United Nations Secretary‑General urges international police cooperation to face the growing cybercrime dimension of transnational crime
(DigWatch) On 6 September 2026, the United Nations marked the International Day of Police Cooperation by highlighting the importance of cross-border collaboration in addressing organised crime and the increasingly significant role of cyber-enabled offences. The observance emphasised that transnational criminal networks operate across jurisdictions and increasingly exploit digital technologies, requiring law enforcement agencies to cooperate beyond national borders and strengthen their ability to exchange information, develop common approaches and respond collectively to emerging threats. United Nations Secretary-General António Guterres stressed that effective international cooperation enables law enforcement agencies to better support survivors, apprehend perpetrators, disrupt criminal networks and enhance safety. This cooperation is supported by a range of international mechanisms and organisations. INTERPOL, which connects police forces in 196 countries, provides a critical infrastructure for international police cooperation and information-sharing. United Nations Police, under the leadership of Under-Secretary-General for Peace Operations Jean-Pierre Lacroix, provide advisory, training and capacity-building support to national police institutions, with a particular emphasis on strengthening policing institutions that are effective, accountable and responsive to the communities they serve. – United Nations Secretary‑General urges international police cooperation to face the growing cybercrime dimension of transnational crime | Digital Watch Observatory
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
(Pierluigi Paganini – Security Affairs) Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases. It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it. Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system. – https://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
(Pierluigi Paganini – Security Affairs) North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s research documents a previously undocumented Linux toolkit hitting South Korea’s automotive and media sectors, and the depth of integration here goes well beyond a typical backdoor bolted onto a system. “A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd.” reads the report published by Rapid7. “This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance”. The implant, which Rapid7 calls the “ted backdoor” based on debug strings the attackers left behind, isn’t a separate process running alongside HAProxy. It’s compiled directly into HAProxy’s own source code as a custom plugin, using the software’s native filter API, internal memory management, and event scheduler to intercept HTTP traffic while completely legitimate load balancing keeps running normally on top of it. “The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12.” continues the report. “It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected”. – https://securityaffairs.com/198656/apt/north-korea-linked-hackers-hide-a-backdoor-inside-haproxy.html
IT Help Desk Impersonation Lets Hackers Bypass MFA
(Pierluigi Paganini – Security Affairs) Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering. Attackers pose as internal IT help desk staff via phone calls and direct executives toward rogue authentication portals. “The threat actors impersonate internal IT or helpdesk personnel by phone and direct them to an authentication-themed URL, often formatted as <victim organization>.<lure domain>.” reads the report published by Artic Wolf. “These attacks most frequently target Directors, Vice Presidents, and other executive staff”. Once victims land on these pages, adversary-in-the-middle panels intercept credentials and multi-factor approvals in real time. Stolen session tokens are then replayed using residential proxy networks that match the victim’s exact geographic location. – https://securityaffairs.com/198634/cyber-crime/it-help-desk-impersonation-lets-hackers-bypass-mfa.html
Indian Central Bureau of Investigation conducts nationwide crackdown on digital arrest scams, searches 89 locations in 20 states
(DigWatch) The Indian Central Bureau of Investigation (CBI) has launched a nationwide crackdown on so-called ‘digital arrest’ scams, conducting coordinated searches at 89 locations across 20 Indian states and arresting three individuals allegedly involved in receiving, layering, and dispersing fraud proceeds. The operation forms part of the CBI’s broader nationwide effort to dismantle cybercrime syndicates that exploit the identity and authority of law enforcement institutions to defraud victims of large sums of money. The action relates to three cybercrime cases involving an alleged combined loss of ₹42.36 crore (~€4M). The cases originated in Gujarat, where the reported loss amounted to ₹19.24 crore; Rajasthan, specifically Pilani, involving ₹7.67 crore; and Karnataka, involving ₹15.45 crore. The scale of the alleged losses illustrates the significant financial impact that digitally facilitated impersonation schemes can have on individual victims. In the Gujarat case, investigators reported that a victim was subjected to an illegal ‘digital arrest’ for approximately three months. Fraudsters allegedly impersonated police officers and maintained prolonged contact with the victim, using threats of arrest and other forms of coercion to induce the transfer of funds. Similar methods were reportedly employed in the Rajasthan and Karnataka cases, where victims were subjected to extended video or telephone calls and threatened with arrest. By creating the appearance of an official law enforcement procedure, the perpetrators allegedly exploited victims’ trust in public institutions to exert psychological pressure and obtain substantial financial transfers. – https://dig.watch/updates/india-cbi-nationwide-crackdown
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
(Pierluigi Paganini – Security Affairs) A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ original report provides the underlying analysis. The alleged dataset covers users across Condé Nast’s publishing portfolio, which includes Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair and other titles. Condé Nast has not publicly confirmed the breach or commented on the new sale listing. The seller claims the database contains 32,815,767 unique email addresses. It also allegedly includes names, postal addresses, gender, dates of birth and phone numbers for portions of the population, but no passwords, password hashes, usernames or payment-card data. “A database of 32,815,767 Condé Nast user records went on sale on a Russian-language hacker forum on 7 September 2026 for $15,000, offered as the full set behind December’s WIRED leak.” Ransomnews states. “Ransomnews tested the 5,000-row sample: it is genuine Condé Nast account data, captured in September and October 2025, and the 30.5 million non-WIRED records have not surfaced publicly before. Condé Nast has never commented on the breach.” – https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
(Pierluigi Paganini – Security Affairs) Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. Several NVIDIA components share a global memory section that gives all users full read/write access. Although the software performs checks to prevent misuse, it reuses data from this shared memory at runtime, which can lead to an out-of-bounds memory write. The researcher says the flaw does not immediately provide SYSTEM-level privileges, but it could potentially allow an attacker to cross user boundaries or even compromise the Windows Desktop Window Manager (dwm.exe) process. They did not fully investigate the impact but suggested that the bug could potentially support a more complete exploit. The researcher also provided a simple proof of concept: run an application using Vulkan or OpenGL, launch the PoC, press Enter, and observe the application crash. – https://securityaffairs.com/198589/hacking/chaotic-eclipse-released-a-poc-for-nvidia-greensection-memory-corruption-zero-day.html
JSCeal Hides Crypto Malware in V8 Bytecode
(Pierluigi Paganini – Security Affairs) JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest research at Black Hat USA 2026 and showed how its team built a tool that converts the hidden code into a form analysts can understand. JSCeal uses a clever trick. Instead of delivering normal JavaScript, its creators compile the malware into V8 bytecode, the format that Chrome and Node.js use to run JavaScript efficiently. They then package the bytecode with a Node.js runtime that executes it. The original JavaScript never reaches the victim’s computer. As a result, most tools designed to analyze JavaScript have little useful code to work with. “JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). ” states the report. “Unlike ordinary JavaScript malware, JSCeal reaches the analyst after two transformations have already removed much of the information that source-oriented tools depend on. First, the JavaScript is heavily obfuscated. Then it is compiled into V8’s internal bytecode representation and shipped as cached data rather than source code. The resulting format is version-specific, poorly served by mature reverse-engineering tooling, and unsuitable for most standard JavaScript deobfuscation workflows.” – https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html