Legacy Core

Official sources · Human review

Legacy Core Intelligence Center

Focused updates that affect trust readiness and responsible data practices, not a general cybersecurity news feed. Nothing appears here until a human reviewer approves the source, lifecycle, summary, and recommended action.

Clear filters
Passed Legislature, awaiting Governor (not final law)

California bill would limit website-tracking lawsuits under the Invasion of Privacy Act

This is a bill, not current law. SB 690 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would limit private lawsuits for alleged pen-register or trap-and-trace violations arising from conduct on a website or app, leaving those actions to the Attorney General.

Published:
Aug 28, 2026
Reviewed:
Sep 2, 2026
Passed Legislature, awaiting Governor (not final law)

California bill would amend the CCPA definition of sensitive personal information

This is a bill, not current law. AB 1542 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would amend the CCPA's sensitive-personal-information provisions.

Published:
Aug 28, 2026
Reviewed:
Sep 2, 2026
Passed Legislature, awaiting Governor (not final law)

California bill would rewrite privacy rules for insurance licensees and their vendors

This is a bill, not current law. SB 354 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would revise California's Insurance Information and Privacy Protection Act for insurance licensees and third-party service providers, including areas such as information safeguards, privacy notices, data handling, retention, third-party relationships, and consumer information rights.

Published:
Aug 28, 2026
Reviewed:
Sep 2, 2026
Passed Legislature, awaiting Governor (not final law)

California bill would address AI-enabled employee surveillance

This is a bill, not current law. AB 1883 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would address AI-enabled employee surveillance practices.

Published:
Aug 28, 2026
Reviewed:
Sep 2, 2026
Enforcement Action

FTC settles impersonation and hidden-fee case against bill-payment firm Doxo

On August 17, 2026 the FTC announced a $2.1 million proposed settlement with Doxo over allegations that it used misleading search ads to impersonate billers and failed to disclose add-on fees. A federal court found Doxo violated the Restore Online Shoppers' Confidence Act. The stipulated order takes effect when signed by the district court.

Published:
Aug 17, 2026
Reviewed:
Aug 17, 2026
Final Rule

FinCEN finalizes narrower beneficial-ownership reporting rule

FinCEN published a final rule on August 14, 2026 adopting, with limited changes, its March 2025 interim rule narrowing beneficial ownership information reporting under the Corporate Transparency Act. The rule is effective August 14, 2026. It continues to exempt reporting of U.S. person beneficial owners and also exempts U.S. person company-applicant reporting and FinCEN-identifier updates by U.S. persons.

Published:
Aug 14, 2026
Reviewed:
Aug 17, 2026
Official Guidance

CISA adds Cisco Secure Firewall vulnerability to the KEV Catalog

CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.

Published:
Aug 11, 2026
Reviewed:
Aug 17, 2026
Official Guidance

CISA adds Apache Tomcat vulnerability to the KEV Catalog

CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.

Published:
Aug 4, 2026
Reviewed:
Aug 17, 2026
Effective

California CCPA regulations on automated decisions, risk assessments, and cybersecurity audits are in force

The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.

Published:
Sep 22, 2025
Reviewed:
Aug 17, 2026
Legacy Core Intelligence Center | Legacy Core