Cyprus officials deepen cooperation on AI and cybersecurity

Cypriot officials have agreed to deepen cooperation on AI, cybersecurity and digital resilience.

Commissioner of Communications Marios Pieris met Chief Scientist for Research, Innovation and Technology Demetris Skourides to discuss a strategic framework for the secure and responsible adoption of AI.

Planned areas of cooperation include support for implementing the EU AI Act and the development of an AI Act Implementation Playbook.

The two offices also intend to organise technical meetings and roundtables with ISO/IEC experts on AI governance and international standards.

Pieris said cybersecurity and AI are closely connected elements of Cyprus’ digital transformation and require cooperation among the relevant authorities.

Skourides highlighted the need to bring together government, research, industry and the innovation community while aligning AI development with European values, transparency and recognised governance standards.

The Commissioner also introduced his office’s AI team as part of efforts to develop joint initiatives in AI, cybersecurity and digital governance.

Both sides agreed to hold regular working meetings focused on innovation, digital resilience and the safe and trustworthy use of AI in Cyprus.

Why does it matter?

Closer coordination could help Cyprus translate the EU AI Act and international standards into consistent guidance for public authorities and businesses. A practical implementation playbook and joint technical work may be particularly valuable for a smaller administration, where fragmented interpretations could increase compliance costs and leave gaps between AI governance, cybersecurity and innovation policy.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Singapore sets three priorities against AI-enabled OT attacks

Singapore has outlined three priorities for protecting operational technology from increasingly capable AI-assisted cyberattacks.

Minister for Digital Development and Information Josephine Teo said the country’s approach would focus on ‘lock down, find first and fix fast’.

Speaking at the Operational Technology Cybersecurity Expert Panel Forum, Teo warned that AI is lowering the technical barriers for attackers targeting critical infrastructure.

She cited an attempted breach of a municipal water utility in Monterrey, Mexico, in which an attacker without prior operational technology expertise reportedly used commercial AI tools to access the organisation’s IT network and identify systems connected to its industrial environment.

Teo also referred to a December 2025 campaign targeting more than 30 wind and solar farms and other industrial facilities in Poland. Electricity generation was not disrupted, but the incident demonstrated the potential for coordinated attacks across multiple operational technology sites.

Under the ‘lockdown’ priority, the Cyber Security Agency of Singapore is releasing an updated Cybersecurity Code of Practice for owners of critical information infrastructure.

The code will place greater emphasis on continuous monitoring, incident detection, response and recovery, with boards and senior management directly accountable for cyber resilience.

CSA also plans to introduce a separate code later in 2026 for critical systems hosted in cloud environments.

To ‘find first’, the agency has launched a sandbox to pilot AI-enabled security operations across critical infrastructure and to share lessons with the wider cybersecurity community.

The ‘fix fast’ priority will focus on faster vulnerability prioritisation, automation and practical mitigation where systems cannot be immediately patched.

CSA is also renewing its agreement with the industrial cybersecurity company Dragos to deepen threat intelligence sharing and jointly develop defensive capabilities.

Why does it matter?

AI could make attacks on operational technology faster and more accessible to people without specialist industrial knowledge, increasing risks to telecommunications, energy, water and other essential services. Singapore’s response combines regulatory expectations, board-level accountability, AI-assisted security testing and intelligence sharing, reflecting the need to strengthen the entire critical infrastructure ecosystem rather than relying only on individual operators.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Zambia and South Sudan tighten cybercrime laws amid free speech concerns

Zambia and South Sudan have stepped up enforcement of cybercrime laws amid concerns over their potential effects on privacy, journalism and freedom of expression.

Zambia’s government has reminded citizens and public officials that the Cyber Crimes Act No. 4 of 2025 remains fully operational, warning against the unauthorised recording and circulation of private communications.

The law, which entered into force in May 2025, makes it an offence to record a private conversation without notifying the participants.

Exceptions include unintentional recordings, certain law-enforcement situations and cases where recording is reasonably necessary to protect the lawful interests of a party to the conversation.

The renewed enforcement focus follows the detention of a Zambian journalist accused of recording and publishing audio from a private meeting. Press freedom advocates argue that the material is a matter of public interest.

South Sudan has meanwhile begun coordinated implementation of its Cybercrime and Computer Misuse Act, 2026, after President Salva Kiir instructed government institutions to enforce the legislation.

Authorities say the law will strengthen cybersecurity, protect critical infrastructure and address offences including hacking, fraud, identity-related crimes and cyber harassment.

Civil society and media rights groups have raised concerns about provisions covering ‘undesirable content’ and ‘false or misleading information’.

Critics warn that broadly worded offences could be used against journalists, political opponents and people expressing legitimate criticism online, particularly without independent oversight and clear enforcement guidelines.

Why does it matter?

The two cases demonstrate the tension between tackling genuine cybercrime and protecting fundamental rights online. Broad offences covering private communications, reputational harm and vaguely defined harmful content may create legal uncertainty for journalists, whistleblowers and ordinary users, especially when enforcement powers lack clear public-interest safeguards and independent oversight.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Kenya restricts presidential website after cybersecurity incident

Kenya temporarily restricted access to the President’s official website after detecting a cybersecurity incident, the Ministry of Information, Communications and the Digital Economy announced.

The ICT Authority activated its established incident response procedures after reports of the attack. Access to the website was restricted as a precaution to support containment, forensic analysis and restoration.

The ministry said mitigation measures had already been implemented and work to restore the website was underway. Officials added that there was no evidence of unauthorised access to sensitive data, data exfiltration or information loss, and that other government systems and digital services remained secure and operational.

The ICT Authority of Kenya is continuing to work with government agencies and technical partners to investigate the incident and determine its full scope and cause.

Why does it matter?

Government websites are high-profile targets because they provide official public information and can influence trust in state institutions even when no sensitive systems are compromised. Temporary restrictions and forensic investigations are standard measures that help contain potential threats while authorities assess the scope of an incident.

The case also highlights the importance of transparent incident reporting. Confirming what was, and was not, affected can help maintain public confidence while allowing investigators time to establish the cause and strengthen future cyber resilience.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Researchers demonstrate prompt injection attacks on Gemini

Kaspersky security researchers have demonstrated new attack techniques that could manipulate Google’s Gemini AI assistant into performing unauthorised actions via prompt injection. The study found that malicious instructions hidden in calendar invites, emails or text messages could bypass safeguards by exploiting how large language models process information.

According to the research, attackers could combine indirect prompt injection, memory poisoning and delayed execution to influence Gemini’s behaviour. Potential outcomes include sending emails, launching applications, controlling compatible smart home devices, displaying false information or embedding malicious instructions into the assistant’s long-term memory, provided the user has granted the necessary permissions.

Researchers also warned that smartphones significantly expand the potential attack surface because Gemini can access notifications containing SMS messages, instant messages and social media alerts. Although Google has addressed the specific vulnerabilities identified in the research, the report argues that prompt injection remains a fundamental challenge for AI systems and that new attack methods are likely to emerge.

The researchers recommend reducing Gemini’s access to notifications, connected apps and system functions where possible, turning off unnecessary AI features and limiting permissions to minimise the impact of future attacks. They also advise users to review AI assistant settings regularly as security protections continue to evolve.

Why does it matter?

Prompt injection represents a major challenge for AI security because it targets how large language models interpret and prioritise information. As AI assistants gain broader access to personal data and connected devices, stronger safeguards will be needed to reduce potential risks.

The research highlights the importance of developing more robust AI security frameworks, including improved permission management and continuous testing, to ensure reliable and responsible adoption of AI technologies.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Ofcom finalises tougher rules against mobile messaging scams

Ofcom has finalised new rules requiring mobile providers to block, limit and disrupt mobile messaging scams, alongside strengthened guidance to tackle international calls that spoof UK mobile numbers.

The regulator said criminals increasingly use text messages and business messaging services to impersonate friends, companies and public bodies, pressuring victims to transfer money, disclose sensitive information or click malicious links.

Fraud accounted for an estimated 45% of reported crime incidents in England and Wales, with £1.28 billion lost to criminals in 2025. Ofcom also found that 40% of UK mobile users had received at least one suspicious message during the previous three months.

The measures target two main forms of messaging fraud: person-to-person messages sent through SIM cards and mass business messages distributed through commercial messaging infrastructure.

For person-to-person scams, mobile providers must collect intelligence on fraudulent messages, malicious links and phone numbers from customers and anti-fraud organisations. They must use that information to block numbers associated with scammers and stop messages containing malicious links or phone numbers from being delivered across their networks.

Providers must also impose volume limits on pay-as-you-go SIM cards, making it harder for criminal groups to send large numbers of fraudulent messages. The measures complement the government’s proposed ban on SIM farms and commitments made by operators under the Fraud Sector Charter.

Business messaging providers and aggregators must carry out initial and ongoing Know Your Customer (KYC) checks on organisations sending messages and monitor their activity through Know Your Traffic controls.

Providers will also verify alphanumeric sender IDs, which display company names instead of telephone numbers. The checks are intended to prevent scammers from impersonating trusted businesses, delivery services and government agencies.

Where providers identify fraudulent messaging activity, they must investigate its source, apply incident management procedures, and block malicious sender IDs, links and telephone numbers. Companies that fail to carry out appropriate checks may also face regulatory action.

Ofcom has separately strengthened its guidance on international calls that spoof UK mobile numbers. Telecoms companies should withhold the caller ID for calls that appear to originate from a UK mobile number roaming abroad unless they can verify that the number is genuine.

The regulator said spoofing makes overseas calls appear more trustworthy and increases the likelihood that potential victims will answer. However, it cautioned that legitimate organisations may also use withheld numbers, meaning users should continue to assess unexpected calls carefully.

Mobile providers already block more than 600 million suspected scam messages each year, but Ofcom said inconsistent protections across the sector continue to leave consumers exposed.

Consumers can report suspicious calls and messages by forwarding them to 7726, enabling mobile operators to update their fraud-detection and network-protection systems.

Why does it matter?

The new rules shift greater responsibility onto mobile providers to prevent scams before they reach consumers. By requiring stronger customer verification, sender authentication, network-level filtering and SIM controls, Ofcom is moving fraud prevention further upstream rather than relying primarily on users to recognise suspicious messages.

The measures also reflect a broader regulatory trend towards placing more accountability on communications providers to combat digital fraud. If successful, the framework could reduce large-scale messaging scams while serving as a model for other jurisdictions seeking to strengthen telecoms security.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Spain promotes national cybersecurity support helpline

Spain’s National Cybersecurity Institute (INCIBE) has highlighted its free and confidential 017 helpline, which provides specialist advice on digital security issues for citizens, businesses, professionals and educational institutions.

The helpline provides guidance on scams, phishing, identity theft, compromised accounts, social media privacy, cyberbullying, device security and protecting personal information. It also advises on parental controls, online child safety, digital identity management and the safe use of apps and social media platforms.

INCIBE stressed that 017 is a cybersecurity advisory service rather than a reporting channel or technical support line. Specialists explain appropriate reporting procedures, direct users to the relevant authorities where necessary and assess each case individually.

The service is available daily from 8:00 to 23:00 via telephone, WhatsApp, Telegram, an online form and, by appointment, in person at INCIBE’s headquarters in León.

Why does it matter?

As cyber threats become more common, many users need trusted advice before or after an incident rather than only technical assistance or law enforcement support. Services such as INCIBE’s 017 helpline can help individuals and organisations respond more effectively while improving awareness of everyday cyber risks.

The initiative also reflects a broader shift towards strengthening national cyber resilience through public support services. By combining technical, legal and practical guidance in a single point of contact, governments can encourage earlier reporting, better cyber hygiene and more effective responses to digital security incidents.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

AI is beginning to carry out live cyberattacks, Check Point warns

AI is moving beyond assisting cybercriminals to carrying out operational tasks during live intrusions, according to Check Point Research’s Annual AI Security Report 2026.

The report argues that AI-enabled cyber operations are entering a new phase in which AI systems can execute parts of an attack rather than simply helping attackers write code, research targets or prepare phishing campaigns. The shift could make cyber operations faster and less dependent on continuous human oversight.

Check Point said it observed AI carrying out hands-on tasks during incidents ranging from China-linked campaigns to a criminal breach affecting several Mexican government agencies. According to the company, these capabilities are spreading beyond state-backed actors to financially motivated cybercriminals.

AI is also being used to create deployment-ready malware and offensive frameworks. One developer reportedly used an AI coding environment to build VoidLink, an 88,000-line command-and-control framework, in less than a week. Check Point noted that AI involvement may be difficult to identify once the finished tool is deployed.

According to the report, attackers increasingly favour commercial AI models over self-hosted alternatives. Rather than relying solely on jailbreak prompts, some are targeting agentic architectures by planting configuration files that AI agents continue to trust across multiple sessions.

The market supporting AI cyberattacks is also becoming more established. Check Point identified phishing-as-a-service products that embed language models with built-in restrictions bypasses, alongside conversational voice-agent services used for vishing and one-time-password theft.

The report warns that synthetic identities are weakening traditional trust signals. Convincing imitations of voices, faces, identity documents, and live video can now be combined across multiple channels, making social engineering operations more coordinated and harder to detect.

AI systems themselves are also emerging as an important attack surface. Models may struggle to distinguish instructions from the content they process, allowing attackers to manipulate AI agents through malicious files, webpages and other external data sources.

Indirect prompt injection is emerging as one of the most important threats to AI systems. Check Point said detections of longer malicious payloads increased roughly fivefold between March and May 2026, reaching close to 1% of observed prompts. Longer payloads are commonly associated with content-based and agentic attack paths.

Enterprise data leakage through generative AI also remains a growing concern. The share of prompts classified as high risk doubled from 2% to 4% over the previous year, while organisations used an average of ten AI applications each month, including tools that had not received official approval.

Exposure varied considerably by sector. Business services recorded the highest rate of high-risk generative AI prompts, at 5.91%, meaning approximately one in every 17 interactions presented a significant risk of exposing sensitive information.

The findings suggest organisations must prepare for threats from two directions: adversaries using AI to automate cyber operations and employees or AI systems exposing sensitive data through insecure adoption.

Why does it matter?

The report suggests AI is reshaping cybersecurity on both sides of the equation. Attackers are increasingly using AI to automate complex tasks, while organisations adopting AI are creating new attack surfaces and data security risks.

As AI systems become more autonomous, cybersecurity strategies will need to extend beyond traditional endpoint and network protection to include AI agents, model security, prompt injection defences, identity verification and governance over how AI is deployed across the enterprise.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

MIT develops safer way to detect harmful AI models

MIT researchers have developed a new auditing method to detect whether generative AI models have been adapted to produce child sexual abuse material without generating illegal content during testing.

The technique was developed with Thorn, a child safety nonprofit focused on protecting children from sexual abuse and exploitation online.

Traditional AI safety testing often involves prompting a model and checking its outputs, but that approach cannot be used for child sexual abuse material, which is illegal to generate in the US and many other jurisdictions.

MIT said the problem has become more urgent as open-source generative AI models become easier to download, adapt and redistribute.

The researchers’ method examines internal changes during fine-tuning, rather than testing the model by generating images.

In tests, the auditing procedure identified model variants adapted to generate child sexual abuse material with 100% accuracy.

MIT said hosting platforms could use the method to flag unsafe models, block uploads or remove harmful adaptations before they spread more widely online.

The researchers also plan to test whether the approach can detect harmful capabilities in a larger set of model variants and in base models before adaptation.

Why does it matter?

The research addresses a serious AI safety blind spot: some harmful model capabilities cannot be tested safely or legally by generating outputs. A non-generative auditing method could give hosting platforms, auditors and law enforcement a safer way to detect models adapted for child sexual abuse material before they are distributed. It also points to a broader governance challenge around open-source generative AI: platforms may need scalable tools to assess harmful adaptations without exposing reviewers to illegal or traumatic content.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Cybercrime accounts for one in five crimes in Spain

Spain recorded 488,426 cybercrimes in 2025, accounting for 19.8% of all reported crime, according to the Spanish Ministry of Interior’s latest Cybercrime Report. The figure shows a 5.1% increase from 2024, demonstrating the growing threat of digital crime nationwide.

Computer fraud and online scams continued to dominate cybercrime, accounting for nearly nine in ten reported offences with 429,677 cases. Internet-related forgery increased by 11.3% to 21,690 cases, while sexual offences rose by 21% and illegal access or interception offences surged by 40.7%, highlighting the growing diversity of cybercriminal activity.

The number of cybercrime victims reached 383,285, up 9.3% from 2024. People aged 51 to 65 were the most frequently targeted, particularly through credit card fraud and travel cheque scams, accounting for 146,737 victims. Although most victims were male, the types of cybercrime varied considerably across age groups and demographics.

Critical infrastructure operators experienced 90 cyberattacks in 2025, a 43.8% decrease from the previous year. The transport sector accounted for 42.2% of incidents, followed by the information and communications technology sector with 15.5%.

Why does it matter?

The report shows that cybercrime has become a mainstream form of criminal activity, accounting for nearly one in five reported offences in Spain. The continued growth in fraud, online scams and unauthorised access highlights how digital crime is evolving alongside greater reliance on online services by individuals, businesses and public institutions.

Although attacks on critical infrastructure declined, the overall increase in cybercrime and victim numbers suggests that law enforcement and cybersecurity authorities will need stronger investigative capabilities, cross-border cooperation and preventive measures to keep pace with increasingly sophisticated digital threats.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot