Supreme Court weighs TikTok ban amid national security concerns

The US Supreme Court on Friday appeared inclined to uphold a law requiring a sale or ban of TikTok in the United States by January 19, citing national security risks tied to its Chinese parent company, ByteDance. Justices questioned TikTok’s potential role in enabling the Chinese government to collect data on its 170 million American users and influence public opinion covertly. Chief Justice John Roberts and others expressed concerns about China’s potential to exploit the platform, while also probing implications for free speech protections under the First Amendment.

The law, passed with bipartisan support and signed by outgoing President Joe Biden, has been challenged by TikTok, ByteDance, and app users who argue it infringes on free speech. TikTok’s lawyer, Noel Francisco, warned that without a resolution or extension by President-elect Donald Trump, the platform would likely shut down on January 19. Francisco emphasised TikTok’s role as a key platform for expression and called for at least a temporary halt to the law.

Liberal and conservative justices alike acknowledged the tension between national security and constitutional rights. Justice Elena Kagan raised historical parallels to Cold War-era restrictions, while Justice Brett Kavanaugh highlighted the long-term risks of data collection. Solicitor General Elizabeth Prelogar, representing the Biden administration, argued that TikTok’s foreign ownership poses a grave threat, enabling covert manipulation and espionage. She defended Congress’s right to act in the interest of national security.

With global trade tensions and fears of digital surveillance mounting, the Supreme Court’s decision will have wide-ranging implications for technology, free speech, and US-China relations. The court is now considering whether to grant a temporary stay, providing Trump’s incoming administration an opportunity to address the issue politically.

Biden pushes for stronger cybersecurity standards in final days of presidency

President Joe Biden is preparing to introduce a new executive order aimed at strengthening cybersecurity standards for federal agencies and contractors. The proposed measures address growing threats from Chinese-linked cyber operations and criminal cyberattacks, which have targeted critical infrastructure, government emails, and major telecom firms. Under the draft order, contractors must adhere to stricter secure software development practices and provide documentation to be verified by the Cybersecurity and Infrastructure Security Agency (CISA).

The order highlights vulnerabilities exposed by recent cyber incidents, including the May 2023 breach of US government email accounts, attributed to Chinese hackers. New guidelines will also focus on securing access tokens and cryptographic keys, which were exploited during the attack. Contractors whose security practices fail to meet standards may face legal consequences, with referrals to the attorney general for further action.

While experts like Tom Kellermann of Contrast Security support the initiative, some criticise the timeline as insufficient given the immediate threats posed by adversaries like China and Russia. Brandon Wales of SentinelOne views the order as a continuation of efforts across the past two administrations, emphasising the need to enhance existing cybersecurity frameworks while addressing a broad range of threats.

The order underscores Biden’s commitment to cybersecurity as a pressing national security issue. It comes amid escalating concerns about foreign cyber operations and aims to solidify protections for critical US systems before the transition to new leadership.

Mudrex pauses crypto withdrawals until 28 January

Indian cryptocurrency exchange Mudrex has temporarily suspended crypto withdrawals, prompting a backlash from its users. The move, announced on 11 January is set to last until 28 January as the platform undergoes a compliance framework upgrade. According to co-founder and CEO Edul Patel, the suspension is necessary to prevent misuse by bad actors, with Patel emphasising the importance of a secure infrastructure in the crypto space.

Mudrex, one of the few Indian exchanges to allow crypto withdrawals, has faced criticism from the community. Trader Vivan Live urged users to withdraw their funds immediately, suggesting the platform’s motives were dubious. Another user, Aakash Athawasya, claimed that Mudrex never truly offered crypto withdrawals, accusing the platform of offering “price exposure” instead of ownership. Despite the criticism, Mudrex reported a significant surge in its user base and trading volume in recent months.

Meanwhile, India’s regulatory environment continues to impact exchanges, with Bybit announcing a temporary suspension of its services in the country due to evolving regulations. On a more positive note, CoinDCX, another Indian exchange, has launched crypto withdrawals, allowing users to withdraw crypto in exchange for disabling Indian rupee deposits.

Thai police seize nearly 1000 Bitcoin mining rigs

Authorities in Thailand have confiscated 996 Bitcoin mining rigs in Chon Buri province, accusing operators of illegally tapping into the power grid. The raid, conducted on 8 January in the Phanat Nikhom district, targeted JIT Co., a digital asset trading firm that allegedly tampered with power meters to avoid electricity charges. Losses to local providers are estimated in the hundreds of millions of baht.

Despite solar panels being present on the site, investigators revealed they were not connected to the equipment, which relies on immense computing power to mine Bitcoin. Thai officials highlighted the heavy energy demands of mining, which can cost hundreds of thousands of baht per Bitcoin, compared to the typical household electricity bill of 750 baht.

The case underscores the growing global challenge of managing crypto mining’s resource demands. Thai regulators reiterated the need to safeguard public utilities as they continue investigating the scheme and identifying additional parties involved.

Brazil’s Lula criticises Meta’s move to end US fact-checking program

Brazilian President Luiz Inácio Lula da Silva has condemned Meta’s decision to discontinue its fact-checking program in the United States, calling it a grave issue. Speaking in Brasília on Thursday, Lula emphasised the need for accountability in digital communication, equating its responsibilities to those of traditional media. He announced plans to meet with government officials to discuss the matter.

Meta’s recent decision has prompted Brazilian prosecutors to seek clarification on whether the changes will affect the country. The company has been given 30 days to respond as part of an ongoing investigation into how social media platforms address misinformation and online violence in Brazil.

Justice Alexandre de Moraes of Brazil’s Supreme Court, known for his strict oversight of tech companies, reiterated that social media firms must adhere to Brazilian laws to continue operating in the country. Last year, he temporarily suspended X (formerly Twitter) over non-compliance with local regulations.

Meta has so far declined to comment on the matter in Brazil, fueling concerns over its commitment to tackling misinformation globally. The outcome of Brazil’s inquiry could have broader implications for how tech firms balance local laws with global policy changes.

Dragos partners with Singapore DIS to enhance national cybersecurity infrastructure

Dragos and Singapore’s Digital and Intelligence Service (DIS) are collaborating to enhance cybersecurity capabilities through a strategic partnership focusing on planning, training, and exchanging information about cyber threats. The agreement, announced during the Critical Infrastructure Defence Exercise (CIDeX) 2024, aims to fortify the defence of Singapore’s critical infrastructure and increase its resilience to cyber attacks.

The partnership builds on Dragos’s long-standing collaboration with Singapore, including a previous agreement in August 2023 with the Cyber Security Agency (CSA) to improve operational technology (OT) cybersecurity. DIS emphasised the importance of expanding cybersecurity partnerships across sectors, while Dragos commended Singapore’s proactive approach to cybersecurity as an example for other nations to follow.

That partnership underscores the shared commitment of both parties to secure critical infrastructure amid an evolving cyber threat landscape. By leveraging their expertise, Dragos and DIS aim to provide Singapore with the necessary tools and knowledge to navigate emerging challenges, ensuring the protection of its infrastructure and citizens.

Hong Kong advances towards global digital transformation leadership with strategic partnerships and initiatives

Hong Kong is advancing its digital economy and smart city initiatives, striving to become a global leader in digital transformation. To support this vision, the Hong Kong Institute of Information Technology (HKIIT) and the Office of the Government Chief Information Officer (OGCIO) have partnered to enhance digital literacy, strengthen cybersecurity, and promote digital transformation in public and government sectors.

The collaboration focuses on specialised training programs covering emerging technologies, cybersecurity, and data analytics to equip public sector employees and industry professionals with critical skills. Practical exercises like real-world cybersecurity simulations aim to improve awareness and resilience against cyber threats. Additionally, data literacy training is prioritised to help public employees utilise data for decision-making and service improvement, aligning with Hong Kong’s goals of innovation and efficiency.

Beyond training, community events like competitions and seminars promote digital awareness, fostering a culture of innovation and collaboration. The initiative builds on prior efforts, such as the ‘Cyber Security Drill 2024’ and certification programs, while future plans aim to expand its reach across more government departments and organisations.

The Vocational Training Council (VTC), Hong Kong’s largest provider of vocational and professional education, plays a key role in these efforts by supporting the city’s innovation agenda and equipping individuals with the skills needed to succeed in a rapidly evolving digital landscape. Through partnerships like the one with OGCIO, VTC institutions such as HKIIT contribute to strengthening the city’s workforce and ensuring its readiness for the challenges of digital transformation.

British universities abandon X over misinformation concerns

British universities are increasingly distancing themselves from Elon Musk’s X platform, citing its role in spreading misinformation and inciting racial unrest. A Reuters survey found that several institutions have stopped posting or significantly reduced their activity, joining a broader exodus of academics and public bodies. Concerns over falling engagement, violent content, and the platform’s perceived toxicity have driven the shift.

The University of Cambridge has seen at least seven of its colleges stop posting, while Oxford’s Merton College has deleted its account entirely. Institutions such as the University of East Anglia and London Metropolitan University report dwindling engagement, while arts conservatoires like Trinity Lab and the Royal Northern College of Music are focusing their communication efforts elsewhere. Some universities, including Buckinghamshire New University, have publicly stated that X is no longer a suitable space for meaningful discussion.

The retreat from X follows similar moves by British police forces, reflecting growing unease among public institutions. Despite the trend, some universities continue to maintain a presence on the platform, though many are actively exploring alternatives. X did not respond to requests for comment on the issue.

AT&T launches outage compensation scheme to regain customer trust

AT&T has introduced a new initiative offering bill credits to customers affected by network outages, aiming to rebuild trust after a series of major service disruptions in 2024. The scheme, called AT&T Guarantee, will provide automatic credits to fibre customers experiencing outages of 20 minutes or more and wireless users facing at least an hour of disruption. The move follows a nationwide service failure last February, which lasted over 12 hours and blocked millions of calls, including thousands of emergency calls to 911.

The telecom industry has faced growing scrutiny over the reliability of its networks, with rivals such as T-Mobile and Verizon also experiencing significant outages. AT&T executives acknowledged that customer dissatisfaction had led to market share losses in recent years. In response, the company has invested over $140 billion in network improvements and nearly $1 billion in customer care and operations. The new guarantee is part of a broader effort to ensure dependable connectivity and restore consumer confidence.

Despite previous challenges, AT&T has maintained strong performance in customer satisfaction rankings, topping J.D. Power’s survey for business wireless service among large enterprises for three consecutive years until 2023. The company believes the new initiative will strengthen its position in the market by demonstrating a commitment to service reliability and customer compensation when expectations are not met.

Hacker claims breach at Gravy Analytics data firm

A hacker claims to have breached US location tracking company Gravy Analytics, leaking around 1.4 gigabytes of data. The allegation, shared on a Russian-language cybercriminal forum, included screenshots suggesting a data theft. Verification attempts were complicated as Gravy’s website remained offline and the company did not respond to messages.

Cybersecurity experts reviewing the leaked data found the breach credible. Marley Smith from RedSense and John Hammond from Huntress both confirmed the data appeared legitimate, though the hacker’s identity remains unclear.

Gravy was previously involved in a crackdown by President Biden’s administration targeting data brokers collecting sensitive location data without proper consent. The Federal Trade Commission (FTC) settled with Gravy and Mobilewalla in December over allegations of deceptive data practices.

The FTC expressed concerns that such data could be misused for stalking, blackmail, and espionage but declined to comment on the breach. FTC Chair Lina Khan recently warned that targeted advertising practices leave sensitive data highly vulnerable.