• Cybersecurity Docket
  • Posts
  • Institute for Critical Infrastructure Technology Report Calls for Operational AI Security

Institute for Critical Infrastructure Technology Report Calls for Operational AI Security

Plus, new WilmerHale podcast series examines AI’s impact on the legal and organizational landscape.

Good morning! Here’s what’s up.

People

Chris Kercher has left Quinn Emanuel after a 17-year career at the law firm, where he founded its AI and Data Analytics group, to launch Kercher Law, a boutique “litigation practice built from the ground up for the AI era,” Kercher announced in a LinkedIn post.

Chris Fall, director of the Commerce Department’s Center for AI Standards and Innovation (CAISI) has resigned after three months in the role, a Commerce spokesperson confirmed to Axios, which first reported the resignation. Arvind Raman, who was recently sworn in as director of the National Institute of Standards and Technology, will serve as acting director in the interim, Axios reported. The spokesperson said the Commerce Department will announce a new director in the coming weeks.

Clips ✂️

ICIT report calls for operational AI security as compliance frameworks fail to keep pace with evolving AI threats

Artificial intelligence is being deployed at unprecedented speed across healthcare, finance, critical infrastructure, government and enterprise operations, but many organizations are relying on conventional cybersecurity controls, compliance certifications and governance frameworks that were not designed to secure AI systems, according to a new paper from the Institute for Critical Infrastructure Technology (ICIT).

The report, When Trust Has No Security, AI Risks Everything, warns that AI introduces new attack surfaces through prompts, language, images, retrieved content and semantic interactions, allowing adversaries to manipulate models in ways that can evade traditional security defenses.

The paper finds that compliance with frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF and PCI DSS does not eliminate AI-specific security exposure, while many AI governance programs lack protections for runtime risks such as prompt injection, semantic attacks and compromised agentic workflows.

by Industrial Cyber

AI In the Public Interest: The Risks Facing Boardrooms

In the Public Interest is excited to continue our “AI In the Public Interest” miniseries examining AI’s impact on the legal landscape and its broader implications for the day-to-day operations of organizations across industries.

With the wider prevalence of companies utilizing AI to assist in decision making and determine future frameworks, these conversations will not only take stock of the current state of AI but will also offer practical insights into what the future may hold.

The second episode features co-host Felicia Ellsworth in conversation with Partners Jessica Lewis and Josh Geltzer, along with President and CEO of EqualAI Miriam Vogel, on the increasing governance risk AI poses to boardrooms.

They discuss why AI regulation and enforcement is quickly being added to board agendas as a pressing emerging challenge. Additionally, they identify specific considerations boards are keeping in mind as they tackle mission-critical AI risks, shifts in oversight structures, the development of incident response escalation plans, and more.

by WilmerHale

👉Listen to Episode 1 of "AI In the Public Interest" here.

Quinn Emanuel Vet’s AI-Native Firm Zeros in on Litigators’ Value

The number of AI-native law firms is exploding, many of them founded by associates frustrated with Big Law’s pace on artificial intelligence. But partners are also leaving, drawn by AI’s potential to be what Cravath partner turned boutique founder Benjamin Gruenstein called a “force multiplier.”

The latest leading litigator to depart from a storied firm is Chris Kercher. After more than 17 years at Quinn Emanuel, where he represented clients such as Elon Musk and Ken Griffin, Kercher left to launch his own boutique, Kercher Law.

Why did Kercher leave Quinn Emanuel — one of the world’s most prestigious and profitable law firms — to hang a shingle?

The short version of his answer is AI. The long version rests on certain timeless aspects of law and the legal profession — which make Kercher confident that lawyers aren’t going anywhere.

by Bloomberg Law

White hat hacker Park Chan-am zeros in on the AI era’s key security challenges

Dubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years.

He has since served as a cybersecurity advisor for various Korean government agencies, including the National Police Agency, and has played a key role in the country’s defense against Democratic People’s Republic of Korea (DPRK)-affiliated cyberattacks.

At a seminar held this month as part of the 15th Information Security Day event hosted and organized by government agencies including the Ministry of Science and ICT and the Korea Internet and Security Agency (KISA), Park, now CEO of security firm Steelion, explained the changes in the security environment in the AI era and the priority response tasks for information security organizations under the theme of “Major AI Threats and Security Priorities.”

by CSO Online

Chick-fil-A discloses data breach after credential stuffing attacks

American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks.

The company revealed in data breach notification letters sent to affected individuals and filed with multiple Attorney General offices that it detected the attacks after identifying suspicious login activity to certain Chick-fil-A One accounts.

As Chick-fil-A discovered while investigating the incident, the attackers targeted Chick-fil-A's website and mobile app in June.

"Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source," it said. "Based on our investigation, we determined on July 13, 2026, that the unauthorized parties may have accessed information in your Chick-fil-A One account."

by Bleeping Computer

Gang claims responsibility for hack at Coca-Cola's fairlife unit

Hacking gang Anubis claimed credit on Tuesday for an attack on Coca-Cola-owned dairy company fairlife, threatening ‌to publish stolen data unless it received an unspecified ransom.

The group made the claim on its dark web site, saying it had stolen 1 terabyte of data from fairlife.

Chicago-based fairlife makes dairy products including protein shakes and filtered milk drinks. Coca-Cola said last week that production at fairlife's U.S. facilities was temporarily suspended after a hack.

Anubis is one of ‌many ⁠cybercriminal gangs that paralyze their victims' networks until a ransom is paid, a practice that can occasionally have dramatic knock-on effects if critical networks are hit. ⁠Hackers typically threaten to publish stolen data in a bid to pressure their victims.

Anubis' operations have a particularly ⁠disruptive edge to them, according to an analysis published last year by cybersecurity firm Trend ⁠Micro, which cited the group's use of file wiping software.

by Reuters

X