More than half of organizations experienced a third-party data breach attributed to external privileged access, and subsequent lack of control, auditing, and monitoring.
Facial recognition firm Clearview AI is facing a new lawsuit for violating Illinois state privacy laws for trawling public sources to vacuum up pictures of millions of people without consent.
CISA directs federal agencies to adhere to the vulnerability management catalog and patch 300 exploited vulnerabilities assigned CVE IDs in 2021 within 2 weeks and 6 months for previous ones.
A threat actor listed on a hacker forum data belonging to over 17 companies containing over 34 million records. Victims include Eatigo and Alibaba-owned Lazada's RedMart online grocery.
Italy’s data protection authority has ruled that Google's data transfers to servers in the United States fall afoul of the rules of the GDPR, with the company not anonymizing IP addresses sufficiently.
Seiko has confirmed that the July 2023 data breach resulted from a ransomware attack and leaked personal information. BlackCat/ALPHV ransomware gang, took responsibility for the attack and claimed to have exfiltrated 2 TB of data.
Recent security breach at password manager LastPass does not appear to be an immediate threat to the encrypted vaults that customers use to store their passwords, but the hackers may have made off with source code and proprietary information.
Alibaba's web scraping data leak exposed over 1 billion user records leading to the imprisonment of the implicated software developer and his employer for three years.
US intelligence leak indicates that China is putting an emphasis on targeting enemy satellites in future conflicts. The country is bending its cyber capabilities toward disrupting and taking over communications and surveillance during whatever clashes might come.
Information from 3.68 million leaked user accounts of Mobifriends dating app allow hackers to exploit password reuse problem and unlock a lot more accounts.










