Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
Proposed EU Cyber Resilience Act includes a vulnerability disclosure requirement that would have all manufacturers report to the government within 24 hours of first discovered exploitation. In most cases, this would mean disclosing before the vulnerability has been mitigated.
The FTC has found that not only has Facebook not fully complied with its obligations, but that it has also been in violation of children's privacy regulations with its Messenger Kids app.
A new record for GDPR fines has been set as the European Data Protection Board (EDPB) is requiring Meta to pay $1.3 billion for its international data transfers related to the dissolution of the Privacy Shield framework.
The long-running Qakbot malware botnet was disrupted by international law enforcement action in August, but its operators appear to still have some capability and are continuing to run spam email campaigns that attempt to pass ransomware.
Dell Technologies is notifying customers of a preventable data breach that exposed their personal information via a poorly protected application programming interface (API). The notification follows a recent BreachForum post by a threat actor auctioning the stolen data, allegedly belonging to 49 million customers.
The stolen API key allows interaction with at least 52 large language AI models (LLMs) that are in development at Musk's xAI, many of these in turn used by the "Grok" AI available through the X social media platform. An errant GitHub update was to blame.
New report shows nearly 75 percent of U.S. federal agencies are still woefully unprepared and deemed to be “at risk” or “at high risk” of a cyber attack.
Hong Kong-based Mixin Networks, a decentralized exchange and cross-chain transfer network, was temporarily forced to suspend operations following a hack of its cloud database. The crypto company is offering a $20 million bug bounty for full return of the stolen funds.
U.S. Department of Defense requires all defense contractors to complete a cybersecurity certification before submitting proposals by 2026, starting with higher-level contractors this June.










