Theft of LastPass’s decrypted password vaults has been tracked to a DevOps engineer. Attackers reportedly targeted a vulnerability in a media software package on the employee's home computer.
Dole Food Company has confirmed a ransomware attack that disrupted regional operations. Leaked memo shows that production was temporarily halted in several plants and deliveries suspended.
For two weeks, a misconfigured email server on the Microsoft Azure government cloud exposed thousands of sensitive military emails from the U.S. Special Operations Command (USSOCOM) branch.
76% of ransomware attacks in 2022 were tied to a known vulnerability that was made public between 2010 and 2019, and old vulnerabilities that were discovered as far back as 2015 are still commonly exploited.
A supply chain attack on a business partner will cost semiconductor giant Applied Materials $250 million in the coming quarter due to disruption of upcoming shipments. Ransomware attack on MKS Instruments is suspected to be the cause.
Among the 116 proposals in the Privacy Act review are calls for safeguards similar to those provided by the EU's GDPR. Small businesses will likely be upset at seeing previously proposed exemptions wiped away, however.
The European Commission and the European Council, the two largest policy bodies in the EU, are the latest government entities to implement a TikTok ban for staff. This includes work devices and also personal devices enrolled in the body's mobile device service.
The central objection raised is a predictable one, and one that some analysts believe will inevitably cause the EU-US data transfer proposal to fail yet another court challenge if it makes it to implementation: the lack of a federal-level data privacy law in the US.
Hackers compromised the Namecheap email system to send DHL and MetaMask phishing emails targeting wallet credentials. The company takes full responsibility after initially blaming a third party.
Twitter cites abuse of the text messaging 2FA option by bad actors as the reason for the change in policy. The service will still allow free use of authentication apps or hardware security keys as an additional account security layer.









