Though it did not suffer a security breach, PayPal is reporting that a massive credential stuffing attack appears to have yielded access to about 35,000 PayPal accounts.
ODIN Intelligence, a law enforcement technology vendor, has experienced a chain of security incidents as of late including a defaced website (and possibly much worse). Company had already been a magnet for controversy over some of its more privacy-invasive products.
A third-party data breach involving a U.S. contractor exposed the personal information of over 2 million Aflac cancer and Zurich automobile insurance policyholders in Japan.
French regulator CNIL found that the tiktok.com website, which allows users to view content via a web browser without logging in, did not have an adequate process for cookie consent.
privacy lawsuit claims to have tested what Apple apps "phone home" with and found that it seemingly makes no difference what the user chooses in terms of analytics data permissions.
An established cybercrime gang leaked sensitive data, including unredacted child abuse files, after a ransomware attack on San Francisco Bay Area Rapid Transit Police department.
Security researchers had matched email addresses to account names, providing an indication that the data leak was legitimate, but Twitter says that the data was gathered via a variety of publicly available sources.
Royal Mail Group warned of disruptions in international export services and stopped accepting parcels for international delivery after a LockBit “cyber incident” caused severe disruption to export services.
The FCC launched a proceeding to strengthen data breach notification regulations for telecommunications companies to ensure faster reporting and to harmonize federal rules with states and other sectors.
Surveyed organizations reporting a 61% drop in ransomware attacks but the average cost of ransomware attacks remains high, even as study shows increasing complacency among organizations in keeping vital safety measures in place.










