While API security remains a major concern for most organizations, most were unprepared, with only 11% having a concrete API security strategy to detect and stop API attacks.
Supply chain vulnerability in the ThroughTek "Kalay" network, a cloud-based communications platform used by an estimated 83 million IoT devices, could allow for remote compromise and control.
The Irish DPC probe centers on an API vulnerability that appears to have been exploited by multiple parties before being detected and remediated. The data breach first came to light in August and was acknowledged by Twitter.
Following closely on the heels of the introduction of new tools designed to provide safety enhancements to WhatsApp users, Meta has announced that it has taken 6.8 million scam accounts off the platform in the first half of 2025.
Chick-fil-A Hit With Privacy Lawsuit Over Data Collection Embedded in Viral Video Marketing Campaign
Privacy lawsuit alleges that by embedding the Meta pixel on pages hosting its videos, Chick-fil-A violated the 1988 Video Privacy Protection Act (VPPA) which applies only to data collection of personally identifiable information when viewing videos.
An April data breach of prescription provider MediSecure has been confirmed to have exposed about 12.9 million records, making it one of the largest in Australian history.
Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
YouTube’s new privacy rules to meet COPPA compliance will require YouTuber to assign each new piece of content on the platform as being ‘for children’ or ‘not for children’.
WK Kellogg Confirms Data Breach from Cleo Managed File Transfer System Attributed to Clop Ransomware
U.S. food giant WK Kellogg Co. has disclosed a data breach that affected Cleo, a third-party managed file transfer system that allowed a threat actor to access sensitive information.
Known for their cyber crime product which infected over 41,000 victims in financial institutions, GozNym is going out of business with their key figures across Eastern Europe charged by U.S. federal court.










