A new report from Mandiant indicates that 70% of 2023's total of 138 exploited vulnerabilities were zero-days when first used, with the average time-to-exploit (TTE) dropping drastically from 32 days to just five.
The SolarWinds hackers (thought to be backed by Russian intelligence) are up to their old tricks with new cloud providers, and have reportedly already breached a number of companies.
Manpower has confirmed a significant data breach affecting one of its independent franchises after a prolific ransomware threat group claimed to have exfiltrated the entire company’s data.
Tinder, Grindr and OKCupid were among the dating apps found to funnel sensitive personal data like gender, age, IP address and GPS location to major advertising and behavior analytics platforms.
Many of the most popular iPhone apps are, without user privacy consent, using “session replay” technology that makes it possible to record their every touch, tap or swipe.
Privacy lawsuit that is attempting to hold Facebook liable for the Cambridge Analytica breach has attached CEO Mark Zuckerberg as a defendant, claiming that he played a key role in decisions.
In the case of the Cambridge Analytica scandal, the lawsuit asserts that Zuckerberg personally oversaw the engineering work that ultimately led to the exposure of Facebook user data.
Marks & Spencer shut down its systems after experiencing an apparent ransomware cyber incident that disrupted order collections and contactless payment.
The sensitive personal and financial information of 672,075 people was compromised during the August 2025 Marquis cyberattack, which was previously misattributed to a Russian ransomware gang.
The 2018 Marriott data breach was one of the biggest of its type in history, and was initially looking at receiving one of the biggest fines of £99 million. However, the UK ICO has reduced the penalty to £18.4 million.










