Biometric privacy lawsuit names Amazon, Google parent company Alphabet and Microsoft as violators of BIPA for their use of IBM's facial recognition database to train their own facial recognition systems.
Study from HP reveals that nation-state cyber attacks have not only doubled since 2017, but are also increasingly incorporating attacks on physical assets (such as infrastructure).
Outgoing UK Information Commissioner Elizabeth Denham has suggested a shift in focus from individual cookie popups at each website to regulation of browsers and devices as the source of expressing user tracking preferences.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.
Massive data leak (handed over to German business newspaper Handelsblatt) reportedly contains troves of customer payment information, employee personal information, and customer safety complaints about the automated driving functions of Tesla vehicles.
The malware that the researchers were able to coax out of DeepSeek was rudimentary and required some manual code editing to make it functional. But the incident demonstrates that the guardrails preventing malicious behavior in generative AI systems remain thin.
The Austrian data protection authority has found that the IP addresses and identifiers in Google Analytics cookie data were sufficiently personal to constitute a GDPR violation for purposes of transfer to the US.
The campaign was conducted by malicious hackers who sold the stolen credentials off, with much of the info being put to use in spam and phishing campaigns. The attack simply made use of open-source tools to scan IP ranges for potentially vulnerable Git config files.
The EU and US have reached an agreement in principle on a Privacy Shield replacement, but details of the data transfer deal are not yet available to the public.
The White House has launched the Cyber Trust Mark labeling program for connected devices to assist consumers in determining whether IoT products are cyber secure.









