noyb has leaked documents that show Facebook approached the EDPB with their concept of “user contracts” that sidestep GDPR rules for user consent after numerous receptive meetings with the Irish DPC.
Botnet discovered by Chinese researchers introduced a backdoor and a web shell on compromised AT&T VoIP servers, mostly in the US, for DDoS attacks and data exfiltration.
Colorado Energy Company, Delta-Montrose Electric Association (DMEA), suffered a malicious cyber attack that shut down 90% of its internal controls and wiped 25 years of historical data.
A new survey reveals deepening frustration with legacy IT vendors such as Microsoft, as supply chain attacks and ransomware attacks fed by vulnerabilities in their software become the "new normal.”
DNA testing firm said the data breach exposed personal and financial data of 2.1 million people, and hackers removed some files from the national genetic testing organization system database.
The narrative around NSO Group's Pegasus spyware thus far has been one of authoritarian governments using it to suppress internal criticism. The story may be shifting to one of international espionage with US State Department iPhones hacked by it.
The SolarWinds hackers (thought to be backed by Russian intelligence) are up to their old tricks with new cloud providers, and have reportedly already breached a number of companies.
Lloyd’s of London has issued a bulletin indicating that its cyber insurance products will no longer cover the fallout of cyber attacks exchanged between nation-states. This definition extends to operations that have "major detrimental impact on the functioning of a state."
Facebook is expanding mandatory two-factor authentication for users flagged as having high-risk accounts and will eventually be locked out of the platform until they enable it.
Google's new Cybersecurity Action Team warned that cybercriminals compromised unsecured or misconfigured Google Cloud instances to perform cryptocurrency mining.










