A security flaw in “Claude in Chrome” enables any Chrome extension, including those without permissions, to execute privileged commands, steal data, and perform agentic actions.
51 top CEOs from companies such as Amazon, IBM, Dell and JP Morgan Chase are pushing for new federal privacy legislation to establish a stable privacy policy environment.
The investment research firm’s first disclosed data breach took place between November 2021 and August 2022, and a notification on January 25 of this year indicated that 820,000 customers were impacted. That number has now been revised to 8.8 million.
Facial recognition firm Clearview AI is facing a new lawsuit for violating Illinois state privacy laws for trawling public sources to vacuum up pictures of millions of people without consent.
A data breach affecting Madison Square Garden Sports and the New York Knicks has leaked the personal information of customers, celebrities, athletes, and their representatives.
Threat actors exploited Log4Shell vulnerability on unpatched VMware servers to gain access, move laterally, deploy malware, and exfiltrate sensitive information.
Facebook, Google and Netflix are facing fines and actions for privacy violations, with Facebook assessed the second-largest amount in the country's history for its treatment of facial recognition templates.
California once again takes the lead with new data privacy law. While tech companies are not delighted and will continue to fight, it is still a better alternative to the November ballot which would have been more problematic.
Lenovo’s Lena is a fairly standard AI chatbot of the type seen at some company websites, offering to retrieve product information and answer customer service questions for visitors. What is different about this one is the relative ease with which it could be recruited for highly damaging actions.
Octo Tempest has gradually stepped up from data theft, to data extortion, and now to ransomware as of this summer (becoming an affiliate of the ALPHV/BlackCat group). The cybercriminals are entirely financially motivated and nearly always leads with either a phishing email/message or a social engineering call. It also looks to execute SIM swap attacks.










