The UK is now firming up what its data handling and privacy rules will look like post-Brexit. The lead item is an announcement of partnerships with countries that have lost "trusted partner" status in the EU, most notably the United States.
Last week's White House cybersecurity summit was the Biden administration's first formal public-private meeting on the subject of national security, drawing together executives from some of the biggest names in key industries.
Microsoft Azure Cosmos DB cloud databases have had their read-write keys exposed by a flaw that has been present since 2019, allowing an attacker to not just access the contents but also to change or delete them.
New Citizens Lab report reveals that the government of Bahrain has used the Pegasus iPhone spyware to track at least nine activists since June 2020. Two zero-days used in zero click iPhone exploit targeting iMessage.
Poor corporate data responsibility hurts consumer trust, preventing users from sharing data because of privacy and safety concerns as organizations stepped up data collection.
Report says merchants are overconfident about their ability to stop online shopping fraud while their customers think otherwise and blame them instead of criminals for breaches.
Microsoft Power Apps appears to list all data types as public unless the default settings are changed. The data leak exposed several coronavirus tracing and vaccination portals, as well as at least one job applicant database that contained social security numbers.
Research on underground forums found that cybercriminals made careers selling network access for up to five figures instead of exploiting the networks themselves.
Germany's data protection authority has determined that Zoom's data transfers to the U.S. are in violation of the terms of the GDPR in light of the Schrems II ruling, and has issued a formal warning.
Most ransomware attacks begin with some combination of phishing and social engineering. An enterprising ransomware gang in Nigeria appears to be skipping this messy step, simply making a direct pitch to employees to join in on the attack.










