To a great degree the strategic plan builds on the previously published CISA Strategic Intent and formalizes a number of cybersecurity strategy initiatives the agency is already well underway with.
Cybersecurity agencies from the Five Eyes Alliance published the list of the 12 most exploited vulnerabilities of 2022, revealing that hackers prefer older unpatched software bugs, with one dating back to 2018.
Under the new terms of the California Privacy Rights Act (CPRA), the California Privacy Protection Agency (CPPA) will be examining a broad range of data collected by car manufacturers, including what the vehicle cameras capture and what is passing through their apps.
Zoom's plan for AI data collection is apparently to scrape it from internal customer activity. The March TOS update changed the platform terms to announce that Zoom reserved the right to use platform video, audio and chat content to train AI models.
Official sources say that Chinese hackers combed Japan's military networks over an extended period between 2020 and 2021 in search of military plans, documentation of capabilities, and assessments of vulnerabilities.
Massive UK Electoral Commission data breach leaked voter data of 40 million individuals who registered to vote between 2014 and 2022. The electoral body said it first detected suspicious activity on its network in October 2022 and discovered that threat actors had accessed the systems 14 months prior.
Since the GDPR went into effect in 2018, Meta has done nearly everything possible to claim legitimate interest to avoid user consent for collecting personal information for targeted ads. The company appears to have finally reached the end of its rope in this area, though a recently announced changeover to a consent basis.
Colorado Department of Higher Education (CDHE) has suffered a massive data breach leaking sensitive personal information of current and former students and educators spanning over a decade.
China’s new rules for facial recognition technology require companies to protect personal information, and to demonstrate a "specific purpose" and "sufficient necessity" when collecting biometric data of this nature.
With fines and penalties (such as potential shutdown of company operations) looming in November of this year, some companies are opting to bail out of China rather than even attempt to comply with the slew of new data regulations.










