Cloud security firm Ermetic found that vulnerable identities and misconfigured environments on most AWS accounts expose 90% of S3 buckets to potential ransomware attacks.
FBI's annual internet crime report says cyber crime losses increased by almost two-thirds while ransomware attacks remain the greatest risk to critical infrastructure organizations.
Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
The PIPC fine to Alibaba Group was accompanied by an order to rectify the privacy violations, along with a set of recommendations to avoid future regulatory action. About 180,000 AliExpress customers are thought to have been impacted.
Study finds RTB adtech systems share online behavior data 294 billion times per day in the U.S. and 197 billion times per day in Europe. Average internet user in the US is exposed 747 times each day; in Europe it is 376 times per day.
Verizon prepaid customers suffered a SIM swap attack after hackers breached their accounts using the last four digits of their credit card numbers likely obtained via stolen employee accounts.
Annual Cisco Consumer Privacy Survey, a study including the opinions of over 2,600 respondents of varying demographics in 12 countries, indicates that consumer awareness of data privacy rights is continuing to grow and that AI has some work to do to earn public trust.
If the new rules are approved, a broad range of Chinese companies will be subject to screening of data transfers that involve personal information or pertain to critical infrastructure.
WEF's newly-released principles for board governance of cybersecurity offer a base of best practices for dealing with increasing cyber risk, with a new element being an emphasis on an organization-wide focus.
A security flaw at the U.K.’s business registry, Companies House, exposed the personal information of business executives and allowed unauthorized alteration.










