Popular "fast fashion" app Shein has landed in some regulatory trouble in the EU, as France's data regulator CNIL has issued a €150 million GDPR fine due to failure to obtain cookie consent.
Google is facing a €325 million fine from French data regulator CNIL for its placement of cookies that may not have been noticed by those signing up for new accounts and its use of ads in Gmail.
SK Telecom was hit with a record $97.2 million (KRW 134.8 billion) data breach fine for failing to stop the April 2025 cyber attack that leaked the sensitive SIM-related information of 23.2 million people.
An as-of-yet undiagnosed compromise of the Salesloft Drift AI-driven platform has led to a rash of stolen OAuth tokens, in turn creating downstream breaches at some of the biggest names in the cybersecurity industry.
Credit monitoring giant TransUnion has suffered an apparent Salesforce data breach, affecting over 4.4 million people, with ShinyHunters claiming responsibility.
Google Threat Intelligence Group has tracked threat actor UNC6395 stealing OAuth tokens via Salesloft Drift integrations in a massive Salesforce data theft campaign.
A cyber attack on Nevada has disrupted state services, including phone lines, websites, and online systems, forcing several offices to close with no expected date of resolution.
A recent campaign of cyber attacks made new and novel use of the Claude AI chatbot in scanning VPN endpoints and automating multiple portions of the attack cycle, representing another step forward in the deployment of LLMs for malicious purposes.
A whistleblower report submitted to Congress and the Office of Special Counsel claims that DOGE employees uploaded a very sensitive Social Security Administration (SSA) database to a vulnerable cloud server while auditing the agency, one that contains Social Security numbers for 300 million Americans as well as associated identity information.
While the Otter privacy policy makes clear that its AI notetaker service may indeed train on the voices of users while they are in meetings, the privacy lawsuit notes that guests without Otter accounts that can be invited to these meetings have not been similarly notified or opted in.










