Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.
Further review of the information leaked in the recent Disney data breach has turned up sensitive and detailed financial and business strategy information, according to a new report from the Wall Street Journal.
EU data protection authorities are increasingly taking the position that the internal data that Google itself receives from the Google Analytics tool is in violation of GDPR terms. Sweden's data protection authority is indicating that it might be the next one in line to ban it.
Law enforcement authorities have seized the notorious cybercrime forum RAMP, which advertised and facilitated the sale of various hacking services, including ransomware.
The first tranche of privacy reforms introduced to Parliament provides the OAIC with new penalties for data violators and a new privacy code for children, along with the addition of a new statutory tort for serious invasions of privacy.
CFIUS will be conducting a national security review on TikTok as top U.S. lawmakers think the company is used by the Chinese state to censor political opinion or snoop on U.S. citizens.
250 hospitals in the US activated critical blood shortage protocols after a ransomware attack on blood center OneBlood disrupted blood and platelets distribution.
Facebook insiders comment on the battle against Apple's IDFA tracking changes. Biggest concern is that it will lose the ability to track the connection between ads shown on Facebook and sales made elsewhere.
State-backed Chinese hackers can modify Cisco routers without being detected and install custom firmware that allows for persistent access, according to a new joint cybersecurity advisory published by CISA and both US and Japanese law enforcement agencies.
A statement from Danske Bank indicates that the GDPR violations are tied to an inability to build data deletion functionality into its complex interlocked IT systems despite beginning efforts in 2016.









