Publishing platform Substack has disclosed a data breach that leaked nearly 700,000 user records after an unauthorized third-party exploited a security flaw.
The use of smart doorbells may be facing new restrictions in the UK, due to a recent court ruling that found an Amazon Ring doorbell pointed at a neighbor's property constituted an invasion of privacy.
Alibaba's security team was the first to discover the Log4j vulnerability. Though Alibaba Cloud was not compromised, the company is nevertheless facing consequences for failing to notify Chinese regulators within two days as required by new laws passed in September 2021.
Microsoft has named "Midnight Blizzard," an established team of Russian state sponsored hackers also referred to as NOBELIUM and Cozy Bear, as the culprit behind a recent security breach that compromised high-level corporate email accounts.
The European Commission is investigating a data breach that compromised the infrastructure used to manage mobile devices, which leaked the staff members’ personal information.
The decision to scrap the data protection bill came from a parliamentary review process. IT minister Ashwini Vaishnaw has told reporters that work was already underway on a new personal data law, no doubt to the delight of big tech companies.
Billions of devices may be affected by a UPnP vulnerability that allows hackers to conduct a DDoS attack and perform data exfiltration on the local network.
UnitedHealth Group (UHG) has confirmed that the February 2024 Change Healthcare data breach leaked the sensitive personal information of 100 million people, making it the worst healthcare leak in history.
Senator Ron Wyden says both Apple and Google are complying with foreign government requests for data from push notifications which can facilitate government surveillance by disclosing apps that the user has installed, the Google or Apple account they use with the phone, and potentially even the text displayed in the notification (if it is not encrypted).
Lloyd's of London has told its global network of insurer groups that new or renewed cyber insurance coverage policies must exclude nation-state attacks as of March 31, 2023.










