Marks & Spencer shut down its systems after experiencing an apparent ransomware cyber incident that disrupted order collections and contactless payment.
A major data breach at health insurance giant Blue Shield of California appears to be a case of misconfiguring advertising analytics tools. Between April 2021 and January 2024, Google Analytics was misconfigured causing some personal information and potentially sensitive health data related to claims and searches to be available to Google’s ad network.
The 18th installment of the DBIR surveyed 22,052 total cyber attacks logged by Verizon's internal threat research team, over half of which (12,195) involved confirmed data breaches. Credential abuse continues in the lead at 22%. Exploitation of vulnerabilities is now up to 20%, followed by phishing at 16%.
CISA warns about heightened security risks from the alleged Oracle Cloud credential leak affecting about 140,000 tenants and advises organizations to apply recommended mitigations.
The Medusa ransomware gang is claiming responsibility for an alleged NASCAR data breach that allegedly leaked one terabyte of data.
Since the start of the Privacy Sandbox project, Google has been strongly pushing to eliminate third party cookies entirely beginning with its Chrome browser. That initiative had seemed to be well underway, but now appears to be over.
Car rental giant Hertz Corporation has confirmed a data breach stemming from the Cleo managed file sharing platform's zero-day vulnerabilities that have affected nearly 100 organizations.
The Irish Data Protection Commission (DPC) has announced that it will be investigating X's use of the platform's posts, replies and user information as AI training data for its embedded "Grok" feature.
A bipartisan bill has been introduced to the Senate that would extend the terms of the Cybersecurity Information Sharing Act of 2015, widely seen as a vital national cybersecurity law.
The secret meeting took place in Geneva in December 2024. The source says that the remarks were "indirect" and "somewhat ambiguous," but were enough to implicate Volt Typhoon and the Chinese government in the cyber attacks that have plagued US critical infrastructure.










