Report found that Russian intelligence agencies FSB and SVR collaborated with ransomware gangs to compromise US government-affiliated organizations using cybercriminals tools and infrastructure.
Reddit hack shows that the industry standard two-factor authentication approach in certain cases might not offer as much protection of vulnerable data as has long been thought.
Polish antitrust investigation is interested in Apple's plans for its own limited targeted advertising product, but apparently will also be examining the real world effectiveness of the App Tracking Transparency framework.
The Open Worldwide Application Security Project (OWASP) suffered a data breach stemming from a server misconfiguration that leaked members' personal information.
Today, data flows have become infinitely more complex in what has come to be known as surveillance capitalism. The challenge is how to future proof privacy legislation, learning the lesson of what worked with credit reporting laws as well as other more recent measures.
Investors can no longer ignore the cyber resilience of their target companies, in fact the new WEF report shows they should be actively play a role in incentivizing responsible and secure innovation.
SolarWinds and its CISO Timothy Brown are facing serious charges in connection with the catastrophic security breach of 2020, with the SEC alleging that he had knowingly ignored and downplayed serious security risks since at least 2018.
Insurance giant Marsh & McLennan is leading a “Cyber Catalyst” program involving top cyber insurance companies to provide seal of approval for top-rated cybersecurity products. How will this impact consumers and the cyber insurance industry?
The Digital Markets Act focuses on Big Tech, and its requirements would force message interoperability among other terms that Facebook and similar services are unlikely to be happy about.
Connected devices will soon be subject to new IoT security laws, with California taking the lead and requiring devices to have “reasonable security features” and U.K. draft law requires devices to have cyber security features labeled on package.









