New York Attorney General Letitia James has sued insurance giant Allstate over two data breaches that exposed the driver’s license numbers of nearly 200,000 people.
A compromise of the popular GitHub Actions tool turned into a massive supply chain attack, at this point thought to be responsible for the follow-on exposure of over 23,000 GitHub repositories.
The Trump administration's "AI Action Plan" will likely shape every aspect of AI development going forward, and OpenAI has submitted its own set of proposals to the White House, one that unsurprisingly calls for light AI regulations.
New research from security firm Dragos finds that Volt Typhoon, one of the primary groups of state-sponsored Chinese hackers menacing the US as of late, was able to dwell in the Massachusetts electric grid for more than 300 days beginning in early 2023.
Microsoft Threat Intelligence warns that the Chinese state-linked threat actor Silk Typhoon is targeting the IT supply chain to compromise primary organizations and access their downstream customers.
Malicious actors are using deepfake videos impersonating YouTube’s CEO to steal users’ credentials in a multi-month phishing campaign. The attackers sent private videos to targeted users via legitimate-looking emails, warning them that YouTube was changing its monetization policies.
A hacktivist group posted evidence of its involvement in the X attack in the form of screenshots on a Telegram channel. It has previously used DDoS attacks to target an assortment of organizations with a strong focus on the US, UAE, Israel and Ukraine.
Nearly 12,000 live API keys were found in an AI training dataset used by various models such as OpenAI and DeepSeek, exposing services like AWS, MailChimp, and Slack to exploitation.
A bill establishing a new vulnerability disclosure program for federal contractors has passed the House, and will now move on to the Senate to be reviewed by the Committee on Homeland Security and Governmental Affairs.
Have I Been Pwned? (HIPB) has added 244 million freshly stolen passwords compromised via infostealer malware to an already existing list of 199 million, impacting 284 million unique user accounts.










