Recent Instagram data scraping by HYP3R has raised many privacy concerns as the trusted Facebook marketing partner was found scraping and re-packaging social media data for advertisers.
A new vulnerability chain discovered by Oasis Security can compromise the Claude AI chatbot and does not require the target to have the app installed or even have an account with the service. The attack chain instead begins with a malicious webpage doctored up to place highly in search results for Claude, which passes the user to a pre-filled chat URL that exploits other vulnerabilities in the AI agent.
The headline items from the 2024 Verizon DBIR include a 180% jump in vulnerability exploitation from 2023's numbers, and non-malicious employee elements continuing to play a role in over two-thirds of breaches as phishing remains a major threat.
A massive data breach has exposed a trove of personal information after a threat actor compromised a French hospital’s electronic...
Many organizations affected by Log4j’s zero-day vulnerability with mass internet scanning detected, suggesting the remote code execution flaw was actively targeted in the wild.
A coalition of some of the biggest names in privacy-focused tech companies is seeking a ban on advertising technologies that use surveillance techniques to track people across the internet.
Digital Services Act would bring new restrictions on how targeted advertising can use sensitive personal information and a requirement that the inner workings of recommender algorithms be visible to the public.
A massive brute force password attack involving 2.8 million IP addresses targets VPN devices from various companies including Palo Alto Networks, Ivanti, and SonicWall.
Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
CNIL said that it is following up on "several" privacy complaints, and Spain is looking to put the ChatGPT topic on the Plenary of the European Data Protection Committee's discussion schedule.










