Hot Topic has suffered a data breach affecting 57 million retail customers stemming from a compromised cloud account without multi-factor authentication (MFA).
Amazon has confirmed that it was impacted by the MOVEit third party breach that took place in 2023, and that a large amount of employee data was included with a massive trove that was offered for sale on a hacking forum.
The US tech companies oppose what they call an "undue expansion of government access," but also a requirement that they seek permission before being allowed to send local data overseas. The proposed data protection law also has vague and expansive terms here.
Google Cloud will enforce mandatory MFA by the end of 2025 due to the sensitive nature of cloud deployments and phishing and stolen credentials being top attack vectors.
French digital automation and energy management giant Schneider Electric is investigating a data breach after a hacker claimed they stole dozens of gigabytes and demanded a hefty ransom in Baguettes, a classic popular French bread item.
CISA and the "Five Eyes" national intelligence agencies have issued their annual advisory on the top exploited vulnerabilities for the prior year, and its findings bolster some other recent reports that a successful attack is becoming increasingly likely to be the result of a zero-day.
South Korea's Meta fine comes as the result of a four-year investigation into Facebook's data collection practices between 2018 and 2022. Meta was found to have collected user information about sexual orientation, political views and religion among other items.
A Nokia security breach has leaked source code from a third-party software development partner, exposing the company’s sensitive data, including keys and hardcoded credentials.
Attackers are targeting the DocuSign APIs to generate large amounts of fake invoices, which often skirt automated security and land in inboxes as they originate from "docusign.net" and appear to be coming from legitimate companies.
The Five Eyes Intelligence Alliance has published security guidance to help tech startups protect their innovations from nation-state threat actors and other hackers.










