Google says it will start distrusting digital certificates issued by two certificate authorities due to, Chunghwa Telecom and Netlock, compliance issues and failure to address public incidents.
Gaming chipmaker Nvidia said hackers started releasing information stolen in the February massive data leak, but no evidence suggests it was a Russian-sponsored ransomware attack.
The FBI says hackers who scraped credit card data by injecting malicious PHP code on an online checkout page were targeting U.S. businesses since September 2020.
German automaker Volkswagen suffered a massive data leak, affecting over 800,000 electric vehicle owners, with over half of EVs leaking precise location data.
Amid concerns that tech companies will share potentially incriminating user data with states that have outlawed abortions after the Roe v. Wade decision, a coalition of Democratic lawmakers and privacy advocates is renewing calls for enhanced regulation.
A widespread 2FA bypass attack compromised Comcast Xfinity customer email accounts and attempted to take over their Coinbase and Gemini Wallets, Evernote and Dropbox accounts.
WhatsApp accounts could be deactivated simply by sending a request from any email address, so long as the attacker knew the associated phone number. Going forward, the account deactivation process now involves a follow-up message that requests verification of ownership of the associated phone number.
The immediate order to cease use of Google Analytics pertains to a particular French website that was the subject of a GDPR complaint over data transfers, but signs show it expanding to the rest of the EU before long.
Google is looking at ₩69.2 billion (about $50 million) and Meta ₩30.8 billion (about $22 million) in fines issued by the country's Personal Information Protection Commission due to privacy law violations.
The final report on the Okta security breach indicates that the attackers were able to access HAR files containing session tokens of 134 customers, but it appears they were very selective in which they chose to pursue follow-up attacks on. Only five instances of successful session hijacking were logged.










