ShinyHunters has claimed responsibility for data breach at American clothing giant Carhartt that affected nearly 13 million people, including customers and employees.
Recent ruling in New Jersey involving the NotPetya attacks indicates that insurers may not be able to use "cyber war" clauses as an excuse to not pay out for remediation of ransomware attacks.
As of February 21, Apple device users in the UK began seeing a notice that the iCloud end-to-end encryption feature is no longer available in their region. That stems from a secret order recently issued by the Home Office, only made known to the public due to inside sources leaking it to the media, requiring Apple to start implementing backdoor access to encrypted cloud data and to begin complying immediately.
Flaws in Safari’s Intelligent Tracking Prevention feature allow hackers to track users as they navigate the Internet and gain access to their cross-site browsing history.
EPA and the White House warns that US water systems lack proper cybersecurity safeguards, risking a crippling cyber attack that could disrupt the critical lifeline of drinking water and impose significant costs.
Study has harsh criticism for the data safety labels that ostensibly inform consumers about the data sharing habits of Android apps. Almost 80% of sampled apps either did not match up with statements made in the privacy policy or were worded in a misleading way.
Positive Technologies found that cybercriminals can penetrate 93% of company networks, disrupt processes and services, steal funds and data, while insiders can breach 100% of networks.
Salesforce has confirmed another third-party breach affecting Gainsight applications integrated with customer instances, enabling attackers to exfiltrate customer data.
In a new California lawsuit, Facebook is accused of failing to adequately comply with information and subpoena requests related to the company’s privacy practices.
Israeli voter data was exposed by the country’s election management site that leaked admin credentials via an unprotected API endpoint in the homepage source code.









