Panda Express, the largest Chinese fast food chain in the US, leaked sensitive personal data during the March 2024 cyber attack that affected the parent company’s corporate systems.
For the most part the exposure appears to have been limited to names and bank details for both active members of the UK armed forces and veterans. The UK government has named SSCL, a business services provider, as the source of the third party breach.
A security breach has affected all users of the eSignature platform Dropbox Sign (formerly HelloSign), including those who received or signed a document without an account.
The new Microsoft security initiative update promises more sweeping changes. This move is also likely tied directly to the company's security woes and issues with cyber threats in 2023 and early 2024.
Austrian GDPR Complaint Claims OpenAI Refuses to Correct Potentially Libelous ChatGPT Hallucinations
Filed by data privacy crusader Max Schrems and his group "noyb," the GDPR complaint asserts that OpenAI refuses to correct ChatGPT output about individuals and will simply try to filter or block requests tied to that name. The complaint also accuses OpenAI of failing to live up to their subject access request (SAR) responsibilities under EU rules.
Qantas Airways Privacy Breach Exposed Passenger Information, Allowed Booking and Flight Cancellation
Australia’s national carrier, Qantas Airways, has apologized for a privacy breach that exposed passenger information and allowed booking, flight cancellation, and seat changes.
The headline items from the 2024 Verizon DBIR include a 180% jump in vulnerability exploitation from 2023's numbers, and non-malicious employee elements continuing to play a role in over two-thirds of breaches as phishing remains a major threat.
The European Data Protection Board (EDPB) has issued non-binding guidance that finds Meta's 'consent or pay' model is unlikely to be found valid if the only choice for consumers is to either give up all of their personal data, or pay a subscription fee for privacy.
Healthcare provider Kaiser Permanente has disclosed a data breach stemming from online tracking that inadvertently shared with third-party advertisers how users interacted with and navigated through the website and mobile applications, and search terms used in the health encyclopedia patient information.
GRU-affiliated Russian hackers targeted 20 Ukrainian critical infrastructure facilities in March 2024, Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed.









