The headline items from the 2024 Verizon DBIR include a 180% jump in vulnerability exploitation from 2023's numbers, and non-malicious employee elements continuing to play a role in over two-thirds of breaches as phishing remains a major threat.
The European Data Protection Board (EDPB) has issued non-binding guidance that finds Meta's 'consent or pay' model is unlikely to be found valid if the only choice for consumers is to either give up all of their personal data, or pay a subscription fee for privacy.
Healthcare provider Kaiser Permanente has disclosed a data breach stemming from online tracking that inadvertently shared with third-party advertisers how users interacted with and navigated through the website and mobile applications, and search terms used in the health encyclopedia patient information.
GRU-affiliated Russian hackers targeted 20 Ukrainian critical infrastructure facilities in March 2024, Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed.
South Korea's National Police Agency has revealed that state-sponsored North Korean hackers have been waging an all-out espionage campaign against the country's defense companies since at least 2022, and have lurked in the networks of some targets for over a year.
The Akira ransomware gang earned approximately $42 million in ransoms after breaching over 250 victims across three continents between March 2023, when the group emerged, and January 2024.
Google's Privacy Sandbox project has been touted as the end of tracking cookies and creepy cross-site following, but it is facing regulatory trouble as the UK ICO has expressed concerns about a collection of "loopholes" that could be used to personally identify and track internet users.
The president signed a bill that requires owner ByteDance to either divest itself of the massively popular app or have it removed from American app stores. National security concerns have driven this process forward, but ByteDance still has the right to challenge the action in court and any ban would be instituted no sooner than January 2025.
UnitedHealth Group has released further details about the devastating Change Healthcare attack that caused widespread damage throughout the US, taking large chunks of revenue from some care providers and in some cases keeping patients from needed medication. The group has confirmed that it made a ransom payment to restore service.
A cyber attack by a suspected cybercrime group has forced Frontier Communications, a Dallas, Texas-based optic-fiber Internet provider, to temporarily shut down its information systems to contain the incident.









