BianLian ransomware group disputed Air Canada's claim that data breach impacted only limited personal information of some employees and certain records. Ransomware group claims to have stolen 210 GB of technical and operational data spanning from 2008 to 2023.
Flagstar Bank suffered a MOVEit data breach via a third-party payment processor and mobile banking services provider, impacting over 800,000 customers in the US.
Cloudflare reports attackers using the HTTP/2 protocol zero-day vulnerability to conduct over 1,100 DDoS attacks at over 10 million requests per second since August, and 184 broke the previous record of 71 million requests. At its peak, 200 million requests per second was observed.
The Delete Act (SB 362) expands an existing right under California state law to have personal data deleted, but streamlines the process so that one request will be sent to all data brokers.
Software supply chain attacks have spiked significantly year-over-year. Sonatype logged over 245,032 malicious packages in open source projects available to public download in 2023, double the number seen from 2019 to 2022. In total, one in eight open source downloads poses a risk.
Israel-Hamas conflict draws in an international coalition of hackers conducting cyber attacks in support of both sides. Report finds that there are about 100 hacker groups that have involved themselves thus far, and that the number skews heavily to Palestine supporters (at 77).
The UK ICO has wrapped up a preliminary investigation into Snap's AI chatbot, and has indicated that it is failing to adequately address children's privacy risks. There are numerous concerns about AI chatbots that are not yet resolved, but children's privacy seems to have driven much of the early action from regulators.
The UK ICO guidelines specify that workplace monitoring must be disclosed to employees (along with its 'clearly defined' purpose), and the 'least intrusive' method must be used to accomplish the stated purpose.
Lyca Mobile said the service disruption caused by the cyber attack “impacted some national and international calling” in all 60 countries in which it operated except for the United States, Australia, Ukraine and Tunisia.
Sony Interactive Entertainment has confirmed a MOVEit data breach that leaked the personal information of current and former employees and their family members.










