Cybersecurity News, Insights and Analysis

privacy security news

Published posthumously, Italo Calvino’s Numbers in the Dark (2002) is a provocative collection of stories written between 1943 and 1984 that explores the effects of digital technologies and data. These are costs that AI companies are externalizing on all of us. Normally, the market would work as a mechanism of survival of the fittest, weeding out business models that don’t really work.

“We have no evidence of impact to customer information stored outside of GitHub’s internal repositories, such as our customer’s own enterprises, organizations, and repositories,” Alexis Wales, Chief Information Security Officer of GitHub, said in a statement. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI , and Grafana Labs . Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. A dual U.S.-Estonian citizen known online as “Bouquet,” he was extradited from Finland and made his first court appearance in Chicago on June 30, as THN reported .

privacy security news

From managing data in AI pipelines and processing deletion requests to expanding categories of personal information, organizations face a tough challenge to keep pace with the evolving global privacy landscape. Learn more about consumer topics at consumer.ftc.gov, or report fraud, scams, and bad business practices at ReportFraud.ftc.gov. This includes a 2023 action that the FTC and Consumer Financial Protection Bureau brought against Trans Union LLC and a subsidiary for failing to ensure the accuracy of tenant screening reports by including inaccurate and incomplete eviction records about consumers, hampering their ability to obtain housing. The agency also has worked to ensure companies comply with the Fair Credit Reporting Act, which sets out requirements for companies that use data to determine creditworthiness, insurance eligibility, suitability for employment, and to screen tenants. The FTC also has remained active in targeting companies that fail to implement reasonable data security measures to protect consumer data.

The TDPSA requires the companies to provide notice and obtain informed consent to use the sensitive data of Texas residents, which includes precise geolocation data. The FDA is accepting comments on the Draft Guidance, which may be submitted online until April 7, 2025. The Draft provides recommendations regarding the contents of marketing submissions for AI-enabled medical devices, including documentation and information that will support the FDA’s evaluation of their safety and effectiveness.

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. The issue was present in .github/workflows/jira_issue.yml , which ran when a public issue was opened and exposed JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN to the same workflow step. “GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action,” the company said. GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.

Signal is moving closer to offering accounts that do not require a phone number during signup. Stay informed about privacy trends, the latest developments in digital privacy, and privacy and security breaches. The new documents address best practices for bias evaluation and the effective implementation of data subject rights, specifically the rights to rectification and erasure when AI systems have been developed with personal data. The Support Pool of Experts program aims to help data protection authorities increase their enforcement capacity by developing common tools and giving them access to a wide pool of experts. Despite the breach, Ashford falsely reported in its November 2023 filings that no customer information was exposed.

privacy security news

Trezor says ShipMonk breach exposed data of 13,700 customers

  • At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.
  • CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
  • Elsewhere, Canada’s privacy regulator published the results of its latest survey of Canadian businesses on privacy issues.
  • “This assessment is based on the convergence of Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated operational use of Chinese-language tools and management software, victi…
  • Would a Big Tech tax for kid-focused nonprofit platforms be complicated?
  • That’s how we ensure recommending only the best of the best privacy tools to you.

The unreleased model, called Astra, showed signs that it could carry out cyberattacks autonomously, says OpenAI. Digital counterstrikes following US attacks on Iran offer the latest reminder that the internet has few solid borders, according to Cloudflare’s latest data. Hackers have been targeting adults and underage users by breaking into their social media accounts to try to uncover the sensitive photos, the FBI says. Large datasets can be useful research tools, but current government efforts to gather medical records depend on policy and technology that falls short of protecting people’s privacy.

  • Civil-society groups warn that these changes weaken public oversight at a time when lobbying by large technology companies is intensifying.
  • But I find these sentiments to be chutzpah because young people are exposing their lives due to the way technology is nudging, pushing, cajoling, manipulating, coercing, and outright forcing them to do so.
  • Encrypted messaging provider Threema says a series of large-scale distributed denial-of-service (DDoS) attacks disrupted its …
  • A report from 404 Media shows how more than a dozen cases around the US have shown police using Flock to illegally stalk victims.
  • The Federal Trade Commission released its Privacy and Data Security Update for 2023 that highlights the FTC’s work to protect consumer privacy and respond to the evolving ways that companies use consumer data such as in the development of artificial intelligence models and misuse of health data.

Three-quarters of Ransomware Attacks Target Mid-Market Firms

These tools allow some users to connect their bank accounts… A US-based education tech provider announced a cybersecurity incident affecting its Canvas platform – used by institutions around the world, including Australia. Two researchers navigate the mind-boggling and often sinister, parallel universe that is known as the digital afterlife industry and chatbots specifically designed to help people grieve. We do extensive research on online privacy, digital security, VPNs, and internet freedom. Privacy International’s recommendations for improving transparency and explainability for algorithmic decisions at work, including concrete and detailed examples of best practices for platforms https://repaircanada.net/the-best-security-and-blockchain-technologies-from-cqr.html to implement.

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders

Targets identified so far span telecoms, banks and other financial services firms, enterprise software vendors including security and data privacy companies, and public sector portals, though Reco… A single piece of infrastructure has been pulling records out of https://bright-person.com/followers/car-cybersecurity-standards-and-regulations.html Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. Crossfuze is built for continuous momentum, ensuring the platform continues to deliver value as organizations scale, priorities change, and technology evolves. Madhu Gottumukkala uploaded multiple “for official use only” contracting documents to OpenAI’s public platform, bypassing DHS-approved AI tools and triggering automated cyber alerts. California sues over 23andMe breach that exposed millions of people’s data. Australia began restricting kids under 16 from social media last year, though a recent study found that many underage users can still access the platforms.

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. Unit 42 released new research showing that in Google’s synced passkey ecosystem, it’s possible for an attacker to take over accounts protected by synced passkeys without user interaction. People’s AI chats have once more been exposed online, multiple updates to previously reported data breaches, and more.


Posted

in

by

Tags: