Tag: data
-
New COPPA Rules to Take Effect Over Child Data Privacy Concerns
New regulations and compliance standards for the Children’s Online Privacy Protection Act reflect how much technology has grown since the Federal Trade Commission last updated it in 2013. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/new-coppa-rules-children-data-privacy-concerns
-
Researchers Detail Zero-Click Copilot Exploit ‘EchoLeak’
Researchers at Aim Security disclosed a Microsoft Copilot vulnerability of critical severity this week that could have enabled sensitive data exfiltration via prompt injection attacks. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/researchers-detail-zero-click-copilot-exploit-echoleak
-
Randall Munroe’s XKCD ‘Neighbor-Source Heat Pump’
Tags: datavia the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2025/06/randall-munroes-xkcd-neighbor-source-heat-pump/
-
Kyndryl and Databricks Partner to Fast-Track AI and Data Modernization
First seen on scworld.com Jump to article: www.scworld.com/news/kyndryl-and-databricks-partner-to-fast-track-ai-and-data-modernization
-
23andMe data deletion sought by nearly 2M customers, exec says
Tags: dataFirst seen on scworld.com Jump to article: www.scworld.com/brief/23andme-data-deletion-sought-by-nearly-2m-customers-exec-says
-
Misconfiguration leaks GonnaOrder data
First seen on scworld.com Jump to article: www.scworld.com/brief/misconfiguration-leaks-gonnaorder-data
-
Microsoft 365 Copilot ‘zero-click’ vulnerability enabled data exfiltration
First seen on scworld.com Jump to article: www.scworld.com/news/microsoft-365-copilot-zero-click-vulnerability-enabled-data-exfiltration
-
Breach Roundup: Critical RCE Flaw in Roundcube Servers
Also, M&S Back Online, Mexican Education Platform Breached, Patch Tuesday. This week, a Roundcube flaw, Mexican student data hacked and Dutch cops scare straight Cracked users. Man imprisoned for hacking tax preparers. M&S update. UNFI ships on a limited basis. U.K. financial regulator staffers used personal emails. Weak web panel security on GPS devices. Patch…
-
23andMe privacy ombudsman recommends company obtains consent for sale of customer data
The recommendation to the bankruptcy judge overseeing the sale is partially based on messages from 23andMe customers who told him they are worried about their genetic data’s inclusion in the sale. First seen on therecord.media Jump to article: therecord.media/23andme-privacy-ombudsman-recommends-consent-sale
-
Unpatched holes could allow takeover of GitLab accounts
Tags: access, attack, authentication, best-practice, ceo, communications, control, cve, cvss, data, github, gitlab, incident response, malicious, mfa, password, risk, service, vulnerabilityCVE-2025-2254, a cross-site scripting issue, which, under certain conditions, could allow an attacker to act like a legitimate user by injecting a malicious script into the snippet viewer.All GitLab CE/EE versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2 are impacted;CVE-2025-0673, a vulnerability that can cause a denial of service by triggering…
-
Vulnerability Databases Face Accuracy and Access Gaps
VulnCheck’s Garrity on the Uncertainty of the CVE Ecosystem and EUVD’s Limitations. Funding shortages and incomplete coverage in critical vulnerability databases are increasing the risk for defenders. Patrick Garrity, security researcher at VulnCheck, discusses how data gaps and scoring confusion hinder response strategies for potential cyberattacks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vulnerability-databases-face-accuracy-access-gaps-a-28670
-
LockBit panel data leak shows Chinese orgs among the most targeted
The LockBit ransomware-as-a-service (RaaS) operation has netted around $2.3 million USD within 5 months, the data leak stemming from the May 2025 hack of a LockBit affiliate … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/06/12/lockbit-data-leak-targets-ransoms/
-
137,000 SoftBank Customers Affected by Data Leak from Third-Party Vendor
SoftBank has previously experienced significant data breaches. In 2004, the company confirmed that personal information on 4,517,039 customers had been leaked through two separate cases involving suspects Yuasa and Kimata. This historical incident demonstrates the scale of data security challenges telecommunications companies face. Current Data Protection Framework SoftBank has established comprehensive data protection policies following…
-
New Cybersecurity Executive Order: What You Need To Know
Tags: ai, cisa, cloud, communications, compliance, computing, control, cyber, cybersecurity, data, defense, detection, encryption, exploit, fedramp, framework, government, identity, incident response, infrastructure, Internet, iot, network, office, privacy, programming, resilience, risk, service, software, supply-chain, technology, threat, update, vulnerability, vulnerability-management, zero-trustA new cybersecurity Executive Order aims to modernize federal cybersecurity with key provisions for post-quantum encryption, AI risk and secure software development. On June 6, 2025, the White House released a new Executive Order (EO) aimed at modernizing the nation’s cybersecurity posture. As cyber threats continue to evolve in scale and sophistication, the EO reinforces…
-
How to delete your 23andMe data
Tags: data23andMe holds millions of customers’ genetic information. Here’s what you can do to protect your data. First seen on techcrunch.com Jump to article: techcrunch.com/2025/06/11/23andme-files-for-bankruptcy-how-to-delete-your-data/
-
AI May Fix a 15-Year-Old Bug It Helped Spread
Researchers Turn to AI to Fix a Zombie Flaw that AI Helped Propagate. Artificial intelligence tools that inadvertently perpetuated a decade-old bug may now also help eliminate it. The path traversal vulnerability became so embedded in developer culture that it found its way into training data for today’s AI models. First seen on govinfosecurity.com Jump…
-
How Waymo Handles Footage From Events Like the LA Immigration Protests
Tags: dataWaymo driverless taxis capture troves of video footage in order to operate, but the company reveals very little about how much data is stored”, and for how long. First seen on wired.com Jump to article: www.wired.com/story/waymo-data-privacy-protests-los-angeles/
-
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
A new attack dubbed ‘EchoLeak’ is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user’s context without interaction. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/
-
Critical flaw in Microsoft Copilot could have allowed zero-click attack
Researchers said the vulnerability, dubbed “EchoLeak,” could allow a hacker to access data without any specific user interaction. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/flaw-microsoft-copilot-zero-click-attack/750456/
-
Critical flaw in Microsoft Copilot could have allowed zero-click attack
Researchers said the vulnerability, dubbed “EchoLeak,” could allow a hacker to access data without any specific user interaction. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/flaw-microsoft-copilot-zero-click-attack/750456/
-
DevOps pros eye Datadog developer portal for ITSM
DataDog advanced onto Atlassian and ServiceNow’s turf with a self-service developer portal that draws on real-time data about the observed state of IT resources. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366625739/DevOps-pros-eye-Datadog-developer-portal-for-ITSM
-
DevOps pros eye Datadog developer portal for ITSM
DataDog advanced onto Atlassian and ServiceNow’s turf with a self-service developer portal that draws on real-time data about the observed state of IT resources. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366625739/DevOps-pros-eye-Datadog-developer-portal-for-ITSM
-
Critical flaw in Microsoft Copilot could have allowed zero-click attack
Researchers said the vulnerability, dubbed “EchoLeak,” could allow a hacker to access data without any specific user interaction. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/flaw-microsoft-copilot-zero-click-attack/750456/
-
23andMe says 15% of customers asked to delete their genetic data since bankruptcy
Tags: dataMore than two dozen states have sued 23andMe to block the sale of genetic data without customers’ permission. First seen on techcrunch.com Jump to article: techcrunch.com/2025/06/11/23andme-says-15-of-customers-asked-to-delete-their-genetic-data-since-bankruptcy/
-
Operation Secure disrupts global infostealer malware operations
An international law enforcement action codenamed “Operation Secure” targeted infostealer malware infrastructure in a massive crackdown across 26 countries, resulting in 32 arrests, data seizures, and server takedowns. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/operation-secure-disrupts-global-infostealer-malware-operations/
-
Forgotten patches: The silent killer
Tags: attack, automation, backup, breach, business, cloud, compliance, control, data, defense, detection, endpoint, exploit, infrastructure, tool, update, vulnerabilityAccuracy over convenience: It’s tempting to prioritize speed or ease. But making patching easier cannot come at the expense of accuracy. Light enforcement, delays in applying updates, or gaps between tools and policy all introduce risk.Patch management must detect when systems drift out of compliance, whether due to misconfiguration, agent failure, or an unexpected event,…
-
Black Duck Elevates Leadership with New Chief Product Technology Officer
Black Duck has announced the appointment of Dipto Chakravarty as Chief Product & Technology Officer. Mr. Chakravarty brings a 30+ year track record of leading product development and technology teams, with domain expertise in AI, data intelligence, cloud security, and open-source technologies. At Black Duck, he will drive the product strategy, product management, and R&D…
-
1.5 TB of James Webb Space Telescope data just hit the internet
Online catalog gives open science access to data from early universe First seen on theregister.com Jump to article: www.theregister.com/2025/06/09/jwst_open_science_data/
-
Researcher Finds Five Zero-Days and 20+ Misconfigurations in Salesforce Cloud
The products affected by the issues are part of the Salesforce OmniStudio suite, including FlexCards and Data Mappers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/zeroday-20-misconfigurations-in/

