Tag: data
-
Security Affairs newsletter Round 522 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Rhysida Ransomware gang claims the hack of the Government of Peru DragonForce group claims the theft of data…
-
TikTok fined Euro530M after EU user data ends up on servers in China
Ireland privacy watchdog says transfers violated GDPR, as Chinese app confirms Euro1B datacenter in Finland First seen on theregister.com Jump to article: www.theregister.com/2025/05/02/tiktok_gdpr_fine/
-
Hacker pleads guilty to orchestrating Disney data heist
First seen on scworld.com Jump to article: www.scworld.com/news/hacker-pleads-guilty-to-orchestrating-disney-data-heist
-
Hackers Weaponize Go Modules to Deliver Disk”‘Wiping Malware, Causing Massive Data Loss
Tags: attack, cyber, cybersecurity, data, exploit, github, hacker, malicious, malware, programming, sans, supply-chainCybersecurity researchers uncovered a sophisticated supply chain attack targeting the Go programming language ecosystem in April 2025. Hackers have weaponized three malicious Go modules-github[.]com/truthfulpharm/prototransform, github[.]com/blankloggia/go-mcp, and github[.]com/steelpoor/tlsproxy-to deploy devastating disk-wiping malware. Leveraging the decentralized nature of Go’s module system, where developers directly import dependencies from public repositories like GitHub sans centralized gatekeeping, attackers exploit namespace…
-
DragonForce group claims the theft of data after Co-op cyberattack
Hackers claim Co-op cyberattack is worse than admitted, with major customer and employee data stolen, and provide proof to the BBC. The attackers behind the recent Co-op cyberattack, who go online with the name DragonForce, told the BBC that they had stolen data from the British retail and provided proof of the data breach. Hackers…
-
Balancing AI Innovation With Security
Accountability Is Key as Enterprises Adopt AI at Scale, Says Saviynt’s Jim Routh. AI governance must balance innovation with security, making it vital that organizations adopt flexible, consensus-driven approach to ensure responsible AI deployment while addressing risks such as data exposure and software resilience, said Jim Routh, chief trust officer at Saviynt. First seen on…
-
Cybersecurity Trends: Impact of Tariffs and Data Sovereignty
Trend Micro’s Kevin Simzer on How Tariffs and Data Sovereignty Shape Cybersecurity. Organizations are beginning to be more cautious in the wake of the ongoing tariff war in terms of budgeting, although the situation is an opportunity for the cybersecurity industry to improve performance overall, said Kevin Simzer, chief operating officer at Trend Micro. First…
-
Ransomware Attacks Up 9% but Payments Are Down
Recorded Future’s Liska on What Happens Next When Ransomware Gets Less Profitable. Data theft-only ransomware attacks have reached 50% of incidents in Q1 2025, said Allan Liska, senior security architect at Recorded Future. Law enforcement has disrupted the major players, leaving less-skilled actors scrabbling for a payday or stealing information. First seen on govinfosecurity.com Jump…
-
Preparing your business for a penetration test
Penetration testing is vital to keeping your business safe in today’s digital landscape, where cyber threats are ever present. It ensures your business’s sensitive data is protected, validating the robustness of the defensive measures your business has implemented. With cyber attacks on the rise, proactive measures like penetration testing (also known as ethical hacking) aren’t”¦…
-
Hundreds of Fortune 500 Companies Have Unknowingly Employed North Korean IT Operatives
North Korean nationals have successfully infiltrated the employee ranks of major global corporations at a scale previously underestimated, creating a pervasive threat to IT infrastructure and sensitive data worldwide. Security experts revealed at the RSAC 2025 Conference that the infiltration extends across virtually every major corporation, with hundreds of Fortune 500 companies unknowingly employing North…
-
Why Many Fraud Victims Don’t Report Attacks
ITRC’s James Lee on Shame, Fatigue and Precision Targeting. Many fraud victims stay silent due to shame, fatigue or fear. James Lee, president of the Identity Theft Resource Center, explains why underreporting is rising and how better data sharing could help reduce the impact of identity-driven cyberattacks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/many-fraud-victims-dont-report-attacks-a-28228
-
Co-op apologises after hackers extract ‘significant’ amount of customer data
The National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) are assisting with the inquiry, the company saidThe Co-op has apologised after hackers <a href=”https://www.theguardian.com/business/2025/apr/30/co-op-forced-to-shut-down-part-of-it-system-after-hack-attempt”>accessed and extracted customer data in one of its systems.The National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) are assisting with the investigation, the company said.…
-
Banking Customer Data Exposed Following Ransomware Attack on Vendor
First seen on scworld.com Jump to article: www.scworld.com/native/banking-customer-data-exposed-following-ransomware-attack-on-vendor
-
iHeartMedia breach exposes sensitive personal data
First seen on scworld.com Jump to article: www.scworld.com/brief/iheartmedia-breach-exposes-sensitive-personal-data
-
Third-party breach compromises Ascension Health patient data
First seen on scworld.com Jump to article: www.scworld.com/brief/third-party-breach-compromises-ascension-health-patient-data
-
Ireland’s DPC fined TikTok Euro530M for sending EU user data to China
Ireland’s Data Protection Commission (DPC) fined TikTok Euro530M for violating data rules by sending European user data to China. Ireland’s Data Protection Commission (DPC) fined the popular video-sharing platform TikTok Euro530 million for violating data laws by transferring data belonging to European users to China. TikTok violated GDPR by transferring EEA user data to China…
-
Co-op confirms data theft after DragonForce ransomware claims attack
The Co-op cyberattack is far worse than initially reported, with the company now confirming that data was stolen for a significant number of current and past customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/
-
Privacy for Agentic AI
Sooner or later, it’s going to happen. AI systems will start acting as agents, doing things on our behalf with some degree of autonomy. I think it’s worth thinking about the security of that now, while its still a nascent idea. In 2019, I joined Inrupt, a company that is commercializing Tim Berners-Lee’s open protocol…
-
Dating app Raw exposed users’ location data and personal information
The app claims it uses end-to-end encryption, but spilled its users’ dating preferences and granular location data to the open web. First seen on techcrunch.com Jump to article: techcrunch.com/2025/05/02/dating-app-raw-exposed-users-location-data-personal-information/
-
Disney Slack Channel Hacker Pleads Guilty
Hacker Who Feigned Russian Hacktivist Persona Faces Up to a Decade in Prison. A California man whose theft of a terabyte of company data from Disney led the media and entertainment conglomerate to eschew Slack pleaded guilty in Los Angeles federal court to two felony charges. Santa Clarita resident Ryan Mitchell Kramer, 25, gained access…
-
Police Seize Dark Web Shop Pygmalion, Access User Data from 7K Orders
German police seized the dark web shop Pygmalion, gaining access to customer data linked to over 7,000 drug… First seen on hackread.com Jump to article: hackread.com/police-seize-dark-web-shop-pygmalion-user-data-orders/
-
Enhancing EHR Security: Best Practices for Protecting Patient Data
In the digital healthcare landscape, electronic health records (EHRs) are foundational to patient care, operational efficiency and regulatory compliance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/enhancing-ehr-security-best-practices-for-protecting-patient-data/
-
Erkenntnisse aus dem Verizon Data Breach Investigation Report (DBIR) 2025
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/verizon-data-breach-investigation-report-2025-erkenntnisse
-
Disney Slack attack wasn’t Russian protesters, just a Cali dude with malware
A 25-year-old California man pleaded guilty to stealing and dumping 1.1TB of data from the House of Mouse First seen on theregister.com Jump to article: www.theregister.com/2025/05/02/disney_slack_hacker_revealed_to/
-
TikTok fined Euro530 million for sending European user data to China
The Irish Data Protection Commission (DPC) has fined TikTok Euro530 million (over $601 million) for illegally transferring the personal data of users in the European Economic Area (EEA) to China, violating the European Union’s GDPR data protection regulations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tiktok-fined-530-million-for-sending-european-user-data-to-china/
-
TikTok Slammed With Euro530 Million GDPR Fine for Sending E.U. Data to China
Ireland’s Data Protection Commission (DPC) on Tuesday fined popular video-sharing platform TikTok Euro530 million ($601 million) for infringing data protection regulations in the region by transferring European users’ data to China.”TikTok infringed the GDPR regarding its transfers of EEA [European Economic Area] User Data to China and its transparency requirements,” the DPC said in a…
-
NCSC Guidance on “Advanced Cryptography”
The UK’s National Cyber Security Centre just released its white paper on “Advanced Cryptography,” which it defines as “cryptographic techniques for processing encrypted data, providing enhanced functionality over and above that provided by traditional cryptography.” It includes things like homomorphic encryption, attribute-based encryption, zero-knowledge proofs, and secure multiparty computation. It’s full of good advice. I…
-
VerizonBreach-Investigation-Report Schwachstellen sind der häufigste Einstiegspunkt für Sicherheitsverletzungen
Der aktuelle Verizon-Data-Breach-Investigation-Report, DBIR 2025, veröffentlicht am 2. Mai 2025 in München, liefert einen umfassenden Überblick über die sich wandelnde Bedrohungslandschaft in der Cybersicherheit. Der Bericht wurde durch die Expertise zahlreicher Partner insbesondere Qualys unterstützt, die entscheidend dazu beitrugen, kritische Muster und Schwachstellen aufzudecken und Unternehmen das nötige Wissen zur Abwehr aktueller und […] First…

