Privacy & Security News

privacy security news

In research published July 13 , Microsoft mapped the campaigns, which ran from mid-2025 into mid-2026, to three distinct techniques. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.

Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones. At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose. The Treasury Inspector General for Tax Administration (TIGTA) found over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents. The Tech Trace reports that a WhatsApp representative has confirmed the messenger is testing out new age verification on some user accounts to comply with a new law in India. The prolific and controversial security researcher who goes by Nightmare-Eclipse released a ninth 0-day vulnerability that allows an attacker to gain SYSTEM level privileges.

While an investigation into the intrusion remains ongoing, Hugging Face said it has found no evidence that the AI agent tampered with public, user-facing models, datasets, or Spaces, and its own software supply chain. In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. Several Artifactory CVE records were published on July 27 with affected-version ranges and fixed-version thresholds, but neither JFrog nor OpenAI has said whether any of those records correspond to the vulnerabilities used during the evaluati… Self-hosted users should review the Artifactory release notes and move to the remediating build for their maintained branch. “One of these four accounts was used as an outbound relay and staging path, and another account was used for data st…

This is relevant to organizations in healthcare, research, wearables and advanced analytics responsible for processing these emerging high-risk data types. Last month, they published guidance addressing the main concepts of neurotechnology and the application of privacy legislation to the processing of neural data. Elsewhere, Canada’s privacy regulator published the results of its latest survey of Canadian businesses on privacy issues. The guidance is expected to require organizations to establish stronger visibility across their AI and analytics pipelines and source data. On June 19, the data complaints handling requirements of the Data (Use and Access) Act 2025 will come into force for organizations in the UK.

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

This enforcement action stemmed from a ransomware attack in September 2023, compromising over 12 terabytes of sensitive hotel customer data, including driver’s licenses and credit card numbers. This decision allows businesses to continue using broader consent practices, maintaining shared consent https://medicalcases.eu/10-top-cybersecurity-predictions-for-2019/ agreements. The Texas Attorney General sued General Motors in August of 2024, alleging similar practices relating to the collection and sale of driver data.

Signal is Looking at Adding an Option to Sign Up Without a Phone Number

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks. A spike in attacks on shipping and logistics companies is likely to result in a lot of exposed data. The lawsuit alleges that TikTok was intentionally designed to be addictive for adolescent users and that the company deceived parents about TikTok content, including by claiming the app is appropriate for children over the age of 12 in violation https://iwantmyopenid.org/category/information-technology/page/9 of the Virginia Consumer Protection Act.

Global Coverage

AI companies are shoving their AI in our faces at every turn, throwing it up against the wall in https://ordercialisjlp.com/?p=19671 a frantic effort and hope that something sticks. There is recent talk about taxing AI, which is probably a non-starter with policymakers adverse to doing anything to stand in the way of tech companies. More than a decade ago, I wrote a post about young people’s views about privacy. Younger people aren’t willingly giving up their privacy—they’re living in a world where having privacy is increasingly difficult and often impossible. But I find these sentiments to be chutzpah because young people are exposing their lives due to the way technology is nudging, pushing, cajoling, manipulating, coercing, and outright forcing them to do so.

  • In May, a federal judge dismissed a criminal indictment against Abrego Garcia, who had been accused of smuggling immigrants in the U.S. illegally.
  • JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
  • Here’s what that would mean for users of the social media platform.
  • The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
  • Sogang University in Seoul has suffered a cyberattack that exposed personal information belonging to roughly 180,000 students, …

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. This week, FTC Chair Andrew Ferguson sent letters to private-sector companies detailing how the commission intends to police compliance once enforcement begins. A new national security memo allowing the private sector to go after criminals in cyberspace leaves legal quandaries. The show was created by Jonathan Glatzer, who was a writer and producer for several TV series including Succession, Better Call Saul, and Bloodline.

  • Torrents become a savior when every service exploits users’ demands with premium offerings.
  • In at least one compromised instance, the attacks led to the deployment of a backdoor and.
  • The show was created by Jonathan Glatzer, who was a writer and producer for several TV series including Succession, Better Call Saul, and Bloodline.
  • More alerts are making your team slower, and an outcome-based SOC fixes that July 20, 2026
  • According to a Biden administration statement released in October, many action items from the AI EO have already been completed.

A hollowed out data layer is making CISOs fly blind into AI attacks August 18, 2026 Geo-blocking systems block sites and apps from users outside specified locations. Torrents become a savior when every service exploits users’ demands with premium offerings. That’s how we ensure recommending only the best of the best privacy tools to you.

privacy security news

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders

privacy security news

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack. The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police. Some Taylor Swift-related searches on X are returning error messages after platform pledged last week to “take appropriate actions” against accounts that shared fake images of singer. AT&T failed to ensure that a third-party vendor adequately protected the telecom carrier’s customers, regulators say. Here’s what that would mean for users of the social media platform.

privacy security news

OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

Anthropic has revealed that Claude AI models compromised third-party organizations Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests

LG to Remove Smart TV Apps that Turn Devices into Residential Proxies

Privacy International and global allies are engaging in the drafting process of an ILO Convention and Recommendation concerning decent work in the platform economy. Civil-society groups warn that these changes weaken public oversight at a time when lobbying by large technology companies is intensifying. AI systems like Mythos make vulnerability discovery faster and more scalable, raising urgent privacy questions about who governs access to powerful tools that could expose centralised stores of personal data. PI’s investigation into two AI recruitment platforms exposes a lack of transparency and fairness for candidates in opaque and often unreliable systems.

Write a Comment

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *