FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

By: THN β€” September 19th 2023 at 04:05
Microsoft on Monday said it took steps to correct a glaring security gaffe that led to the exposure of 38 terabytes of private data. The leak was discovered on the company's AI GitHub repository and is said to have been inadvertently made public when publishing a bucket of open-source training data, Wiz said. It also included a disk backup of two former employees' workstations containing secrets
☐ β˜† βœ‡ The Hacker News

India Passes New Digital Personal Data Protection Bill (DPDPB), Putting Users' Privacy First

By: THN β€” August 14th 2023 at 05:20
The Indian President Droupadi Murmu on Friday granted assent to the Digital Personal Data Protection Bill (DPDPB) after it was unanimously passed by both houses of the parliament last week, marking a significant step towards securing people's information. "The Bill provides for the processing of digital personal data in a manner that recognizes both the rights of the individuals to protect their
☐ β˜† βœ‡ The Hacker News

Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

By: THN β€” July 28th 2023 at 05:07
Cybersecurity agencies in Australia and the U.S. haveΒ publishedΒ a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data. This includes a specific class of bugs called Insecure Direct Object Reference (IDOR), a type of access control flaw that occurs when an
☐ β˜† βœ‡ The Hacker News

E.U. Regulators Hit Meta with Record $1.3 Billion Fine for Data Transfer Violations

By: Ravie Lakshmanan β€” May 22nd 2023 at 17:48
Facebook's parent company Meta has been fined a record $1.3 billion by European Union data protection regulators for transferring the personal data of users in the region to the U.S. In a binding decision taken by the European Data Protection Board (EDPB), the social media giant has been ordered to bring its data transfers into compliance with the GDPR and delete unlawfully stored and processed
☐ β˜† βœ‡ The Hacker News

Kodi Confirms Data Breach: 400K User Records and Private Messages Stolen

By: Ravie Lakshmanan β€” April 14th 2023 at 10:22
Open source media player software provider Kodi has confirmed a data breach after threat actors stole the company's MyBB forum database containing user data and private messages. What's more, the unknown threat actorsΒ attempted to sellΒ the data dumpΒ comprising 400,635 Kodi usersΒ on the now-defunctΒ BreachForumsΒ cybercrime marketplace. "MyBB admin logs show the account of a trusted but currently
☐ β˜† βœ‡ The Hacker News

Google Mandates Android Apps to Offer Easy Account Deletion In-App and Online

By: Ravie Lakshmanan β€” April 6th 2023 at 03:40
Google is enacting a new data deletion policy for Android apps that allow account creation to also offer users with a setting to delete their accounts in an attempt to provide more transparency and control over their data. "For apps that enable app account creation, developers will soon need to provide an option to initiate account and data deletion from within the app and online," Bethel
☐ β˜† βœ‡ The Hacker News

LockBit 3.0 Ransomware: Inside the Cyberthreat That's Costing Millions

By: Ravie Lakshmanan β€” March 18th 2023 at 05:17
U.S. government agencies have released a joint cybersecurity advisory detailing the indicators of compromise (IoCs) and tactics, techniques, and procedures (TTPs) associated with the notoriousΒ LockBit 3.0 ransomware. "The LockBit 3.0 ransomware operations function as a Ransomware-as-a-Service (RaaS) model and is a continuation of previous versions of the ransomware, LockBit 2.0, and LockBit,"
☐ β˜† βœ‡ The Hacker News

Tick APT Targeted High-Value Customers of East Asian Data-Loss Prevention Company

By: Ravie Lakshmanan β€” March 15th 2023 at 09:23
A cyberespionage actor known as Tick has been attributed with high confidence to a compromise of an East Asian data-loss prevention (DLP) company that caters to government and military entities. "The attackers compromised the DLP company's internal update servers to deliver malware inside the software developer's network, and trojanized installers of legitimate tools used by the company, which
☐ β˜† βœ‡ The Hacker News

Experts Reveal Google Cloud Platform's Blind Spot for Data Exfiltration Attacks

By: Ravie Lakshmanan β€” March 6th 2023 at 11:51
Malicious actors can take advantage of "insufficient" forensic visibility into Google Cloud Platform (GCP) to exfiltrate sensitive data, a new research has found. "Unfortunately, GCP does not provide the level of visibility in its storage logs that is needed to allow any effective forensic investigation, making organizations blind to potential data exfiltration attacks," cloud incident response
❌