Veeam warns of critical RCE flaw in Backup & Replication software

September 5, 2024 at 10:23AM Veeam has released a security bulletin addressing 18 high and critical severity flaws in Veeam Backup & Replication, Service Provider Console, and ONE. The most severe is a remote code execution vulnerability on Veeam Backup & Replication, posing a high risk of ransomware exploitation. Multiple critical vulnerabilities have also been … Read more

Planned Parenthood confirms cyberattack as RansomHub claims breach

September 5, 2024 at 01:36AM Planned Parenthood experienced a cyberattack, prompting the organization to shut down parts of its IT systems to mitigate the impact. Based on the meeting notes, it appears that Planned Parenthood experienced a cyberattack that impacted its IT systems, leading to the need to take certain parts of its infrastructure offline … Read more

California Approves Privacy Bill Requiring Opt-Out Tools

September 4, 2024 at 06:23AM The California state legislature passed a bill requiring internet browsers and mobile operating systems to offer a mechanism for users to opt out of the sale or sharing of their personal information. The bill now awaits Governor Gavin Newsom’s signature. This will result in a standardized process for opt-out requests, … Read more

Clearview AI Faces €30.5M Fine for Building Illegal Facial Recognition Database

September 4, 2024 at 05:18AM The Dutch Data Protection Authority has fined Clearview AI €30.5 million for violating the GDPR by creating an “illegal database” of billions of facial photos without consent. Clearview faces further penalties if it doesn’t cease violations. The company claims it isn’t subject to EU regulations, but the Dutch DPA is … Read more

Clearview AI fined €30.5 million for unlawful data collection

September 3, 2024 at 01:17PM The Dutch Data Protection Authority fined Clearview AI €30.5 million for illegal facial recognition data collection of Dutch citizens. The company’s technology compiles a vast database of faces from public internet sources without consent, prompting privacy and ethical concerns. Clearview AI disputes the fine, claiming lack of EU jurisdiction. Additional … Read more

Data watchdog fines Clearview AI $33M for ‘illegal’ data collection

September 3, 2024 at 11:42AM The Dutch Data Protection Authority fined Clearview AI €30.5 million for “illegal” collection of images, violating the GDPR. Clearview argues it’s not subject to EU laws. Despite being based in the US, the DPA believes the company must comply. They’re also considering holding Clearview’s management personally liable. The company’s future … Read more

BlackCat Spinoff ‘Cicada3301’ Uses Stolen Creds on the Fly, Skirts EDR

September 3, 2024 at 10:23AM Cicada3301, a new ransomware, has evolved from the infamous 4chan puzzle project. It has already compromised 21 companies, mainly in Europe and North America. With advanced features and similarities to BlackCat ransomware, it poses a significant threat. Its stealth tactics and obfuscation have raised concerns, emphasizing the need for robust … Read more

Clearview AI Fined $33.7 Million by Dutch Data Protection Watchdog Over ‘Illegal Database’ of Faces

September 3, 2024 at 10:18AM The Netherlands’ Data Protection Agency fined Clearview AI 30.5 million euros for creating an “illegal database” of billions of photos without sufficient consent. Clearview’s chief legal officer contested the decision, claiming it falls outside EU data protection regulations. The company faces further penalties if it continues to breach regulations. Clearview … Read more

Intel Responds to SGX Hacking Research

September 3, 2024 at 06:51AM Security researcher Mark Ermolov claims to have made progress in hacking Intel’s SGX data protection technology, extracting cryptographic keys. Johns Hopkins University’s Pratyush Ranjan Tiwari highlighted the severity of this breach, affecting older processors widely used in embedded systems. Intel responded, stating the tests were conducted on unmitigated systems with … Read more

Business services giant CBIZ discloses customer data breach

September 2, 2024 at 11:39AM CBIZ, a management consulting company, reported a data breach involving unauthorized access and theft of customer data. The breach, detected on June 24, 2024, affected nearly 36,000 individuals, exposing personal information such as names, contact details, and Social Security numbers. Impacted clients have been offered credit monitoring and identity theft … Read more