White House to Issue Executive Order on Personal Information Protection

A coming White House Executive Order seeks to protect personal information by preventing the mass transfer of Americans’ sensitive data to countries of concern.
The post White House to Issue Executive Order on Personal Information Protection appeared f… Continue reading White House to Issue Executive Order on Personal Information Protection

Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

Atlassian warns that a critical vulnerability in Confluence Data Center and Server could lead to significant data loss if exploited.
The post Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability appeared first o… Continue reading Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages

Exposed data includes backup of employees workstations, secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages.
The post Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages appeared… Continue reading Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages

API Security Need to Know: Lessons Learned From the Peloton Security Incident

By now most have heard about the Peloton data breach incident and no doubt the security team at Peloton is working long, hard hours to pull themselves out of this horrible situation. The damage is done but there are lessons we can, and should, learn fr… Continue reading API Security Need to Know: Lessons Learned From the Peloton Security Incident

Good Heavens! 10M Impacted in Pray.com Data Exposure

The information exposed in a public cloud bucket included PII, church-donation information, photos and users’ contact lists. Continue reading Good Heavens! 10M Impacted in Pray.com Data Exposure

GrowDiaries Exposes Emails, Passwords of 1.4M Cannabis Growers

Cannabis journaling platform GrowDiaries exposed more than 3.4 million user records online, many from countries where pot is illegal. Continue reading GrowDiaries Exposes Emails, Passwords of 1.4M Cannabis Growers

Freepik Company Discloses Data Breach Affecting More Than 8 Million Users

The Freepik Company has disclosed a data breach impacting the login information of more than 8 million Freepik and Flaticon users. According to a press release, the security incident was the result of a SQL injection in Flaticon, one of the world’s lar… Continue reading Freepik Company Discloses Data Breach Affecting More Than 8 Million Users

Canada Revenue Agency Discloses Credential Stuffing Attack on 5,500 Service Accounts

A credential stuffing attack targeting Canada Revenue Agency (CRA) accounts has forced the government tax collector to suspend its online services over the weekend. The compromised accounts were linked to the GCKey portal, a system used by 30 federal d… Continue reading Canada Revenue Agency Discloses Credential Stuffing Attack on 5,500 Service Accounts