Skip to main content

Tag: data protection

492 articles

student data Shocking Risky Exposure in School Email

student data Shocking Risky Exposure in School Email

A routine flu jab email at a Birmingham secondary school accidentally exposed personal details for hundreds of students, leaving parents alarmed and prompting urgent questions about data handling. The blunder shows how simple communication mistakes can erode trust—and why schools and health providers need stronger safeguards and clearer, safer ways to share information.

Analyst 207
SAP NetWeaver Must-Have Patch: Critical Risk Fix

SAP NetWeaver Must-Have Patch: Critical Risk Fix

SAP released urgent patches for critical NetWeaver and S/4HANA flaws — including a CVSS 10.0 deserialization bug that can enable remote code execution — so teams should quickly identify affected systems and apply fixes or mitigations.

Analyst 207
fitness call recordings: Stunning Privacy Risk

fitness call recordings: Stunning Privacy Risk

Imagine your gym keeping 1.6 million unprotected call recordings—names, payment details and even voiceprints—on an open database anyone could access. This wake‑up call shows how easily convenience becomes a privacy disaster unless companies encrypt, limit retention and lock down access now.

Analyst 207
SAP S/4HANA vulnerability: Critical Risky Threat

SAP S/4HANA vulnerability: Critical Risky Threat

A critical SAP S/4HANA vulnerability (CVE-2025-42957) is already being exploited in the wild, turning routine patching into an urgent race. Inventory exposed systems, apply mitigations or patches now, and hunt for signs of compromise before attackers reach your finance and HR systems.

Analyst 207
JLR cyberattack: Exclusive Risky Extortion Claim

JLR cyberattack: Exclusive Risky Extortion Claim

Jaguar Land Rover is probing claims by a group calling itself Scattered Spider that it stole data and issued an extortion demand. The incident highlights growing cyber risks for automakers — from customer privacy to vehicle software and supply-chain vulnerabilities.

Analyst 207
live facial recognition: Risky Exclusive Retail Trial

live facial recognition: Risky Exclusive Retail Trial

Sainsbury’s is trialling live facial recognition in two stores to catch repeat shoplifters, promising reduced losses and safer staff—but privacy advocates warn it’s intrusive, error-prone and could normalize constant surveillance. Will a few prevented thefts justify scanning shoppers’ faces, or will public concern and regulation redraw the line?

Analyst 207
cookie privacy failures: Stunning Harsh Fines Exposed

cookie privacy failures: Stunning Harsh Fines Exposed

France’s privacy watchdog hit Google and SHEIN with big fines for dropping tracking cookies and serving ads without proper consent — a wake-up call that could reshape online advertising and give users real control over their data.

Analyst 207
data leaks: Must-Have Critical Detection Tips

data leaks: Must-Have Critical Detection Tips

A single exposed ClickHouse instance showed how quiet misconfigurations can hand attackers the breadcrumbs they need; detecting leaks early turns that slow-burning risk into a manageable incident. Start with inventory, automated scans, and clear playbooks to stop a minor misstep from becoming a full-blown disaster.

Analyst 207
cyber incident: Stunning Risky Blow to Jaguar Sales

cyber incident: Stunning Risky Blow to Jaguar Sales

A recent cyber incident forced Jaguar to take IT systems offline, halting production and leaving workers home and customers wondering about deliveries. It’s a clear reminder that modern, connected factories can be brought to their knees by digital attacks — with real costs to sales, jobs and reputation.

Analyst 207
exposed Ollama servers: Risky Must-Have Security Fix

exposed Ollama servers: Risky Must-Have Security Fix

Cisco Talos found 1,100+ publicly exposed Ollama servers, creating easy paths for data theft, malicious model swaps, and other abuse. It’s a wake-up call to fix misconfigurations, enforce authentication, and make secure defaults the norm.

Analyst 207
restaurant robots: Shocking Security Risks Exposed

restaurant robots: Shocking Security Risks Exposed

A researcher known for probing McDonald’s systems found Pudu Robotics left administrative controls wide open, letting attackers redirect delivery bots and issue arbitrary commands. Restaurants, hotels and regulators need to act now to secure these ubiquitous machines before misuse causes safety, privacy or reputational harm.

Analyst 207
generative AI Stunning Risky Ban Divides Web

generative AI Stunning Risky Ban Divides Web

Vivaldi CEO Jon von Tetzchner drew a line in the sand by banning generative AI agents from browsing the web, arguing automation undermines consent, copyright and publishers’ income. The move reignites a crucial debate over who gets to shape the future of the open web.

Analyst 207
systemic failures: Stunning $97M fine signals severe risk

systemic failures: Stunning $97M fine signals severe risk

SK Telecom was slapped with a record ₩134.5 billion (≈$97M) fine after regulators found basic security blunders that left internal networks exposed — a sharp reminder that weak segmentation and access controls can turn routine services into a breach gateway. The penalty is meant to punish the lapses and push the industry toward stronger, lasting protections for user data.

Analyst 207
Church of England Shocking Data Leak: Damaging Trust Breach

Church of England Shocking Data Leak: Damaging Trust Breach

A London law firm’s mass-email blunder exposed nearly 200 Church of England abuse survivors, shredding fragile trust and reigniting fears about privacy and stigma. Survivors are asking for concrete, survivor-led fixes—independent audits, better tech and trauma‑informed protections—if an apology is to mean anything.

Analyst 207
cybersecurity legislation: Must-Have Rules, Risky Tradeoffs

cybersecurity legislation: Must-Have Rules, Risky Tradeoffs

A new CIISec poll shows most security professionals want tougher, clearer cybersecurity laws—urging policymakers to create practical, enforceable rules that boost defenses without stifling innovation. If lawmakers listen and invest in enforcement and workforce skills, stronger regulation could deliver real protection for businesses and citizens.

Analyst 207
Commvault RCE: Critical Exploit – Patch Immediately

Commvault RCE: Critical Exploit – Patch Immediately

Could your backup system be a backdoor? Commvault patched four pre-auth vulnerabilities (notably CVE-2025-57788) in 11.36.60 that can be chained into remote code execution—update now or apply compensating controls to protect your backups and recovery.

Analyst 207
SIM-swap attacks: Must-Have Urgent Defenses

SIM-swap attacks: Must-Have Urgent Defenses

A major breach exposing SIM identifiers makes SIM‑swap attacks a real and urgent risk — but you can protect yourself now by switching from SMS to app- or hardware-based MFA, adding a carrier PIN or passphrase, and watching your accounts for suspicious activity.

Analyst 207
unauthenticated remote code execution: Critical Must-Have Patch

unauthenticated remote code execution: Critical Must-Have Patch

Commvault has released urgent patches after researchers published working exploits for two unauthenticated remote‑code‑execution chains—if you use Commvault, update now and audit your systems. This wake‑up call shows how critical backup infrastructure is and why quick patching, stronger access controls, and offline or immutable backups are essential to avoid catastrophic breaches.

Analyst 207
Warlock ransomware: Exclusive Critical Threat to SharePoint

Warlock ransomware: Exclusive Critical Threat to SharePoint

If your organization still runs on-premises SharePoint, Trend Micro’s findings are a wake-up call: attackers are using a ToolShell exploit to turn unpatched SharePoint instances into staging grounds for multi-stage Warlock ransomware campaigns that can steal data and cripple recovery. Patch promptly, lock down admin access, and treat collaboration platforms as critical assets before a trusted service becomes an easy path to extortion.

Analyst 207
Allianz Life data breach: Stunning Risky Fallout

Allianz Life data breach: Stunning Risky Fallout

About 1.1 million Allianz Life customers may have had personal data exposed in a breach tied to the ShinyHunters group — here’s what to watch for and the quick steps you can take now to protect your identity and finances.

Analyst 207
body-worn video Shocking Breach: Must-Have Fixes

body-worn video Shocking Breach: Must-Have Fixes

When 96,000 body‑cam files disappeared during a system migration, the ICO’s rebuke laid bare how fragile trust in police video can be — and why stronger technical safeguards, clear retention rules and independent oversight aren’t optional but essential to restore confidence.

Analyst 207
website after cyberattack: Risky Stunning Supply Outage

website after cyberattack: Risky Stunning Supply Outage

What do you do when the system that tells retailers what’s on the shelf goes dark? Stock in the Channel pulled its site after a cyberattack — saying customer data appear safe but providing no forensic report or timeline — leaving partners scrambling with manual checks, delayed orders and shaken trust.

Analyst 207
manpower data breach: Exclusive Risky Impact Revealed

manpower data breach: Exclusive Risky Impact Revealed

Manpower has disclosed a breach exposing personal data of nearly 145,000 registrants, putting jobseekers, contractors and clients at heightened risk of identity theft and fraud. If you applied for temp work, monitor your accounts and credit, be wary of recruitment scams, and ask Manpower what specific data was exposed.

Analyst 207
portable forensics labs: Must-Have, Game-Changing Upgrade

portable forensics labs: Must-Have, Game-Changing Upgrade

Imagine turning a scrap of blood or a smudge of a fingerprint into an ID in minutes, not days. The Marine Corps’ new portable forensics kits put lab-grade collection, analysis and secure reporting in warfighters’ hands to speed investigations, protect troops and sharpen intelligence—while calling for rigorous training, chain‑of‑custody rules and legal safeguards.

Analyst 207