IT Security & Privacy

South Korea Issues Detailed Guidelines for Foreign Companies on Data Protection Compliance

The Personal Information Protection Commission (PIPC) of South Korea has released comprehensive guidelines titled "Guidelines on Applying the Personal Information Protection Act to Foreign Business Operators." These guidelines aim to help foreign companies navigate and comply with South Korea's Personal Information Protection Act (PIPA), particularly in light of major amendments made to the law in 2023.

Verizon Subsidiary Hit with $16M FCC Fine Over API Security Lapses

TracFone Wireless has agreed to pay $16 million to settle Federal Communications Commission (FCC) investigations into a series of data breaches that exposed customer information. The settlement, announced on July 22, 2024, highlights growing concerns over API security in the telecommunications industry.

The Evolving Landscape of Cybersecurity: Challenges & Opportunities in 2024

The cybersecurity sector faces a delicate balancing act between protection, progress, and business enablement. As cyber threats grow more sophisticated and widespread, organizations are increasingly challenged to safeguard their operations while still driving innovation and efficiency. This dynamic environment demands a comprehensive approach to cybersecurity that addresses rising costs, emerging threats, and the integration of advanced technologies.

ESAs Establish Framework to Strengthen Coordination in Case of Systemic Cyber Incidents

The three European Supervisory Authorities (EBA, EIOPA, and ESMA – collectively known as the ESAs) have announced the establishment of the EU Systemic Cyber Incident Coordination Framework (EU-SCICF). This initiative, rooted in the Digital Operational Resilience Act (DORA), aims to bolster the financial sector’s response to cyber incidents that threaten financial stability by enhancing coordination among financial authorities and other relevant entities within the European Union, as well as with key international actors.

Disney Hit by Data Leak from Internal Slack Channels

The Wall Street Journal has reported that entertainment giant Disney is facing a significant data breach, with internal communications from its Slack workplace collaboration system leaked online. The breach, claimed by an anonymous hacking group called Nullbulge, reportedly includes discussions about ad campaigns, studio technology, and interview candidates.

Rite Aid Reports Data Breach Affecting Customers from 2017-2018

Rite Aid Corporation announced today that it has fallen victim to a cybersecurity incident, potentially exposing personal information of customers who made purchases between June 6, 2017, and July 30, 2018. The pharmacy chain, currently trading over-the-counter following its Chapter 11 bankruptcy filing last year, is in the process of notifying affected individuals.

AT&T Reports Illegal Download of Customer Data in Major Security Breach

In a significant cybersecurity incident, AT&T has recently disclosed that customer data was illegally downloaded from a third-party cloud platform workspace in April. The telecommunications giant is now working closely with law enforcement to apprehend those responsible for the breach, with at least one person already in custody.