IT Security & Privacy

16 Billion Credentials Exposed in Unprecedented Breach

Somewhere, buried in an unsecured cloud server, were 16 billion reasons to worry about your organization’s security posture. They weren’t ransomware payloads or zero-days. They were passwords. And not just a few stray credentials, 16 billion of them.

Irish DPC Report Shows Continued AI Scrutiny, Record Fines, & Public Concern Over Data Use

Ireland’s Data Protection Commission (DPC) published its 2024 Annual Report this week, offering a wide-ranging account of enforcement activity, regulatory developments, and public sentiment around data protection in a year marked by growing scrutiny of artificial intelligence and increasing cross-border responsibilities.

23andMe Fined for Failing to Protect UK Users' Genetic Data

In the wake of a 2023 data breach that exposed the sensitive personal data of over 155,000 UK residents, genetic testing company 23andMe has been fined £2.31 million by the UK Information Commissioner’s Office (ICO) for failing to implement adequate security measures to protect user information.

Norwegian Data Protection Authority Cracks Down on Unlawful Data Sharing Through Tracking Pixels

The Norwegian Data Protection Authority’s (DPA) has uncovered troubling breaches of personal data laws across six websites. These sites, all of which shared personal data without proper consent, are now facing the consequences of their actions. The DPA’s findings reveal that in some cases, sensitive personal information, including that of vulnerable children, was sent to third parties without users’ knowledge, a clear violation of GDPR.

EU Adopts New Cyber Crisis Management Blueprint to Strengthen Response

In a move that reflects both urgency and foresight, the European Union has adopted a revised Cybersecurity Crisis Management Blueprint. The newly updated framework, approved by EU Member States at a recent Council meeting, aims to fortify the Union’s ability to handle large-scale cyber incidents and crises. It’s a response to a growing reality of cyber threats evolving faster than ever, and the Union needs a well-coordinated plan to face these challenges head-on.

New Developments in the EU’s National Cybersecurity Strategies

Cybersecurity has never been more crucial than it is today. To keep pace with the increasing number of threats, the European Union is taking a bold step forward with the unveiling of the updated National Cybersecurity Strategies (NCSS) Interactive Map, a game-changing platform from the European Union Agency for Cybersecurity (ENISA). Think of it as your go-to hub for all things EU cybersecurity, offering not only valuable insights but a fresh perspective on how nations are building their digital defenses.

South Korea is Set to Launch Global Cross-Border Privacy Rules

The Personal Information Protection Commission (PIPC), in collaboration with the Korea Internet & Security Agency (KISA), has announced the official launch of the Global Cross-Border Privacy Rules (Global CBPR) Certification System. Starting June 2, 2025, this new system will help businesses easily navigate the complex world of international data flows, allowing them to expand into global markets while prioritizing privacy.