IT Security & Privacy

Nationwide Hospital System Paralyzed by Devastating Cyber Attack

In a crippling blow to the healthcare sector, a widespread cyber attack has thrown hospital systems across the United States into disarray, leading to the suspension of medical services, the diversion of ambulances, and the scramble to find alternative solutions. Prospect Medical Holdings, a prominent healthcare provider based in California, confirmed the incident, highlighting the severity of the data security breach.

Instagram Agrees to $68.5 Million Settlement in Landmark Illinois Biometric Privacy Lawsuit

Instagram, a subsidiary of Meta Platforms, has reached a settlement of $68.5 million to resolve a class-action lawsuit stemming from alleged violations of the stringent Illinois Biometric Information Privacy Act (BIPA). This landmark settlement highlights the growing challenges tech companies face in adhering to state-specific biometric privacy laws.

Escalating Toll: MOVEit Data Breach Damage Grows as Health Records of Millions Exposed

The fallout from the colossal MOVEit data breach has intensified as a US government contractor, Maximus, reveals that up to 11 million records of sensitive health data have been exposed. The breach, attributed to the Russian hacking group Cl0p, has sent shockwaves through various sectors, with at least 500 victims identified so far. The incident underscores the far-reaching consequences of cyberattacks and the urgent need for robust cybersecurity measures.

Meta Faces Increased Pressure from European Regulator Over Data Privacy

Social media giant Meta Platforms, known for its flagship platform Facebook and Instagram, is confronting mounting pressure from European privacy regulators over its data privacy practices. The company is considering a major policy shift that would give European users the option to decide whether they want to see ads targeted based on their interactions with Meta's apps.

Contributor Insight: Navigating Cybersecurity Risk Management Strategy in the Face of New SEC Rules

Contributor Insight - On July 26th, the Securities and Exchange Commission (SEC) adopted long-anticipated rules that require public companies to disclose material cybersecurity incidents and their cybersecurity risk management strategy. These rules are designed to provide greater transparency and keep investors and the public informed about a company’s cybersecurity resilience and recovery efforts.

Contributor Press Release: AuditBoard Unveils New IT Risk Management Solution

Contributor Press Release - AuditBoard today announced the availability of AuditBoard ITRM, its new IT Risk Management solution. This new offering will enable IT security and risk management professionals to manage their threat landscape, quantify IT-related risks, and improve cyber resilience — helping their organizations keep pace in a world of continuously evolving and expanding business risk.

California State Agency Probes Automakers Over Data Privacy Concerns

Amid increasing concerns about the extensive collection of data by vehicles, the California Privacy Protection Agency (CPPA) has initiated a review of the privacy practices of automakers and vehicle technology companies. The CPPA's Enforcement Division is currently conducting inquiries into the data privacy policies of vehicles equipped with various features such as location sharing, web-based entertainment, smartphone integration, and cameras. The agency highlighted the critical nature of these vehicle privacy considerations, as modern vehicles act as connected computers on wheels, capable of collecting a wealth of information that may include consumers' locations, personal preferences, and details about their daily lives.