Topic: incident reporting
-
CISA warns Medusa ransomware hit 500+ organizations
Medusa ransomware has compromised over 500 organizations since June 2021, targeting critical infrastructure sectors including healthcare, defense, manufacturing, and government services, according to a joint FBI, CISA, and HHS advisory updated with FBI casework through April 2026. The operation e...
Read More » -
Tesla FSD v14 swerved toward ditch, driver reports
Tesla FSD v14.3.6 attempted to veer into a ditch at 110 km/h on an empty, clearly marked highway after missing an exit ramp, requiring manual driver intervention to prevent a crash. The incident occurred under ideal conditions (clear markings, dry pavement, no traffic) with no warning cues, highl...
Read More » -
Researcher buys noreply.net, receives company secrets
A security researcher who owns the domains noreply.us and noreply.net has inadvertently created a "honeypot," receiving over 400,000 emails since December 2024,roughly 700 per day,containing sensitive data like injury reports, service orders, and corporate credentials. The flood occurs because co...
Read More » -
NVIDIA Unveils SAFE Initiative for Agentic Threat Intel Sharing
More than 120 tech firms launched the Shared AI Findings Exchange (SAFE) framework to enable confidential, collaborative sharing of agentic AI security threat intelligence, addressing the lack of a community standard for discussing AI operational failures. SAFE's draft principles include confiden...
Read More » -
Prompt Injection Still Top LLM Threat Despite Few Cases
OWASP's 2026 Top 10 for LLM Applications again ranks prompt injection as the top threat, despite few recorded incidents, because security teams invest heavily in preventing it before exploitation. Prompt injection, which manipulates LLMs into unintended behavior like leaking sensitive data, remai...
Read More » -
KT Fined $39M Over Misleading Femtocell Campaign
South Korea's PIPC fined KT approximately $39 million after hackers exploited a stolen femtocell certificate to intercept traffic and make unauthorized micropayments, defrauding 368 customers of about $175,000 and compromising data for 16,647 users. The regulator found KT's femtocell management s...
Read More » -
South Korea fines KT $39M for customer data breach
South Korea's data protection regulator fined telecom giant KT Corporation approximately $39 million (KRW 53.979 billion) after a femtocell-based network intrusion went undetected for nearly a year, exposing data of 16,647 subscribers and enabling fraudulent mobile payments affecting at least 368...
Read More » -
Waymo robotaxis return to freeways
Waymo is gradually resuming freeway routes in Phoenix, Los Angeles, and the San Francisco Bay Area after pausing them in May due to issues near construction zones, with software updates improving scene recognition and routing capabilities. The pause and restart come amid heightened scrutiny from ...
Read More » -
India's CERT-In Mandates 12-Hour Patch Fix for Critical Flaws
CERT-In mandates a 12-hour remediation window for known exploited vulnerabilities on internet-facing systems in India, driven by the accelerating threat of AI-powered cyberattacks. The directive establishes a risk-based patching schedule with escalating timelines for different vulnerability categ...
Read More » -
OpenLoop Health Data Breach Affects 716,000
OpenLoop Health, a telehealth platform, suffered a data breach in January 2026 that compromised the personal information of approximately 716,000 individuals, including names, addresses, Social Security numbers, and medical data. The company has notified affected users and is offering credit moni...
Read More » -
UK Cybersecurity Market Hits £14.7bn, Fueled by AI Growth
The UK cybersecurity sector generated £14.7bn in revenue last year, contributed £9.1bn in gross value added (a 17% increase), and now supports nearly 70,000 jobs, while the number of AI-powered cybersecurity firms surged by 68% to 111. The government launched the Cyber Resilience Pledge, encourag...
Read More » -
Credential Management as a Financial Risk Control in DORA
DORA's Article 9 mandates that financial institutions implement least-privilege policies and strong authentication mechanisms (like FIDO2/WebAuthn), making credential security a legal requirement with supervisory consequences. Stolen credentials are the leading initial attack vector in 2025, acco...
Read More » -
FBI: Chinese Mobile Apps Pose Privacy Risks
The FBI warns that foreign-developed mobile apps, particularly from China, pose significant privacy risks as their developers can be legally compelled to share user data with foreign governments. These applications often engage in extensive, sometimes surreptitious, data harvesting, collecting se...
Read More » -
Most European Financial Firms Fail DORA Compliance
Most European financial institutions are struggling to achieve full compliance with the Digital Operational Resilience Act (DORA), facing significant operational hurdles and the threat of severe penalties for non-compliance. A major compliance obstacle is creating the mandatory Register of Inform...
Read More » -
EU Strengthens Cybersecurity Rules for Tech Supply Chains
The European Commission has launched a new cybersecurity strategy, updating the EU Cybersecurity Act to secure ICT supply chains and ensure products are inherently secure through a standardized certification process. A reformed European Cybersecurity Certification Framework (ECCF) will enable fas...
Read More » -
Tesla Granted 5-Week Extension in FSD Probe
The NHTSA has extended Tesla's deadline to comply with a broad information request for its safety probe into the Full Self-Driving (FSD) beta software, which is under investigation due to reports of traffic control violations. The regulator demands extensive data, including a full U.S. vehicle in...
Read More » -
Parliament Seeks Security Experts to Bolster Cyber Resilience
A UK parliamentary committee is actively seeking expert evidence to refine the proposed Cyber Security and Resilience Bill, a major legislative update for critical infrastructure protection. The bill expands regulatory scope to include new entities like managed service providers, mandates stricte...
Read More » -
Instagram Resolves Password Reset Email Glitch
Instagram resolved a widespread glitch that erroneously sent password reset emails to users, confirming an external party triggered the automated messages. The platform assured users their accounts remained secure with no unauthorized access, advising recipients to simply ignore the unsolicited e...
Read More » -
Ransomware Gangs Extorted $2.1B in Two Years: FinCEN
Ransomware extortion surged, with criminals collecting over $2.1 billion from 2022-2024, nearly matching the total from the previous eight years. While 2023 was a peak year, ransom payments dropped sharply in 2024, largely due to successful law enforcement actions against major gangs like ALPHV/B...
Read More » -
UK Cyber Resilience Bill: Key Provisions Unveiled
The UK is introducing the Cyber Security and Resilience Bill in response to a 130% surge in significant cyber incidents, aiming to strengthen national digital defenses and protect essential services. The bill expands regulatory scope by classifying data centers, managed service providers, and oth...
Read More »