Topic: incident reporting

  • CISA warns Medusa ransomware hit 500+ organizations

    CISA warns Medusa ransomware hit 500+ organizations

    Medusa ransomware has compromised over 500 organizations since June 2021, targeting critical infrastructure sectors including healthcare, defense, manufacturing, and government services, according to a joint FBI, CISA, and HHS advisory updated with FBI casework through April 2026. The operation e...

    Read More »
  • Tesla FSD v14 swerved toward ditch, driver reports

    Tesla FSD v14 swerved toward ditch, driver reports

    Tesla FSD v14.3.6 attempted to veer into a ditch at 110 km/h on an empty, clearly marked highway after missing an exit ramp, requiring manual driver intervention to prevent a crash. The incident occurred under ideal conditions (clear markings, dry pavement, no traffic) with no warning cues, highl...

    Read More »
  • Researcher buys noreply.net, receives company secrets

    Researcher buys noreply.net, receives company secrets

    A security researcher who owns the domains noreply.us and noreply.net has inadvertently created a "honeypot," receiving over 400,000 emails since December 2024,roughly 700 per day,containing sensitive data like injury reports, service orders, and corporate credentials. The flood occurs because co...

    Read More »
  • NVIDIA Unveils SAFE Initiative for Agentic Threat Intel Sharing

    NVIDIA Unveils SAFE Initiative for Agentic Threat Intel Sharing

    More than 120 tech firms launched the Shared AI Findings Exchange (SAFE) framework to enable confidential, collaborative sharing of agentic AI security threat intelligence, addressing the lack of a community standard for discussing AI operational failures. SAFE's draft principles include confiden...

    Read More »
  • Prompt Injection Still Top LLM Threat Despite Few Cases

    Prompt Injection Still Top LLM Threat Despite Few Cases

    OWASP's 2026 Top 10 for LLM Applications again ranks prompt injection as the top threat, despite few recorded incidents, because security teams invest heavily in preventing it before exploitation. Prompt injection, which manipulates LLMs into unintended behavior like leaking sensitive data, remai...

    Read More »
  • KT Fined $39M Over Misleading Femtocell Campaign

    KT Fined $39M Over Misleading Femtocell Campaign

    South Korea's PIPC fined KT approximately $39 million after hackers exploited a stolen femtocell certificate to intercept traffic and make unauthorized micropayments, defrauding 368 customers of about $175,000 and compromising data for 16,647 users. The regulator found KT's femtocell management s...

    Read More »
  • South Korea fines KT $39M for customer data breach

    South Korea fines KT $39M for customer data breach

    South Korea's data protection regulator fined telecom giant KT Corporation approximately $39 million (KRW 53.979 billion) after a femtocell-based network intrusion went undetected for nearly a year, exposing data of 16,647 subscribers and enabling fraudulent mobile payments affecting at least 368...

    Read More »
  • Waymo robotaxis return to freeways

    Waymo robotaxis return to freeways

    Waymo is gradually resuming freeway routes in Phoenix, Los Angeles, and the San Francisco Bay Area after pausing them in May due to issues near construction zones, with software updates improving scene recognition and routing capabilities. The pause and restart come amid heightened scrutiny from ...

    Read More »
  • India's CERT-In Mandates 12-Hour Patch Fix for Critical Flaws

    India's CERT-In Mandates 12-Hour Patch Fix for Critical Flaws

    CERT-In mandates a 12-hour remediation window for known exploited vulnerabilities on internet-facing systems in India, driven by the accelerating threat of AI-powered cyberattacks. The directive establishes a risk-based patching schedule with escalating timelines for different vulnerability categ...

    Read More »
  • OpenLoop Health Data Breach Affects 716,000

    OpenLoop Health Data Breach Affects 716,000

    OpenLoop Health, a telehealth platform, suffered a data breach in January 2026 that compromised the personal information of approximately 716,000 individuals, including names, addresses, Social Security numbers, and medical data. The company has notified affected users and is offering credit moni...

    Read More »
  • UK Cybersecurity Market Hits £14.7bn, Fueled by AI Growth

    UK Cybersecurity Market Hits £14.7bn, Fueled by AI Growth

    The UK cybersecurity sector generated £14.7bn in revenue last year, contributed £9.1bn in gross value added (a 17% increase), and now supports nearly 70,000 jobs, while the number of AI-powered cybersecurity firms surged by 68% to 111. The government launched the Cyber Resilience Pledge, encourag...

    Read More »
  • Credential Management as a Financial Risk Control in DORA

    Credential Management as a Financial Risk Control in DORA

    DORA's Article 9 mandates that financial institutions implement least-privilege policies and strong authentication mechanisms (like FIDO2/WebAuthn), making credential security a legal requirement with supervisory consequences. Stolen credentials are the leading initial attack vector in 2025, acco...

    Read More »
  • FBI: Chinese Mobile Apps Pose Privacy Risks

    FBI: Chinese Mobile Apps Pose Privacy Risks

    The FBI warns that foreign-developed mobile apps, particularly from China, pose significant privacy risks as their developers can be legally compelled to share user data with foreign governments. These applications often engage in extensive, sometimes surreptitious, data harvesting, collecting se...

    Read More »
  • Most European Financial Firms Fail DORA Compliance

    Most European Financial Firms Fail DORA Compliance

    Most European financial institutions are struggling to achieve full compliance with the Digital Operational Resilience Act (DORA), facing significant operational hurdles and the threat of severe penalties for non-compliance. A major compliance obstacle is creating the mandatory Register of Inform...

    Read More »
  • EU Strengthens Cybersecurity Rules for Tech Supply Chains

    EU Strengthens Cybersecurity Rules for Tech Supply Chains

    The European Commission has launched a new cybersecurity strategy, updating the EU Cybersecurity Act to secure ICT supply chains and ensure products are inherently secure through a standardized certification process. A reformed European Cybersecurity Certification Framework (ECCF) will enable fas...

    Read More »
  • Tesla Granted 5-Week Extension in FSD Probe

    Tesla Granted 5-Week Extension in FSD Probe

    The NHTSA has extended Tesla's deadline to comply with a broad information request for its safety probe into the Full Self-Driving (FSD) beta software, which is under investigation due to reports of traffic control violations. The regulator demands extensive data, including a full U.S. vehicle in...

    Read More »
  • Parliament Seeks Security Experts to Bolster Cyber Resilience

    Parliament Seeks Security Experts to Bolster Cyber Resilience

    A UK parliamentary committee is actively seeking expert evidence to refine the proposed Cyber Security and Resilience Bill, a major legislative update for critical infrastructure protection. The bill expands regulatory scope to include new entities like managed service providers, mandates stricte...

    Read More »
  • Instagram Resolves Password Reset Email Glitch

    Instagram Resolves Password Reset Email Glitch

    Instagram resolved a widespread glitch that erroneously sent password reset emails to users, confirming an external party triggered the automated messages. The platform assured users their accounts remained secure with no unauthorized access, advising recipients to simply ignore the unsolicited e...

    Read More »
  • Ransomware Gangs Extorted $2.1B in Two Years: FinCEN

    Ransomware Gangs Extorted $2.1B in Two Years: FinCEN

    Ransomware extortion surged, with criminals collecting over $2.1 billion from 2022-2024, nearly matching the total from the previous eight years. While 2023 was a peak year, ransom payments dropped sharply in 2024, largely due to successful law enforcement actions against major gangs like ALPHV/B...

    Read More »
  • UK Cyber Resilience Bill: Key Provisions Unveiled

    UK Cyber Resilience Bill: Key Provisions Unveiled

    The UK is introducing the Cyber Security and Resilience Bill in response to a 130% surge in significant cyber incidents, aiming to strengthen national digital defenses and protect essential services. The bill expands regulatory scope by classifying data centers, managed service providers, and oth...

    Read More »