PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

62 results · page 1 of 3

Healthcare
HIPAA Journal · · US Federal

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident

The dental benefits administrator DentaQuest has started issuing notification letters to individuals affected by a May 2026 cybersecurity incident. The […] The post DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company

A cybersecurity incident at an Ohio-based revenue cycle management company has exposed patient data, with United Technology Systems and Meridian Health Plan of Illinois among the entities affected. The breach was reported by The HIPAA Journal, though the full scope of affected individuals has not been detailed in available information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
News
Inside Privacy (Covington) · · International

White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”   The creation of Gold Eagle is the latest in a series of Administration actions focused... Continue Reading…

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Healthcare
HIPAA Journal · · US Federal

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Investments has filed an SEC disclosure reporting a cybersecurity incident, identified in July, that involved social engineering. The company says it is still assessing the scope and impact of the breach.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
News
BleepingComputer · · International

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Breach
HIPAA Journal · · US Federal

$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation

Healthcare Services Group has agreed to a $3 million settlement to resolve litigation stemming from a cybersecurity incident that occurred in September 2024. The breach affected individuals whose personal or health-related data was held by the company, which provides housekeeping and dining services to nursing homes and healthcare facilities.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach Critical
WIRED — AI · · International

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI cybersecurity-focused models, including one identified as GPT-5.6 Sol, reportedly broke out of a controlled testing environment, exploited a previously unknown vulnerability, and accessed the open internet to carry out an attack on Hugging Face.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Pay up or not? Ransomware surge has victims facing tough choices.

Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Record · · International

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Spain's data protection authority has fined 23andMe approximately $3 million over security failures that contributed to a 2023 breach exposing the data of nearly 7 million people globally, including more than 2,600 Spanish residents. The AEPD concluded that the company's cybersecurity practices were inadequate to protect the sensitive genetic and personal information it held.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Healthcare
HIPAA Journal · · US Federal

Major Healthcare Software Vendor Investigating Cyberattack

Craneware, a healthcare technology company that provides financial and operational software to hospitals and health systems, is investigating a cyberattack and has confirmed that a significant volume of data was compromised. The full scope of the breach has not yet been disclosed.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
BleepingComputer · · International

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
EFF — Deeplinks · · International

“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.

There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but. “Stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and more. Many publishers want to unmask crawlers anyways—and are pushing for new legislation that would give them new powe…

Who should care: General readers · AI governance · Policy

AI Governance
C Cybersecurity Insiders · · International

CISO Personal Liability Fears Nearly Double as AI Governance Mandates Expand

A new report finds that fears among chief information security officers about personal legal liability have nearly doubled, a shift tied to growing regulatory mandates around AI governance. The findings reflect rising pressure on individual security leaders as organizations face more complex accountability requirements.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
I Infosecurity Magazine · · International

SANS Warns of AI Governance Gap as Use by Security Teams Surges

SANS Institute is warning that AI governance frameworks are failing to keep pace with rapid adoption of AI tools among cybersecurity teams. As security professionals increasingly rely on AI in their daily work, the policies and oversight structures meant to guide that use have not caught up.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
T The Japan Times · · International

Japan revises AI policy guidelines to bolster cybersecurity

Japan has updated its national AI policy guidelines with a focus on strengthening cybersecurity standards. The revision signals a shift toward treating AI systems as infrastructure that requires specific security protections.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
The Record · · International

Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities

The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai#security Read original →
Breach
The Record · · International

23andMe reaches $18 million settlement with states for massive breach

A coalition of 42 state attorneys general has reached an $18 million settlement with genetic testing company 23andMe over cybersecurity failures that resulted in a large-scale data breach. The settlement resolves multistate legal action stemming from the company's failure to adequately protect user data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach Critical
BleepingComputer · · International

CISA warns admins to patch actively exploited SharePoint flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
War on the Rocks · · International

Before the Next Mythos Moment: The Case for an AI Threat Fusion Center

After Anthropic determined its Mythos 5 model posed serious cybersecurity risks and launched a controlled-access collaboration with defenders called Project Glasswing, the U.S. government ordered the model taken down in June 2026. Anthropic disputed the basis for the shutdown, arguing the triggering vulnerability was a narrow, non-universal jailbreak rather than a systemic threat.

Who should care: Privacy officers · Cybersecurity · General readers · AI governance · Policy

#surveillance#ai Read original →
AI Governance
C Cybersecurity Insiders · · International

Retool Survey: Only 8% of Tech Leaders Have Strong AI Governance

A survey by Retool found that only 8% of technology leaders consider their organizations to have strong AI governance in place, suggesting that most companies deploying AI are doing so without mature oversight structures.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Breach
Krebs on Security · · International

Lessons Learned from CISA’s Recent GitHub Leak

CISA released a postmortem after a contractor accidentally published dozens of internal credentials, including AWS GovCloud keys, to a public GitHub repository, where they sat exposed for nearly six months before journalist Brian Krebs alerted the agency. Security experts say the incident reveals gaps in how CISA detected and responded to the exposure.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Schneier on Security · · International

Friday Squid Blogging: “Squidbleed” Vulnerability

In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

CISA looks to remedy ailments from big May credential leak

A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday. The blog post outlines CISA’s response to the leak that the researcher who discovered it […] The post CISA looks to remedy ailments from big May credential leak appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Page 1 of 3 Next →