PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

498 results · page 12 of 21

News
Microsoft Threat Intelligence · · International

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.

Who should care: General readers · AI governance · Policy

AI Governance
M MSSP Alert · · International

Fortinet expands FortiEndpoint with AI governance and data protection

Fortinet has expanded its FortiEndpoint platform to include AI governance and data protection capabilities, according to a trade report aimed at managed security service providers. The update positions the product as a more integrated tool for organizations trying to manage AI-related risk alongside traditional endpoint security.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
News
BleepingComputer · · International

AI Agents Broke the Security Playbook. Here's What Replaces It.

Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments. [...]

Who should care: General readers · AI governance · Policy

AI Governance
I Infosecurity Magazine · · International

SANS Warns of AI Governance Gap as Use by Security Teams Surges

SANS Institute is warning that AI governance frameworks are failing to keep pace with rapid adoption of AI tools among cybersecurity teams. As security professionals increasingly rely on AI in their daily work, the policies and oversight structures meant to guide that use have not caught up.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
News
The Guardian — Tech · · International

Moroccan intelligence insider reveals widespread use of Pegasus hacking software

A former Moroccan intelligence officer has come forward with detailed accounts of how Morocco deployed Pegasus spyware starting in 2017 to surveil journalists, human rights activists, French politicians, and Spanish government officials. The disclosure offers rare insider confirmation of how a state security service used NSO Group's tool against both domestic and foreign targets.

Who should care: Privacy officers · Cybersecurity

#surveillance Read original →
AI Governance
T The Japan Times · · International

Japan revises AI policy guidelines to bolster cybersecurity

Japan has updated its national AI policy guidelines with a focus on strengthening cybersecurity standards. The revision signals a shift toward treating AI systems as infrastructure that requires specific security protections.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Breach
Microsoft Threat Intelligence · · International

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
C Central Oregon Daily · · International

Some California grocery stores are using facial recognition to stop shoplifters. Shoppers are divided

A number of California grocery stores have deployed facial recognition technology as a loss-prevention tool to identify suspected shoplifters. Shoppers appear split on whether the security benefit justifies the practice.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
AI Governance
The Record · · International

Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities

The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai#security Read original →
Healthcare
EFF — Deeplinks · · International

Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features

A review of popular wearable devices — including Oura Ring, Apple Watch, Garmin, and Whoop — finds that most fall short on basic privacy and security standards, lacking transparency reports and strong encryption options despite collecting continuous personal health data from roughly 40 percent of Americans.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
News
EFF — Deeplinks · · International

California Steps Back From Dangerous Expansion of its Age-Gating Law

California legislators have removed the most contentious provisions from A.B. 1856, a bill that would have broadened the state's existing age-verification requirements for operating systems and app stores. The Electronic Frontier Foundation, which opposed the expansion, still considers the underlying 2025 law unconstitutional.

Who should care: General readers · Privacy officers · Policy

Breach
The Record · · International

23andMe reaches $18 million settlement with states for massive breach

A coalition of 42 state attorneys general has reached an $18 million settlement with genetic testing company 23andMe over cybersecurity failures that resulted in a large-scale data breach. The settlement resolves multistate legal action stemming from the company's failure to adequately protect user data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Enforcement
R Reuters · · International

Clayton says reporter subpoenas part of 'national security investigation'

U.S. Attorney for the Southern District of New York Jay Clayton has confirmed that subpoenas issued to reporters are connected to what he describes as a national security investigation. The disclosure comes amid broader concerns about the use of legal process to compel journalists to reveal sources or information.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Breach
Google Cloud · · International

The Risk of Exposed Cloud Functions and How to Harden

Exposed cloud functions — small, event-driven pieces of code that run in environments like Google Cloud — can become serious security vulnerabilities when left without proper access controls. When misconfigured or publicly accessible, they can serve as entry points to broader cloud infrastructure and the data stored within it.

Who should care: Cybersecurity · Privacy officers · Administrators

GDPR / Intl
Just Security · · US Federal

To Audition for the Role of Attorney General, Blanche Is Prosecuting to Please

Legal analysts at Just Security argue that Todd Blanche, Trump's nominee for Attorney General, has pursued prosecutions of figures like James Comey in ways that appear designed to satisfy political preferences rather than independent legal judgment. Critics describe the pattern as prosecutorial sycophancy aimed at securing the top law enforcement post.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
AI Governance
T Techzine Global · · International

Red Hat OpenShift 4.22 focuses on zero-trust and AI governance

Red Hat has released OpenShift 4.22, a platform update centered on zero-trust security architecture and AI governance tooling. The release signals a push to give enterprise teams more control over how AI workloads are deployed and secured in production environments.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Breach Critical
BleepingComputer · · International

CISA warns admins to patch actively exploited SharePoint flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
← Prev Page 12 of 21 Next →