PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

497 results · page 4 of 21

Breach
Microsoft Threat Intelligence · · International

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A self-propagating worm embedded in over 400 malicious npm packages spread through software supply chains by automatically republishing infected updates, stealing credentials along the way. Microsoft's security team has published a detailed breakdown of how the attack worked and how to detect or remediate it.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
News
BleepingComputer · · International

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [...]

Who should care: General readers · AI governance · Policy

News
CyberScoop · · US Federal

AISI, OpenAI report more ‘unsanctioned’ model hacks

Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Breach
CyberScoop · · US Federal

Massive supply-chain attack compromises 440 packages under four hours

Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
WIRED — AI · · International

The White House Is Keeping Its AI Cybersecurity Framework Secret

The Trump administration briefed major AI companies, including OpenAI and Anthropic, on its AI cybersecurity framework while keeping the details from the public. No timeline for broader disclosure has been announced.

Who should care: General readers · AI governance · Policy

Healthcare
B BankInfoSecurity · · International

Senate Committee Advances Health Data Privacy Bill

A U.S. Senate committee has moved a health data privacy bill forward, advancing legislation aimed at strengthening protections for personal health information. The bill now heads to the broader Senate for further consideration.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
News
Microsoft Threat Intelligence · · International

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

Microsoft has expanded its Zero Trust security strategy to cover AI agents and DevSecOps pipelines, releasing new tools and guidance aimed at helping organizations apply least-privilege and verify-everything principles to AI-driven environments.

Who should care: Lawyers · Compliance · General readers · AI governance · Policy

#regulation#ai Read original →
Breach
Microsoft Threat Intelligence · · International

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
EFF — Deeplinks · · International

Technology's Power in the Hands of the People

The Electronic Frontier Foundation is attending the summer security conference week in Las Vegas — BSides, Black Hat, and DEF CON 34 — and is using the occasion to solicit member support for its ongoing legal and advocacy work on privacy and free expression.

Who should care: General readers · Privacy officers · Policy

News
R Reuters · · International

Obsidian Security raises funding at $1.1 billion valuation on AI security demand

Obsidian Security has raised a new funding round that values the cybersecurity company at $1.1 billion, with investors citing growing demand for tools that secure AI-related systems and applications. The funding reflects broader market appetite for security products built around the risks that AI adoption creates inside organizations.

Who should care: General readers · AI governance · Policy

AI Governance
H Help Net Security · · International

EU begins enforcing AI Act, putting AI models under the microscope

The European Union has begun active enforcement of the AI Act, marking the transition from legislative text to real regulatory scrutiny of AI models operating in the EU market. Companies deploying or providing AI systems must now demonstrate compliance with the law's requirements or face penalties.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
N National League of Cities · · International

Strategies for Cyber Resilience, AI Governance & Smarter Municipal Decision Making

The National League of Cities has put forward guidance aimed at helping municipal governments strengthen cybersecurity practices, establish AI governance frameworks, and improve data-informed decision making at the local level.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Breach
BleepingComputer · · International

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
R Reuters · · International

US House panel seeks briefing on OpenAI's AI agent security breach

A US House committee has requested a briefing from OpenAI following a reported security breach involving its AI agent systems. The congressional inquiry signals growing legislative attention to vulnerabilities in agentic AI products.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
News
EFF — Deeplinks · · International

The Youth AI Privacy Act’s Privacy Paradox

The Senate Commerce Committee is preparing to take up the Youth AI Privacy Act, which would require AI companies to build separate privacy protections and safe design features for minors. Critics argue the bill's age-based framework would paradoxically require more data collection overall and could restrict access to lawful online speech.

Who should care: Lawyers · Compliance · General readers · AI governance · Policy · Privacy officers

#regulation#ai#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

Is Your Organization Ready for a HIPAA Security Incident?

The HIPAA Journal is prompting healthcare organizations to evaluate their readiness for security incidents by conducting formal risk assessments that identify threats to protected health information and gauge the likelihood those threats materialize.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

HIPAA Security Risk Assessment Checklist

The HIPAA Journal has published a checklist guide covering how organizations should conduct security risk assessments under HIPAA, including identifying threats to protected health information and evaluating how likely those threats are to occur.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

Free HIPAA Security Risk Assessment

The HIPAA Journal is offering a free security risk assessment resource aimed at helping covered entities and business associates evaluate threats to protected health information. The tool is designed to walk organizations through identifying risks, estimating likelihood, and addressing gaps in their HIPAA security posture.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Enforcement
HIPAA Journal · · US Federal

CISA Issues Updated Guidance on Minimum Elements of an SBOM

CISA, the FBI, the NSA, and 15 international partners have released updated guidance defining the minimum required elements of a Software Bill of Materials (SBOM), a structured record of the components that make up a software product. The joint guidance builds on earlier frameworks and reflects growing international coordination around software supply chain transparency.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare#regulation Read original →
News
Just Security · · US Federal

Regulate, Don’t Ban, Chinese AI Models

A policy argument published in Just Security contends that Chinese AI models should face the same pre-deployment and ongoing safety testing required of domestic models, rather than being subject to outright bans. The piece frames this as a matter of regulatory consistency rather than national-security exception.

Who should care: Lawyers · Compliance · General readers · AI governance · Policy

#regulation#ai Read original →
← Prev Page 4 of 21 Next →