PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

883 results · page 7 of 37

News
Schneier on Security · · International

AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source. Simon Willison comments: Anil points out that this rate of discovery appears incompatible with existing open source embargo prac…

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Breach Critical
BleepingComputer · · International

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA has confirmed that a critical remote code execution vulnerability in WatchGuard Firebox firewalls, previously flagged as actively exploited in December, is now being used in ransomware attacks. The agency added the flaw to its known exploited vulnerabilities catalog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
WIRED — AI · · International

I Let an AI Agent Hack All My Gadgets—and I’d Do It Again

A writer disabled safety restrictions on an open-source AI model and used it as an autonomous agent to probe household devices for security vulnerabilities. The model successfully found weaknesses and broke into a PC, then provided guidance on how to fix the exposed flaws.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
Microsoft Threat Intelligence · · International

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation#security Read original →
AI Governance
S securityboulevard.com · · International

The EU AI Act for the Downstream Provider: What You Owe When You Just Call an API

The EU AI Act places obligations not just on companies that build AI models, but also on businesses that integrate AI capabilities by calling third-party APIs. Downstream providers — those who use rather than build the underlying model — face their own compliance responsibilities under the law.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
News
EPIC · · US Federal

The Eastern Herald: Trump Takes Voter-Roll Purge Database Fight to Supreme Court With Midterms Eight Weeks Out

The Trump administration has asked the Supreme Court to intervene in a legal fight over access to federal immigration and Social Security databases used to scrub voter rolls, with midterm elections roughly eight weeks away. The lawsuit, filed by voting rights and privacy organizations, argues the data being used is unreliable for identifying ineligible voters.

Who should care: General readers · Privacy officers · Policy

Breach
BleepingComputer · · International

Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm, a healthcare technology company, has disclosed a data breach affecting patient personal data following a cyberattack on one of its third-party vendors. A ransomware group has claimed responsibility for the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy#security Read original →
Enforcement
EPIC · · US Federal

LawNews: Protester Surveillance DHS Lawsuit: What a San Diego Parking Lot Reveals About Federal Power

A federal lawsuit filed July 24, 2026 by the Electronic Privacy Information Center and three individual plaintiffs from California, Minnesota, and South Carolina alleges that the Department of Homeland Security has been surveilling protesters and bystanders across the country.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
News
CyberScoop · · US Federal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.

Who should care: General readers · AI governance · Policy

Breach
EDPB · · EU

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

France's data protection authority, the CNIL, fined Hôpital Privé de la Loire €500,000 after an attacker gained unauthorized access to its centralized patient records system in summer 2025. The hospital was found in violation of GDPR rules on security of processing and breach notification to affected individuals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

#breach#enforcement#healthcare#privacy Read original →
AI Governance
Krebs on Security · · International

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai#security Read original →
News
Nextgov/FCW · · US Federal

NSA looks to AI to help analysts sift through vast data troves

The NSA is deploying AI tools to help analysts process large volumes of data more quickly, according to the agency's cybersecurity chief. Work that currently takes days or weeks could be accelerated significantly with these systems.

Who should care: General readers · AI governance · Policy

AI Governance
D District Administration · · International

What back-to-school AI policy is really telling cybersecurity leaders

School districts are rolling out AI policies as the academic year begins, and those policies are being read by cybersecurity professionals as signals about how institutions understand — or misunderstand — the risks AI tools bring into their networks.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Breach
BleepingComputer · · International

220 million traveler records exposed in Vietnam-linked APIS leak

A misconfigured Advance Passenger Information System database linked to Vietnam exposed roughly 220 million passenger and crew records, including passport numbers, dates of birth, nationalities, and flight details covering nearly a decade. Researchers reached the cloud-hosted system using default credentials, suggesting basic security controls were never changed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Weverse Data Leak Affects More Than 422,000 K-Pop Fan Accounts

Weverse, the fan community platform run by HYBE-affiliated Weverse Company, confirmed a data breach affecting more than 422,000 user accounts. The company says the exposed data was mostly internal identifiers with limited use outside the platform.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

Mathspace, an online math education platform, confirmed a data breach affecting over 1 million users in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user records. The breach involves students, parents, teachers, and company staff.

Who should care: Cybersecurity · Privacy officers · Administrators

← Prev Page 7 of 37 Next →