Back to Feed

Tag

Policy

50 items tagged #policy

Articles

APD/GBA (Belgium) - 101/2026

Belgian DPA fines tech company €176,946.61 for unlawfully retaining contractor's email account after departure.

🚨🇺🇾 Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed https://t.co/n2zsCshQ1r

Uruguay's DNIC citizen database with 5.8M records allegedly leaked online.

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

INTERPOL Operation Ramz arrests 200+ individuals, seizes 53 malware and phishing servers across MENA region.

Lul... CISA Admin Leaked AWS GovCloud Keys on GitHub https://t.co/V8j07muRXS

CISA administrator accidentally exposed AWS GovCloud credentials on GitHub.

White House cyber official: identity security matters more than ever in the age of AI

White House cyber official: identity security remains critical defense against AI-powered attacks on federal networks.

‼️🇧🇫 Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents E...

50,000+ scanned Burkina Faso passport and ID records allegedly leaked online.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA adds CVE-2026-20182 Cisco SD-WAN authentication bypass to KEV Catalog as actively exploited.

‼️🇬🇷 Municipality of Agrinio allegedly breached: 28 databases exposed via SQL injection on the...

Municipality of Agrinio breached; 28 databases exposed via SQL injection attack.

German National Indicted Over Money Laundering Tied to Defunct "Dream Market" Darknet Marketplace

German national indicted for laundering $2M+ from defunct Dream Market darknet marketplace.

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

US House Committee demands briefing on Instructure Canvas data breach affecting 275M individuals

NAIH (Hungary) - NAIH-3344-1/2026

Hungarian DPA fines university HUF 1.5M for excessive data processing in dormitory admissions.

AP (The Netherlands) - Decision of 11 December 2023 imposing administrative fine on Uber

Dutch DPA fines Uber €10M for lacking transparency and failing data subject rights access.

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner for equal consent options.

AP (The Netherlands) - 2025-005323

Dutch DPA finds Yango app unlawfully transferred EEA user data to Russia without proper safeguards

CE - N. 433539

French Supreme Administrative Court strikes down ARCOM copyright enforcement decree for lacking GDPR safeguards on

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner with equivalent consent options.

ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA

Siemens, Schneider Electric, and CISA publish May 2026 Patch Tuesday advisories for ICS vulnerabilities.

UK fines water supplier $1.3M for exposing data of 664k customers

UK ICO fines water supplier £963,900 for 2020-2022 cyberattack exposing 664k customers.

Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days

Microsoft May 2026 Patch Tuesday fixes 120 flaws with 17 critical vulnerabilities, no zero-days.

BVwG - W171 2303402-1/7E

Austrian court upholds DPA order requiring ORF to redesign cookie banner with balanced consent options.

OLG Stuttgart - 4 U 353/24

German appeals court partially upholds GDPR data subject rights against social media company tracking via third-party

AP (The Netherlands) - 2025-005323

Netherlands DPA fines Yandex €100M for unlawful data transfers to Russia without adequate safeguards.

AP (The Netherlands) - 2025-005323

Dutch DPA fines Yango €100M for unlawful data transfers to Russia without safeguards.

‼️🇮🇩 Kementerian Kesehatan Republik Indonesia allegedly leaked exposing 20 million antigen test...

Indonesian Ministry of Health data breach exposes 20 million antigen test records.

‼️🇫🇷 La Suite Numérique allegedly breached exposing over 18 million records from the French gov...

La Suite Numérique breach exposes 18M+ records from French government digital workspace.

Customer data exposure at CB Financial Services (CBFV) prompts material cybersecurity filing

CB Financial Services discloses material breach exposing customer names, SSNs, birthdates via unauthorized AI app.

‼️ Possible ShinyHunters clearnet domain seizure as of about 7 hours ago detected by my FBI Watch...

ShinyHunters clearnet domain possibly seized by FBI.

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested

German police shut down resurrected Crimenetwork marketplace; administrator arrested in Mallorca.

Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms

Two US men sentenced to 18 months for operating laptop farms enabling North Korean hackers to infiltrate 70+ US firms.

In Other News: Train Hacker Arrested, PamDOORa Linux Backdoor, New CISA Director Frontrunner

SecurityWeek roundup: US targets 72-hour patch cycles, PamDOORa Linux backdoor, CISA director frontrunner named.

CISA gives feds four days to patch Ivanti flaw exploited as zero-day

CISA mandates four-day patch deadline for zero-day Ivanti EPMM flaw being actively exploited.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA adds BerriAI LiteLLM SQL injection vulnerability to Known Exploited Vulnerabilities catalog.

Former govt contractor convicted for wiping dozens of federal databases

Former federal contractor convicted for destroying 96 government databases after termination.

Instructure Status

Instructure Canvas suffers confirmed security breach; names, emails, student IDs, and messages compromised.

American duo sentenced for hosting laptop farms for North Korean IT workers

Two U.S. nationals sentenced to 18 months for hosting laptop farms enabling North Korean IT workers.

Americans sentenced for running 'laptop farms' for North Korea

Two Americans sentenced to 18 months for running laptop farms enabling North Korean IT worker fraud at 70+ U.S. firms.

World Password Day 2026: The Credential Crisis Hasn’t Gone Away, It’s Just Got More Dangerous

World Password Day 2026 report reveals default credentials remain the largest credential exposure vector despite

CISA Adds One Known Exploited Vulnerability to Catalog

CISA adds CVE-2026-6973 Ivanti EPMM improper input validation flaw to KEV Catalog.

CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict

CISA launches CI Fortify program to help critical infrastructure operate independently for weeks during cyberattacks.

Karakurt Ransomware Negotiator Sentenced to Prison

Latvian Karakurt ransomware negotiator sentenced to 8.5 years in US prison.

TS - 1590/2026

Spanish Supreme Court upholds GDPR data minimisation ruling against penitentiary authority over excessive medical data

LinkedIn locks your GDPR rights behind a paywall

LinkedIn paywalls GDPR Article 15 access to profile visitor data despite monetizing it.

DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts

DHS used 1930s customs law to demand Google surrender location and activity data on Canadian critic of immigration

Microsoft confirms April Windows updates cause backup failures

Microsoft April 2026 updates block psmounterex.sys driver, breaking third-party backup applications.

Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M

Global crackdown arrests 276 suspects, shuts 9 crypto scam centers, seizes $701M.

2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware

Two US cybersecurity experts sentenced to 4 years for aiding ALPHV BlackCat ransomware group.

✅ GOOD - Alleged Silk Typhoon hacker extradited to the U.S. for cyberespionage - European author...

Alleged Silk Typhoon hacker extradited to US for cyberespionage charges.

15-year-old detained over French govt agency data breach

15-year-old detained for selling 11.7M records stolen from French ANTS govt agency.

Two US Security Experts Sentenced to Prison for Helping Ransomware Gang

Two US cybersecurity experts sentenced to 4 years prison for aiding BlackCat/Alphv ransomware gang.

Preparing for a ‘vulnerability patch wave’

NCSC warns organisations to prepare for incoming 'vulnerability patch wave' addressing decades of technical debt.