Latest Publications

Share:

Attack Against Salesloft Drift App Includes Google Workspace

An attack against Salesforce between August 8 and August 18 targeting data through its Salesloft Drift app “is more extensive than at first thought.” The attack targeted numerous Salesforce customers “systematically...more

CISA Issues Advisory on Chinese State-Sponsored Actors Targeting Critical Infrastructure

On August 27, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a Cybersecurity Advisory entitled “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage...more

Privacy Tip #456 – Bipartisan Coalition Urges Instagram to Change New Precise Location-Sharing Feature

On August 15, 2025, a bipartisan coalition of 37 state Attorneys General, led by Georgia Attorney General Chris Carr and New Mexico Attorney General Raul Torrez, sent a letter to Instagram requesting that it make “immediate...more

Android VPN Apps Linked to Chinese Co (Qihoo 360) Tied to PRC

Researchers at Arizona State University and Citizen Lab have discovered that three families of Android VPN applications, used by millions of people worldwide, are related and owned by companies or individuals located in...more

Law Enforcement Disrupts BlackSuit (Royal) Gang

In this line of work, I am often asked if law enforcement is ever successful in finding and punishing the threat actors who have wreaked havoc on U.S. businesses and stolen millions of dollars in ransomware attacks. I am so...more

Legal Update: After Purl v. HHS: Navigating the Shifting Landscape of Reproductive Health Privacy

In a ruling issued on June 18, 2025, in Purl v. Department of Health and Human Services, Docket No. 2:24-cv-00228-Z, Doc. 110 (N.D. Tex. 2025), the District Court for the Northern District of Texas largely vacated the privacy...more

Illinois Enacts Act Prohibiting AI Therapy

On August 4, 2025, Illinois Governor JB Pritzker signed the Wellness and Oversight for Psychological Resources Act into law, which went into immediate effect, and “prohibits anyone from using AI to provide mental health and...more

CISA Releases Malware Analysis Report for Microsoft SharePoint Vulnerabilities

Threat actors continue to exploit ToolShell to gain unauthorized access to on-premises SharePoint servers. On August 6, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released a malware analysis report...more

New Updates to CCPA Regulations: California’s Focus on Automated Decisionmaking Technology, Cybersecurity Audits, Risk...

On July 24, 2025, during a public meeting following public comment, the California Privacy Protection Agency (CPPA) Board unanimously approved amendments to the California Consumer Privacy Act (CCPA). These substantial...more

Privacy Tip #454 – Students Sue Kansas School District Over AI Surveillance Tool

Current and former students at Lawrence High School and Free State High School, located in Lawrence, Kansas, have sued the school district, alleging that its use of an AI surveillance tool violates their privacy....more

Federal Jury Finds Against Meta for Collecting Data from Flo Health

On August 1, 2025, a California federal jury found that Meta violated the California Invasion of Privacy Act (CIPA) by collecting data from the Flo Health app without the consent of the individuals who downloaded the app and...more

Legal Update: New Updates to CCPA Regulations: California’s Focus on ADMT, Cybersecurity Audits, Risk Assessments, and More

On July 24, 2025, the California Privacy Protection Agency (CPPA) Board unanimously approved amendments to the California Consumer Privacy Act (CCPA). These substantial changes include new compliance obligations for...more

CISA + Partners Release Advisory on Scattered Spider

On July 29, 2025, the Cybersecurity & Infrastructure Security Agency (CISA), along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security...more

Privacy Tip #452 – Temu + TikTok—Assess Risk Before Downloading

We have repeatedly warned our readers about the risks associated with TikTok. We are reminding our readers that the popular Temu app raises the same concerns....more

Kentucky AG Sues Temu for “Stealing Kentuckians’ Data”

Following in the footsteps of almost two dozen attorneys general in other states, Kentucky Attorney General Russell Coleman filed a lawsuit on July 17, 2025, against Chinese online shopping platform Temu, alleging that it...more

White House Releases AI Action Plan

On July 24, 2025, the White House released the “White House AI Action Plan,” which includes over 90 policy actions focused on accelerating innovation, building AI infrastructure, and increasing international diplomacy around...more

SharePoint Server Vulnerabilities Exploited Despite Emergency Patch

Microsoft has confirmed that vulnerabilities in its on-premises SharePoint Server installations, a network spoofing vulnerability (CVE-202549706), and a remote code execution vulnerability (CVE-2025-49704) are being actively...more

Privacy Tip #451 – Disaster Victims Fall Prey to FEMA Impersonators

In the wake of the recent July 4th flooding tragedy in Texas, scammers and criminals are reaching out to victims to take advantage of their vulnerability. Unfortunately, this is not the first time criminals have used natural...more

CISA Alert: Liteon Electric Vehicle Chargers

If you own an electric vehicle, keep an eye on cybersecurity issues that may affect your car and its accessories. You wouldn’t think that an electric vehicle charger could include a vulnerability that allows threat actors to...more

June Sees Significant Jump in BECs

According to Cybersecurity Dive, “Americans lost $16.6 billion to cyber fraud and internet crimes last year (2024), up 33% from the previous year. Phishing, spoofing and extortion topped the list of complaints, but investment...more

What to Know About SafePay Ransomware Group

The SafePay ransomware group has been active since fall 2024 and has increased its activity this spring and summer. According to NCC Group, SafePay hit the most victims of any threat actor in May 2025—it is linked to 248...more

Privacy Tip #449 – Scammers Hijacking Websites to Insert Fake Support Number

Malwarebytes recently reported that it has found scammers hijacking websites of name brands, including banks, software companies, and social media platforms to trick victims into calling a fraudulent telephone number instead...more

How Does Your AI Platform Rank?

Incogni recently issued its “Gen AI and LLM Data Privacy Ranking 2025” where it “delved deep into the most popular LLMs and developed a set of 11 criteria for assessing data privacy risks associated with advanced machine...more

FBI Warns Airline and Transportation Sectors About Scattered Spider

On June 27, 2025, the Federal Bureau of Investigation (FBI) issued a warning on X to the airline and transportation sectors that the notorious cyber criminal ring Scattered Spider is attacking those sectors....more

Joint Release Warns of Iranian-Backed Cyber-Attacks

On June 30, 2025, a Joint Advisory was issued by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation and the Department of Defense Cyber Crime Center issued...more

2,239 Results
 / 
View per page
Page: of 90

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide