Latest Publications

Share:

Stolen Hotel Reservation Data Used in Targeted Phishing Scams

A new report by Wired states that customer data from “more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams.” According to the report, travelers’ information and booking...more

Senate Bill 5 and the New Compliance Frontier for AI in Connecticut

On May 27, 2026, Connecticut Governor Ned Lamont signed Senate Bill 5 (“the Bill”) into law, creating a broad framework for artificial intelligence oversight in the state. The Bill reaches beyond any single category of AI use...more

Privacy Tip #494 – Signal Users Targeted with Phishing Scam

If you are a Signal user, be on the alert for a new phishing campaign that attempts to steal recovery keys used to access cloud backups. If successful, the attackers could have access to entire message archives,...more

Verizon’s 2026 Data Breach Investigations Report Highlights

I am a big fan of Verizon’s yearly Data Breach Investigations Report. I follow it closely, as it confirms what we are seeing in the field, and provides validation for defense strategies employed to protect against attacks....more

Shadow AI Continues to Expose Company IP

Verizon recently published its 2026 Data Breach Investigations Report, which is full of helpful information for cybersecurity professionals to implement strategies for protection of systems....more

Privacy Tip #493 – Stop Using Shadow AI!

As you can tell, I am obsessed with Verizon’s Data Breach Investigations Report. It is worthy of full immersion, and I am picking it apart with precision. I always spend a lot of time delving into it as it informs and...more

CISA Passwords Used to Access DHS Systems Exposed

The Cybersecurity and Infrastructure Security Agency (CISA), which is part of the Department of Homeland Security, is responsible for cybersecurity and infrastructure security throughout the federal government, to improve...more

Privacy Tip #492 – FTC Enforcing the Take It Down Act

On May 19, 2026, the Federal Trade Commission (FTC) announced that it will begin enforcing the Take It Down Act (TIDA) immediately. TIDA was made law in May 2025 and requires platforms to remove non-consensual intimate...more

Privacy Tip #491 – ShinyHunters Hit Zara

According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack  and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident...more

ShinyHunters Hit Instructure + Downs Canvas Learning Management System

Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule....more

ShinyHunters Target Medical Device Company Medtronic

Global medical device company Medtronic recently confirmed that it had been attacked by the threat actor group, ShinyHunters. According to Bleeping Computer, Medtronic is “the largest medical device maker in the world by...more

CISA Warning: Firestarter Malware Persists in Cisco Devices

The Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) have confirmed that threat actors are using FIRESTARTER malware to maintain persistence on Cisco network devices,...more

Privacy Tip #490 – Dating App Hijacks + Repurposes College Student’s TikTok Video

In the category of how technology can be fun, yet dangerous, a 19 year old college student alleges that the dating app Meete took a video she innocently posted on TikTok of her high school graduation, then “overlayed it with...more

Phishing Now Top Method for Initial Unauthorized Network Access

According to Cisco Talus researchers, phishing is the primary method threat actors use to gain unauthorized access to networks, accounting for more than one-third of all incidents in the first quarter of 2026. This increase...more

Tempus AI Faces Class Action Cases for Collection of Genetic Information in Acquisition

Multiple class action cases have been filed against Tempus AI alleging that, during its acquisition of Ambry Genetics, the company improperly collected and disclosed genetic information without obtaining prior written consent...more

Privacy Tip #489 – Social Media Scams #1 in 2025

The Federal Trade Commission (FTC) recently reported that, in 2025, social media scams were the costliest of all scams against consumers, with a whopping $2.1 billion lost. Thirty percent of those who reported losing funds in...more

DOJ’s Big Win in North Korean IT Worker Fraud Scheme

On April 15, 2026, the Department of Justice (DOJ) announced that two U.S. nationals, Kejia Wang and Zhenxing Wang, were sentenced for facilitating a North Korean IT worker scheme that compromised over 80 U.S. identities,...more

Privacy Tip #488 – Account Change Phishing Alerts from “Apple” Are Tricking Users

A new, yet old, scheme has been quite successful and users should beware. If you get an account change message from Apple, be on high alert that it is fake and malicious....more

Social Engineering Schemes Target C-Suite Executives

March was a busy month for former Black Basta affiliates who are using old social engineering techniques to target executives in the manufacturing, professional, scientific, and technical services industries. According to...more

Privacy Tip #487 – Eurail Notifies 300,000+ Individuals of Data Breach

I have very fond memories of using a Eurail pass back in the day while backpacking through Europe as a student. I was saddened to see that Eurail was the victim of a data breach in December 2025 when attackers obtained access...more

Joint Advisory Warns of Iran Cyber Actors Attacking U.S. Critical Infrastructure

Iran has always been a formidable cyber threat to the United States, but after the war in Iran commenced, the attacks are coming frequently and in full force. According to the Joint Cybersecurity Advisory issued on April 7,...more

Water Treatment Facility Downed with Ransomware Attack

Critical infrastructure operators at the water treatment plant in Minot, North Dakota, were forced to resort to manual processes when its Supervisory Control and Data Acquisition (SCADA) system became inoperable as a result...more

Winona County Victim of Cyber Attack

Minnesota Governor Tim Walz issued an emergency executive order on April 7, 2026, dispatching the Minnesota National Guard after Winona County requested assistance following a cyber attack disrupting its “critical systems and...more

Privacy Tip #486 – “Stolen Credentials Are a Major Threat”

According to Security Week’s recent article, “Stolen Logins Are Fueling Everything from Ransomware to Nation-State Cyberattacks,” cybersecurity firm Ontinue’s 2H 2025 Threat Intelligence Report, showcases that “Attackers...more

FBI Warns: Iran Cyber Actors Using Telegram to Push Malware

The Federal Bureau of Investigation (FBI) recently released a FLASH warning highlighting malicious cyber activity conducted by threat actors operating on behalf of Iran’s Ministry of Intelligence and Security. According to...more

2,330 Results
 / 
View per page
Page: of 94

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide