Vulnerabilities
Council of Europe Confirms It Is Investigating Reported Breach Claims
The Oracle PeopleSoft campaign coverage extends into a major European intergovernmental institution.
Stay informed on the latest data breaches. Get expert analysis on affected companies, compromised data types, and critical steps for immediate victim protection.
Vulnerabilities
The Oracle PeopleSoft campaign coverage extends into a major European intergovernmental institution.
Policy & Government
The largest data-protection fine in South Korean history reframes the cost of breaches in the Korean market and signals an Asia-wide enforcement escalation.
Data Breaches
Pharma giant Novo Nordisk discloses a clinical-trial data theft on the same day UK regulators greenlight its Wegovy pill — a reminder of the sector's persistent threat profile.
Data Breaches
The sovereign-messaging assumption gets a hard test — Tchap's 73,000-account breach reframes the conversation.
Vulnerabilities
Google Threat Intelligence confirmed mass exploitation of an Oracle PeopleSoft zero-day by ShinyHunters; universities are the primary target and the extortion has begun.
Threat Intelligence
Mandiant's published findings on a financially motivated campaign give defenders in legal and financial services a sector advisory to act on.
Cybersecurity 101
A practitioner's guide to data breach notification laws in 2026: what triggers a notice, who you must tell, the GDPR 72-hour rule, HIPAA, SEC and US state deadlines, the penalties for getting it wrong, and how to build notification into your incident response plan.
Data Breaches
DentaQuest, a Sun Life dental-benefits administrator serving 35 million people, confirmed a breach of 2.6 million accounts after ShinyHunters leaked about 234 GB of data — including names, dates of birth, Medicaid IDs and health-insurance information.
Data Breaches
The UN World Food Programme says its self-registration application for Palestine was breached, exposing names, ID and mobile numbers and location data for roughly 600,000 Gaza households — potentially the largest-known breach of humanitarian beneficiary data to date.
Cybersecurity 101
An incident response plan is the document that turns a breach from chaos into a process. This guide covers what an IR plan contains, the NIST and SANS frameworks behind it, how it differs from the incident response process, and how to build and test one.
Cybercrime
Spain's National Police arrested a suspect accused of publishing personal data of officials from its most sensitive bodies — including the cyber agency INCIBE, the police, Civil Guard and prosecutors — a doxxing campaign police say endangered both the individuals and their institutions.
Account Takeover (ATO)
Dashlane now says the brute-force attack it disclosed on May 31 succeeded: by defeating 2FA on about 20 customer accounts, attackers downloaded copies of those users' encrypted password vaults. The vaults stay locked behind each user's master password, but affected users should rotate.