Security & Privacy News for CIOs & IT Leaders

Cybersecurity and privacy for IT leaders — breaches, critical vulnerabilities, regulation, and the controls that reduce real exposure.

2,917 stories · updated continuously · open in the command center

  • Security & PrivacyHacker News3m

    Water system controllers don't belong on the internet, says ex-NSA chief

    Critical infrastructure water systems across at least 12 US states have been compromised in suspected Iranian cyberattacks targeting programmable logic controllers (PLCs), prompting ex-NSA chief Paul Nakasone to warn that operational technology devices should never connect to the internet. With 50,000 fragmented US water municipalities historically underfunded and lacking dedicated cybersecurity staff, IT leaders must fundamentally redesign their defensive strategies through public-private partnerships and implement network segmentation to isolate critical operational technology from internet connectivity. This incident exposes a systemic vulnerability in critical infrastructure that demands immediate architectural changes and resource investment to prevent potential public health emergencies.

  • Security & PrivacyTechCrunchZack Whittaker2m

    Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

    Security researchers discovered over 10,000 Polish public entities and 250,000 websites containing critical vulnerabilities, including critical infrastructure like courts, hospitals, and airports—exposing the nation to significant cyber risks amid ongoing state-sponsored attacks. The findings highlight systemic gaps in vendor patch management, lack of bug bounty programs, and insufficient vulnerability reporting mechanisms across public sector organizations. IT leaders must recognize this as a wake-up call that legacy systems, end-of-life software, and fragmented security practices create enterprise-wide risk that extends beyond individual organizations to national security and public safety.

  • Security & PrivacyArs TechnicaJon Brodkin2m

    Judge rules Meta caused "public nuisance" and must fund mental health treatment

    A New Mexico judge ruled that Meta created a "public nuisance" by designing its platforms to maximize engagement while inadequately protecting minors from exploitation and mental health harms, ordering the company to pay $567 million into a mental health treatment fund on top of $375 million in civil penalties. This landmark ruling establishes significant legal liability for social media platforms' business practices and algorithmic design decisions, signaling that courts may increasingly hold tech companies financially accountable for societal harms caused by engagement-optimization strategies. Technology leaders should anticipate similar litigation across other jurisdictions and prepare for potential regulatory requirements around platform safety features, content moderation, and youth protection that could necessitate fundamental product redesigns.

  • Security & PrivacyHacker News3m

    Responding to the next frontier of critical cyber capabilities

    Organizations must prepare for advanced cyber threats that target critical infrastructure and digital ecosystems, requiring IT leadership to evolve beyond traditional security approaches. Strategic resilience depends on integrating AI-driven threat detection, zero-trust architecture, and cross-functional incident response capabilities to minimize business disruption and maintain operational continuity. CIOs should prioritize cyber risk as a board-level governance issue and allocate resources toward predictive defense mechanisms rather than reactive measures.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Computer maker Framework notifies ‘all customers’ of a data breach

    Framework Computer notified all customers of a data breach affecting names, email addresses, phone numbers, and physical addresses—stemming from an upstream zero-day vulnerability in third-party business intelligence vendor Metabase. This incident highlights a critical supply chain security risk: organizations are exposed to breaches not just through their own infrastructure but through vendors' unpatched vulnerabilities, requiring IT leaders to reassess third-party risk management and incident response protocols. The breach underscores that even niche manufacturers can be targets, and that payment data exclusion provides limited mitigation when personal identifiers enable identity theft and social engineering attacks.

  • Security & PrivacyHacker News3m

    99% of My Website Traffic Is Bots

    The prevalence of bot traffic presents a critical business challenge for organizations, distorting analytics, inflating engagement metrics, and masking the true value of digital investments, which directly undermines strategic decision-making and ROI calculations. IT leaders must recognize that without effective bot detection and mitigation strategies, organizations risk making flawed infrastructure and marketing decisions based on artificially inflated traffic numbers, ultimately impacting budget allocation and competitive positioning. This issue demands a comprehensive approach to traffic validation, security hardening, and analytics integrity to ensure that technology investments drive measurable business outcomes rather than chasing phantom metrics.

  • Security & PrivacyArs TechnicaCyrus Farivar2m

    AI chatbots have failed people in crisis. Can that be fixed?

    AI chatbots are causing documented harm to vulnerable users, particularly those in mental health crises, creating significant legal and reputational liability for technology companies. While AI safety has incrementally improved, critical gaps remain in crisis detection, professional care handoff, and appropriate boundary-setting—requiring greater transparency, third-party evaluation, and clinician involvement in model development. IT leaders must recognize that deploying AI systems without mental health safeguards and explainability creates enterprise risk and erodes public trust.

  • Security & PrivacyCIO Online2m

    Snowflake attacker pleads guilty to hack of 165 companies’ data

    A Canadian hacker pleaded guilty to participating in coordinated attacks on 165 organizations using Snowflake, stealing billions of sensitive records and extorting millions of dollars from victims including AT&T, Ticketmaster, and Neiman Marcus. This case demonstrates the critical vulnerability of cloud data warehouses to credential-based attacks and highlights the evolving threat landscape where attackers exploit inadequate access controls to compromise massive datasets. CIOs must recognize this as a watershed moment for cloud security strategy, signaling that traditional perimeter defenses are insufficient and that comprehensive identity governance, multi-factor authentication, and behavioral monitoring are now essential operational requirements.

  • Security & PrivacyTechMeme2m

    At Black Hat, OpenAI reconstructs the OpenAI-Hugging Face incident and examines its implications for AI security, cyber resilience, and alignment (Black Hat on YouTube)

    OpenAI presented a technical reconstruction of a significant security incident involving Hugging Face at Black Hat, highlighting critical vulnerabilities in AI system security and alignment that pose enterprise-wide risks. This incident demonstrates the expanding threat surface for organizations deploying AI models and underscores the need for robust cyber resilience frameworks specifically designed for AI infrastructure. IT leaders must recognize that traditional security controls are insufficient for AI systems and that misalignment or compromise of AI models can have cascading effects across enterprise operations.

  • Security & PrivacyTechCrunchIvan Mehta2m

    New Mexico court orders Meta to pay additional $567M in child safety case

    Meta faces escalating regulatory and financial liability with a New Mexico court ordering an additional $567M fine (totaling $942M) for child safety harms, alongside operational mandates including restricted notifications and limited usage for minors—signaling a critical shift toward state-level enforcement and precedent-setting platform regulation. This ruling, combined with ongoing litigation from 33 states and others, creates significant legal and compliance risks that will likely ripple across the industry, forcing technology leaders to reassess their own child safety protocols, engagement algorithms, and regulatory exposure. Organizations must prepare for potential similar regulations affecting their digital properties and user engagement strategies, particularly around youth protections and algorithmic transparency.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite Podcast: Why scammers love FaceTime now

    Scammers are increasingly exploiting FaceTime's video calling feature to impersonate financial institutions and conduct social engineering attacks, exploiting the psychological trust that live video communication generates. This emerging threat poses significant risk to enterprise security, as employees may inadvertently expose sensitive corporate data or credentials through seemingly legitimate video interactions. IT organizations must implement employee awareness training and leverage Apple-specific security controls to detect and prevent such impersonation attempts across managed device fleets.

  • Security & PrivacyTechMemeMackenzie Hawkins2m

    Sources: the US Commerce Department's BIS is reviewing how Chinese AI companies access Nvidia chips overseas, including by legally renting foreign data centers (Mackenzie Hawkins/Bloomberg)

    The US Commerce Department's Bureau of Industry and Security is investigating how Chinese AI companies circumvent export restrictions by legally accessing Nvidia chips through foreign data centers, potentially signaling tighter regulatory controls on semiconductor access abroad. This regulatory scrutiny could reshape global cloud infrastructure markets, affect international partnerships, and force technology companies to reassess their supply chain strategies and geographic data center operations. IT leaders should expect increased compliance complexity, potential restrictions on serving certain customers, and possible changes to how semiconductor allocation and foreign data center services are governed.

  • Security & PrivacyCIO Online6m

    Deepfakes are targeting your executives. Here’s what actually works

    Executive impersonation via deepfakes has evolved from theoretical risk to active enterprise threat, with detection and response capabilities currently lagging attacker sophistication—existing forensics tools work only post-incident while liveness detection systems remain immature for real-time verification during high-stakes calls. CIOs must implement a comprehensive operational framework combining multi-factor human verification (pre-agreed authentication phrases), proactive monitoring of executives' digital identity surfaces, incident response playbooks, specialized training for executives and their support staff, and cross-functional coordination rather than relying on immature detection tools as a standalone solution. This represents a critical shift in executive risk management requiring immediate protocol-based defenses alongside technology investments.

  • Security & PrivacyThe VergeJess Weatherbed2m

    Meta ordered to pay an additional $567 million in public nuisance ruling

    Meta faces nearly $1 billion in total penalties from New Mexico for operating platforms as a public nuisance contributing to teen mental health crises, with $567 million designated for child safety abatement programs. This ruling establishes a significant legal precedent that technology companies can be held liable for societal harms caused by their platforms' design and practices, signaling increased regulatory and litigation risks for the tech industry. IT leaders and CIOs must recognize that platform safety, content moderation, and teen protection mechanisms are now critical business risks that directly impact corporate financial liability and brand reputation.

  • Security & PrivacyHacker News3m

    Meta ordered to pay $567M in New Mexico for teen mental health fund

    A New Mexico court ordered Meta to pay $567 million for harms to children's mental health, bringing total penalties to $942 million, establishing a legal precedent that could trigger similar state-level actions nationwide. The ruling imposes significant operational requirements on Meta including age verification improvements, enhanced safety features, and biannual compliance reporting, signaling that regulatory pressure through litigation may increasingly shape technology company product design and data practices. For IT leaders, this case demonstrates that social media and technology platforms face mounting legal liability for child safety outcomes, suggesting similar compliance demands could extend across the industry as other states pursue comparable cases.

  • Security & PrivacyHacker News3m

    Framework discloses data breach via Metabase 0-day

    Framework experienced a data breach via a Metabase 0-day vulnerability that exposed customer PII, but demonstrated exceptional incident response by notifying customers within 6 hours of discovering the breach—setting a benchmark for transparency that contrasts sharply with industry norms. However, the incident exposes critical gaps in data governance practices, as organizations are sharing excessive customer information with third-party analytics platforms without proper access controls, creating unnecessary risk exposure. Technology leaders must recognize that rapid notification alone is insufficient; the breach highlights the need for comprehensive data minimization strategies and stricter third-party access controls to reduce attack surface and regulatory liability.

  • Security & PrivacyHacker News3m

    Hackers Stalked Me by Hijacking a Smartwatch for Kids

    Security researchers discovered critical vulnerabilities across three major Chinese-based GPS tracking platforms used by tens of millions of children's smartwatches and car trackers, enabling attackers to silently track locations, eavesdrop on audio, capture photos/video, and intercept communications without any user notification. These vulnerabilities affect 30+ brands sold globally through insecure supply chains with minimal authentication controls, creating widespread exposure for children and IoT device users. IT leaders must recognize this as a systemic supply chain security risk that extends beyond consumer devices to enterprise IoT deployments and underscores the urgency of vendor security assessment and device hardening policies.

  • Security & PrivacyTechMeme2m

    New Mexico trial: a judge orders Meta to pay $567M and make changes for underage users after finding its platforms helped create a public nuisance harming teens (KOB 4)

    A New Mexico judge has ordered Meta to pay $567 million and implement platform changes after ruling that its social media services created a public nuisance harmful to minors, setting a significant legal precedent that could expose technology companies to substantial financial liability and regulatory scrutiny. This ruling signals that platforms may be held accountable for child safety failures, with implications for how tech companies must redesign product features, implement age-gating, and monitor harmful content—potentially requiring IT organizations across the industry to prioritize safety compliance and risk mitigation. CIOs should expect increased pressure from regulators and stakeholders to implement stronger safeguarding mechanisms, conduct safety audits, and align engineering practices with child protection standards.

  • Security & PrivacyHacker News3m

    Welcoming the Nepalese Government to Have I Been Pwned

    Have I Been Pwned has onboarded Nepal as its 47th government partner, providing the National Cyber Security Centre with free access to monitor Nepalese government domains against a database of compromised credentials and breached accounts. This initiative enables government IT teams to rapidly identify credential exposure across government email addresses and respond to security incidents before attackers can exploit compromised accounts. The expanding adoption of HIBP by governments worldwide represents a critical shift toward proactive threat monitoring and improved incident response capabilities for public sector organizations.

  • Security & PrivacyWiredAndy Greenberg, Matt Burgess, Yulia Almazova2m

    Hackers Stalked Me by Hijacking a Smartwatch for Kids

    Security researchers discovered that tens of millions of GPS-enabled smartwatches and tracking devices—sold under 60+ brand names but powered by just three Chinese-based platforms—contain critical vulnerabilities allowing unauthorized location tracking, audio eavesdropping, photo capture, and device hijacking with no user notification. The flaws affect children's safety devices and connected car accessories, with millions of devices exposed to exploitation by bad actors with minimal technical skill. IT leaders must recognize this as a supply chain risk that extends beyond consumer devices, as these same vulnerabilities could affect enterprise IoT deployments and highlight the broader challenge of securing third-party IoT platforms.

  • Security & PrivacyTechCrunchZack Whittaker2m

    China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

    A sophisticated Chinese-linked spyware platform called LightSpy has expanded globally to target organizations in 13 countries including the US and NATO members, now operating as a commercialized platform with modular capabilities to compromise smartphones, servers, routers, and network infrastructure. The platform's evolution from state-sponsored tool to multi-customer commercial offering represents a significant escalation in threat sophistication, featuring data exfiltration, device destruction, and network-wide compromise capabilities that bypass traditional perimeter security. This development signals that critical infrastructure and enterprise networks face elevated risk from well-resourced threat actors with commercial incentive structures, requiring IT organizations to assume compromise of network devices and implement zero-trust architectures.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Google says hackers are calling financial firm employees to hack and extort victims

    Coordinated hacking groups are successfully targeting financial and investment firms through voice phishing—calling employees on personal devices while impersonating IT staff to steal credentials and sensitive data for extortion purposes. This campaign, tracked by Google across four identified groups (Falcon, Helix, Pink, and Redact) potentially operating under the umbrella UNC6671, has extracted approximately $10 million in cryptocurrency and demonstrates that basic social engineering remains highly effective against even sophisticated organizations, posing significant data breach and financial risk to enterprises across multiple sectors. For IT organizations, this highlights a critical vulnerability in employee authentication processes and the need for security controls that extend beyond traditional perimeter defenses to protect against targeted human-centric attacks.

  • Security & PrivacyWiredCaroline Haskins2m

    Flock Highlighted Police Departments Using Its Tech. Now 4 Face Allegations of Misuse

    Flock's automatic license plate reader (ALPR) technology has been misused by multiple police departments featured in the company's promotional materials, creating significant reputational and liability risks for organizations deploying surveillance technology without robust governance frameworks. These incidents highlight critical gaps in access controls, audit mechanisms, and accountability structures that IT leaders must address when implementing law enforcement or data-intensive systems. The widespread nature of ALPR misuse across multiple states signals an urgent need for organizations to establish stronger internal controls, continuous monitoring systems, and clear accountability protocols before deploying sensitive data technologies.

  • Security & PrivacyTechMemeAnna Tong2m

    Docs: US data labeling companies, like Surge AI and Mercor, that sell training datasets to US AI labs and the government are also selling them to Chinese labs (Anna Tong/Forbes)

    US data labeling companies are simultaneously selling AI training datasets to both American AI labs and the US government while also supplying Chinese competitors, creating significant national security and competitive intelligence risks. This dual-supply practice undermines export controls and enables foreign adversaries to access the same training data fueling American AI leadership, potentially accelerating China's AI capabilities while compromising classified and sensitive government projects. IT organizations must immediately audit their data sourcing practices and implement strict vendor controls to prevent proprietary training datasets from reaching strategic competitors.

  • Security & PrivacyTechMeme2m

    Google and data: hackers used phone calls, phishing websites, and "meticulous" tactics to target dozens of US PE firms and other businesses over the past month (Reuters)

    A sophisticated threat actor has orchestrated a coordinated campaign targeting dozens of U.S. private equity firms and other financial institutions using multi-vector attacks combining phone-based social engineering, phishing websites, and meticulous reconnaissance tactics. This represents a significant escalation in targeting high-value organizations and demonstrates that traditional security controls are insufficient against determined adversaries willing to invest substantial effort in reconnaissance and personalized attacks. IT leaders must recognize that financial services and PE firms are prime targets and that human-centric attack vectors remain a critical vulnerability despite technological defenses.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple releases security updates to macOS Tahoe, Sequoia, and Sonoma [U]

    Apple released emergency security updates across three macOS versions (Sonoma, Sequoia, and Tahoe) without beta testing, including a critical Screen Sharing vulnerability fix that suggests the vulnerability posed significant risk. This rapid, unscheduled patching cycle indicates Apple is prioritizing security issue resolution and IT organizations should treat these updates as high-priority given the expedited release pattern and potential threat severity. Organizations managing heterogeneous macOS environments must implement a swift deployment strategy to minimize vulnerability exposure across their device fleet.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple’s latest macOS updates address a serious Screen Sharing vulnerability

    Apple released emergency security updates across three macOS versions (Sonoma, Sequoia, and Tahoe) to patch a critical Screen Sharing vulnerability (CVE-2026-65400) that could allow unauthenticated network attackers to remotely access Mac systems without valid credentials. This authentication bypass poses significant risk to enterprise environments where remote access capabilities are leveraged, potentially enabling unauthorized screen viewing, file access, and system manipulation. The urgency of this out-of-cycle, multi-version patch indicates Apple's assessment of the severity and the need for immediate IT deployment across all affected Mac deployments.

  • Security & PrivacyHacker News3m

    Zapscape (CVE-2026-64561)

    Zapscape (CVE-2026-64561) is a critical KVM escape vulnerability enabling guest-to-host privilege escalation in virtualized environments, allowing attackers with guest root access to execute arbitrary code on the host kernel with root privileges. This poses severe risks for multi-tenant cloud environments and any organization running untrusted workloads on KVM/x86 hypervisors, potentially enabling data breaches, lateral movement across tenant VMs, and complete infrastructure compromise. IT leaders must urgently assess their KVM deployments, apply patches across the affected kernel versions (2020-2026), and implement additional isolation controls for untrusted guest workloads.

  • Security & PrivacyTechCrunchSarah Perez2m

    OpenAI says Apple’s own security practices undermine its trade secrets case

    OpenAI's defense against Apple's trade secrets lawsuit highlights critical vulnerabilities in enterprise security practices, arguing that Apple's inadequate employee offboarding procedures and use of personal accounts for work undermine the legal protection of its confidential information. This case signals that poor data governance and access controls can significantly weaken intellectual property claims, creating substantial legal and competitive risks for technology organizations. For IT leaders, the case underscores that robust security practices are not just operational best practices but essential legal safeguards that directly impact the defensibility of proprietary assets.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Hacker pleads guilty to stealing data from more than 165 Snowflake customers

    A Canadian hacker pleaded guilty to breaching over 165 companies through Snowflake, stealing billions of records from major enterprises like AT&T, LendingTree, and Ticketmaster, with victims suffering $9.5 million in documented losses. This incident underscores critical vulnerabilities in cloud infrastructure security and the escalating sophistication of supply-chain attacks that can compromise multiple organizations simultaneously through a single compromised provider. IT leaders must reassess their cloud vendor security posture, access controls, and incident detection capabilities, as traditional perimeter defenses prove insufficient against determined threat actors targeting infrastructure providers.

Other categories