#Data Exposure

Every story tagged Data Exposure, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

5 stories · open in the command center

  • Security & PrivacyHacker News3m

    A web page that shows you everything the browser told it without asking

    This interactive web page demonstrates how browsers automatically expose sensitive user data—including location, device specifications, installed fonts, and login status—to websites without explicit user consent, highlighting a critical security and privacy gap in web standards. For IT leaders, this reveals a fundamental tension between web functionality and user privacy that existing security controls cannot adequately address, as these data exposures occur through standard, documented browser APIs by design. Organizations must reassess their data governance strategies and user privacy protection mechanisms, as traditional defenses (VPNs, cookie blocking, incognito browsing) cannot prevent this passive fingerprinting and identification.

  • Security & PrivacyHacker News3m

    UK Biobank health data keeps ending up on GitHub

    UK Biobank has filed 110 DMCA takedown notices since July 2025 to remove participant health data inadvertently uploaded to GitHub by researchers across 14+ countries, exposing a critical vulnerability in data governance where copyright mechanisms are being misused as a privacy enforcement tool. This incident reveals significant risks in research data management practices and highlights the inadequacy of existing legal frameworks—the UK lacks privacy-specific takedown provisions—leaving organizations vulnerable to data exposure and forcing reactive rather than preventive security measures. IT leaders must recognize this as a systemic organizational risk requiring stronger data loss prevention controls, researcher training, and governance frameworks to prevent sensitive data from reaching public repositories in the first place.

  • Security & PrivacyTechCrunch2m

    Cosmetics giant Rituals confirms data breach of customer membership records

    Rituals, a €2.4 billion cosmetics retailer with 41 million customers, disclosed a data breach of its membership database affecting customers across Europe, the UK, and the US, exposing names, dates of birth, addresses, phone numbers, and account preferences. This incident exemplifies the growing targeting of retail customer databases for extortion, requiring IT organizations to strengthen identity and access controls, audit third-party data handling practices, and implement robust breach detection capabilities. The breach underscores critical governance gaps, as Rituals declined to provide breach timeline details or affected customer counts, indicating potential deficiencies in incident response and stakeholder communication protocols.

  • Security & PrivacyTechCrunch2m

    Fashion retailer Express left customers’ personal data and order details exposed to the internet

    Fashion retailer Express exposed sensitive customer data including names, addresses, phone numbers, emails, and partial payment card information through a misconfigured web vulnerability that allowed sequential order number manipulation to access other customers' records. This incident exemplifies a critical pattern of preventable data exposures among major retailers and underscores the urgent need for IT organizations to implement robust access controls, secure APIs, and vulnerability disclosure programs to mitigate data breach risks and regulatory compliance obligations. The company's inability to quickly notify customers and lack of a clear security incident response process highlights the business and reputational damage that inadequate security maturity can inflict on large enterprises.

  • Security & Privacy9to5Mac2m

    36M Xfinity customers had their data exposed – here’s how to claim your payout

    A significant breach affecting 36 million Xfinity customers in 2023 has resulted in a $117.5 million settlement, highlighting critical risks in third-party software supply chain vulnerabilities—in this case, a Citrix product patch that was delayed in deployment. For IT leaders, this incident underscores the business impact of delayed vulnerability remediation and the importance of robust vendor risk management, as organizations remain exposed even after patches are available. Organizations must accelerate their patching cadence and implement stricter controls over critical third-party dependencies to avoid similar costly breaches and regulatory exposure.

Browse all tags