Tag: data privacy

Italy Bans Chinese DeepSeek AI Over Data Privacy and Ethical Concerns
News

Italy Bans Chinese DeepSeek AI Over Data Privacy and Ethical Concerns

Due to insufficient information about how DeepSeek uses customers' personal data, Italy's data protection watchdog has barred the Chinese artificial intelligence (AI) company's service within the nation. This comes days after DeepSeek was questioned by the Garante, the authority, over its data management procedures and the source of its training data. It specifically sought to ascertain what personal information is gathered by its mobile app and web platform, from what sources, for what reasons, under what legal circumstances, and whether it is kept in China read more about Italy Bans Chinese DeepSeek AI Over Data Privacy and Ethical Concerns. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, bre...
Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations
News

Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations

OpenAI, the company behind ChatGPT, was fined €15 million ($15.66 million) by Italy's data protection regulator for the way the generative AI program manages user data. The penalties was imposed almost a year after the Garante discovered that ChatGPT had violated the General Data Protection Regulation (GDPR) of the European Union by processing user data to train its service. According to the authority, OpenAI handled user personal data to train ChatGPT without having a sufficient legal basis and failed to notify it of a security incident that occurred in March 2023. Additionally, the corporation was accused of violating the transparency principle and its related disclosure duties to users read more about Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations. Get...
FTC Slams Avast with $16.5 Million Fine for Selling Users Browsing Data
News

FTC Slams Avast with $16.5 Million Fine for Selling Users Browsing Data

The Federal Trade Commission (FTC) of the United States has fined antivirus company Avast $16.5 million for allegedly selling customers' browser information to marketers while falsely advertising that its products would prevent internet monitoring. Furthermore, the business is not permitted to sell or license any web browsing data for commercial use. Additionally, it must inform users whose browsing information was sold to unaffiliated third parties. Avast "unfairly collected consumers' browsing information through the company's browser extensions and antivirus software, stored it indefinitely, and sold it without adequate notice and consumer consent," according to the FTC's lawsuit against the company read more FTC Slams Avast with $16.5 Million Fine for Selling Users Browsing Data...
MongoDB Suffers Security Breach Exposing Customer Data
News

MongoDB Suffers Security Breach Exposing Customer Data

On Saturday, MongoDB announced that it is now looking into a security incident that resulted in the disclosure of customer account metadata and contact details due to illegal access to "certain" business systems. The American database software provider claimed that on December 13, 2023, it saw unusual behavior for the first time and that night, it launched its incident response operations. While noting that "this unauthorized access has been going on for some period of time before discovery," it said that it is "aware of any exposure to the data that customers store in MongoDB Atlas." It omitted information regarding the precise duration read more MongoDB Suffers Security Breach Exposing Customer Data. Get up to date on the latest cybersecurity news and enhance your&nbs...
New critical Citrix NetScaler flaw exposes ‘sensitive’ data
News

New critical Citrix NetScaler flaw exposes ‘sensitive’ data

There is a critical severity fault in Citrix NetScaler ADC and NetScaler Gateway that makes it possible for sensitive data to be revealed from susceptible appliances. With a 9.4 CVSS rating, the vulnerability—tracked as CVE-2023-4966—is remotely exploitable without requiring a lot of human involvement, high rights, or complexity. However, in order for the appliance to be exposed to assaults, it must be set as either a AAA virtual server or a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy). Although using the vulnerability may result in "sensitive information disclosure," the vendor has not specified what information read more New critical Citrix NetScaler flaw exposes 'sensitive' data. Stay informed with the best cybersecurity news and raise your cybersecurity awarene...
Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data
News

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

Microsoft announced on Monday that it has taken action to address a flagrant security blunder that had exposed 38 terabytes of sensitive information. The leak was found on the company's AI GitHub repository, and it's believed to have accidentally become public when a collection of open-source training data was published, according to Wiz. Additionally, it had a disk backup of the workstations of two former workers, which contained over 30,000 internal Teams communications in addition to secrets, keys, and passwords. The repository, known as "robust-models-transfer," is no longer reachable. It provided the raw code and machine learning models read more Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data. Stay informed with the best cybersecurity news and...
Multiple Flaws in CyberPower and Dataprobe Products Put Data Centers at Risk
News

Multiple Flaws in CyberPower and Dataprobe Products Put Data Centers at Risk

Multiple security flaws affecting Dataprobe's iBoot Power Distribution Unit (PDU) and CyberPower's PowerPanel Enterprise Data Centre Infrastructure Management (DCIM) platform could potentially be used to gain unauthorised access to these systems and cause irreparable harm to target environments. The nine vulnerabilities, with severity levels ranging from 6.7 to 9.8, from CVE-2023-3259 to CVE-2023-3267, give threat actors the ability to shut down entire data centres, compromise data centre deployments, steal data, or carry out large-scale assaults. According to a report published with The Hacker News by Trellix security experts Sam Quinn, Jesse Chick, and Philippe Laulheret, "An attacker could chain these vulnerabilities together to gain full access to these systems read more Multipl...
Encryption Flaws in Popular Chinese Language App Put Users’ Typed Data at Risk
News

Encryption Flaws in Popular Chinese Language App Put Users’ Typed Data at Risk

A popular Chinese language input tool for Windows and Android has been discovered to have major security weaknesses that could allow a hostile intruder to understand the text inputted by users. The findings come from the University of Toronto's Citizen Lab, which examined the encryption algorithm used in Tencent's Sogou Input Method, an app with over 455 million monthly active users on Windows, Android, and iOS. The flaws are in EncryptWall, the service's own encryption mechanism, and allow network eavesdroppers to extract textual content and get access to sensitive data read more Encryption Flaws in Popular Chinese Language App Put Users' Typed Data at Risk. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of t...
Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China
News

Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China

Due to the discovery of two file management apps on the Google Play Store as spyware, up to 1.5 million Android users' security and privacy are at risk. These applications act dishonestly and covertly transmit private user information to malicious servers in China. This ominous intrusion was discovered by Pradeo, a top mobile security firm. According to the research, the same organisation is responsible for both spyware applications, File Recovery and Data Recovery (com.spot.music.filedate), which has received over a million downloads, and File Manager (com.file.box.master.gkd) which has received over 500,000 downloads. These ostensibly innocent Android apps, which activate automatically when the device reboots without user input, employ similar harmful techniques read more Two Spy...
Swedish Data Protection Authority Warns Companies Against Google Analytics Use
News

Swedish Data Protection Authority Warns Companies Against Google Analytics Use

Following similar actions taken by Austria, France, and Italy last year, the Swedish data protection agency has advised businesses against using Google Analytics due to concerns associated with American government spying. The development follows an audit that the Swedish Authority for Privacy Protection (IMY) conducted on behalf of the four businesses CDON, Coop, Dagens Industri, and Tele2. "In its audits, IMY considers that the data transferred to the U.S. via Google's statistics tool is personal data because the data can be linked with other unique data that is transferred read more Swedish Data Protection Authority Warns Companies Against Google Analytics Use. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cy...