Search Articles

Search through our archive of curated compliance and cybersecurity news.

Found 4 results for "data breach"

Clear search

Wegman's Supermarket chain is collecting biometric facial recognition data from customers without apparent explicit consent or transparency. This practice raises significant privacy concerns and potential violations of biometric data protection re...

My Take: If you're deploying facial recognition in retail without explicit consent and clear signage, you're not just risking BIPA fines in Illinois—you're writing checks your legal team will be cashing for years across multiple state laws. The "we'll stay quiet and hope nobody notices" approach stopped working the moment Clearview AI became a cautionary tale.

From digest: 2026-01

Covenant Health Data Breach Impacts 478,000 Individuals

Jan 02, 2026 SecurityWeek data breach

Covenant Health, a Massachusetts-based healthcare provider, disclosed a significant data breach affecting 478,188 individuals after a ransomware attack on May 18, 2025. The breach exposed sensitive personal and health information including names, ...

My Take: Props to Covenant for not paying—refusing to fund criminal operations is the right call even when it hurts. But here's the hard truth: if Qilin got in and exfiltrated 478k records, your HIPAA "compliance" program failed at the only job that actually matters.

From digest: 2026-01

The biggest cybersecurity and cyberattack stories of 2025

Jan 01, 2026 BleepingComputer security incident

This article summarizes major cybersecurity incidents and cyberattacks from 2025, including the PornHub data breach affecting 200+ million subscribers and widespread ClickFix social engineering attacks targeting multiple platforms. The incidents i...

My Take: The PornHub breach is a nightmare scenario for privacy teams—GDPR fines aside, good luck explaining to your board why you're managing *that* kind of sensitive data without defense-in-depth. ClickFix attacks are the reminder that your security awareness training needs to catch up to 2025: users don't click attachments anymore, they're copying malicious commands because a fake CAPTCHA told them to.

From digest: 2026-01

Infosecurity's Top 10 Cybersecurity Stories of 2025

Jan 01, 2026 Infosecurity Magazine security incident

This article is a roundup of major cybersecurity stories from 2025, highlighting multiple high-profile security incidents including IoT device infections, Fortinet firewall credential leaks, and vendor withdrawals from security evaluations. The in...

My Take: If your 2025 incident response plan doesn't account for supply chain compromise and legacy IoT devices, you're planning for last year's threats. The Fortinet credential leak is the headline, but the real pattern here is how quickly "secure by default" vendors become single points of failure.

From digest: 2026-01