Tag: Information Security Buzz

PayPal Customer Data Exposed for Six Months in Breach

PayPal has disclosed a data breach that exposed some of its customers’ personal information and led to fraudulent transactions.  The company said it happed due to an error in its PayPal Working Capital (“PPWC”) loan application, an offering that gives businesses a cash advance based on…

Microsoft Copilot Flaw Exposed Confidential Emails

A bug has been causing Microsoft Copilot to read and summarise users’ confidential emails, and it’s been happening since late January.   Microsoft says the issue stems from a code error that bypassed data loss prevention (DLP) policies designed to stop sensitive information from being accessed in…

CISA Warns of Critical Security Vulnerability in Honeywell Cameras

CISA has warned that a critical security vulnerability (CVE-2026-1670) has been identified in four Honeywell CCTV camera models.  “Successful exploitation of this vulnerability could lead to account takeovers and unauthorized access to camera feeds; an unauthenticated attacker may change the recovery email address, potentially…

Who Can You Trust?

Scammers, confidence men, swindlers. Whatever you call them, for all of human history, people have made a living cheating others out of their hard-earned possessions. While that’s never going to change, their tactics, however, always will. In Q4 2025, email…

Eurail User Records Up for Sale on the Dark Web

Eurail BV has confirmed that some customer data impacted by the previously reported security incident has been offered for sale on the dark web and a sample data set has been posted on Telegram.   The company said it is continuing to investigate the scope…

Dutch Telecoms Company Odido Discloses Breach Affecting Approximately 6.2 Million Customers

Dutch telecoms business Odido has disclosed a cyberattack on its customer contact system that happened on 7 February.   The personal information of approximately 6.2 million customers was disclosed, including names, residential addresses, mobile phone numbers, email addresses, account numbers, and ID information such as passports and driver’s licenses.   In a statement, the company…

Customer data from Volvo Group North America exposed in Conduent breach

Almost 17,000 Volvo employees have had their personal data exposed after attackers breached Conduent, an outsourcing company that manages workforce benefits and back-office services.   In a filing with the Maine Attorney General, Volvo Group North America said it learned in late January that employee data had been exposed through systems run by Conduent.  …

Closing the Cross-Platform Security Gap in Citizen Developer Apps

In many ways, managing security for citizen-developer apps is like flying several planes built by different manufacturers all at once. That’s because each no-code development platform uses separate dashboards, controls, policy engines, etc. Microsoft Power Platform measures altitude in feet,…

The Top Pentesting Platforms of 2026: What You Need to Know

What to Look for in a Pentesting Platform? Pen testing is increasingly becoming the way companies prove compliance with data privacy laws and battle-test their defenses. As the primary way of finding and exploiting vulnerabilities (before attackers do), pen testing…