This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
US Lawmakers Grapple with Warrantless Surveillance as Spy Laws Near Expiration
As US spy laws approach their expiration date, lawmakers are divided on how to protect American citizens from warrantless surveillance. This debate highlights the ongoing tension between national security interests and individual privacy rights, particularly concerning government access to communications data. The outcome will significantly shape the legal framework for intelligence gathering and its oversight for years to come. Privacy advocates are pushing for stronger safeguards to prevent potential abuses of power.
A breach involving the loss of an encrypted USB drive containing personal data:
Always requires notification to all data subjects, as required under the breach notification provisions
Always requires notification to the supervisory authority, in accordance with the security obligations framework
Qualifies as a security incident but falls below the notification threshold established for supervisory authority reporting
May not require notification if the encryption was strong enough to make the data unintelligible to unauthorized persons and the key was not compromised
Educational publisher McGraw Hill has reportedly fallen victim to a ransomware attack, resulting in the exposure of 13.5 million records. This incident underscores the critical vulnerability of large organizations holding sensitive personal data. The breach highlights the pervasive threat of ransomware and the extensive impact it can have on data privacy.
A report indicates that Google Chrome offers insufficient protection against sophisticated browser fingerprinting techniques, a common method for tracking users online without cookies. This vulnerability allows for persistent, unconsented user tracking across websites and sessions. It raises significant concerns about user privacy and the effectiveness of existing browser privacy settings.
Anthropic, an AI company, has reportedly not taken responsibility for a 'design flaw' in its products that could put 200,000 servers at risk. This alleged neglect highlights the critical need for robust security by design in AI systems and the potential for widespread vulnerabilities when AI developers do not prioritize security. The incident raises questions about accountability when AI systems introduce significant security risks.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.