Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

US Cyber Agency CISA Exposed Sensitive Credentials on Public GitHub Repository

The United States top cyber defense agency, CISA, left a GitHub repository publicly accessible containing highly sensitive information including passwords, API keys, and tokens. This significant lapse in security was compounded by the use of incredibly obvious filenames for these critical assets. The exposure underlines persistent challenges even for leading cybersecurity entities in maintaining stringent data protection practices. This incident highlights vulnerabilities in safeguarding critical operational data even within organizations tasked with national cyber defense.

Today's question

A UK public sector organisation experiences a cyber incident due to unpatched software, leading to unauthorised access to its content management system and potential exposure of sensitive personal data for approximately 10,000 individuals. Under the UK GDPR, what is the primary obligation infringed by the organisation's failure to maintain adequate security?

  1. Article 5(1)(a) - Lawfulness, fairness and transparency
  2. Article 32(1) - Security of processing
  3. Article 33(1) - Notification of a personal data breach to the supervisory authority
  4. Article 25(1) - Data protection by design and by default

Answer this question on the site

Worth knowing

  1. Discord Implements End-to-End Encryption for All Voice and Video Calls

    Discord has rolled out end-to-end encryption for all its voice and video calling features for every user. This move significantly enhances user privacy by ensuring that only the communicating parties can access the content of their conversations. It represents a major step forward in protecting real time communications on the platform.

  2. NYC Health + Hospitals Breach Exposes Medical Data and Fingerprints of 1.8 Million Individuals

    NYC Health + Hospitals confirmed a data breach where hackers stole sensitive medical data and fingerprints belonging to at least 1.8 million people. This incident underscores the severe risks associated with healthcare data breaches including the compromise of biometric information. The scale of the breach highlights the critical need for robust security measures in healthcare institutions.

  3. Poland Seeks Replacement for Signal with State Developed 'Secure' Alternative

    Poland's government is directing officials to abandon the widely used encrypted messaging app Signal in favor of a new state developed 'secure' alternative. This move signals a national preference for sovereignty over communication channels, raising potential concerns about governmental oversight and data access. The shift may impact the privacy expectations of Polish officials and potentially set a precedent for other nations.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.