This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
Military Personnel Targeted by Adversaries Using Location Data, Raising National Security Concerns
Reports indicate that U.S. troops' phone location data has been exposed and exploited by foreign adversaries. This vulnerability stems from commercial data brokers who collect and sell sensitive location information, which can then be acquired by hostile actors. A U.S. senator has highlighted the advertising industry's data collection practices as a significant national security threat due to the potential for misuse of such valuable personal data. This incident underscores the critical intersection of personal privacy, commercial data practices, and national security.
A public sector organisation in the EU plans to deploy a new AI system for processing citizen applications, which is classified as high risk under the AI Act. What is a mandatory step this organisation must take before deploying the system, starting December 2027?
Conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35.
Perform a Fundamental Rights Impact Assessment (FRIA) as per the AI Act.
Obtain prior authorisation from the European Data Protection Board (EDPB).
Implement a 'privacy by design' approach and document it internally.
France's data protection authority, the CNIL, has imposed a 5 million euro fine on IQVIA for unlawful processing of health data. The sanction underscores the strict regulatory stance on sensitive personal information, particularly within the healthcare sector, and highlights the importance of adhering to GDPR principles regarding data minimization and consent.
Carnival Cruise Line has confirmed that the ShinyHunters hacking group accessed and exfiltrated approximately 6 million customer records during an April breach. This incident adds to a growing list of large scale data breaches impacting various sectors, underscoring the persistent threat of cyberattacks and the need for robust data security measures.
The GreyVibe hacking group is reportedly leveraging advanced AI models like ChatGPT and Gemini to enhance their cyberattack capabilities. This development highlights the dual use nature of AI technologies and the increasing challenge for cybersecurity professionals to defend against AI augmented threats, pointing to a critical need for effective AI governance frameworks.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.