Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Oracle PeopleSoft Zero Day Exploited in Over 100 Company Breaches by ShinyHunters

The ShinyHunters cybercrime group has claimed responsibility for exploiting a zero day vulnerability in Oracle PeopleSoft to breach over 100 organizations. Oracle has recently mitigated this critical vulnerability, but the widespread exploitation highlights significant supply chain security risks. Many organizations use PeopleSoft for human resources and enterprise resource planning, making this a high impact data theft event. The incident underscores the severe consequences of unpatched software and the rapid weaponization of zero day exploits by sophisticated threat actors.

Today's question

When a processor acts outside controller instructions, they:

  1. Remain strictly a processor regardless of their actions
  2. Are automatically exempt from GDPR rules in such cases, as determined by the applicable regulatory criteria
  3. Face no consequences at all for acting outside instructions
  4. May be considered a controller for that unauthorized processing

Answer this question on the site

Worth knowing

  1. South Korea Imposes Record Fine on Coupang for Data Breach Affecting Millions

    South Korea's privacy regulator has levied a staggering fine exceeding $400 million on e commerce giant Coupang following a data breach that impacted millions of users. This monumental penalty highlights the ongoing global trend of stricter enforcement against organizations failing to adequately protect personal data. The severity of the fine underscores regulators' growing intolerance for negligence in data security practices.

  2. Fake Data Breach Notifications Abused via Maine AG's Portal

    An unsettling incident reveals that Maine's Attorney General's office breach notification portal was exploited to publish fraudulent data breach disclosures, including one falsely claiming a breach at VRChat. This highlights a concerning vector for misinformation and potential reputational damage to companies. Such abuses of official channels can erode consumer trust and complicate genuine breach response efforts.

  3. Signal Warns UK Proposal to Scan Devices for Nude Images Endangers All

    Signal has issued a strong warning that the UK's proposed plan to scan user devices for child sexual abuse material (CSAM), specifically nude images, would compromise end to end encryption and endanger the privacy and security of all users. The messaging service argues that such measures create backdoors that can be exploited by malicious actors, diminishing the overall security framework. This policy debate pits child protection against fundamental digital privacy rights.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.