Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Massive Fortinet Firewall Breach Exposes VPN Credentials of Tens of Thousands of Organizations

A large scale cyberattack has resulted in the compromise of an estimated 73,000 to 75,000 Fortinet firewalls globally. Threat actors exploited vulnerabilities to steal VPN credentials, giving them unauthorized access to numerous organizational networks. This incident highlights critical supply chain risks and the far reaching consequences of widespread security flaws in essential network infrastructure. The compromise affects a significant number of companies and organizations relying on Fortinet products for their network security.

Today's question

The concept of 'compatible further processing' under Article 5(1)(b) is assessed by considering:

  1. The link between original and new purposes, the context of collection, the nature of the data, possible consequences, and the existence of appropriate safeguards (as per Article 6(4))
  2. Only whether the data subject consented, following the requirements set out in the GDPR provisions, especially for large-scale processing activities, following a documented assessment process
  3. Only whether the controller finds the new purpose convenient, following the requirements set out in the GDPR provisions, subject to appropriate oversight mechanisms
  4. Only the financial cost of new processing, under the standard data protection compliance framework, with corresponding procedural safeguards

Answer this question on the site

Worth knowing

  1. Digital Sovereignty Requires a Defined Operating Model amidst Global Cybercrime Spike

    The concept of digital sovereignty, aiming for national control over digital infrastructure and data, requires a clear operating model to be effective. This call comes as cyber offenses increasingly dominate crime statistics in regions like Asia and the South Pacific, highlighting the urgent need for defined national strategies to protect data and critical digital assets. Without structured policies and implementation plans, the aspirational goal of digital sovereignty remains largely theoretical in the face of escalating cyber threats.

  2. Google Plans to Use UK and EU User IP Addresses for Ad Personalization

    Google intends to utilize user IP addresses for ad personalization within the UK and EU, raising questions regarding privacy implications and compliance with stringent regional data protection regulations. The move could provide more granular targeting for advertisers but equally presents challenges for Google in demonstrating lawful processing and obtaining necessary consent under GDPR and similar frameworks. Privacy advocates are likely to scrutinize this change closely for its impact on user rights and data minimization principles.

  3. India Imposes Temporary Telegram Ban over Exam Fraud Concerns, Prompting VPN Usage

    India has temporarily banned Telegram, citing widespread concerns over its use in facilitating exam fraud, a decision that also affected users in the UAE. The ban underscores a growing global trend of governments restricting access to communication platforms in response to perceived misuse, often raising questions about freedom of speech and digital rights. Users are reportedly circumventing the ban using VPNs, highlighting the technical challenges of enforcing such national restrictions.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.