news
California CCPA Cybersecurity Audit Deadline In 2026
California’s new CCPA cybersecurity audit rules took effect on January 1, 2026, giving covered businesses a phased path toward annual cybersecurity audits and executive certifications that begin in 2028. The California Privacy Protection Agency finalized the rules in 2025 after a multi-year rulemaking process, making cybersecurity audits a central privacy compliance duty for companies that…
Read MoreHHS Corrects And Republishes Proposed HIPAA Security Rule Text
HHS has proposed technical corrections and a complete republication of the HIPAA Security Rule text as part of its sweeping cybersecurity overhaul, but the changes have not become law. The correction and republication language comes from the proposed rule published on January 6, 2025, while the latest federal regulatory agenda now targets July 2027 for…
Read MoreAnthropic Source Code Leak Unleashes Massive Chaos
Anthropic accidentally exposed internal source code for Claude Code on March 31, 2026, after a public npm release shipped a debugging source map that let outsiders reconstruct the tool’s readable TypeScript codebase. Anthropic said the incident came from human error in the release process, not a hack, and said no customer data, credentials, or model weights…
Read MoreHawk Law Group Hit by Incransom Ransomware
What Happened in the BreachOn January 31 2026 the ransomware group Incransom (also known as INC Ransom) allegedly breached systems belonging to Hawk Law Group, a personal injury law firm based in Augusta, Georgia. Threat‑intelligence monitoring site Ransomware.live listed Hawk Law Group as a victim of Incransom with an estimated attack date of January 31…
Read MoreFlickr Data Breach Exposes User Data
Flickr said a vulnerability in a third-party email service provider’s system on February 5, 2026 may have allowed unauthorized access to certain Flickr user data fields, including names, email addresses, IP addresses, general location, and account activity, while passwords and payment card numbers were not affected.What Happened in the BreachFlickr told users it learned on…
Read MoreJapan Airlines Luggage System Breach Hits 28k Users
What Happened in the BreachJapan Airlines JAL disclosed that its reservation system for the Same Day Luggage Delivery Service, which allows passengers to send bags from airports to hotels, was infiltrated by a third party and may have leaked personal data of up to 28,000 customers. The unauthorized access targeted the baggage delivery system and…
Read MoreIDMerit Data Breach Exposes Billions of Records
What Happened in the BreachCybersecurity researchers from the Cybernews investigative team uncovered an unprotected MongoDB instance on November 11, 2025 that they traced to US based identity verification firm IDMerit. The exposed server, used to store know your customer KYC data, held multiple databases totaling more than 3 billion records and nearly 1 terabyte of…
Read MoreMassive Adidas Breach Exposes 815K Accounts
What Happened in the BreachA major data leak involving the Adidas Extranet exposed approximately 815,000 rows of information after cybercriminals accessed a third‑party service used by the sportswear giant. Security outlets reported that the stolen dataset contained first and last names, email addresses, passwords, birthdays and company names. The extranet is a restricted portal used by…
Read MorePanera Bread Data breach Exposes 5.1M Customers
What Happened in the BreachPanera Bread told Reuters that an incident occurred and that authorities were notified, and it described the exposed data as customer “contact information.”The extortion group ShinyHunters claimed it stole a much larger dataset and threatened publication, then released data after the extortion attempt failed, according to multiple security and tech outlets…
Read MorePayPal Breach Exposed Data for 6 Months, Funds Stolen
What Happened in the BreachPayPal confirmed that a software error in its PayPal Working Capital (PPWC) loan application led to a data exposure that lasted nearly six months. According to PayPal’s breach notice filed with Massachusetts authorities, the error in the PPWC application exposed personal data to unauthorized individuals between July 1 2025 and December 13…
Read More