The Breach News

France Declares Google Analytics Noncompliant with GDPR Data Protection Law

French data protection authority, CNIL, has determined that Google Analytics breaches the European Union’s General Data Protection Regulation (GDPR). This ruling follows a similar finding in Austria just weeks prior. The CNIL’s investigation into the transatlantic transfer of Google Analytics data revealed that this practice lacks appropriate regulatory oversight, particularly…

Read MoreFrance Declares Google Analytics Noncompliant with GDPR Data Protection Law

Seven Tactics Hackers Use to Manipulate ChatGPT’s Responses

Cybersecurity firm Tenable has unveiled significant vulnerabilities in OpenAI’s ChatGPT, uncovering seven distinct risks that could allow malicious actors to compromise user data, circumvent security measures, and embed persistent threats within the model’s architecture. The analysis, referred to as HackedGPT, highlighted that several of the vulnerabilities identified in ChatGPT-4 have…

Read MoreSeven Tactics Hackers Use to Manipulate ChatGPT’s Responses

CISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical security vulnerability affecting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. This action was taken in light of evidence indicating ongoing exploitation of this flaw. Identified as CVE-2024-23113, this vulnerability has a CVSS…

Read MoreCISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

North Korea Leveraged VPN Vulnerability to Breach South Korea’s Nuclear Research Institute

On Friday, the Korea Atomic Energy Research Institute (KAERI), a government-funded entity based in South Korea, reported a breach of its internal network. The infiltration is believed to have been executed by a threat actor linked to North Korea, with the actual breach occurring on May 14. The attackers exploited…

Read MoreNorth Korea Leveraged VPN Vulnerability to Breach South Korea’s Nuclear Research Institute

Proposed Legislation Aims to Provide HIPAA-Style Protections for Consumer Health Data

Data Privacy, Data Security, Healthcare Senate HELP Committee Chair Advocates for Data Protection in Wearable Tech and Health Applications Marianne Kolbasuk McGee (HealthInfoSec) • November 7, 2025 Sen. Bill Cassidy, R-La., a physician and chair of the Senate HELP Committee, is advocating for legislation aimed at aligning new consumer health…

Read MoreProposed Legislation Aims to Provide HIPAA-Style Protections for Consumer Health Data