home.social

#digitalrisk — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #digitalrisk, aggregated by home.social.

fetched live
  1. This Gmail hack is unsettling not because it’s flashy, but because it’s bureaucratic. Attackers aren’t breaking encryption or outsmarting algorithms. They’re filling out forms. By changing an account’s age and abusing Google’s Family Link feature, they can quietly reclassify an adult user as a “child” and assume parental control. At that point, the rightful owner isn’t hacked so much as administratively erased.

    The clever part is that everything happens inside legitimate features. Passwords are changed. Two-factor settings are altered. Recovery options are overwritten. And when the user tries to get back in, Google’s automated systems see a supervised child account and do exactly what they were designed to do: say no.

    Google says it’s looking into the issue, which suggests this wasn’t how the system was supposed to work. But it’s a reminder of an old lesson. Security failures often happen when protective mechanisms are combined in ways no one quite imagined. The tools aren’t broken. The assumptions are.

    There’s no dramatic fix here, only mildly annoying advice that suddenly feels urgent. Review recovery settings. Lock down account changes. Use passkeys. Because once an attacker controls the recovery layer, proving you’re you can become surprisingly difficult.

    TL;DR
    🧠 Family safety tools are being weaponized
    ⚡ Account recovery can be shut down entirely
    🎓 Legitimate features enable the lockout
    🔍 Prevention matters more than appeals

    forbes.com/sites/daveywinder/2

    #Cybersecurity #Gmail #IdentitySecurity #AccountRecovery #DigitalRisk #security #privacy #cloud #infosec

  2. Stellantis hit by a cyberattack via a third-party provider, exposing the auto industry’s fragile digital supply chains. With rivals facing similar crises and Stellantis already battling losses, it’s clear cybersecurity is now as vital as engineering.

    #Stellantis #CyberAttack #DataBreach #AutoIndustry #CyberSecurity #EV #DigitalRisk #TECHi

    Read Full Article Here :- techi.com/stellantis-cyberatta

  3. Just dropped a new post in a loooong time: AI Instrumental Convergence – A New Enterprise Threat

    If you're not thinking about how AI could accidentally outmanoeuvre your business, you're already behind.

    Read now: ivos.pro/ai-instrumental-conve

    #CyberSecurity #AIThreats #InfoSec #EnterpriseRisk #TechLeadership #AIConvergence #DigitalRisk #CIO #CTO

  4. North Korea’s 🇰🇵 IT worker scams are getting more sophisticated, while Western defenses remain reactive. Over 1,000 emails and new personas tied to DPRK operatives have been exposed, revealing lavish lifestyles, AI-generated fake identities, and state-level monitoring.

    TL;DR
    🕵️ Researchers exposed key operatives and email networks
    🧠 DPRK IT workers use AI, stolen IDs, and fake personas
    🎭 Operatives get autonomy, luxury, and state protection
    📡 Internal surveillance and quotas drive risky behavior

    wired.com/story/north-korean-i
    #nationalsecurity #cyberespionage #digitalrisk #infosecleadership #security #privacy #cloud #infosec #cybersecurity

  5. ⏰ Just 24 hours.

    That’s all EU companies now have to report a significant cyber incident under new laws like NIS2.

    This isn’t just red tape—it’s Europe’s attempt to build real-time digital resilience.

    Could your org meet the deadline?

    📖 Read more: blueheadline.com/cybersecurity

    #CyberSecurity #TechPolicy #DigitalRisk #BlueHeadline #CyberResilience #EURegulation #NIS2 #CyberDefense #InfoSec #Technology

  6. ⚠️ Genetic privacy alert: 23andMe’s bankruptcy puts your DNA data at risk 🔬📉

    With user data now part of potential asset sales, EFF is urging all customers to act now:

    🧬 Download your data — store it securely for personal use
    🗑️ Delete your account + data — this includes reports, raw data, and family tree connections
    ❌ Revoke research consent — and explicitly request sample destruction

    Why it matters:
    • DNA reveals more than identity — it exposes health, ancestry, and family connections
    • The data doesn’t just belong to you — it can implicate relatives who never opted in
    • A new owner might not respect your privacy

    Take control now. Your genes deserve better security than a bankruptcy fire sale.

    #Privacy #DNA #DataRights #CyberSecurity #23andMe #DigitalRisk #security #privacy #cloud #infosec

    eff.org/deeplinks/2025/03/how-

  7. 🔓 200M X (Twitter) user records leaked in a 34GB free-for-all—again.

    Data enthusiast “ThinkingOne” released the files after allegedly failing to get a response from X. The breach combines:
    ・Data from a 2022 vulnerability X previously downplayed
    ・January 2025 breach data
    ・A total of 2.8 billion records spanning X user IDs, emails, bios, locations & more

    X continues to deny its systems were the direct source of the leak. But researchers confirm much of the data is real—and the scale is unmatched.

    💡 The kicker? ThinkingOne believes this might’ve required internal access, or an attack of unprecedented sophistication.

    Even without passwords, this treasure trove fuels phishing, impersonation, and targeted disinformation.

    👉 forbes.com/sites/daveywinder/2

    #CyberSecurity #DataBreach #Privacy #XPlatform #InfoSec #Twitter #SecurityAwareness #DigitalRisk #UserData

  8. 🔐 Let's protect your business: Extreme and real peril of cyberthreats 🌐
    Dive into the dynamic realm of cybersecurity with us! From surging threats to regulatory nuances, discover key strategies for a resilient digital future for your business. Let's fortify our defenses together! 🔒💻
    relianoid.com/blog/identify-th

  9. In this blog series, the author discussed how digital strategy and digital risk are essential to kickstarting a security transformation journey. He then looked into the use cases of secure access service edge (SASE) architecture with security service edge (SSE) capabilities and zero trust as part of the journey. netskope.com/blog/3-key-use-ca #DigitalStrategy #DigitalRisk #SecureAccessServiceEdge #ZeroTrust