Denmark’s central population register (CPR) was the target of a large-scale data access event: unauthorized parties used a private company’s legitimate access rights to query the register and, according to official statements, obtained names, addresses and personal identification numbers for roughly 8.8 million people. The activity lasted about ten days in September and was discovered by the register’s administration on
Category: Compliance and Privacy
GDPR, CCPA, HIPAA, PCI-DSS, SOC 2, ISO 27001, NIST, DORA, NIS2, data privacy, data protection, privacy policy, compliance audit, regulatory compliance, data governance, DPO, data processing agreement, right to erasure, data residency, privacy by design, AI Act, EU AI Act, digital identity, eIDAS, cookie consent, consent management, PECR, data localisation, breach notification
When a Private Diary Becomes Evidence: How a Claude Entry Led to Real-World Charges
A single chat entry that a user treated like a private diary prompted Anthropic’s safety team to escalate a report to law enforcement, and now a Florida woman faces felony charges. The incident — involving statements about an intended attack on a sheriff’s office — is a blunt reminder that conversations with AI systems are not necessarily private and can
Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw
Atlassian has released emergency fixes for a critical arbitrary file access vulnerability that affects eight of its products — including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589 with a CVSS score of 9.3, the flaw allows unauthenticated attackers to retrieve specific files from an application’s web root if they can guess the exact path and filename. While the bug does
Amazon Drops NDAs as Data Center Backlash Grows
Amazon’s recent move to stop using nondisclosure agreements (NDAs) with government agencies marks a tactical shift in a widening dispute over the role of large data centers in local communities. Announced by AWS CEO Matt Garman in a blog post, the change comes as cities and states across the U.S. consider moratoriums and tougher scrutiny of new facilities. The announcement
Lee Orders Nationwide Security Sweep After Multiple South Korean Bank Breaches
South Korea’s president, Lee Jae Myung, has ordered an urgent and comprehensive investigation into a string of recent data breaches that exposed personal information across several banks and finance firms. The incidents, reported in early October 2026, have raised alarms about the security of employee-support systems and third-party services that sit outside core customer banking platforms. Authorities are probing whether
ShinyHunters’ “Rey” Detained in Jordan: What His Cooperation Means for the FBI Probe
A suspected member of the ShinyHunters group who uses the online alias “Rey” has reportedly been detained in Jordan and is cooperating with U.S. law enforcement. Identified in reporting as Saif al‑Din Khader (also known online as ReyXBF), he was allegedly taken into custody on September 29, 2026. Sources say his cooperation is already assisting the FBI and other agencies





