PowerSchool hacked, Cyber Force study, EC gets GDPR fine
Jan 9, 2025
auto_awesome
PowerSchool faces a major hack, impacting over 50 million students' data. Lawmakers are pushing for a revived Cyber Force to tackle escalating cyber threats. The European Commission receives its first GDPR fine related to a data mishap with Facebook. Phishing schemes targeting Microsoft 365 raise alarms, while Akamai pulls out of China amid regulatory challenges. Emerging threats are highlighted, including vulnerabilities affecting the UN and the Green Bay Packers, adding urgency to cybersecurity measures.
PowerSchool's data breach affected over 50 million students, highlighting vulnerabilities in edtech security and the need for robust protections.
Lawmakers are pushing for a dedicated cyber force to enhance national security, emphasizing the urgency of a comprehensive cyber defense strategy.
Deep dives
PowerSchool Data Breach and Response
PowerSchool, a leading edtech company, experienced a significant data breach affecting over 50 million U.S. students. Threat actors accessed the customer support portal using compromised credentials on December 28th, obtaining sensitive information such as names, addresses, and potentially social security numbers, depending on the school district. In response to the incident, PowerSchool confirmed that while it did not suffer a ransomware attack, it paid an extortion demand to prevent data leaks. The company is providing credit monitoring services for affected adults and identity protection services for minors to mitigate the impact of this breach.
Legislative Efforts for a U.S. Cyber Force
House lawmakers are re-examining the establishment of a dedicated cyber force within the U.S. military to enhance national digital defense capabilities. Representative Morgan Luttrell has emphasized the need for an independent assessment of this initiative, having previously supported an amendment in the defense policy bill that required such a study. Although the final bill was signed into law without a specified deadline for the assessment to be completed, Luttrell expressed concerns that the absence of a timeline could hinder progress. He warned that if this initiative fails for a third consecutive year, he would consider lobbying future leadership to renew discussions on the matter.
Lawmakers expected to revive attempts for new Cyber Force study
European Commission receives first GDPR fine
Huge thanks to our sponsor, Nudge Security
Nudge Security is the only solution for SaaS security and governance that can discover up to two years of historical SaaS spend along with usage insights so you can uncover wasted spend and sources of unnecessary risk. Start a free 14-day trial today
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode