LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
what to do now

A company says my data was in a breach

You received a notification, or read a story, that a service you use lost customer data.

The first thirty minutes

  1. Change the password on that service, and on any other site where you used the same one.
  2. Turn on two-factor authentication there.
  3. Read what was taken. Passwords and card numbers need action now; names and emails mean more phishing, so be suspicious of related messages for months.

The next day

  1. If financial details were taken, watch statements weekly and consider a card replacement.
  2. If government id numbers were taken, ask your country's credit bureaus about a fraud alert or freeze.
  3. Keep the notification. If the company was negligent, regulators and class actions rely on it.

Keep this evidence

Do not

Who to report to

Usually nothing to report yourself; the company must notify the data-protection regulator. Report if you are then defrauded. Find the numbers and portals for your country in the reporting directory.

General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.

← All playbooks