Skip to main content

Activity

Incidents and actions from tracked entities.

Microsoft issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability tracked as CVE-2026-21509, with a CVSS score of 7.8 out of 10.0. The vulnerability allows attackers to bypass document security checks and is being actively exploited in the wild via malicious files. The emergency patch was released outside Microsoft's normal Patch Tuesday schedule due to active exploitation.

$186.0M

The FTC announced a proposed order to settle allegations that cryptocurrency company Nomad (Illusory Systems Inc.) failed to implement adequate security measures leading to a breach in which hackers stole $186 million from customers. The FTC alleged that Nomad prominently touted its security in advertising, claiming 'security-first' services, but failed to live up to these promises by failing to use secure coding practices, implement processes for receiving and addressing vulnerability reports, respond to security incidents, or utilize widely known technologies that might have helped mitigate consumer losses.

Dario Amodei, along with all six other Anthropic cofounders, pledged to donate 80% of their wealth, citing concerns about wealth concentration from the AI boom. In an essay titled 'The Adolescence of Technology,' Amodei wrote: 'The thing to worry about is a level of wealth concentration that will break society. Wealthy individuals have an obligation to help solve this problem.' Each cofounder's net worth is estimated at ~$3.7B, potentially directing tens of billions to philanthropy. The pledge is not legally binding and no donations have been made yet - equity is 'set aside' pending implementation.

$68.0M

Google agreed to pay $68 million to settle class action claims that Google Assistant-enabled devices (Google Home, Nest Hub, Pixel phones) surreptitiously recorded users' private conversations without consent. The recordings occurred due to 'false accepts' — the device mistakenly activating and recording when no wake word was spoken. Final approval hearing is scheduled for March 19, 2026.

On January 23, 2026, ByteDance and a consortium including Oracle, Silver Lake, and the Abu Dhabi state-backed MGX finalized TikTok USDS Joint Venture LLC, reducing ByteDance's stake in TikTok's US operations to 19.9% while Oracle became the venture's security partner storing US user data on its cloud and auditing compliance. However, ByteDance retained a licensing agreement covering TikTok's recommendation algorithm -- the kind of ongoing 'operational relationship' the 2024 Protecting Americans from Foreign Adversary Controlled Applications Act explicitly required be eliminated. National security experts, including former State Department official Michael Sobolik, called the arrangement a 'unilateral surrender to Beijing' that 'allows Beijing to manipulate content and steal Americans' data, even after today's announcement.' Sen. Ed Markey stated the deal 'maintained an operational relationship between ByteDance and TikTok USDS, violating the spirit, if not the letter, of the law' and said the White House had provided 'virtually no details' on whether the algorithm is truly free of Chinese influence, calling for Congressional investigation. Even Rep. John Moolenaar, chair of the House Select Committee on China and a supporter of the underlying law, said after the deal closed that 'questions... need to be answered' about whether China retains algorithmic influence and whether user data is secure.

A January 2026 Citizen Lab report found Cellebrite equipment was used in at least seven cases to extract data from phones seized from activists and a journalist detained during pro-Palestinian protests in Jordan between late 2023 and mid-2025. None of the individuals consented to the searches. All four devices forensically analyzed showed Cellebrite product use in 2024-2025.

At Intuit's January 22, 2026 Annual Meeting of Stockholders, a proposal submitted by the conservative National Center for Public Policy Research -- requesting the board report on the financial return and legal/reputational risk of Intuit's diversity, equity and inclusion programs -- was decisively rejected by shareholders. Per Intuit's SEC 8-K vote-results filing, 228,853,804 votes were cast against the proposal versus 1,753,458 for (~99.2% against). Intuit's board had recommended stockholders vote against the proposal, calling it 'unnecessary and wasteful' and affirming that employees are one of the company's four key 'True North' stakeholders. The rejection came amid a wave of similar anti-DEI shareholder proposals and corporate DEI rollbacks across the tech and broader corporate sector in 2025-2026, making Intuit's active defense of its programs a notable outlier.

Vietnam's competition authority summoned VNG over Zalo's updated user terms, which required forced consent to broad data collection days before Vietnam's Personal Data Protection Law took effect in late December 2025. Vietnamese regulators separately fined VNG (alongside TikTok) roughly $64,700 total for user data transgressions on Zalo, and fined VNG over a game distributed with content that did not match its approved license. VNG said it cooperated with authorities and revised several policies.

On January 21, 2026, Cisco disclosed a critical code injection vulnerability (CVE-2026-20045, CVSS 8.2) affecting Unified Communications Manager, Webex Calling, and related products that was actively exploited as a zero-day before a patch was available. The vulnerability allowed attackers to send crafted HTTP requests to obtain user-level access to the underlying operating system and escalate privileges to root. Cisco's PSIRT was aware of attempted exploitation in the wild. The U.S. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies until February 11, 2026 to deploy updates. The zero-day status indicates attackers discovered the vulnerability before Cisco's security teams, representing a failure to identify and remediate critical vulnerabilities before exploitation.

Poland's consumer protection authority UOKiK filed formal greenwashing charges against Bolt (alongside Tchibo and Zara) on January 21, 2026, alleging its 'Project Zero' and 'zero-emission vehicles' marketing misleads consumers into believing rides are broadly zero-emission when the vast majority of its fleet still uses internal combustion engines and only the driving stage, not the vehicle lifecycle, is emission-free. UOKiK also challenged Bolt's '100% renewable energy' claims for offices, warehouses and charging stations, which rely largely on Energy Attribute Certificates offsetting consumption rather than direct renewable purchases, without clearly disclosing scope. Bolt faces potential fines of up to 10% of turnover per contested practice.

A November 2025 internal German Ministry of Defense presentation found Helsing's HX-2 loitering munitions suffered high failure rates on takeoff and vulnerability to electronic jamming during Ukrainian frontline testing. Ukraine suspended additional orders and Germany said it would not place follow-on orders until Ukraine formally expressed renewed interest. Helsing disputed the characterization, said it was unaware of the internal presentation, rejected the reported failure rates, and said it was 'too early to draw conclusions from limited frontline testing.'

An IT sector union (NITES) flagged that Wipro had delayed onboarding of more than 250 engineering graduates who had received offer letters, in some cases for over a year, leaving them unemployed without pay or clear start dates. India's central labour ministry referred the complaint to the Karnataka state labour department for investigation. The pattern echoes similar onboarding-delay complaints against other large Indian IT services firms.

A widespread malware campaign abused Google's Chrome Web Store for months, exposing private AI chatbot conversations and browsing data from roughly 900,000 users. The campaign involved two malicious browser extensions identified as 'ChatGPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' and 'AI Sidebar with DeepSeek, ChatGPT, Claude.' The extensions remained available in the Chrome Web Store despite the security vulnerabilities.

42 State Attorneys General issued a letter to Microsoft (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

Crunchbase confirmed it was hacked in January 2026 after the cybercriminal group ShinyHunters published samples of stolen data. The company stated they detected a cybersecurity incident where a threat actor exfiltrated certain documents from their corporate network. Investigators linked the attack to a broader ShinyHunters campaign focused on voice phishing targeting Okta single sign-on credentials, with similar techniques tied to recent breaches at SoundCloud and Betterment.

42 State Attorneys General issued a letter to Google (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

42 State Attorneys General issued a letter to Meta (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

The Wikimedia Foundation announced commercial partnerships through Wikimedia Enterprise with Amazon, Meta, Microsoft, Mistral AI, and Perplexity for structured API access to Wikipedia data for AI training. This formalizes relationships that previously involved unpaid scraping, creating a sustainable revenue model.

VP Lisa Jackson, essentially Apple's chief sustainability officer, retired in January 2026 and Apple eliminated the CSO role rather than replacing her. This represents a significant organizational shift for one of the world's largest tech companies, removing dedicated executive leadership for sustainability despite Apple's strong environmental track record including 60% CO₂ emissions reduction since 2015 and 100% renewable electricity for all corporate operations since 2018.

Nike disclosed it is investigating unauthorized access that resulted in the extraction of approximately 1.4 terabytes of internal data. The incident involves a large volume of files taken from internal systems, which signals sustained access rather than a short-lived intrusion. The breach represents a significant compromise of Nike's internal systems and data.

Pinterest announced in January 2026 that it plans to cut 15% of its workforce, with approximately 700 employees expected to lose their jobs. A spokesperson stated the social media company is 'making organizational changes to further deliver on our AI-forward strategy, which includes hiring AI-proficient talent.' The layoffs represent a shift in capital allocation as the company pours money into AI.

In January 2026, YouTube CEO Neal Mohan announced that the platform has paid over $100 billion to creators, artists, and media companies in the past four years. YouTube now has over 3 million channels enrolled in its ad and subscription revenue-sharing program (YPP). Mohan also stated YouTube would lobby for policymakers to recognize creators in labor data and acknowledge them in industry forums, advocating that 'Being a creator is a full-time job with an international audience.'

In January 2026, a UK tribunal approved a £656 million ($840 million) class action against Valve representing up to 14 million UK gamers. The lawsuit alleges Valve has been price-rigging since 2018 through its 30% commission and anti-competitive practices on the Steam platform. Steam holds approximately 75% of the PC game distribution market. Epic Games CEO Tim Sweeney publicly voiced support for the lawsuit. A separate US class action (Wolfire Games v. Valve) with a certified class of ~32,000 publishers is also proceeding.

In January 2026, Shopify cut approximately 100 people (~33%) from its Partnerships division, followed by at least 30 more from Revenue Operations in April/May 2026. CEO Tobi Lutke's April 2025 'AI-before-headcount' memo continues to guide the company's hiring decisions. (Note: an earlier, unrelated internal sales-fraud investigation at Shopify, originally bundled into this incident, was split out as its own incident — see the separate 2025 sales-fraud/exec-departure record.)