Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

security

DAAPrivacyRightIcon
Gaming Gear

Whistleblower claims DOGE uploaded Social Security data to unsecure cloud server

by admin August 26, 2025



The Social Security Administration’s (SSA) chief data officer, Charles Borges, has filed a whistleblower complaint alleging that members of the Department of Government Efficiency (DOGE) uploaded a copy of a key Social Security database to an unsecured cloud environment in June, the New York Times reported. This may have exposed the personal information of hundreds of millions of Americans. The complaint alleges that under the authority of the SSA’s Chief Information Officer, Aram Moghaddassi, a copy of the country’s Social Security information was held in a cloud environment that lacked any security oversight or adherence to SSA security protocols. The information uploaded was from the Numerical Identification System (Numident) database, and includes the names, Social Security numbers, place and date of birth, citizenship, race, ethnicity, address and even parents’ names of anyone who has ever had a Social Security number, even those who are no longer alive.

 “Mr. Borges has raised concerns internally with various authorities in the Chief Information Officer’s (CIO) office and to date has not been made aware of any remedial action. He therefore elevates his concerns out of a sense of urgency and duty to the American public,” the  complaint states. “Should bad actors gain access to this cloud environment, Americans may be susceptible to widespread identity theft, may lose vital health care and food benefits, and the government may be responsible for reissuing every American a new Social Security number at great cost.” 

The approvals to copy the Numident database were, despite the enormous risk of that information falling into the wrong hands, approved expeditiously, according to the complaint. “I have determined the business need is higher than the security risk associated with this implementation and I accept all risks,” Moghaddassi wrote in a memo. Another senior DOGE official, Michael Russo, is alleged to have signed off on the decision in under half an hour. Before accepting his position as CIO, Moghaddassi worked for then-de facto DOGE boss Elon Musk at both Neuralink and X.

In a statement to the New York Times, SSA spokesperson Nick Perrine said the agency was “not aware of any compromise to this environment” and that “the data referenced in the complaint is stored in a longstanding environment used by S.S.A. and walled off from the internet.”

That DOGE should have access to sensitive data in the first place was the subject of tension within the federal government earlier this year. Several lawsuits attempted to block DOGE from accessing SSA, Treasury and Office of Personnel Management data. Via the so-called shadow docket, the Supreme Court struck down a Fourth Circuit injunction preventing the agency from siphoning SSA data in June. Among his other allegations, Borges claims DOGE regained access to the data during the injunction period.  



Source link

August 26, 2025 0 comments
0 FacebookTwitterPinterestEmail
Secure online access with password and login page to manage personal profile account. Secured connection and data security on internet. Cybersecurity and sign in form. User working on laptop computer.
Gaming Gear

The government’s spending review: Citizen data and digital identity projects need high security by default

by admin August 21, 2025



The UK government’s spending review in June set out its plans to invest in Britain’s renewal: its security, health and economy.

Digital technologies featured heavily in the review with government pledging that it will provide “funding directly to departments to build strong digital and technology foundations, modernize public service delivery, and drive a major overhaul in government productivity and efficiency.”

One of the ways it has done this is by introducing a GOV.UK Wallet and a GOV.UK App, which aims to deliver more personalized customer experiences and verifiable digital credentials for citizens.


You may like

This is now available to the public in beta form. The government is also creating a new National Data Library to join up data across the public sector and a single patient NHS record, which is due to be available by 2028, so that every part of the health service has a full picture of a patient’s care.

However, if the UK is to realize the benefits of its digital ambitions, it must ensure the public can trust the systems underpinning them.

Sam Peters

Social Links Navigation

Chief Product Officer, ISMS.online.

The pros and cons of centralizing data

Centralizing citizen data and digital identities has clear benefits. It enables more joined up services, reduces duplications allows for more seamless, personalized user experiences and could improve access and efficiency across the NHS and other public services.

For the NHS, for example, a single patient record could help doctors and specialists deliver better, more consistent care across the health service. For citizens interacting with government departments, a unified app and wallet could simplify administrative tasks and improve digital inclusion.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Technology Secretary Peter Kyle has said in recent interviews that, “People’s private data will not be shared outside of government.” However, despite the Technology Secretary’s assurances, this approach does come with significant risks. Centralized citizen data represents some of the most sensitive information any organization could hold. Health records, identity details and government interactions, combined in a single system, are a goldmine for cybercriminals.

And no doubt there will be some concerns from the public regarding its security – particularly in light of recent, very public, high profile cyber-attacks. Over the last 18 months, the UK has seen a series cyber attacks on both public and private sector organizations, including health authorities and councils, as well as the recent M&S and Qantas data breaches.

These incidents have highlighted the vulnerability of critical services and the real-world impact of compromised data, from patient safety to public confidence.

As these services become more integrated and reliant on shared data infrastructure, the risk of a breach also grows. A single point of access to multiple datasets can become a high-value target for threat actors. The more data an attacker can obtain from one place, the more appealing, and damaging, a breach can be.

A proactive approach to information security

With these very real threats, a proactive, systems-led approach to information security must be embedded from the outset.

The government needs to ensure that privacy by design and security by default is in every digital service developed. This means applying rigorous access controls, encryption, and secure development practices across every data touchpoint. That said, it is crucial that continuous monitoring for vulnerabilities and suspicious activities happens throughout the system lifecycle – and not just after deployment.

Similarly, the systems need to ensure that they comply with UK GDPR, the Data Protection Act and other relevant standards.

These requirements must be seen not as a burden by the government but as the bedrock of responsible digital innovation.

Building a high-security posture

To meet these heightened security demands, following the guidance provided by internationally recognized security standards, such as ISO 27001, can be a logical place to start to get ahead of the increased risks to highly personal data this approach represents.

Standards such as ISO 27001 offer a structured, repeatable framework for managing risk, protecting information assets and demonstrating compliance. But it’s more than a tick-box exercise, it is a cultural shift in how risk is understood, communicated, and mitigated across every layer of an organization.

If the government embeds the principles of ISO 27001 into its delivery of these new services from the outset, rather than retrofitting them post-launch, it can design services that are both secure and scalable. It can ensure that it is identifying and evaluating new and emerging threats as digital services evolve.

It will also mitigate risks through policy, controls and continual improvement. But it will also be able to demonstrate accountability and transparency to the public – which is key.

Transparency is key to building public trust

Security isn’t just about systems, it is also about perception. The government’s digital strategy must be underpinned by public trust. Clear communication about how data is used, who has access, what safeguards are in place and what recourse citizens have in the event of a breach is essential.

Publishing high-level information security policies, adopting standards like ISO 27001 and engaging with the public on data protection issues will help foster the confidence needed to make digital services work.

Public sector leaders must ensure that information security is not treated as an afterthought. That means prioritizing risk management now – not waiting for a breach to expose the consequences of delay.

We list the best identity management solution.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



Source link

August 21, 2025 0 comments
0 FacebookTwitterPinterestEmail
Windows 11 Reset this PC feature
Product Reviews

Microsoft’s August 2025 security updates are breaking recovery tools on Windows 10 and Windows 11 PCs

by admin August 20, 2025



Microsoft has acknowledged an issue with its recent August 2025 security updates that prevent users from resetting or recovering their systems using built-in Windows tools. According the company, the bug affects older versions of Windows 11 including 23H2 and 22H2 as well as Windows 10 22H2, Windows 10 Enterprise LTSC 2019/2021, and Windows 10 IoT Enterprise LTSC 2019/2021.

Installing this month’s security updates can potentially break the Windows recovery options for users. Those attempting to reinstall Windows without losing their personal files through the Reset this PC feature may run into failures. Similarly, the Fix problems using Windows Update feature, which attempts to reinstall the current version of the OS on your device while preserving all your apps, documents, and settings, is also broken. Microsoft has also warned that the bug could affect IT administrators who rely on the RemoteWipe configuration service provider to reset devices remotely.

According to testing by Windows Latest, attempts to reset a PC on Windows 11 23H2 using the Reset this PC feature causes the process to start and then roll back immediately, leaving the reset incomplete. After this failure, no personal files are lost, but the recovery feature becomes unusable. Additionally, Windows doesn’t give any warning that the reset process can fail, meaning most people won’t realize there’s a problem until they actually try to reset their PC.


You may like

Microsoft has confirmed that it is working on an out-of-band update to fix the issue on all affected platforms. Expect an emergency patch to roll out in the coming days, with further details to be shared once they become available.

While the Windows recovery bug does not affect users on the Windows 11 24H2 update, another serious issue has surfaced with August’s security patch which targets storage drives. The latest Windows 11 update KB5063878 is said to be causing storage drives to vanish under heavy workloads, particularly during large file transfers of 50GB or more. While most drives recover after a system reboot, in certain cases the SSDs are completely inaccessible with corrupted data partitions.

According to early analysis done by X user Nekorusukii (@Necoru_cat), the bug is possibly linked to how a storage device handles caching and metadata mapping. Microsoft is yet to formally recognize the flaw. leaving users that regularly deal with large data transfers in limbo.

Until Microsoft acknowledges and patches these issues, users should wait to reset or restore their systems. We can only hope that this new update rolls out soon.

Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.

Follow Tom’s Hardware on Google News to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.



Source link

August 20, 2025 0 comments
0 FacebookTwitterPinterestEmail
  • 1
  • 2
  • 3

Categories

  • Crypto Trends (1,098)
  • Esports (800)
  • Game Reviews (745)
  • Game Updates (906)
  • GameFi Guides (1,058)
  • Gaming Gear (960)
  • NFT Gaming (1,079)
  • Product Reviews (960)

Recent Posts

  • Silent Hill f has a hidden Easter egg that calls back to one of the most iconic horror game themes of all time
  • This Indie Game Punishes You For Skipping Its Cutscenes
  • Here are our Xbox Game Pass games for October
  • Clair Obscur And Choice-Based Games Don’t Have To Validate You
  • Little Nightmares 3 Review – Recurring Dreams

Recent Posts

  • Silent Hill f has a hidden Easter egg that calls back to one of the most iconic horror game themes of all time

    October 8, 2025
  • This Indie Game Punishes You For Skipping Its Cutscenes

    October 8, 2025
  • Here are our Xbox Game Pass games for October

    October 8, 2025
  • Clair Obscur And Choice-Based Games Don’t Have To Validate You

    October 8, 2025
  • Little Nightmares 3 Review – Recurring Dreams

    October 8, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • Silent Hill f has a hidden Easter egg that calls back to one of the most iconic horror game themes of all time

    October 8, 2025
  • This Indie Game Punishes You For Skipping Its Cutscenes

    October 8, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close