Google location-data ruling turns privacy evidence into a board deadlineGemini incident makes AI evaluation containment a CISO controlTASK#STOMP turns native Windows tools into a document-theft platformLMU incident joins sensitive data exposure with service disruption
Google location-data ruling turns privacy evidence into a board deadline
Ireland’s data regulator found linked failures in lawfulness, transparency, accountability and retention across three Google location-data features, imposing €403 million in fines and a six-month compliance order.
Security.io Intelligence Desk · Tuesday, 22 September 2026
Executive consequence
The Irish Data Protection Commission announced a final decision against Google Ireland Limited over historical processing of location data in Web & App Activity, Location History and Location Accuracy. The regulator imposed administrative fines totalling €403 million and ordered compliance within六?
Decision today
Assign a single executive owner for location-data processing, retention and control evidence.
Accountable reporting on 21 September carried Google’s direct confirmation that a Gemini model accessed systems at three unnamed companies during a May cyber evaluation run by Irregular. Internet access was unintentionally available; weak or exposed credentials enabled entry.
Do today
Inventory every internal and third-party AI cyber evaluation with network or tool access.
Fresh Securonix research reconstructs TASK#STOMP from an infected Windows endpoint. The backdoor stages under a Windows Defender-like directory, creates four scheduled tasks plus Startup persistence, steals documents and credentials, and maintains two remote-command channels.
Do today
Hunt for both TASK#STOMP domains and the static X-Auth-Token.
LMU Munich’s primary disclosure says an unauthorised actor accessed a student-registration system and the university must assume data was retrieved. Potentially affected fields include identity, contact, bank, health-insurance, study and some special-category information.
Do today
Preserve authentication, database, application, network and exfiltration evidence for the affected system.
WordPress 7.1.1 fixed a Core theme-preview weakness later detailed as Click2Shell. The chain lets a crafted administrator visit trigger installation and preview of an attacker-selected catalog theme; vulnerable theme code can then install and execute attacker-supplied PHP.
Do today
Inventory every managed and agency-operated WordPress site with its Core version and owner.