An anonymous researcher picked up a $25,633 bug bounty for discovery a critical vulnerability in Chrome (CVE-2016-1629), which Google has now patched in version 48.0.2564.
PCI DSS version 3.2, scheduled for release in the first half of 2016, likely March or April, will address the current threat landscape as well as "trending attacks causing compromises" detailed in current breach forensics reports.
Twitter's password recovery systems briefly contained a bug that potentially exposed the email addresses and phone numbers of about 10,000 active account-holders.
California AG Kamala Harris released the state's data breach report; 178 breaches were reported in 2015 and 24 million personal records were compromised.
A Tax Foundation executive asked the IRS to remove its "Get My Electronic Filing PIN" webpage because it continues to offer the potential for identity theft.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.