Key developments
South Korea offers safeguards after startup leak
The Korea Herald reported that South Korea’s Ministry of SMEs and Startups said Monday it will provide trade secret original certification to applicants in the Startup for All program after a leak involving 5,000 first-round successful candidates. First Vice Minister Roh Yong-seok apologized and said external investigations and security inspections will follow; the breach arose after a participating AI solutions company exploited a website vulnerability to access email addresses, startup idea summaries, and judges’ evaluation comments. Korea JoongAng Daily also reported that prime minister nominee Han Seong-sook apologized, authorities sought a police investigation, and affected applicants will receive free trade secret certification plus one year of technology escrow services.
Why it matters
The exposed data includes entrepreneurial ideas and evaluation comments, making the harm both a privacy issue and a potential ownership or competitive-disclosure dispute.
Sources & driving stories
THE KOREA HERALD
The Korea Herald coverageKOREA JOONGANG DAILY
Korea JoongAng Daily coverageShinyHunters publishes Council of Europe employee data
Tech Times reported that ShinyHunters published 297 GB of Council of Europe employee data after a June 16 ransom deadline passed and said stolen files would be distributed through mirrors and torrents. The exposed records cover more than 10,000 current and former employees, contractors, and job applicants, including names, dates of birth, home addresses, phone numbers, employee IDs, bank details, medical records, salary histories, and social security data spanning 2011 to 2026. Tech Times tied the compromise to a critical Oracle PeopleSoft zero-day that Mandiant said was exploited across more than 100 organizations before Oracle warned users; the Council of Europe is investigating but had not announced notification or credit-monitoring plans.
Why it matters
Permanent mirror-and-torrent distribution can turn a single breach into a long-term identity theft and personnel-security risk.
Sources & driving stories
TECH TIMES
Tech Times coverageTexas license vendor breach affects 3 million
Cybernews reported that the Texas Parks and Wildlife Department said a vendor used for hunting and fishing license sales suffered a breach affecting more than 3 million people, after Texas Cyber Command notified TPWD on May 13, 2026. Reported exposed fields include names, addresses, driver’s license or government ID information, and other personal data; sources conflict on Social Security numbers, with Veri Sızıntısı saying a subset was compromised while Cybernews and SOC Defenders reported they were not obtained or not compromised. TPWD reportedly implemented new safeguards and offered credit-monitoring or identity-theft protection.
Why it matters
A vendor incident at this scale exposes a large public-record-adjacent population to identity fraud risk and raises third-party governance questions for state agencies.
Sources & driving stories
Worth noting
WORTH NOTING
OkCupid AI data-sharing settlement
Mondaq’s Jana Gouchev reported that an FTC proposed order would bar Match Group Americas and Humor Rainbow from misrepresenting data collection, use, sharing, purposes, and privacy controls after allegations that OkCupid shared photos, demographic data, location data, and nearly 3 million user photos with an unrelated AI company without contractual use limits.
WORTH NOTING
Meta smart-glasses faceprint scrutiny
Northeastern Global News’s Hannah Morse reported that WIRED found code in Meta’s AI app that could create phone-stored biometric faceprints from smart-glasses camera captures, after which Meta removed traces of the feature while Pennsylvania considers smart-glasses recording-consent rules.
WORTH NOTING
Belgian intelligence Ivanti exposure
Techzine Global’s Mels Dees reported that Belgian State Security employee names, phone numbers, email addresses, device identifiers, and GPS metadata may have been accessed through Ivanti EPMM vulnerabilities, though classified internal systems reportedly were not reached.
Still unclear
OPEN QUESTION
Which TPWD fields and timelines are definitive?
Current reporting diverges on whether Social Security numbers or dates of birth were exposed and on incident timing, which directly affects risk assessment, notices, and mitigation.
OPEN QUESTION
Can standard remediation handle permanent leak infrastructure?
ShinyHunters’ use of mirrors and torrents reduces takedown effectiveness and may require longer-term monitoring for identity theft, phishing, and personnel targeting.
