23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach

2026-07-18T08:51:44Za208565301a1113c14251523ee9c84c422a8fad094f214623a0180133eb6a7f0
1passwordactive-exploitationai-securityautonomous-ai-attackchrome-extension-flawclaudeclicklockdata-breachgenetic-datahugging-facemac-malwaremalwaremfa-bypassmicrosoft-365oauthpasswordless-authpatch-tuesdayphishingprivacyremote-account-takeoversettlementthird-party-breach','gdpr','regulation','fcc','identity-verficiavulnerabilityzero-dayzoom

What happened

This collection highlights a wave of high-impact security and privacy events: 23andMe agreed to an $18M settlement with 43 states over its 2023 genetic-data breach that exposed nearly 7 million people; Zoom patched a critical Windows flaw that could enable remote account takeover alongside multiple high-severity privilege-escalation bugs; and Microsoft released a record 570 fixes in July Patch Tuesday, including three zero-days and actively exploited bugs. Threat activity includes new Jalisco and OmegaLord phishing kits abusing device-code/OAuth flows and MFA prompts to maintain access, Click

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
techrepublic_security
Record identifier
a208565301a1113c14251523ee9c84c422a8fad094f214623a0180133eb6a7f0
Enrichment time
2026-07-18T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.