Sylvaris

Code Exposure and Tightening Privacy Rules

2026-W03 — week of 12 January 2026

Cover illustration for Canopy issue 2026-W03: Code Exposure and Tightening Privacy Rules

Good morning. This week brings two distinct reminders that infrastructure security and regulatory compliance continue to demand attention.

Target is managing the fallout from a breach that didn't touch customer records but instead exposed 860 GB of internal source code — the kind of loss that quietly makes future attacks easier to design. Meanwhile, three US states have ended their privacy law grace periods, meaning organizations now face immediate enforcement without time to remedy violations first.

Two stories this week, each pulling at different threads in the broader fabric of organizational risk.

Security · 4 min read

Target confirms theft of 860 GB internal source code

Target confirms theft of 860 GB internal source code

Unlike customer data breaches, stolen source code exposes how systems work, making future attacks easier to plan.

Read the full story →
Privacy & Regulation · 4 min read

Three US states begin privacy law enforcement as cure periods expire

Organizations can now face immediate fines for privacy violations in multiple states, with no grace period to fix problems first.

Read the story →

Read all stories on Canopy