HackMyIP

Privacy News

121 stories tagged Privacy

← All cybersecurity news

2026-08-14KrebsOnSecurity
DecryptAds: Free Tool Exposes Hidden Ad Trackers and Data Brokers

Every website visit and mobile app interaction leaves behind a trail of adtech relationships that most users never see. A newly launched service called DecryptAds ...

PrivacyThreat IntelAI Threats
Read More → Use Tool →
2026-08-14The Record
France Tax Authority Breach: Hacker Claims 600,000 Victims' Data Stolen

France's Directorate General of Public Finances (DGFiP) confirmed that an attacker breached its information systems in late June, exfiltrating data belonging to individuals and bus...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-08-13The Record
Brazil Forces Discord to Suspend Go Live After Teen Suicide Investigation

Brazil's National Data Protection Authority (ANPD) has ordered Discord to disable its Go Live livestreaming feature nationwide while regulators investigate whether the platform ade...

RegulationPrivacyIncident Response
Read More → Use Tool →
2026-08-13The Record
Flock Safety Tightens License Plate Reader Privacy Controls After Officer Abuse

Flock Safety, the Atlanta-based license plate reader (LPR) company, announced expanded privacy controls on Thursday in response to mounting scandals over law enforcement misuse of ...

PrivacyRegulation
Read More → Use Tool →
2026-08-12SecurityWeek
WhatsApp Scam Alert Uses On-Device AI to Detect Fraud Without Breaking Encryption

WhatsApp has begun a limited beta rollout of Scam Alert, an optional feature that uses an on-device machine learning model to flag suspicious messages sent by unknown contacts. The...

AI SecurityPrivacyEncryption
Read More → Use Tool →
2026-08-12The Hacker News
737 Malicious Chrome VPN Extensions Caught Routing Traffic Through Proxies

Security researchers at Socket have uncovered a sprawling campaign involving 737 malicious Chrome VPN and proxy extensions that impersonate 66 well-known privacy brands to intercep...

PrivacySupply ChainMalware
Read More → Use Tool →
2026-08-12The Record
FBI Warns: Hackers Use Social Engineering to Hijack Accounts and Steal Explicit Content

The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belong...

PhishingAuthenticationPrivacy
Read More → Use Tool →
2026-08-11The Hacker News
North Korean IT Workers Caught in Fake Crypto Startup Sting

Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...

APTThreat IntelPrivacy
Read More → Use Tool →
2026-08-11The Record
NSA Appoints Kerianne Tobitsch as General Counsel Ahead of FISA Renewal

The NSA has quietly appointed Kerianne Tobitsch as its new general counsel, effective June 15, 2026. Tobitsch joins the electronic eavesdropping agency from the Department of Homel...

RegulationPrivacy
Read More → Use Tool →
2026-08-11SecurityWeek
Banned Chrome AI Extension Returns with Malicious Update via Google CDN

A Chrome extension previously banned for stealing ChatGPT and DeepSeek conversation data has resurfaced on the Chrome Web Store and is now reaching enterprise endpoints through Goo...

MalwareSupply ChainPrivacy
Read More → Use Tool →
2026-08-10Dark Reading
Sherlock Holmes: The OG Social Engineer and His Modern Hacking Lessons

Long before phishing emails and OSINT frameworks, Arthur Conan Doyle's Sherlock Holmes was already mastering the art of social engineering—wearing disguises, cultivating intelligen...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-08-07The Record
New Mexico Court Orders Meta to Pay $567M in Youth Safety Case

A New Mexico state court judge has ordered Meta to pay $567 million and impose sweeping restrictions on how minors use Facebook and Instagram, escalating legal pressure on the soci...

PrivacyRegulation
Read More → Use Tool →
2026-08-06Dark Reading
Inside the DNC's Security-First Culture: Lessons from Former CSOs

When Bob Lord joined the Democratic National Committee as its first-ever chief security officer in the aftermath of the 2016 election breach, he inherited an organization still ree...

Incident ResponseAuthenticationPrivacy
Read More → Use Tool →
2026-08-05The Hacker News
Poison Claude: 881 Users Exposed as Operator Logs Every Prompt

Okta Threat Intelligence researchers Jeremy Kirk and Mathew Woodyard have uncovered a gray-market AI service called Poison Claude that sells deeply discounted access to Anthropic's...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-08-03The Hacker News
Thermo Fisher Patches DNA File Tampering Flaw Exploitable via AI (CVE-2026-17583)

Thermo Fisher Scientific has addressed a high-severity vulnerability (CVE-2026-17583, CVSS v4.0 score of 8.2) in its Applied Biosystems human identification software that could all...

VulnerabilityAI SecurityPrivacy
Read More → Use Tool →
2026-07-31Dark Reading
California's DROP Platform Launches to Help Residents Erase Digital Footprint

California is rolling out a new privacy tool aimed at giving residents unprecedented control over their personal data. The Delete Request and Opt-out Platform (DROP), set to launch...

PrivacyRegulation
Read More → Use Tool →
2026-07-31Dark Reading
USA Fencing Automates Identity Verification to Secure Amateur Athletes

USA Fencing, the national governing body for the sport and the organization responsible for fielding Team USA's Olympic and Paralympic fencing squads, has deployed automated ide...

AuthenticationPrivacyAI Security
Read More → Use Tool →
2026-07-30Ars Technica
Chrome Speeds Up Security Patches: No More Restart Needed

Google is reportedly planning to deliver Chrome security patches faster and without requiring users to restart their browser. According to Ars Technica, the last two Chrome release...

VulnerabilityPrivacy
Read More → Use Tool →
2026-07-29The Record
FTC Sues Hims & Hers Over Patient Data Shared With Meta and Snap

The Federal Trade Commission filed a lawsuit Wednesday against telehealth provider Hims & Hers Health, alleging the San Francisco-based company shared sensitive patient health info...

PrivacyRegulationData Breach
Read More → Use Tool →
2026-07-28SecurityWeek
Origin Energy Breach Exposes Data of 900,000 Australian Customers

Australian energy giant Origin Energy has confirmed a significant data breach affecting approximately 900,000 current and former customers, exposing sensitive personal information ...

Data BreachRansomwarePrivacy
Read More → Use Tool →
2026-07-27SecurityWeek
MCBS Data Breach Exposes 1.2 Million Records via PEAR Ransomware

Atlanta-based medical revenue cycle management company MCBS (Medical Computer Business Services) has disclosed that a September 2025 cyberattack compromised the personal data of mo...

RansomwareData BreachPrivacy
Read More → Use Tool →
2026-07-24Dark Reading
CISOs and Boards Face Growing Communication Gap on Cybersecurity Priorities

As ransomware attacks, supply chain compromises, and state-sponsored intrusions continue to escalate, corporate boards are increasingly recognizing cybersecurity as a strategic pri...

RegulationIncident ResponsePrivacy
Read More → Use Tool →
2026-07-24Dark Reading
Vatican's Click To Pray App Exposes 700K+ Users' PII via Insecure API

A critical security flaw in the Vatican's official prayer application has exposed the personal information of more than 700,000 users worldwide, raising serious concerns about data...

Data BreachPrivacyVulnerability
Read More → Use Tool →
2026-07-24The Record
Wrench Attacks on Crypto Holders Surge 33% in First Half of 2026

Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...

Threat IntelPrivacyAuthentication
Read More → Use Tool →
2026-07-23Ars Technica
Google Selfie Video Login: New Way to Reset Passwords & Verify Age

Google has introduced a password recovery method that lets users regain access to their accounts by recording a short selfie video. The biometric verification system, detailed by A...

AuthenticationPrivacyAI Security
Read More → Use Tool →
2026-07-22The Hacker News
Adobe Acrobat Chrome Extension Flaw Exposed WhatsApp Web Data of 314M Users

Cybersecurity researchers at Guardio Labs have disclosed a now-patched vulnerability in the Adobe Acrobat Chrome extension—used by more than 314 million users—that could allow a ma...

VulnerabilityPrivacy
Read More → Use Tool →
2026-07-22The Hacker News
AI Governance Is the New Seat at the CISO Table

Shadow AI is no longer a fringe problem. According to McKinsey's State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55 percent the year before...

AI SecurityRegulationPrivacy
Read More → Use Tool →
2026-07-22SecurityWeek
Suno and Paidwork Breaches Expose 78M Records – Check Your Data

Hackers have stolen tens of millions of user records from AI music generation platform Suno and gig-work marketplace Paidwork, according to bre...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-07-22KrebsOnSecurity
LG to Ban Residential Proxy SDKs from WebOS Smart TV Apps

LG Electronics has announced a crackdown on residential proxy software development kits (SDKs) embedded in apps distributed through its webOS smart TV platform. The decision follow...

PrivacySupply Chain
Read More → Use Tool →
2026-07-21The Hacker News
Apple Patches Hide My Email Bug That Leaked Real Addresses in Mail Logs

Apple has resolved a critical privacy flaw in its Hide My Email service that silently exposed users' real email addresses in mail transfer logs, effectively defeating the feature's...

PrivacyVulnerabilityCloud Security
Read More → Use Tool →
2026-07-17The Hacker News
EU Forces Google to Open Android AI Features to Rivals by 2027

The European Commission has issued a binding specification ordering Google to grant rival AI assistants the same deep access to Android that its own Gemini currently enjoys—camera,...

RegulationAI SecurityPrivacy
Read More → Use Tool →
2026-07-14The Hacker News
Grok Build Secretly Uploads Entire Git Repositories to xAI Cloud

A security researcher publishing as cereblab has uncovered that xAI's Grok Build coding CLI was uploading entire Git repositories—including full commit history—to a Google Cloud St...

AI SecurityPrivacyData Breach
Read More → Use Tool →
2026-07-13The Record
EU Eyes Age-13 Social Media Floor to Shield Children Online

European Commission President Ursula von der Leyen is pushing for an EU-wide mandate that would set a minimum age of 13 for creating social media accounts, framing the initiative a...

RegulationPrivacy
Read More → Use Tool →
2026-07-13The Hacker News
ModHeader Pulled From Chrome and Edge After Hidden Data Collector Found

Google and Microsoft have removed ModHeader, a popular HTTP header-editing browser extension with roughly 1.6 million combined installs, after security researchers identified a dor...

Supply ChainPrivacyThreat Intel
Read More → Use Tool →
2026-07-10Dark Reading
Jen Ellis MBE: Bridging Cybersecurity Advocacy and Policy

Jen Ellis, Vice President of Community and Public Affairs at Rapid7, has been awarded a Member of the Order of the British Empire (MBE) for her outstanding contributions to cyberse...

RegulationPrivacy
Read More → Use Tool →
2026-07-08The Record
Greek Victims Sue Intellexa for €7.6M Over Predator Spyware Scandal

Eight Greek citizens confirmed to have been targeted by the Predator commercial spyware suite have filed a civil lawsuit against Intellexa, the Cyprus-based surveillance vendor, an...

PrivacyMalwareRegulation
Read More → Use Tool →
2026-07-06The Hacker News
NetNut 2M-Device Proxy Botnet Disrupted; WhatsApp Usernames Spark Impersonation Fears

Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for ma...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
Opera GX Flaw Let Sites Silently Steal Data via Mod Auto-Install

A serious vulnerability in Opera GX, the gaming-focused browser from Opera, allowed a malicious website to silently install a browser modification and use it to extract sensitive d...

VulnerabilityBug BountyPrivacy
Read More → Use Tool →
2026-07-03The Hacker News
EU Lawmaker Probing Pegasus Spyware Was Herself Hacked With Pegasus

A former Member of the European Parliament who served on a committee investigating commercial spyware abuse was herself repeatedly targeted with NSO Group's Pegasus spyware, accord...

MalwareZero-DayPrivacy
Read More → Use Tool →
2026-07-03The Record
Pegasus Spyware Found on EU Parliament Member Probing Its Misuse

A phone belonging to former Greek Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware on at least two occasions during his tenure on the PEGA C...

PrivacyMalwareAPT
Read More → Use Tool →
2026-07-02The Hacker News
Google Disrupts NetNut Proxy Network Spanning 2 Million Hacked Home Devices

Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-07-02BleepingComputer
Medtronic Data Breach Exposes 9M Records in ShinyHunters Attack

Healthcare device manufacturer Medtronic has begun notifying customers of a data breach that exposed personally identifiable information (PII) to an unauthorized third party. The c...

Data BreachIncident ResponsePrivacy
Read More → Use Tool →
2026-06-30The Hacker News
Silent Swap Clipper Hijacks Crypto Wallets via Fake Google Notes Extension

McAfee Labs has uncovered an active browser extension campaign dubbed Silent Swap that stealthily replaces cryptocurrency wallet addresses during transactions, red...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-29The Hacker News
WhatsApp Rolls Out Usernames to Protect Phone Number Privacy

WhatsApp, the Meta-owned messaging platform used by more than three billion people, officially began global username reservations on Monday. The new optional feature allows users t...

PrivacyAuthentication
Read More → Use Tool →
2026-06-25BleepingComputer
Anthropic Tests Mobile Claude Cowork: AI Agent Goes Remote-Control

Anthropic is preparing to bring its agentic Claude Cowork experience to mobile devices, according to screenshots shared on X. Claude Cowork, the desktop-focused agentic mode introd...

AI SecurityPrivacy
Read More → Use Tool →
2026-06-25The Hacker News
Chrome Ad Blocker With 10M Installs Has Hidden Script Injection Flaw

A widely used Google Chrome ad-blocking extension, Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), carries a dormant capability to inject arbitrary Jav...

MalwarePrivacySupply Chain
Read More → Use Tool →
2026-06-25The Hacker News
Curl 24-Year-Old Bug, Hoppscotch RCE, Cloudflare PACT: Weekly Threats

This week's threat landscape blended privacy innovation with two decades of dormant risk. Cloudflare announced a partnership with Google Chrome, Microsoft Edge, and Mozilla Firefox...

VulnerabilityPrivacyCloud Security
Read More → Use Tool →
2026-06-24BleepingComputer
Google Splits Activity History: New Privacy Controls for Search Services

Google is rolling out new privacy controls across its Search services and Google Play, giving users more granular control over saved history and personalized recommendations. In an...

Privacy
Read More → Use Tool →
2026-06-19BleepingComputer
Texas Vendor Breach Exposes 3M Driver's Licenses in TPWD Hack

The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its external license system vendor on June 19, 2026, compromising the personal information of more than 3 ...

Data BreachSupply ChainPrivacy
Read More → Use Tool →
2026-06-19The Hacker News
Apple Patches Beats Studio Buds Bluetooth Spy Flaw as Unpatchable A12/A13 Exploit Emerges

Apple has released a firmware update for its Beats Studio Buds wireless earbuds to remediate a high-severity Bluetooth vulnerability, tracked as CVE-2025-20701, that allowed nearby...

VulnerabilityZero-DayPrivacy
Read More → Use Tool →
2026-06-18KrebsOnSecurity
Popa Botnet: 1.4M Hacked Android TV Boxes Linked to Israeli Firm NetNut

Security researchers from Qurium, HUMAN Security, and XLAB have concluded that the massive Popa botnet is operated by NetNut, a residential proxy service run by publicly-traded Isr...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-18The Hacker News
SearchJack Chrome Extensions Hit 758K Users as macOS ClickFix Spreads RAT

A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...

Threat IntelMalwarePhishingPrivacyCloud Security
Read More → Use Tool →
2026-06-17BleepingComputer
Google to Use EU and UK IP Addresses for Ad Tracking Starting August 2026

Google has begun notifying advertisers that, starting on or shortly after August 3, 2026, it will repurpose IP addresses collected from users in the European Economic Area (EEA), t...

PrivacyRegulation
Read More → Use Tool →
2026-06-17BleepingComputer
India's Telegram Ban Triggers BGP Hijack, Disrupts UAE Users

On June 16, 2026, India's Ministry of Electronics and Information Technology invoked Section 69A of the IT Act to block Telegram nationwide until June 22, following a recommendatio...

RegulationPrivacyIncident Response
Read More → Use Tool →
2026-06-16BleepingComputer
UK to Require ID or Face Scan for All New Social Media Accounts

The UK government will require anyone opening a new social media account to verify their age by uploading government-issued ID or passing a facial age scan, under regulations annou...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-06-16BleepingComputer
FTC: Americans Lost Record $3.5 Billion to Imposter Scams in 2025

The U.S. Federal Trade Commission has revealed that Americans lost a record $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020 and accounting f...

PhishingRegulationPrivacy
Read More → Use Tool →
2026-06-16The Hacker News
94% of Security Incidents Now Involve Anonymized Infrastructure, Survey Finds

Security teams are drowning in IP data but starving for context, according to a new industry study from Spur Intelligence. The survey of more than 200 security practitioners found ...

Threat IntelPrivacyIncident Response
Read More → Use Tool →
2026-06-16The Record
UK to Ban Social Media for Under-16s with Strict Age Verification by 2027

The UK government has announced plans to block anyone under 16 from accessing social media platforms, with Prime Minister Keir Starmer calling the measures the strongest child onli...

RegulationPrivacy
Read More → Use Tool →
2026-06-15The Hacker News
152 Chrome Wallpaper Extensions Exposed as Adware with 105K Installs

Cybersecurity researchers at Socket have uncovered a sprawling network of 152 Google Chrome extensions posing as live wallpaper and new tab add-ons that covertly distribute a poten...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-06-13BleepingComputer
Anthropic Suspends Fable 5 and Mythos 5 Globally After US Export Control Order

Anthropic has pulled the plug on its two most powerful AI models, Fable 5 and Mythos 5, for every user worldwide after receiving a US government export control directive on June 12...

AI SecurityRegulationPrivacy
Read More → Use Tool →
2026-06-12The Record
23andMe Data Breach: $47M Settlement Approved for 7M Victims

A Missouri bankruptcy court administrator has greenlit a $46.8 million settlement fund compensating millions of victims of the 2023 23andMe data breach. The deal, confirmed on Wedn...

Data BreachPrivacyRegulation
Read More → Use Tool →
2026-06-12The Record
FISA Section 702 Lapses After Congress Fails to Renew Surveillance Powers

Section 702 of the Foreign Intelligence Surveillance Act (FISA) expired at midnight Friday after Congress and the White House failed to reach a deal to renew the controversial spy ...

PrivacyRegulationThreat Intel
Read More → Use Tool →
2026-06-11BleepingComputer
Japanese Energy Firm Loses Drive with Data of 10.9 Million Clients

Kyushu Electric Power Co., Inc., one of Japan's largest regional electric utilities serving over 12.6 million residents across the Kyushu region, has disclosed a physical security ...

Data BreachPrivacyIncident Response
Read More → Use Tool →
2026-06-09The Hacker News
Meta Expands Off-Site Data Use to Feeds and AI Personalization

Meta announced on Tuesday that it will broaden its use of cross-site business data to personalize user experiences across Facebook and Instagram feeds, as well as responses generat...

PrivacyAI Security
Read More → Use Tool →
2026-06-09The Hacker News
FROST Attack Uses SSD Timing to Spy on Your Browsing History

Researchers at Graz University of Technology have unveiled FROST, a new side-channel attack that lets any malicious website determine which sites you visit and which applications y...

PrivacyVulnerability
Read More → Use Tool →
2026-06-08The Hacker News
Meta Blocks NSO Group WhatsApp Phishing Attack, Files Contempt Order

Meta announced on Monday that it detected and neutralized a new wave of spear-phishing campaigns orchestrated by Israeli commercial spyware vendor NSO Group, targeting journalists,...

PhishingPrivacyEncryption
Read More → Use Tool →
2026-06-06The Hacker News
OpenAI Rolls Out ChatGPT Lockdown Mode to Block Data Exfiltration

OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-06-06The Hacker News
Bright Data SDK Quietly Turns Smart TVs Into AI Scraping Proxies

A reverse-engineering analysis published June 5 by Include Security and independent researcher Buchodi has exposed how Bright Data, the successor to Luminati and operator of what i...

PrivacyAI ThreatsSupply Chain
Read More → Use Tool →
2026-06-05The Hacker News
Asin Android Spyware Targets Arabic Users via Fake News, PDF, and War Map Apps

ESET researchers have uncovered a new Android spyware strain dubbed "Asin" that has been actively targeting Arabic-speaking users through a series of malicious apps disguised as le...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-04BleepingComputer
Brave Origin: Paid Minimalist Browser Strips Out Crypto, AI Features

Brave Software has publicly launched Brave Origin, a $59.99 paid version of its privacy-focused browser that removes cryptocurrency wallets, AI integrations, rewards programs, and ...

PrivacyAI Security
Read More → Use Tool →
2026-05-29BleepingComputer
California AG Sues 23andMe Over 2023 Data Breach Exposing 7M Customers

California Attorney General Rob Bonta has filed a lawsuit against 23andMe (now Chrome Holding Co.) for failing to protect sensitive customer genetic and personal information during...

Data BreachPrivacyRegulation
Read More → Use Tool →
2026-05-25SecurityWeek
Radiology Associates of Richmond Data Breach: 266,000 Affected

Radiology Associates of Richmond (RAR), a Richmond, Virginia-based medical imaging services provider, has disclosed a significant data breach affecting 266,183 individuals. The bre...

Data BreachPrivacy
Read More → Use Tool →
2026-05-22The Hacker News
Operation Saffron Takes Down First VPN Used by 25 Ransomware Groups

Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-05-19BleepingComputer
Discord Deploys End-to-End Encryption for All Voice and Video Calls

Discord has officially announced the completion of its end-to-end encryption (E2EE) deployment for all voice and video calls, marking a significant milestone in user privacy protec...

EncryptionPrivacy
Read More → Use Tool →
2026-05-17BleepingComputer
MiniPlasma Windows Zero-Day Exploit Grants SYSTEM Access - PoC Released

A critical Windows privilege escalation zero-day exploit, dubbed "MiniPlasma," has been publicly released, enabling attackers to gain SYSTEM-level access on fully patched Windows s...

Zero-DayVulnerabilityPrivacy
Read More → Use Tool →
2026-05-10BleepingComputer
German Police Shut Down Relaunched Crimenetwork Marketplace, Arrest Admin

German law‑enforcement agencies, led by the Federal Criminal Police Office (BKA) and the Hessian State Criminal Police Office (LKA Hessen) in close coordination with Europol’s Euro...

PrivacyEncryptionThreat Intel
Read More → Use Tool →
2026-05-08The Record
GM Pays $12M in Largest CCPA Settlement for Driver Data Violations

General Motors has agreed to pay a $12.75 million settlement to the State of California for collecting and sharing sensitive driver data without proper consent, marking the largest...

PrivacyRegulationData Breach
Read More → Use Tool →
2026-05-08The Hacker News
Fake Call History Apps Steal Payments After 7.3M Google Play Downloads

Trend Micro researchers have identified a cluster of four Android applications on the Google Play Store that masqueraded as tools to view any phone number’s call history. The apps,...

MalwarePrivacySupply Chain
Read More → Use Tool →
2026-05-08BleepingComputer
NVIDIA Confirms GeForce NOW Data Breach Affects Armenian Users

NVIDIA has officially confirmed a data breach impacting its GeForce NOW service, exposing personal information for a subset of users in Armenia. The disclosure, made in a statement...

Data BreachPrivacyCloud Security
Read More → Use Tool →
2026-05-08BleepingComputer
Zara Data Breach Exposes 197K Customers’ Personal Data

Zara, the Spanish fast‑fashion giant, has confirmed a data breach that exposed the personal information of approximately 197,000 customers. The compromise was uncovered after the b...

Data BreachPrivacy
Read More → Use Tool →
2026-05-08Dark Reading
ShinyHunters Claims Second Instructure Breach: 300M+ Users Exposed

ShinyHunters, the notorious threat group behind a string of high‑profile data thefts, announced on March 5 that it had executed a second intrusion into Instructure, the education‑t...

Data BreachAPTPrivacy
Read More → Use Tool →
2026-05-07BleepingComputer
How Browsers Bypass DLP: AI Prompts and Copy/Paste Create Data Leakage

Organizations investing heavily in data loss prevention (DLP) solutions are discovering a critical blind spot: the browser has become the primary vector for inadvertent data exfilt...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-05-07BleepingComputer
US Sentenced for Laptop Farms Used by North Korean Remote IT Workers

Two U.S. nationals were sentenced to 18 months in federal prison each for managing laptop farms that facilitated North Korean IT workers in securing remote positions at nearly 70 A...

APTSupply ChainPrivacy
Read More → Use Tool →
2026-05-07BleepingComputer
California Man Gets 6.5 Years for $230M Crypto Heist, Money Laundering

Ethan J. Rivera, a 20‑year‑old from Los Angeles, California, was sentenced on Friday to 78 months (6.5 years) in federal prison for his role in a sophisticated criminal operation t...

Threat IntelPrivacyEncryption
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-05The Hacker News
1M Exposed AI Services Reveal Alarming Security Gaps

A joint research effort by the Security Research Lab (SRL) and the AI Security Initiative (AISI) scanned over one million publicly reachable AI endpoints across IPv4 space between ...

AI SecurityVulnerabilityPrivacy
Read More → Use Tool →
2026-05-05BleepingComputer
Instructure Breach: Hacker Claims 280M Records from 8,800 Schools

Education technology provider Instructure has disclosed a significant data breach after a threat actor operating under the alias 'CSAMKing' claimed to have stolen approximately 280...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
FTC Bans Kochava from Selling US Location Data Without Consent

The Federal Trade Commission announced a settlement with data broker Kochava and its subsidiary Collective Data Solutions (CDS) that prohibits them from selling or sharing precise ...

PrivacyRegulation
Read More → Use Tool →
2026-05-05BleepingComputer
Vimeo Data Breach Exposes 119,000 Users' Personal Information

The ShinyHunters extortion group has claimed responsibility for a significant data breach at Vimeo, the popular online video platform owned by IAC. Security researchers first ident...

Data BreachPrivacy
Read More → Use Tool →
2026-05-05BleepingComputer
CloudZ RAT Abuses Microsoft Phone Link to Steal SMS & OTPs

Security researchers have uncovered a new variant of the CloudZ remote‑access trojan (RAT) that delivers a previously undocumented plugin named Pheno. This plugin exploits the Micr...

MalwarePrivacyVulnerability
Read More → Use Tool →
2026-05-04BleepingComputer
Credit Union Loan Fraud: Stolen Identity Verification Exposed

Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...

AuthenticationThreat IntelPrivacy
Read More → Use Tool →
2026-05-03BleepingComputer
Instructure Data Breach: ShinyHunters Claim 4.5M Records Stolen

Instructure, the educational technology company behind the popular Canvas learning‑management system, confirmed on March 5 2026 that unauthorized actors had accessed its internal n...

Data BreachThreat IntelPrivacy
Read More → Use Tool →
2026-05-02BleepingComputer
Microsoft Unveils Faster Windows 11 Run Dialog with Dark Mode

Microsoft has begun rolling out a preview of a modernized Run dialog for Windows 11, promising a noticeable boost in responsiveness and the addition of a native dark mode. The upda...

VulnerabilityPrivacy
Read More → Use Tool →
2026-05-01Dark Reading
Join Our Caption Contest: Celebrate 20 Years of Cybersecurity Progress

Dark Reading is inviting security professionals and enthusiasts to take part in a caption contest that reflects on two decades of cybersecurity evolution. The competition, titled "...

VulnerabilityPrivacy
Read More → Use Tool →
2026-05-01Dark Reading
Dark Reading Celebrates 20 Years of Cybersecurity Coverage

Dark Reading marks its 20th anniversary this month, reflecting on two decades of delivering timely cybersecurity news, analysis, and insights to professionals worldwide. Launched o...

Threat IntelPrivacyRegulation
Read More → Use Tool →
2026-05-01BleepingComputer
15-Year-Old Detained Over France Titres Data Breach

French police (the Direction centrale de la police judiciaire, DCPJ) and the Paris Prosecutor’s Office have detained a 15‑year‑old, known by the alias "M4L", on suspicion of sellin...

Data BreachPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
BleepingComputer Retracts Instructure Data Breach Story After Review

BleepingComputer published a story on March 5, 2026 claiming that Instructure, the education‑technology company behind the Canvas learning‑management platform, had suffered a new d...

Data BreachPrivacy
Read More → Use Tool →
2026-05-01BleepingComputer
Microsoft Lets Admins Uninstall Pre-installed Store Apps in Windows 11

Microsoft has expanded its Windows 11 in‑box app removal policy by adding a dynamic list that lets IT administrators select exactly which pre‑installed Microsoft Store applications...

PrivacyVulnerability
Read More → Use Tool →
2026-05-01BleepingComputer
Windows 11 KB5083631 Security Update Adds Xbox Mode, 34 Fixes

Microsoft released the optional cumulative update KB5083631 for Windows 11 22H2, delivering 34 changes that span new functionality, performance tweaks, and critical security patche...

VulnerabilityPrivacy
Read More → Use Tool →
2026-04-28Dark Reading
Chris Inglis Reflects on NSA Failures 13 Years After Snowden Leaks

Chris Inglis, who served as NSA Deputy Director from 2011 to 2014 under Director Keith Alexander, has broken his silence on the agency's missteps during the Edward Snowden affair, ...

PrivacyThreat IntelRegulation
Read More → Use Tool →
2026-04-27The Hacker News
Fake CAPTCHA IRSF Scam: 120 Keitaro Campaigns Fuel Global SMS and Crypto Fraud

Security researchers at Group-IB have uncovered a large-scale smishing operation that combines fake CAPTCHA verification pages with International Revenue Share Fraud (IRSF) and cry...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-24Dark Reading
Helping Romance Scam Victims: Cross-Agency, Proactive Approach

Romance scams, a form of confidence scheme that preys on emotional trust, continue to trap thousands of victims each year. Security analysts note that those who fall prey to these ...

PhishingPrivacyRegulation
Read More → Use Tool →
2026-04-24Dark Reading
US Charges 29 in Myanmar Investment Fraud Ring, Seizes 500+ Domains

The US Department of Justice has announced the indictment of 29 individuals linked to a cyber fraud syndicate operating from Myanmar, charging them with conspiracy to commit wire f...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-24The Hacker News
Fake Apple Crypto Wallet Apps Steal Seed Phrases – 26 Apps Detected

Cybersecurity researchers at CleverSight Threat Intelligence have uncovered a cluster of 26 malicious iOS applications that masquerade as popular cryptocurrency wallets such as Tru...

MalwarePhishingPrivacy
Read More → Use Tool →
2026-04-20Dark Reading
WhatsApp Metadata Leak Exposes User Info to Attackers

WhatsApp has patched a critical flaw that allowed attackers to harvest user metadata simply by knowing a victim's phone number, according to a Dark Reading analysis published this ...

PrivacyVulnerabilityData Breach
Read More → Use Tool →
2026-04-06KrebsOnSecurity
Germany Doxes 'UNKN', Head of REvil & GandCrab Ransomware Gangs

German authorities have publicly exposed the identity of the notorious hacker known as "UNKN", linking the alias to 31‑year‑old Russian national Daniil Maksimov. Maksimov is allege...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-03-17Ars Technica
World ID Iris Tokens to Secure AI Agents, Prevent Swarms

Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...

AI SecurityPrivacyAuthentication
Read More → Use Tool →
2026-03-08KrebsOnSecurity
AI Assistants Redefine Cybersecurity Landscape

AI assistants, often marketed as autonomous "agents", are rapidly becoming a staple in developer toolchains, promising to automate everything from code generation to system configu...

AI SecurityAI ThreatsPrivacy
Read More → Use Tool →
2026-03-03Ars Technica
Google Tightens Android Developer Verification: Security vs Open Access

Google has announced significant changes to its Android app distribution model, implementing mandatory developer verification for all apps published on Google Play Store. The new r...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-01-15Ars Technica
Google Fast Pair Flaw Exposes Bluetooth Devices to WhisperPair Attack

Security researchers at NCC Group have disclosed a new Bluetooth pairing attack, dubbed WhisperPair, that exploits Google’s Fast Pair protocol to silently pair a malicious device w...

VulnerabilityPrivacyZero-Day
Read More → Use Tool →
2025-12-15Ars Technica
Google Ends Dark Web Report Service: Leaked Data Alerts Stop

Google announced on Monday that it will retire the Dark Web Report feature from its Google Account dashboard, ending a service that warned users when their personal information app...

Data BreachPrivacy
Read More → Use Tool →
2025-10-30Ars Technica
Pixel Devices Exposed: Which Pixels Are Vulnerable to Cellebrite?

A leaked document published by the dark‑web user W1ckedG0pher has disclosed the full roster of Google Pixel phones that can be compromised by Cellebrite’s Universal Forensic Extrac...

VulnerabilityPrivacyEncryption
Read More → Use Tool →
2025-10-03Ars Technica
Google Confirms Android Developer Verification Tiers: Free and Paid Options

Google has officially announced its Android developer verification program will feature both free and paid tiers, marking a significant shift in how developers are authenticated be...

Supply ChainAuthenticationPrivacy
Read More → Use Tool →
2025-09-08Ars Technica
WhatsApp Security Boss Sues Meta Over 'Cult' Culture, User Growth Over Safety

Former WhatsApp security chief filed a lawsuit against Meta Platforms Inc., alleging that the company consistently placed user‑acquisition targets ahead of critical security measur...

PrivacyVulnerability
Read More → Use Tool →
2025-07-09Ars Technica
Browser Extensions Hijack 1M Browsers for Scraping Bots

Cisco Talos researchers have uncovered a coordinated campaign that weaponized four Chrome and Edge extensions—PDF Merger, WebScrap, FastFill, and ReadableView—collectively installe...

MalwarePrivacySupply Chain
Read More → Use Tool →
2025-07-07Ars Technica
Android Gemini Access to Third‑Party Apps: Privacy Risks in 2024

Starting Monday, Google began rolling out a platform update for Android 14 (API level 34) that expands the capabilities of its on‑device AI assistant, Gemini. The change introduces...

PrivacyAI Security
Read More → Use Tool →
2025-06-05Ars Technica
Nintendo Warns Switch 2 GameChat Records Chats, Shares Data on Request

Nintendo has alerted owners of its upcoming Switch 2 console that the built‑in GameChat feature creates temporary local copies of voice and text conversations, and that those recor...

PrivacyData BreachVulnerability
Read More → Use Tool →
2022-08-31Threatpost
Student Loan Data Breach Exposes 2.5M Records

Over the weekend, Nelnet Servicing, a major U.S. student‑loan servicer operating under contract with the Department of Education’s Federal Student Aid (FSA) office, disclosed a dat...

Data BreachPrivacyVulnerability
Read More → Use Tool →
2022-08-25Threatpost
Chinese Surveillance Camera Flaw Exposes Thousands to Hackers

Cybercriminals are now hawking root access to tens of thousands of unpatched Chinese‑made surveillance cameras, a market that has surged after the disclosure of a critical remote‑c...

VulnerabilityZero-DayPrivacy
Read More → Use Tool →
2022-08-24Threatpost
Twitter Security Lapses: Whistleblower Alleges National Risk

Peiter “Mudge” Zatko, Twitter’s former head of security, filed a whistleblower complaint in July 2022 with the Federal Trade Commission (FTC) and the Senate Select Committee on Int...

PrivacyData BreachRegulation
Read More → Use Tool →
2022-08-22Threatpost
Fake Travel Reservation Links Target Weary Travelers

A wave of phishing campaigns masquerading as airline and hotel reservation confirmations is compounding the frustration of travelers already grappling with cancellations and overbo...

PhishingMalwarePrivacy
Read More → Use Tool →