MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · Privacy
A security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras.
Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the… Source https://databreaches.net/2026/08/09/kr-3pro-tv-data-breach-exposes-460000-records-including-2979-bank-accounts/1post-1participantReadfulltopic
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly , the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products. Meta said it disagreed with the ruling and planned to appeal. “We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.” But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico.
Summary Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive neurological and biometric data: As adoption grows, larger volumes of brain activity, biometric, and behavioral data will be collected by commercial platforms, creating new opportunities for data theft, misuse, and exploitation. China and the United States (US) are engaged in strategic competition in neurotechnology development: The US leads in the number of neurotechnology firms, and brain-computer interface (BCI) research has been a long-term research priority for the US military. At the same time, China’s five-year guidance for BCI development, subsidies for major wearable technology firms, and military research into human-machine integration suggest that neurotechnology is a strategic priority.
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records Hackread
The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data. The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications. In the last round of this ongoing battle , the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read.
A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely. It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click. We spotted the scam showing up in our anonymized Scam Guard submissions. WhatsApp is popular with cybercriminals, and the third most common channel where we see scams delivered, behind websites and email. At first glance, nothing seems out of the ordinary. But the link doesn’t lead to a real voting page. Instead, it redirects to a page that appears to be related to WhatsApp, often involving the legitimate wa.
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems. From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails. The AI Act moved from theory to practice for three big areas: • General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place. DROP was created under California’s Delete Act , which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry. Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency. DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency.
Today marks the release of Metasploit Pro 5. 1 - building upon the foundation laid in 5. 0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6. 5. Malleable C2 Profiles One of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffic into legitimate-looking patterns. Metasploit Pro 5. 1 brings full Malleable C2 profile support, powered by Metasploit Framework 6. 5, directly into the Pro UI — no command-line knowledge required. Malleable C2 profiles let you load a standard profile and reshape Meterpreter's HTTP(S) traffic to emulate legitimate services, browser sessions, or any other traffic pattern you need.
Hey there, I hope you’ve been doing well! 🏜️ Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet new cool people. Even if it’s going to be 115°F, which is roughly 40 degrees too hot for me. We’re doing some workshops with SpecterOps on “ Operationalizing Codex for Malware Triage ” and a talk (same page), we’ve got booths at Black Hat and DEF CON, and I’ll be around at various events. I think OpenAI is having a happy hour, but I don’t have a link handy. I’ll try to post about it on my LinkedIn next week. Oh yeah funny anecdote- apparently some of my colleagues have used Codex + ChatGPT Sites to spin up a quick web app tracking like over 1,000 Hacker Summer Camp events.
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?” Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The data is siloed, context is missing, and time rapidly slips away. Today, the window between a vulnerability’s disclosure and its active exploitation in the wild has essentially collapsed, making predictive lead time a thing of the past.
Key takeaways • Data exfiltration and IP theft and departing employee cases are common enterprise investigations, and mobile devices are increasingly central to how they get resolved. • Sixty-six percent of DFIR teams report growing mobile device volume, yet 53% can only extract limited data, the top mobile challenge for the third year in a row. • Consent-based, category-scoped extraction is how DFIR teams get defensible mobile evidence without over-collecting an employee’s personal data. When a company suspects an employee of taking a trade secret, client list, or product plans to a competitor, that’s an insider threat. These internal investigations often start with laptops and corporate email. Increasingly, the evidence that proves intent lives somewhere else: a bring your own device (BYOD) phone, in a messaging app the company has no visibility into.
Executive Summary Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has previously linked to TAG-127 as an operator and customer. (Insikt Group has directly observed TAG-127 deploying TinyEgg via “ClickFix”-style campaigns that use fake security verification pages to trick victims into manually executing malicious commands that download and install malware payloads via a legitimate Windows system utility.)
What are AI security posture management (AI-SPM) platforms? AI Security Posture Management (AI-SPM) platforms are specialized tools that discover, monitor, and secure AI models, pipelines, and data, mitigating risks like data leakage and model poisoning. They offer continuous visibility, manage misconfigurations, and enforce security policies across cloud services like Azure OpenAI and Bedrock. By consolidating security controls and automated monitoring for AI components, AI-SPM platforms help organizations prevent data leaks, model misuse, and unauthorized AI deployments. They typically integrate with existing IT and cloud infrastructures, offering real-time insights into the security state of AI assets across different environments.
Key takeaways • Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption. • Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network. • Effective advanced persistent threat detection requires minimizing breakout time, the window between initial access and lateral movement, by identifying threats before they establish deep persistence. • To defeat modern APTs, organizations must move from reactive internal monitoring to proactive threat intelligence, tracking adversary infrastructure on the open, deep, and dark web before an attack is launched.
Executive Summary Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran demonstrated that its strategic resilience does not depend on possessing the most advanced AI capabilities; rather, the source of Iranian power remains the asymmetric playbook itself. During these crises, Iran compensated for conventional military and economic disadvantages through scalable, low-cost, and deniable asymmetric capabilities.
What are dependency management tools? Dependency management tools are software solutions designed to automate and streamline the process of handling external libraries, modules, or packages that a project relies on. These tools help developers specify, install, update, and track dependencies, ensuring that all required components are present and compatible. By maintaining a centralized record of dependencies, these tools reduce manual intervention and errors, improving the consistency and reliability of software builds across different environments. These tools have become essential in modern development workflows, where projects often integrate numerous third-party packages. Without proper management, tracking and updating dependencies can quickly become unmanageable, leading to version conflicts, security vulnerabilities, or broken builds.
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2. 3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice , Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".
Illustration: fria / Privacy Guides Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. What was originally just a simple protocol to send messages between machines has morphed beyond what it was originally intended for into the de facto authentication, identity, and "secure" communication channel for almost all technology users today. It's been updated many times to fix security issues and there are more updates to come, but is it worth trying to fix a decades-old protocol, or should we scrap it all and start over? Current State of Email Security The Simple Mail Transport Protocol ( SMTP ) is the standard used to send emails. Over the years, multiple protocols have been introduced to fix security issues and improve the usability of email, resulting in a complex mess that we're still feeling the consequences of to this day.
Real-Name Policies: The War Against Pseudonymity Illustration: Em / Privacy Guides • Photo: Marija Zaric / Unsplash Real-name policies have existed for well over a decade already, and the problems they cause aren't new. But these problems have become exponentially harmful in today's world, where real-name policies are coupled with monopolistic platforms, increased mass surveillance, AI technologies, and facial recognition capabilities. It's time to fight back against this unsafe and discriminatory privacy-invasive practice. Pseudonymity, or the use of a nickname or fictitious name online, has always been deeply valued on the internet. It grants people protections and freedoms that are often impossible to benefit from offline.
What is Differential Privacy? Image: Privacy Guides / Jordan Warne Is it possible to collect data from a large group of people but protect each individual's privacy? In this entry of my series on privacy-enhancing technologies , we'll discuss differential privacy and how it can do just that. Problem It's useful to collect data from a large group of people. You can see trends in a population. But it requires a lot of individual people to give up personally identifiable information. Even things that seem innocuous like your gender can help identify you. Latanya Sweeney in a paper from 2000 used U. S. Census data to try and re-identify people solely based on the metrics available to her. She found that 87% of Americans could be identified based on only 3 metrics: ZIP code, date of birth, and sex.
Ghosts in the Machine: The Fight for Privacy After Death Photo: Panyawat Auitpol / Unsplash In the early hours of 6 June 2020, Nicole Smallman and her sister Bibaa Henry had just finished celebrating Bibaa's birthday with friends in a park in London. Alone and in the dark, they were both fatally and repeatedly stabbed 36 times. Guest Contributor Please welcome Peter Marsden as a first-time guest contributor! Privacy Guides does not publish guest posts in exchange for compensation, and this tutorial was independently reviewed by our editorial team prior to publication. But the police didn’t just fail them in life—they failed them in death too. PC Deniz Jaffer and PC Jamie Lewis, both of the Metropolitan Police, took selfies with the dead bodies of the victims, posting them on a WhatsApp group. And no privacy laws prevented them from doing so.
What is Multi-Party Computation? Illustration: Jordan Warne / Privacy Guides We know how to secure data in storage using E2EE , but is it possible to ensure data privacy even while processing it server-side? This is the first in a series of articles I'll be writing covering the privacy-enhancing technologies being rolled out. History In a seminal paper called "Mental Poker" by Adi Shamir, Ronald L. Rivest, and Leonard M. Adleman from 1979, the researchers attempt to demonstrate a way of playing poker over a distance using only messages and still have it be a fair game. To explain, fan favorites Alice and Bob will make a return. First, Bob encrypts all the cards with his key, then sends them to Alice. Alice picks five to deal back to Bob as his hand, then encrypts five with her own key and sends those to Bob as well.
Chat Control Must Be Stopped, Act Now! Illustration: Em / Privacy Guides • Photo: Ramaz Bluashvili / Pexels If you've heard of Chat Control already, bad news: it's back. If you haven't, this is a pressing issue you should urgently learn more about if you value privacy, democracy, and human rights. This is happening right now, and we must act to stop it right now. Take a minute to visualize this: Every morning you wake up with a police officer entering your home to inspect it, and staying with you all day long. The agent checks your bathroom, your medicine cabinet, your bedroom, your closets, your drawers, your fridge, and takes photos and notes to document everything. Then, this report is uploaded to the police's cloud. It's "for a good cause" you know, it's to make sure you aren't hiding any child sexual abuse material under your bed. Every morning. Even if you're naked in bed.
“We [Don't] Care About Your Privacy” Illustration: Em / Privacy Guides • Photo: Lilartsy / Unsplash They all claim "Your privacy is important to us." How can we know if that's true? With privacy washing being normalized by big tech and startups alike, it becomes increasingly difficult to evaluate who we can trust with our personal data. Fortunately, there are red (and green) flags we can look for to help us. If you haven't heard this term before, privacy washing is the practice of misleadingly, or fraudulently, presenting a product, service, or organization as being trustworthy for data privacy, when in fact it isn't. Privacy washing isn't a new trend, but it has become more prominent in recent years, as a strategy to gain trust from progressively more suspicious prospect customers.
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
Privacy Washing Is a Dirty Business Photo: Marija Zaric / Unsplash Perhaps you haven't heard the term privacy washing before. Nonetheless, it's likely that you have already been exposed to this scheme in the wild. Regrettably, privacy washing is a widespread deceptive strategy. What is privacy washing Similarly to whitewashing (concealing unwanted truths to improve a reputation) and greenwashing (deceptively presenting a product as environmentally friendly for marketing purposes), privacy washing misleadingly, or fraudulently, presents a product, service, or organization as being responsible and trustworthy with data protection, when it isn't. Your privacy is* important to us. *not! The term has been used for over a decade already. It's saddening to see that not only is this not a new problem , but it has only gotten worse through the years.
Privacy Is Like Broccoli Illustration: Em / Privacy Guides If you are just starting the journey to improve your privacy online, you might feel overwhelmed by all the information you recently learned. This is normal, don't panic! When we first start learning about how much data is collected on us, and all the things we need to do to protect it, it's very common to feel stressed and distressed. In a state of panic, you might be tempted to try doing it all at once, driven by an urgent desire to delete yourself from the entire internet, like right now! While this feeling is very understandable, this is the wrong approach. The right approach is to see privacy like broccoli. Yes, broccoli, you have not misread me. Privacy is like good health habits Good privacy is very similar to good health habits.
How To Improve Your Privacy and Security on Mastodon Montage: Em / Privacy Guides • Illustration: @dopatwo@mastodon.social (1) • Mastodon mascot by @dopatwo@mastodon.social and Mastodon logo used with permission from Mastodon gGmbH. This site is not otherwise affiliated with Mastodon gGmbH. Increasingly, more and more people have joined Mastodon in recent years. The advantages provided by a decentralized network and using open-source software maintained by a nonprofit organization are undeniable. Mastodon offers much more robust protections for your privacy than commercial social media platforms do. This tutorial will show you how to make the most of it. This tutorial is the second of a series of two articles on Mastodon. If you would like to read a general overview about privacy and security on Mastodon, start with reading the first article of this series.
Privacy and Security on Mastodon Illustration: Em / Privacy Guides • Logo: Mastodon gGmbH Mastodon is an open-source and decentralized social network that has been growing in popularity for the past few years. While most social media rely on commercial models harvesting users' data to sell to advertisers, Mastodon offers a human-centric alternative that doesn't seek profits from your data and attention. This means better social connections, better controls, and better privacy. Mastodon doesn't use your data to make money. This fact alone comes with incredible benefits for data privacy and security. Because the goal isn't to collect as much information as possible on its users, Mastodon embraces data minimization and only requires providing what is truly needed to run the service for you.
Queer Dating Apps: Beware Who You Trust With Your Intimate Data Illustration: Em / Privacy Guides • Photo: Surasak Ch / Unsplash When discussing the intersection of data privacy and LGBTQ+ experiences, it's inevitable to also talk about queer dating apps. Due to a smaller percentage of the population and a number of factors complicating in-person dating, people part of the queer community are more likely to seek online platforms to meet lovers and friends. Unfortunately, using queer dating apps can be very dangerous for privacy, and even for safety. Dating apps are generally horrible for everyone's privacy, but the queer population is at an even higher risk of harm due to discrimination, and even criminalization in certain regions . Despite the risks, LGBTQ+ people still need to fulfill their social and romantic needs like anyone else.
You Can Say NO Photo: Gabby K / Pexels In the age of facial recognition and age verification, it might feel like our data is being harvested left and right, completely outside our control or consent. Yet, we still have a powerful weapon to fight back against surveillance: The power to say no. The power to say no is one we severely underutilize. Of course, there are circumstances where it can be difficult (impossible even!) to refuse. Saying no can come at a cost, but this isn't true everywhere, and (more importantly) that cost might be worth paying. There are many occasions where we could indeed refuse to comply with privacy-invasive requests, but miss the opportunity. However, it is vital as a community and as individuals that we exercise this right every time we possibly can, if we want to stand a fighting chance against the normalization of mass surveillance.
Creating a Tricked-Out Monero Server with TrueNAS Illustration: Jonah Aragon / Privacy Guides In this guide, we will walk you through setting up a very powerful Monero server on TrueNAS. By completing these steps, you will be able to connect to your own self-hosted Monero node with the official Monero wallet and Cake Wallet, and you will be able to connect to your own self-hosted Monero LWS server with Edge Wallet and MyMonero. Guest Contributor Please welcome Justin Ehrenhofer as a first-time guest contributor! Justin is the president of MAGIC Grants, a nonprofit which supports public cryptocurrency infrastructure and promotes privacy, and operates as Privacy Guides' fiscal host . Privacy Guides does not publish guest posts in exchange for compensation, and this tutorial was independently reviewed by our editorial team prior to publication.
Stay Safe, but Stay Connected Photo: Jiroe Matia Rengel / Unsplash In data privacy, we often talk about the dangers of data collection and exposed data. It can get overwhelming to learn more about all the information that is collected on us, especially at the beginning. As a coping mechanism, some people react by downplaying concerns, disregarding dangers, and ignoring precautions altogether. Others react the opposite way: by isolating themselves, and no longer sharing anything with anyone. But neither is a viable solution. Staying isolated to avoid all data exposure risks other dangers. Dangers that might not seem related to data privacy directly, but are nevertheless worth mentioning here: Suicide and depression are very real dangers that we cannot ignore. Keeping our data safe shouldn't mean staying alone, and isolation is especially dangerous for LGBTQ+ people .
Selling Surveillance as Convenience Illustration: Em / Privacy Guides • Photo: Zeki Okur / Unsplash Increasingly, surveillance is being normalized and integrated in our lives. Under the guise of convenience, applications and features are sold to us as being the new better way to do things. While some might be useful, this convenience is a Trojan horse . The cost of it is the continuous degradation of our privacy rights, with all that that entails. As appalling as it is, the truth is the vast majority of software companies do not consider privacy rights and data minimization practices strongly enough, if at all. Most fail to implement the principles of Privacy by Design that should guide development from the start. Whether this comes from ignorance, incompetence, greed, or malicious intent can be debated.
This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool) and Sikha Pentyala (University of Washington Tacoma), who were winners in the UK-US PETs Prize Challenges . We discuss real-world data
How can you know that you’re maximizing your cyber performance plans without tracking them? We share key tracking metrics to measure upskilling and gain board support.