MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · Privacy
Socket identified a Firefox extension that ships with no hardcoded malicious code and fetches a remote payload after installation to silently automate Google account takeover, targeting Portuguese- and Spanish-speaking users since September 11, 2026. Socket's Threat Research team identified a malicious Firefox extension posing as a utility for identity verification before opening protected PDF documents. The extension, pdf-para-texto@extensao. local , was published to the Firefox Add-ons store on September 3, 2026, and its malicious functionality was first introduced in version 1. 4 on September 11, 2026. The extension does not have a significant user base, and the expected impact is fairly low.
Legis Legis is a well-known Latin American publisher that creates specialized legal and business information resources. Founded over 60 years ago, the company serves professionals across six countries including Colombia, Venezuela, Argentina, Mexico, Peru, and Chile. DATABASES (SQL)PST/OSTLEGAL DOCUMENTS:Tutela - constitutional actions with claimants' personal dataID card copies (cedulas) of shareholders and third partiesEnvironmental sanction proceedings against the company (AUTO 10852)Sanction dispute with the pension authority (UGPP)Signed cease & desist - trademark dispute (Xpandia case)Personal data transfer agreements (Colsubsidio, Universidad Externado)Litigation log of all company lawsuitsContract matrix, payment agreements, reorganization documentsFINANCE & OWNERSHIP:Shareholder and ultimate-beneficial-owner register with ID copiesOwnership structure: ~99.
Virtual Private Networks provide users with privacy and safety from prying eyes, that is if it is from a trusted service. Choose Proton VPN for a true zero-log tool instead of untrustworthy ones on the App Store and save up to 70%. Proton VPN is a safe and trustworthy tool with a zero-logs policy. Image source: Proton It's easy to assume that the Apple App Store is safe and free of manipulative software and privacy-invasive schemes. However, that has never been the case, and recent research reveals exactly how bad things are for VPN software. Users are becoming more and more aware and educated about the existence and use of Virtual Private Networks, or VPNs. They are meant to encrypt your traffic and keep you anonymous, but not all of them can prove they are as private as they say. Continue Reading on AppleInsider
Meta glasses privacy backlash reaches Dutch office Cybernews
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security portfolio. Built on the BarracudaONE platform, the solution combines AI visibility, data protection, threat defense, and governance into a single … More → The post Barracuda brings AI security and governance within reach of smaller organizations appeared first on Help Net Security .
Huge batteries, privacy displays, and smarter rear screens round things out.
OpenAI’s advertising infrastructure can link activity on third-party advertiser websites to a user’s ChatGPT account through a cross-site cookie called __obi. The mechanism resembles established ad-tech tracking systems, but its use around an AI assistant raises additional privacy questions because ChatGPT conversations can be highly sensitive. Independent researcher ‘Buchodi’ reproduced the behavior on Chrome for … The post ChatGPT advertising system reportedly tracks users across websites appeared first on CyberInsider .
Child Safety and Digital Surveillance: What Works Online? Cybernews
Discord age verification faces privacy backlash Cybernews
Dutch privacy watchdog calls for camera glasses ban in hospitals and courts Cybernews
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1. 8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2. 2 million people. [... ]
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website. The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation. After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone.
Pewdiepie family vlogging ends over son’s privacy Cybernews
The Irish data privacy regulator found Google guilty misusing users' location history and web activity.
Vonder's new wearable is designed to be glasses first, and an assistant second.
Four-way blocking gives the S26 Ultra an edge over HUAWEI and Xiaomi, but display quality and user comfort take a hit.
BYD removes China and surveillance references from car privacy policy Cybernews
View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: • API =2.0.1 • CVSS Vendor Equipment Vulnerabilities
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: • OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: • MQTT Client Application =2.0.1 • CVSS Vendor Equipment Vulnerabilities
Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars. To do that, they need more permissions, account connections, and sensitive data. So, when Meta promised that “Muse is built from the ground up for privacy and security,” we did not expect an AI agent that can easily be manipulated into handing all that access to an attacker. Meta says Muse can handle appointments, forms, customer-service interactions, purchases, document creation, and connections to services such as WhatsApp, email, calendars, and social platforms.
A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally (and inevitably) leave behind markers of their own: prompt templates, provider endpoints, API keys, jailbreak terms, and other artifacts embedded throughout their tooling. When we consider these strings as cognitive artifacts , or vestiges left behind from AI integration, we can enable a new, metadata-first hunting methodology for AI-integrated malware that is fast and scalable. These artifacts can be extracted, related, and classified without ever touching the underlying binary. Today, Cisco Talos is releasing this methodology in the form of CAIRN (Cognitive Artifact Intelligence Research Network), a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
Your conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.
A critical vulnerability in MaxKB, tracked as CVE-2026-77521, could allow attackers to use prompt injection to trigger arbitrary shell commands through AI assistants configured with tools, MCP integrations, skills, or sub-applications. The flaw affects MaxKB versions up to and including 2. 10. 3-lts and has been fixed in version 2. 10. 5-lts. The issue carries a CVSS v3. 1 score of 10. 0, with network-based exploitation requiring no authentication or user interaction. Researchers at Lasso Security reported that an attacker can exploit an exposed agent execution path to run commands on the underlying host or, in containerized deployments, potentially execute commands as root. Critical MaxKB AI Agent Flaw MaxKB routes conversations through a deepagents agent whenever an assistant has a connected tool, MCP server , skill, or sub-application.
Quick Answer: Biometric buying now splits into three jobs. Onboarding (prove the person is real and matches their ID): Entrust/Onfido, Jumio, Veridas. High-assurance verification against deepfakes and injection attacks: iProov’s liveness science leads. Continuous fraud defense after login: BioCatch behavioral biometrics. Government/enterprise infrastructure at national scale: IDEMIA and HID Global. Voice and speech: ID R&D. The deepfake era made liveness detection not matching accuracy the deciding criterion. Who This Guide Is For Fraud and identity teams adding selfie-to-document onboarding, security architects defending against injection and deepfake attacks, and banks layering behavioral signals over sessions. Eight picks organized by the job biometrics does enrollment, verification, or continuous monitoring because those are different purchases with different failure modes.
Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after receiving complaints from several European consumer groups, including BEUC, about how Google handled location data. The investigation covered the period from 25 May 2018, when the GDPR came into force, to 4 February 2020. “The scope of the Inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy” between the date of application of the GDPR, 25 May 2018 to 4 February 2020.” reads the DPC’s press release .
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek .
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which
Ireland’s Data Protection Commission (DPC) has fined Google Ireland Limited €403 million after concluding that the technology giant violated the General Data Protection Regulation (GDPR) while processing users’ location data . Announced on September 21, 2026, the decision also orders Google to bring the affected processing operations into compliance within six months. The enforcement action follows an own-volition inquiry opened in February 2020 after the regulator received complaints from several European consumer-rights organizations, including BEUC. Acting as Google’s lead supervisory authority in the European Union, the DPC examined location-data processing carried out from May 25, 2018, the date the GDPR became applicable, through February 4, 2020.
This week on the Lock and Code podcast… If you want AI to tell you a story, it will. If you want that story to sound like one of your favorite authors, it can. And if you’re one of the authors that AI can imitate, you might be a little upset at what feels like theft. In 2024, the authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson sued Anthropic, the creator of Claude, alleging that the company had wrongfully digested millions of copyrighted works—including some of their very own—to train its AI models. The lawsuit grew to include more than 300,000 writers, and in September 2025, Anthropic agreed to pay $1. 5 billion to settle the claims . That headline-worthy payout, however, would eventually be paired with more startling news. In January 2026, a district court judge unsealed thousands of documents related to the litigation.
Ireland’s Data Protection Commission (DPC) has fined Google €403 million after finding that the company violated multiple GDPR requirements while processing users’ location data. The regulator also ordered Google to bring the affected processing practices into compliance within six months. The decision follows an own-volition inquiry launched by the DPC in February 2020 after complaints … The post Ireland fines Google €403 million over location data processing appeared first on CyberInsider .
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [... ]
Spanish authorities have ordered internet providers to block Archive. today and six of its mirror domains under the country’s intellectual property enforcement system. Users attempting to access the affected addresses are instead redirected to a government warning page describing the websites as illegal. The blocking order was issued by the Second Section of Spain’s Intellectual Property … The post Spain blocks anonymous service Archive.today and all mirror domains appeared first on CyberInsider .
OpenAI’s advertising measurement system appears to use a cross-site cookie that can link activity on advertiser websites to a person’s ChatGPT account. The cookie, named __obi, is created. At the same time, a user visits ChatGPT and can later be sent back to OpenAI when that user loads sites running OpenAI’s advertising pixel. The mechanism was independently reproduced on a mobile device and observed across 936 advertiser pixels on 1,029 hostnames. It resembles the cross-site conversion tracking used by major ad platforms. However, its connection to an AI service raises new privacy questions. When a user opens ChatGPT, the client generates a random identifier and requests a short-lived signed token from OpenAI’s backend. The token contains an account-linked subject value, an obi identifier, and a consent decision marked as analytics_allowed.
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights with a keystroke. That’s not a hypothetical. It’s what happened during a two week test by Four Corners and a cybersecurity researcher named Dan Hreszczuk. Hreszczuk runs Fortify Labs in Canberra and specialises in car security. His job was simple: find out what BYD, or anyone with access to BYD’s systems in China, could see and do to the vehicle remotely. He didn’t expect it to be quick. “It was easier than we were expecting.” Hreszczuk says. That wasn’t just an offhand comment. Hreszczuk makes a living finding ways to break into cars, so the fact that he was surprised by how easy it was is significant.
No drop-off in quality when the Privacy Display feature is not in use? Sign me up!
Every identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions, invalidate the refresh tokens, then go hunting. It is the right instinct. Against adversary-in-the-middle phishing, where the whole prize is a stolen session cookie, revocation is the move that ends the incident. Then I spent a few days taking apart a backdoor where that step buys you nothing at all. The reason sits in one function, and it is the last place most of us would think to look. The sample is GraphWorm, a custom implant tied to the China-nexus APT group Webworm. One thing I found there rewrote a line in my own incident response procedure, and I think it belongs in yours. The C2 channel is somebody’s OneDrive GraphWorm has no C2 domain, no beacon to a rented VPS, no hardcoded address to block.