Tag: privacy
450 articles

third-party breaches: Stunning, Risky Wake-Up Call
Stellantis warns a third‑party supplier may have exposed customer personal data, leaving millions wondering what may actually means. Customers deserve clear answers about who was affected, what was leaked, and what protections will be offered.

EV charging infrastructure Critical Risk: Must-Fix Leak
An EV charging provider warned some customers that a third‑party security incident may have exposed names and email addresses — a reminder that the clean‑tech convenience we love can still leave personal data vulnerable. Stay alert for phishing, enable MFA where you can, and expect the industry to tighten vendor security as it responds.

surveillance and propaganda: Exclusive, Risky Systems
A cache of leaked documents peels back the Great Firewall to reveal a bustling industry of Chinese companies — not state bureaus — building surveillance, automated moderation, and influence tools in close partnership with universities and local governments. Those familiar Silicon Valley playbooks, applied with far less transparency, raise urgent questions about oversight, export risks, and everyday impacts on speech and civic life.

artificial intelligence: Must-Have or Risky for Banks
UK banks are sprinting to unlock AI’s productivity and customer‑service gains while racing to prevent unvetted public models from exposing millions of customers, pushing firms to build private registries, tighter governance, and controlled sandboxes. The big question: can they innovate fast enough to reap AI’s benefits while keeping regulators and customers confident their data is safe?

zero-click vulnerability: Stunning Gmail Privacy Risk
Imagine your inbox spilling secrets without you clicking anything — researchers found a zero-click flaw in the ChatGPT Deep Research agent that could let crafted web pages make the agent access and reveal Gmail content while browsing. It’s a wake-up call to tighten permissions and rethink how AI assistants access personal accounts.

ShadowLeak ChatGPT bug: Stunning Serious Risk
A single crafty email was enough to trick ChatGPT’s Deep Research agent into spilling Gmail messages — Radware dubbed the flaw “ShadowLeak” and OpenAI says it’s now patched. It’s a stark reminder that smarter AI assistants can widen the attack surface, so vigilance matters.

Silent Courier: Must-Have Secure Portal
MI6’s new Tor portal, Silent Courier, offers step-by-step guidance to help overseas sources contact the agency anonymously — a smart, modern shortcut that could surface lifesaving leads. But putting recruitment on the dark web also sparks tough questions about verification, misuse and source safety.

hardcoded secrets: Stunning Risky Mobile Crisis
One in three Android apps — and over half of iOS apps — are leaking sensitive data through insecure APIs and hardcoded secrets, putting your personal info and company systems at risk. Luckily, with smarter developer practices, better tooling and a few simple precautions, we can close those easy doors before attackers walk through.

Five Eyes Exclusive: Risky .com Crackdown Stirs Debate
With the UK’s NCA now chairing the Five Eyes law‑enforcement group and reportedly zeroing in on the .com domain, investigators and tech companies face tough choices about disrupting crime without breaking the internet — or people’s rights. How that balance is struck will shape both cybercrime fightbacks and the future of a stable, open web.

kids social media ban: Exclusive Risky Rules Revealed
Australia has handed Big Tech a thorny challenge: prove users are 16+ using layered age checks without turning signups into surveillance. Expect a scramble of tech experiments, policy fights and messy trade‑offs as platforms race to balance child safety, privacy and practicality before the December 10 deadline.

Law Enforcement Request System: Stunning Risky Breach
Google just revealed that criminals created a fraudulent account in its Law Enforcement Request System (LERS), exposing a worrying gap in the trusted channel police and courts use to obtain sensitive user data. The incident sparks a necessary push to tighten verification, protect investigations, and rebuild public confidence in the systems meant to keep us safe.

API security: Must-Have Defenses Against Risky Breaches
Thales’ report of 40,000+ API incidents in H1 2025 shows APIs have gone from a niche technical risk to a boardroom emergency — attackers are automating probes, scraping data and abusing business logic at scale. Now’s the moment to move API security from a checkbox to a strategic priority with discovery, fine‑grained auth, rate limiting and runtime protection.

Online Safety Act: Must-Have Reforms or Risky Overreach
As the House of Lords quizzes campaigners and experts on Ofcom’s tighter Online Safety Act guidance, peers must weigh protecting children from real harms against the risk of costly, privacy‑eroding rules that could stifle speech and small platforms. Their scrutiny could reshape how the UK balances safety, free expression and innovation — with real consequences for families, tech firms and regulators alike.

spyware campaign Exclusive Critical Alert for France
Apple quietly warned some French iCloud users they may have been targeted by sophisticated spyware, and CERT-FR confirmed this is the fourth such alert in 2025—suggesting a focused campaign rather than a mass outbreak. If you saw the Apple Security notice, update your devices, review account access and authentication, and consider expert help to secure sensitive communications.

Apple spyware campaign: Exclusive Risky Threat Guide
Worried about your iPhone? Apple warned multiple French users in 2025 they may have been targeted by sophisticated spyware — a wake‑up call to update, tighten protections, and demand clearer rules around commercial surveillance.

national digital ID: Risky Must-Have That Fails
A national digital ID might streamline services and cut fraud, but it also risks turning everyday life into a constant identity check — concentrating power, widening surveillance and still doing little to stop small‑boat crossings. Without strong legal safeguards, decentralised design and real alternatives, a BritCard could trade convenience for serious privacy and security dangers.

script kiddie Risky Trend: Must-Have Parental Guide
Think a school outage means a shadowy hacker? More often it’s curious teens — the ICO says students cause over half of school cyberattacks — so parents can steer curiosity into clubs, supervised learning, and clear conversations about ethics before experimentation becomes real harm.

data breaches in schools: Urgent Exclusive Warning
A new ICO warning shows student hacks are increasingly exposing sensitive school data and could be training tomorrow’s cybercriminals. Schools urgently need practical security upgrades, ethics lessons and better funding to protect pupils and restore parental trust.

surveillanceware market: Explosive, Risky Surge
U.S. investors are fueling a boom in surveillanceware that can turn phones and cameras into powerful spying tools. Without tougher safeguards and accountability, that profit-driven surge risks privacy, civil society and national security.

data hygiene: Must-Have Best Practice for Mission Success
When every prediction can affect lives, the DoD is taking “garbage in, garbage out” seriously—cleaning, governing, and engineering data so AI becomes a reliable, mission-ready partner.

end-to-end encryption: Stunning Risky Debate in Europe
Brussels is wrestling with whether to preserve strong end‑to‑end encryption or require engineered access that law enforcement says is needed to fight child abuse and serious crime. Security experts warn any backdoor would create systemic vulnerabilities that could harm journalists, victims and businesses, while proponents argue tougher tools are essential to protect the public.

supply chain attack: Stunning, Risky Threat to Passengers
LNER has confirmed a supply-chain attack on a third-party supplier exposed some customers’ contact and journey details, and the company is notifying those affected and offering support. If trusted partners can become breach points, passengers are rightly asking who’s protecting their privacy.

Jaguar Land Rover Exclusive: Risky Cyber Breach Hits Trust
Jaguar Land Rover says a cyberattack forced key systems offline and affected some data, leaving dealerships, factories and customers seeking clear answers. As investigators dig in, the real test will be how quickly JLR restores services and rebuilds trust in connected cars.

student data Shocking Risky Exposure in School Email
A routine flu jab email at a Birmingham secondary school accidentally exposed personal details for hundreds of students, leaving parents alarmed and prompting urgent questions about data handling. The blunder shows how simple communication mistakes can erode trust—and why schools and health providers need stronger safeguards and clearer, safer ways to share information.