# Privacy Guides > Established in 2021, Privacy Guides is the largest impartial, non-profit media outlet focused on finding privacy tools and learning about protecting your digital life. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [Donate (Monero)](https://www.privacyguides.org/donate-monero.md) - Thank you for supporting our project! We are with one of the few non-profits which proudly supports donations via anonymous cryptocurrency. 💡We recommend that you donate Monero (XMR) through the MAGIC Grants campaign website instead of the address below. This allows you to specify if you would lik… - [Privacy & Security News](https://www.privacyguides.org/news.md) - RSS Feed • Follow @PrivacyNews@mstdn.plus on Mastodon • Find more news on the forum - [Welcome](https://www.privacyguides.org/welcome-members.md) - Thank you for your support, members! ## Posts - [Why Did Google Disable this Security Feature?](https://www.privacyguides.org/livestreams/2026/09/04/why-did-google-disable-this-security-feature.md) - This Week in Privacy #69 - [Data Breach Roundup (Aug 28 - Sep 3, 2026)](https://www.privacyguides.org/news/2026/09/04/data-breach-roundup-aug-28-sep-3-2026.md) - This week saw data breaches from more hospitals, a toy company, an age verification service, an update to a French breach from last year, and more. - [Signal Android Beta Has Merged Support for Numberless Accounts, Although It's Not Enabled Yet](https://www.privacyguides.org/news/2026/09/03/signal-android-beta-has-support-for-numberless-accounts.md) - Signal has merged numberless accounts into the code as a feature in the upcoming Android beta 8.26, although you can't use it yet. - [Google Messages Bug Sends Old Texts to Random People](https://www.privacyguides.org/news/2026/09/02/google-messages-bug-sends-old-texts-to-random-peopl.md) - A bug in Google Messages is causing some people's texts from months or years ago to be sent to random people instead. - [Pixel 11 Has Hardware MTE Support, "May Still Be Usable" for GrapheneOS](https://www.privacyguides.org/news/2026/09/01/pixel-11-has-hardware-mte-support-may-still-be-usable-for-grapheneos.md) - After GrapheneOS previously hit a roadblock porting to the Pixel 11 due to a missing security feature, they found the hardware does have "at least bare minimum support for MTE." - [Router Manufacturer Found With Multiple Backdoors in its Products](https://www.privacyguides.org/news/2026/08/31/router-manufacturer-found-with-multiple-backdoors-in-its-products.md) - Researchers at VulnCheck found multiple backdoors in routers from Chinese manufacturer Zbtlink allowing a remote server root access to the router with no authentication. - [GrapheneOS Unable to Complete Pixel 11 Port Due to Cut Security Feature](https://www.privacyguides.org/news/2026/08/29/grapheneos-unable-to-complete-pixel-11-port-due-to-cut-security-feature.md) - GrapheneOS has completed a partial port to the new Pixel 11 devices, but they say they're unable to complete it due to Google dropping ARM Memory Tagging Extension (MTE) support. - [Could This Be The End of Privacy Frontends?](https://www.privacyguides.org/livestreams/2026/08/28/could-this-be-the-end-of-privacy-frontends.md) - This Week in Privacy #68 - [Data Breach Roundup (August 21 - 27, 2026)](https://www.privacyguides.org/news/2026/08/28/data-breach-roundup-august-21-27-2026.md) - Once again, multiple hospitals have been hit this week, as well as apparel companies, airports, and more. - [Windows is Testing New Privacy Protections For Apps](https://www.privacyguides.org/news/2026/08/28/windows-is-testing-new-privacy-protections-for-apps.md) - Windows is making new app-level permissions such as location, camera, and microphone available to Windows Insiders users. - [WhatsApp Offers Improved Security Features](https://www.privacyguides.org/news/2026/08/27/whatsapp-offers-improved-security-features.md) - Meta's end-to-end encrypted messenger remains popular around the world, so it's still a win that they offer additional protections to users. - [2026 Password Manager Tier List: Does Yours Stack Up?](https://www.privacyguides.org/videos/2026/08/26/2026-password-manager-tier-list-does-yours-stack-up.md) - We compared the top password managers (and the ones not quite there yet) to find out how they stack up. - [X.com Sends Privacy Frontend Nitter a Cease and Desist, Permanently Shuts It Down](https://www.privacyguides.org/news/2026/08/26/x-com-sends-privacy-frontend-nitter-a-cease-and-desist-permanently-shuts-it-down.md) - The popular privacy frontend Nitter has received a cease and desist letter from X Corp demanding a permanent takedown of the project's repository and all instances. - [Android Car Head Units Are Getting Hacked Through Their Built-In Updates](https://www.privacyguides.org/news/2026/08/25/android-car-head-units-are-getting-hacked-through-their-built-in-updates.md) - Researchers at Securelist discovered a new type of Android malware that infects car infotainment systems without any user interaction using the built-in updater. - [Plain English Words Used to Hide Windows Malware](https://www.privacyguides.org/news/2026/08/21/plain-english-words-used-to-hide-windows-malware.md) - In a currently active malware campaign, hackers are now hiding Windows malware inside lists of plain English words. - [Data Breach Roundup (August 14 - 20, 2026)](https://www.privacyguides.org/news/2026/08/21/data-breach-roundup-august-14-20-2026.md) - The CEVA Logistics breach continues to impact companies, a people search site left their databases exposed, and a couple small updates on the scope of previously-disclosed breaches. - [Microsoft Copilot Continues To Be A Nightmare](https://www.privacyguides.org/livestreams/2026/08/21/microsoft-copilot-continues-to-be-a-nightmare.md) - This Week in Privacy #67 - [Windows Copilot Hacks Itself to Steal Your Data in a Single Click](https://www.privacyguides.org/news/2026/08/20/windows-copilot-hacks-itself-to-steal-your-data-in-a-single-click.md) - CoSnitch is a one-click vulnerability discovered by researchers at Varonis Threat Labs and co-discovered by Copilot itself, that allows an attacker to exfiltrate sensitive data using Copilot's access to your computer. - [Android Will Allow You to Lock Any App Behind Your Fingerprint or PIN](https://www.privacyguides.org/news/2026/08/18/android-will-allow-you-to-lock-any-app-behind-your-fingerprint-or-pin.md) - Android 17 QPR2 Beta 3 adds a native App Lock feature allowing you to lock any app you want behind your biometrics or phone PIN. - [Meta Files Patent for Facial Recognition, Automatic Recording of People](https://www.privacyguides.org/news/2026/08/17/meta-files-patent-for-facial-recognition-automatic-recording-of-people.md) - Meta filed for a patent that includes a "memory recall" system that appears to detect people via facial recognition and record them automatically, and show you a highlights real later. - [Microsoft Making Passkeys the Default for Microsoft Accounts and Phasing Out SMS Authentication](https://www.privacyguides.org/news/2026/08/17/microsoft-making-passkeys-the-default-for-microsoft-accounts-and-phasing-out-sms-authentication.md) - Microsoft says they'll soon stop sending SMS codes for authentication for personal Microsoft accounts and will transition to "passwordless accounts, passkeys, and verified email." - [How to Securely Generate a Random Bitcoin Seed](https://www.privacyguides.org/videos/2026/08/16/how-to-generate-a-bitcoin-seed-securely.md) - We're going to generate a cryptocurrency seed phrase in the real world with only a 6-sided die, to guarantee our randomness isn't subject to an unknown software flaw. - [The Pixel 11 is Here, Will it Support GrapheneOS?](https://www.privacyguides.org/livestreams/2026/08/14/the-pixel-11-is-here-will-it-support-grapheneos.md) - This Week in Privacy #66 - [Data Breach Roundup (August 7 - 13, 2026)](https://www.privacyguides.org/news/2026/08/14/data-breach-roundup-august-7-13-2026.md) - A spike in attacks on shipping and logistics companies is likely to result in a lot of exposed data. - [Google Announced the Pixel 11 With Their New Titan M3 "Quantum-Safe" Secure Boot](https://www.privacyguides.org/news/2026/08/13/google-announced-the-pixel-11-with-their-new-titan-m3-quantum-safe-secure-boot.md) - Google announced its new Pixel 11 series of phones that bring with them a big security boost in the form of the new Titan M3 security chip that supports post-quantum cryptography for secure boot. - [Nightmare-Eclipse Releases Yet Another Devastating Windows 0-day Vulnerability](https://www.privacyguides.org/news/2026/08/13/nightmare-eclipse-releases-yet-another-devastating-windows-0-day-vulnerability.md) - The prolific and controversial security researcher who goes by Nightmare-Eclipse released a ninth 0-day vulnerability that allows an attacker to gain SYSTEM level privileges. - [Severe Zoom Vulnerabilities Allow Malicious Meeting Participants to Take Over Your Device](https://www.privacyguides.org/news/2026/08/12/severe-zoom-vulnerabilities-allow-malicious-meeting-participants-to-take-over-your-device.md) - Researchers identified critical vulnerabilities in Zoom that allows a full device takeover with no user interaction, and present on all devices. - [This Billion-Dollar Network Is Secretly Tracking Your Car](https://www.privacyguides.org/videos/2026/08/11/this-billion-dollar-network-is-secretly-tracking-your-car.md) - If you drive in America today, you've almost certainly been scanned by a Flock camera, maybe even hundreds of times. Your location, along with a timestamp and photo, all stored in a cloud database accessible to police departments across the country. - [California City Declares State of Emergency After Cyberattack](https://www.privacyguides.org/news/2026/08/11/california-city-declares-state-of-emergency-after-cyberattack.md) - Suisun City's public safety systems - including 911 - were shut down Friday morning. - [Signal is Looking at Adding an Option to Sign Up Without a Phone Number](https://www.privacyguides.org/news/2026/08/10/signal-is-looking-at-adding-an-option-to-sign-up-without-a-phone-number.md) - References in Signal's source code point to a new feature to sign up without giving a phone number, potentially requiring a one-time payment. - [The Secret War on Encryption: Inside Bullrun](https://www.privacyguides.org/videos/2026/08/09/the-secret-war-on-encryption-inside-bullrun.md) - This is the story of Bullrun, the National Security Agency's probably-ongoing effort to have eyes into every single digital service on the planet, and how you can you defend yourself against it. - [18-Year-Old Linux Kernel Bug Allows Full System Takeover](https://www.privacyguides.org/news/2026/08/07/18-year-old-linux-kernel-bug-allows-full-system-takeover.md) - Researchers at Tencent Zhuque Lab uncovered an 18-year-old vulnerability in the Linux kernel that can escape containers and gain full root privileges on the host system. - [Apple’s “Private” Relay Exposed Your IP Address?!](https://www.privacyguides.org/livestreams/2026/08/07/apples-private-relay-exposed-your-ip-address.md) - This Week in Privacy #65 - [Data Breach Roundup (July 31 - August 6, 2026)](https://www.privacyguides.org/news/2026/08/07/data-breach-roundup-july-31-august-6-2026.md) - This week featured only two data breaches from the UK and from Switzerland. Both affected federal governments, however. - [Spectre is Back: CPU Mitigations Found to Be Ineffective](https://www.privacyguides.org/news/2026/08/07/spectre-is-back-cpu-mitigations-found-to-be-ineffective.md) - Researchers found a way to bypass the latest Spectre mitigations and exploit AMD and Intel processors to leak secrets like passwords and encryption keys. - [North Korean Hackers Breached Over 1,600 Organizations Worldwide](https://www.privacyguides.org/news/2026/08/06/north-korean-hackers-breached-over-1-600-organizations-worldwide.md) - New research shows the shocking extent of North Korea's state sponsored hacking team. - [Data Breach Roundup (July 24 - 30, 2026)](https://www.privacyguides.org/news/2026/08/05/data-breach-roundup-july-24-30-2026.md) - People's AI chats have once more been exposed online, multiple updates to previously reported data breaches, and more. - [Apple's Private Relay Leaks Your Real IP Address in Safari](https://www.privacyguides.org/news/2026/08/05/apples-private-relay-leaks-your-real-ip-address-in-safari.md) - App developer/security researchers at Mysk discovered several leaks in Apple's Private Relay and all other browser proxies that allow websites to see your real IP address. - [WhatsApp is Testing Age Verification](https://www.privacyguides.org/news/2026/08/04/whatsapp-is-testing-age-verification.md) - The Tech Trace reports that a WhatsApp representative has confirmed the messenger is testing out new age verification on some user accounts to comply with a new law in India. - [Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts](https://www.privacyguides.org/news/2026/08/03/multiple-flaws-in-googles-synced-passkey-implementation-allow-attackers-to-take-over-your-accounts.md) - Unit 42 released new research showing that in Google's synced passkey ecosystem, it's possible for an attacker to take over accounts protected by synced passkeys without user interaction. - [Nearly 1,400 Bitcoin Hacked from Coldcard Wallets](https://www.privacyguides.org/news/2026/08/03/nearly-1400-bitcoin-hacked-from-coldcard-wallets.md) - A flaw in Coinkite's Coldcard hardware wallet firmware cost victims millions of dollars, all of whom believed they were investing in state of the art security - [CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet](https://www.privacyguides.org/news/2026/07/31/cisa-releases-guidance-urging-water-treatment-facilities-to-disconnect-equipment-from-the-internet.md) - CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks. - [This Graphene OS Feature Can Get You Arrested](https://www.privacyguides.org/livestreams/2026/07/31/this-graphene-os-feature-can-get-you-arrested.md) - This Week in Privacy #64 - [New "Dynamic Patching" in Chrome Would Allow Updates Without Restarting](https://www.privacyguides.org/news/2026/07/30/new-dynamic-patching-in-chrome-would-allow-updates-without-restarting.md) - In a blog post, Google announced it is working on a system in Chrome to apply updates without needing to restart the browser in order to keep up with a mountain of patches. - [Pokémon Stores Implementing Facial Recognition to Combat Scalpers](https://www.privacyguides.org/news/2026/07/29/pokemon-stores-implementing-facial-recognition-to-combat-scalpers.md) - The Pokémon Company announced that they've implemented mandatory facial recognition in Japanese Pokémon stores to combat card scalpers. - [Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information](https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information.md) - The Treasury Inspector General for Tax Administration (TIGTA) found over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents. - [Surveillance Cameras Can Now Be Retrofitted to Track Your Wireless Device Fingerprint](https://www.privacyguides.org/news/2026/07/27/surveillance-cameras-can-now-be-retrofitted-to-track-your-wireless-device-fingerprint.md) - Flock-style license plate reader vendor Leonardo announced a new system called SignalTrace that can fingerprint your wireless devices while you drive by and track you around without needing to see your license plate. - [Why Are People Mad at Mullvad?](https://www.privacyguides.org/livestreams/2026/07/24/why-are-people-mad-at-mullvad.md) - This Week in Privacy #63 - [Data Breach Roundup (July 17 - 23, 2026)](https://www.privacyguides.org/news/2026/07/24/data-breach-roundup-july-17-23-2026.md) - After last week's lack of news, the breaches are back with a vengeance. - [macOS Vulnerability Allows Attackers to Replace Any App With Malicious Code](https://www.privacyguides.org/news/2026/07/24/macos-vulnerability-allows-attackers-to-replace-any-app-with-malicious-code.md) - Researchers Talal Haj Bakry and Tommy Mysk discovered a vulnerability in macOS that allows an attacker to replace already installed apps with malicious versions that look indistinguishable from the real app. - [Gemini is Allowing Attackers to Bypass the Android Lock Screen](https://www.privacyguides.org/news/2026/07/23/gemini-is-allowing-attackers-to-bypass-the-android-lock-screen.md) - The Register received multiple reports of people being able to access features such as sending SMS or WhatsApp messages from the lock screen when Gemini is enabled. - [Apple Finally Fixes Hide My Email Vulnerability After a Year](https://www.privacyguides.org/news/2026/07/21/apple-finally-fixes-hide-my-email-vulnerability-after-a-year.md) - 404 Media says Apple has fixed a vulnerability in HideMyEmail that would allow anyone to find your real email address after knowing about the issue for over a year. - [Malware Stored in SVG Images Used to Hack Developers' Machines](https://www.privacyguides.org/news/2026/07/21/malware-stored-in-svg-images-used-to-hack-developers-machines.md) - According to Cyber Security News, North Korean hackers are targeting developers with fake job interviews containing malicious code stored in SVG images. - [LG Monitors Caught Installing Adware and App With Access to "All System Resources" Without Asking](https://www.privacyguides.org/news/2026/07/17/lg-monitors-caught-installing-adware-and-app-with-access-to-all-system-resources-without-asking.md) - Gamers Nexus tested an LG monitor and found it automatically installs an LG app on a Windows system without asking permission, which has access to "All System Resources" and includes McAfee ads. - [Windows 0 Day Exploit Situation Is Wild](https://www.privacyguides.org/livestreams/2026/07/17/windows-0-day-exploit-situation-is-wild.md) - This Week in Privacy #62 - [Data Breach Roundup (July 10 - 16, 2026)](https://www.privacyguides.org/news/2026/07/17/data-breach-roundup-july-10-16-2026.md) - This week was slow with only one breach (that we know of). - [California Age Checking Law Walks Back Some of Planned Expansion](https://www.privacyguides.org/news/2026/07/16/california-age-checking-law-walks-back-some-of-planned-expansion.md) - California AB 1856 has had its planned expansion of age checking to browsers and websites removed, leaving just closed-source operating systems on the hook for age checking. - [Interview With Cape, a Privacy-Focused Carrier](https://www.privacyguides.org/videos/2026/07/16/interview-with-cape-a-privacy-focused-carrier.md) - Can You Actually Have a Private Phone Plan? - [Secure Boot Easily Bypassable Using Decade-Old Vulnerabilities](https://www.privacyguides.org/news/2026/07/16/secure-boot-easily-bypassable-using-decade-old-vulnerabilities.md) - Researchers at ESET discovered that secure boot on Linux and Windows could be bypassed using decade-old UEFI shim bootloaders still signed by Microsoft. - [The Next Version of Meta's AI Glasses Will Activate the Camera Without the Camera Indicator Light](https://www.privacyguides.org/news/2026/07/13/the-next-version-of-metas-ai-glasses-will-activate-the-camera-without-the-camera-indicator-light.md) - The next model of Meta's smart AI glasses will reportedly activate the onboard camera for AI features without notifying anyone via the camera indicator LED. - [OpenAI's AI Atlas Browser Discontinued After Less Than a Year](https://www.privacyguides.org/news/2026/07/11/openais-ai-atlas-browser-discontinued-after-less-than-a-year.md) - OpenAI's James Sun announced that their agentic AI browser, Atlas, launched just last October, will be discontinued. - [Did Apple Add A Keylogger to the App Store?](https://www.privacyguides.org/livestreams/2026/07/10/did-apple-add-a-keylogger-to-the-app-store.md) - This Week in Privacy #61 - [Data Breach Roundup (July 3 - 9, 2026)](https://www.privacyguides.org/news/2026/07/10/data-breach-roundup-july-3-9-2026.md) - This week's unexpected entry: Nextcloud. - [Apple Patches App Privacy Issue, Many More Left Unaddressed for Now](https://www.privacyguides.org/news/2026/07/10/apple-patches-app-privacy-issue-many-more-left-unaddressed-for-now.md) - Apple fixed an app fingerprinting issue in iOS 27 Developer Beta 3, an early preview of the next major version of iOS, making it a bit harder for apps to fingerprint you. - [15-Year-Old Linux Kernel Vulnerability Allows Full System Takeover](https://www.privacyguides.org/news/2026/07/08/15-year-old-linux-kernel-vulnerability-allows-full-system-takeover.md) - Researchers at Nebula Security discovered a privilege escalation bug in the Linux kernel that's been lying dormant for over 15 years that affects every Linux distribution before version 7.1. - [Google and FBI Shut Down Malicious Residential Proxy Network Installed in Millions of Smart Devices](https://www.privacyguides.org/news/2026/07/07/google-and-fbi-shut-down-malicious-residential-proxy-network-installed-in-millions-of-smart-devices.md) - Google, Lumen, and the FBI have worked in lockstep to disrupt the massive malicious residential proxy network NetNut, also known as Popa, that has its claws in millions of devices. - [New Phishing Technique Steals Account Tokens Through Legitimate Microsoft Login Page](https://www.privacyguides.org/news/2026/07/06/new-phishing-technique-steals-account-tokens-through-legitimate-microsoft-login-page.md) - Attackers are exploiting a new phishing technique to get access to your account from a legitimate Microsoft login page, according to Kaspersky. - [CalyxOS Is Officially Back!](https://www.privacyguides.org/livestreams/2026/07/03/calyxos-is-officially-back.md) - This Week in Privacy #60 - [Data Breach Roundup (June 26 - July 2, 2026)](https://www.privacyguides.org/news/2026/07/03/data-breach-roundup-june-26-july-2-2026.md) - ShinyHunters continue to run amock in the latest cascading data breach. - [First Documented Ransomware Attack Ran Exclusively by Agentic AI Discovered](https://www.privacyguides.org/news/2026/07/03/first-documented-ransomware-attack-ran-exclusively-by-agentic-ai-discovered.md) - The Sysdig Threat Research Team has discovered what they believe to be the first ever ransomware attack carried out fully end-to-end by agentic AI. - [Brave Adds Containers to Separate Your Browsing](https://www.privacyguides.org/news/2026/07/03/brave-adds-containers-to-separate-your-browsing.md) - Brave has released a new containers feature to allow you to isolate your browsing between different identities. - [Google Wants to Scan Your Hand for its reCAPTCHA](https://www.privacyguides.org/news/2026/07/01/google-wants-to-scan-your-hand-for-its-recaptcha.md) - Google's reCAPTCHA service will start asking for camera permission to scan your hand in different positions to determine if you're human. - [Multiple Vulnerabilities Found in Apple AirDrop and Android Quick Share](https://www.privacyguides.org/news/2026/07/01/multiple-vulnerabilities-found-in-apple-airdrop-and-android-quick-share.md) - Researchers have discovered six vulnerabilities across Apple's AirDrop and Android's Quick Share file sharing protocols, some of which are zero-clicks. - [Fake GTA 6 Crypto Scams Drain Wallets and Install Malware](https://www.privacyguides.org/news/2026/06/30/fake-gta-v6crypto-scams-drain-wallets-and-install-malware.md) - Fake GTA 6 "early access" sites promise access to the game if you pay hundreds in cryptocurrency, but offer only malware instead. - [Framingham, MA Flock Contract Cancelled After Public Backlash](https://www.privacyguides.org/news/2026/06/27/framingham-ma-flock-contract-cancelled-after-public-backlash.md) - Framingham, MA has cancelled its contract for Flock Safety cameras after months of extensive public backlash due to privacy concerns. - [No News is Good News? Q&A Episode](https://www.privacyguides.org/livestreams/2026/06/26/no-news-is-good-news-q-a-episode.md) - This Week in Privacy #59 - [Data Breach Roundup (June 19-25)](https://www.privacyguides.org/news/2026/06/26/data-breach-roundup-june-19-25.md) - This week bad luck (or poor planning) struck LastPass, Polymarket, Meta, and an "AI-powered healthcare company." - [DOJ Stopped From Requiring Apple and Google to Hand Over the Data of 100,000 People](https://www.privacyguides.org/news/2026/06/26/doj-stopped-from-requiring-apple-and-google-to-hand-over-the-data-of-100-000-people.md) - A court has determined that the US DOJ cannot force Apple and Google to hand over the information of around 100,000 users of the EZ Lynk app. - [Meta's Keystroke-Logging Employee AI Training Program on Pause After Internal Data Leak](https://www.privacyguides.org/news/2026/06/23/metas-keystroke-logging-employee-ai-training-program-on-pause-after-internal-data-leak.md) - According to Business Insider, n internal program at Meta to train AI on employees' data is on pause after an internal leak exposing keystrokes, private conversations, and transcriptions. - [It's Time to Ditch Plex Media Server...](https://www.privacyguides.org/videos/2026/06/23/its-time-to-ditch-plex-media-server-video.md) - Plex just announced they are raising the price of their lifetime Plex Pass, in this video we explain how to switch & setup Jellyfin a free and open source alternative. - [Kansas City Pushes for Facial Recognition on Public Buses](https://www.privacyguides.org/news/2026/06/23/kansas-city-pushes-for-facial-recognition-on-public-buses.md) - Kansas City, Missouri is gearing up to equip public buses with facial recognition cameras designed to detect if a rider is on a list of banned or missing people. - [Android 17 has arrived on GrapheneOS! (Sort Of)](https://www.privacyguides.org/livestreams/2026/06/19/android-17-has-arrived-on-grapheneos-sort-of.md) - This Week in Privacy #58 - [Connectivity Standards Alliance Releases Matter 1.6 and Product Security 1.1 Specifications](https://www.privacyguides.org/news/2026/06/19/connectivity-standards-alliance-releases-matter-1-6-and-product-security-1-1-specifications.md) - The Connectivity Standards Alliance (CSA), creators of the Matter, Zigbee, and Aliro standards for IoT devices, released their new Matter 1.6 and Product Security 1.1 specifications for securing smart homes. - [Data Breach Roundup (June 12 - 18, 2026)](https://www.privacyguides.org/news/2026/06/19/data-breach-roundup-june-12-18-2026.md) - Novo Nordisk, the Knicks, Peter Thiel, and many more are among this week's numerous big names who were breached. - [Unpatchable Exploit Found Apple's A12 and A13 Chips](https://www.privacyguides.org/news/2026/06/19/unpatchable-exploit-found-apples-a12-and-a13-chips.md) - Researchers at Paradigm Shift discovered a new unwatchable vulnerability, dubbed "usbliter8," in Apple's A12, S4/S5, and A13 chips. - [Linux Removes Support for Legacy AppleTalk Protocol in Response to AI Patches](https://www.privacyguides.org/news/2026/06/18/linux-removes-support-for-legacy-appletalk-protocol-in-response-to-ai-patches.md) - A surge of AI-generated patches in the Linux kernel has resulted in the removal of support for older protocols, the latest of which being AppleTalk. - [Android 17 Launched, What New Privacy/Security Features Does it Bring?](https://www.privacyguides.org/news/2026/06/17/android-17-launched-what-new-privacy-security-features-does-it-bring.md) - Android 17 has now officially launched, bringing with it a slew of new privacy and security upgrades like the new Contact Picker and post-quantum app signing. - [WhatsApp Claims it Thwarted an NSO Spyware Campaign](https://www.privacyguides.org/news/2026/06/14/whatsapp-claims-it-thwarted-an-nso-spyware-campaign.md) - WhatsApp claims they detected and stopped an NSO spyware campaign against its users. - [Around 1,500 AUR Packages Compromised with "Rootkit-Like" Malware](https://www.privacyguides.org/news/2026/06/12/around-1-500-aur-packages-compromised-with-rootkit-like-malware.md) - Researchers at Sonatype uncovered a massive supply chain attack against the Arch User Repository (AUR) to harvest credentials and exfiltrate user data by hijacking around 1,500 packages. - [License Plate Readers Are Framing Innocent People](https://www.privacyguides.org/livestreams/2026/06/12/license-plate-readers-are-framing-innocent-people.md) - This Week in Privacy #57 - [You're Creating Passwords Wrong - Here's Why](https://www.privacyguides.org/videos/2026/06/12/youre-creating-passwords-wrong-heres-why.md) - Most people don't know how to create a secure password and often reuse them across websites, in this video we explain the best practices. - [Data Breach Roundup (June 5 - 11, 2026)](https://www.privacyguides.org/news/2026/06/12/data-breach-roundup-june-5-11-2026.md) - This was a busy week with breaches from several universities, the French government, Flock, and more. - [Microsoft Patches Some Vulnerabilities from Nightmare Eclipse, Others Left Unpatched](https://www.privacyguides.org/news/2026/06/10/microsoft-patches-some-vulnerabilities-from-nightmare-eclipse-others-left-unpatched.md) - Microsoft has patched some vulnerabilities from anonymous security researcher going by the pseudonym Nightmare Eclipse, who published yet another vulnerability the same day. - [Ransomware Gang Exploiting Legacy VPN Protocol in US Federal Agencies](https://www.privacyguides.org/news/2026/06/10/ransomware-gang-exploiting-legacy-vpn-protocol-in-us-federal-agencies.md) - According to TechCrunch, CISA is giving US federal agencies until the end of Wednesday to fix an actively exploited VPN vulnerability in the deprecated IKEv1 key exchange protocol. - [Common Speakers Can Be Remotely Hacked and Used to Take Over Your PC](https://www.privacyguides.org/news/2026/06/08/common-speakers-can-be-remotely-hacked-and-used-to-take-over-your-pc.md) - Ethical hacker Rasmus Moorats in a blog post revealed an exploit in Sound Blaster Katana V2X speakers, dubbed "Pwnd Blaster," that would allow an attacker to remotely take over your PC. - [Brave Launches Paid, "Minimalist" Brave Origin Browser](https://www.privacyguides.org/news/2026/06/07/brave-launches-paid-minimalist-brave-origin-browser.md) - Brave has officially released Brave Origin, a minimal version of the regular Brave browser without a lot of the optional features such as Rewards, Leo AI, and Brave's VPN, for a one-time fee. - [GTA V Cheaters Just Got Exposed!](https://www.privacyguides.org/livestreams/2026/06/05/gta-v-cheaters-just-got-exposed.md) - This Week in Privacy #56 - [Data Breach Roundup (May 29 - June 4, 2026)](https://www.privacyguides.org/news/2026/06/05/data-breach-roundup-may-29-june-4-2026.md) - This week saw data breaches impacting GTA Online cheaters, a health wearable, a UN food assistance program for Palestinians, and an update to the neverending 23andMe saga. - [Meta’s AI Support Agent Used by Hackers to Take Over Instagram Accounts](https://www.privacyguides.org/news/2026/06/04/metas-ai-support-agent-used-by-hackers-to-take-over-instagram-accounts.md) - An exploit described as “remarkably simple” allows anyone to add a new email address to any Instagram account using Meta’s AI chat bot, allowing full account takeover. - [No Right to Remain Silent: Negative Rights in a Positive-Rights World](https://www.privacyguides.org/posts/2026/06/01/no-right-to-remain-silent-negative-rights-in-a-positive-rights-world.md) - Rights exist so that you do not have to argue every time for the legitimacy of your everyday freedoms. Without an explicit right to your opacity, the rights you do already have can be called into question. - [GrapheneOS is Taking Accessibility Seriously!](https://www.privacyguides.org/livestreams/2026/05/29/grapheneos-is-taking-accessibility-seriously.md) - This Week in Privacy #55 - [Data Breach Roundup (May 22 - 28, 2026)](https://www.privacyguides.org/news/2026/05/29/data-breach-roundup-may-22-28-2026.md) - A complex travel booking breach, multiple government breaches around the world, some updates, and much more. This was a busy week for cybercriminals. - [Google Family Link Exploit Enables Account Lockout and Surveillance](https://www.privacyguides.org/news/2026/05/29/google-family-link-exploit-enables-account-lockout-and-surveillance.md) - Google Family Link, Google's child safety feature, can be leveraged by an attacker to lock you out of your Google account and surveil and control your activity - [Signal macOS Desktop App Doesn't Actually Delete Messages When it Should](https://www.privacyguides.org/news/2026/05/29/signal-macos-desktop-app-doesnt-actually-delete-messages-when-it-should.md) - Security researcher Harry Sintonen disclosed that the macOS desktop Signal app doesn't actually delete messages when they're deleted in the UI of the app. - [Town Councilmember Proposes Internet and Phone Ban After Flock Contract is Cancelled](https://www.privacyguides.org/news/2026/05/28/town-councilmember-proposes-internet-and-phone-ban-after-flock-contract-is-cancelled.md) - After the town of Bandera, Texas voted 3-2 to end its contract with the dystopian surveillance company Flock, a pro-Flock councilmember proposed a ban of phones, cameras, the internet, and nearly all technology. - [Apple Publishes Source Code for Their Cryptography on GitHub](https://www.privacyguides.org/news/2026/05/28/apple-publishes-source-code-for-their-cryptography-on-github.md) - Apple has published the source code for their corecrypto libraries on GitHub, along with the tools and formal verification libraries they used to evaluate their cryptography, so independent cryptography experts can verify it for themselves. - [The US DOJ Wants Identities and Addresses of Over 100,000 Users of a Car App](https://www.privacyguides.org/news/2026/05/27/the-us-doj-wants-identities-and-addresses-of-over-100-000-users-of-a-car-app.md) - The US DOJ is demanding the data of all users, equating to over 100,000 people, of the EZ Lynk app over alleged violations of the Clean Air Act, which the company denies. - [CISA Leaks Secret Credentials in a Public Github Repo](https://www.privacyguides.org/news/2026/05/26/cisa-leaks-secret-credentials-in-a-public-github-repo.md) - Brian Krebs found a public GitHub repository with sensitive internal CISA credentials "including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets." - [First Public Kernel Memory Exploit of on Apple's M5 Chip Found](https://www.privacyguides.org/news/2026/05/26/first-public-kernel-memory-exploit-of-on-apples-m5-chip-found.md) - Security researchers at Calif have found the first public memory corruption exploit on Apple's M5 chip, surviving Memory Integrity Enforcement protections. - [Discord Makes All Voice/Video Calls E2EE](https://www.privacyguides.org/news/2026/05/25/discord-makes-all-voice-video-calls-e2ee.md) - After Discord announced their DAVE end-to-end encryption protocol for audio and video calls in 2024, they’ve finally finished migrating all calls to use it by default. - [Google’s Smart Glasses Are A Privacy Disaster](https://www.privacyguides.org/livestreams/2026/05/22/googles-smart-glasses-are-a-privacy-disaster.md) - This Week in Privacy #54 - [Data Breach Roundup (May 15 - 21, 2026)](https://www.privacyguides.org/news/2026/05/22/data-breach-roundup-may-15-21-2026.md) - This week had some particularly noteworthy breaches including facial recognition systems, fingerprint scans, and Trump Mobile. - [Bonus Questions! Naomi Brockwell Interview](https://www.privacyguides.org/videos/2026/05/22/bonus-questions-naomi-brockwell-interview.md) - A few bonus questions just for members from our latest interview with Naomi Brockwell - [Dirty Frag Sequel Continues the Streak of Linux Kernel Privilege Escalation Vulnerabilities](https://www.privacyguides.org/news/2026/05/17/dirty-frag-sequel-continues-the-streak-of-linux-kernel-privilege-escalation-vulnerabilities.md) - Fragnesia, the latest local privilege escalation vulnerability in the same family as Dirty Frag, emerges as an “unintended side effect of one of the patches addressing the original Dirty Frag vulnerabilities” according to the original creator of Dirty Frag, Hyunwood Kim. - [From Content Creator to Policymaker: Naomi Brockwell Interview](https://www.privacyguides.org/videos/2026/05/16/from-content-creator-to-policymaker-naomi-brockwell-interview.md) - We spoke with Naomi Brockwell about the Surveillance Accountability Act she just helped draft, advocating for privacy on the internet, and the importance of defending our digital liberties. - [Data Breach Roundup (May 8 - 14, 2026)](https://www.privacyguides.org/news/2026/05/16/data-breach-roundup-may-8-14-2026.md) - This week featured some high-risk breaches including banks, cars, and water utilities. - [BitLocker Bypass Found In Latest Series of Windows Vulns](https://www.privacyguides.org/news/2026/05/15/bitlocker-bypass-found-researcher-warns-of-more-unreleased-vulnerabilities.md) - An anonymous security researchers known as Nightmare-Eclipse has published two more Windows zero-day exploits, YellowKey and GreenPlasma, after already publishing 3 earlier this year. - [Android 17 Is Looking Great for Privacy & Security](https://www.privacyguides.org/livestreams/2026/05/15/android-17-is-looking-great-for-privacy-security.md) - This Week in Privacy #53 - [Help Defeat Censorship - How To Run A Signal Proxy](https://www.privacyguides.org/videos/2026/05/14/help-defeat-censorship-how-to-run-a-signal-proxy.md) - In this video we explain how you can setup a Signal Proxy to help people access Signal in countries where it is blocked. - [Android Introduces New Privacy and Security Protections, with a Focus on Agentic AI](https://www.privacyguides.org/news/2026/05/13/android-introduces-new-privacy-and-security-protections-with-a-focus-on-agentic-ai.md) - Android has introduced some new protections against scammers and malware, some powered by agentic AI. - [Data Breach Roundup (May 1 - May 7, 2026)](https://www.privacyguides.org/news/2026/05/11/data-breach-roundup-may-1-may-7-2026.md) - The Canvas breach quickly became the biggest hack of the week, but a couple others slipped under the radar. - [Utah Targets VPNs for Age Verification](https://www.privacyguides.org/news/2026/05/11/utah-targets-vpns-for-age-verification.md) - Governor Spencer Cox has signed a law stating that websites are accountable for determining if a user is physically located in Utah, even from behind a VPN. - [Canvas System Used by Over 40% of US Schools Breached](https://www.privacyguides.org/news/2026/05/09/canvas-system-used-by-over-40-of-us-schools-breached.md) - Canvas, software used by thousands of schools in the U.S., has been hacked and the private data of staff and students stolen. - [Healthcare Marketplaces Shared Sensitive Data With Advertisers](https://www.privacyguides.org/news/2026/05/09/healthcare-marketplaces-shared-sensitive-data-with-advertisers.md) - A new investigation from Bloomberg has revealed how state-run health insurance marketplaces have - often accidentally - been sharing sensitive data with tech giants. The United States healthcare landscape is complicated. The healthcare system is largely privatized. Many employers offer health insur… - [CalyxOS Is (Almost) Back But Is It Any Better?](https://www.privacyguides.org/livestreams/2026/05/08/calyxos-is-almost-back-but-is-it-any-better.md) - This Week in Privacy #52 - [Two More Major Linux Vulnerabilities Discovered in the Same Class as Copy Fail](https://www.privacyguides.org/news/2026/05/08/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail.md) - Two new Linux local privilege escalation vulnerabilities were discovered in the same vulnerability class as Copy Fail, affecting most Linux distributions. - [Chrome for Android Now Supports Approximate Location](https://www.privacyguides.org/news/2026/05/07/chrome-for-android-now-supports-approximate-location.md) - Google announced that “you can now choose to share your approximate location with websites, instead of sharing precise location” on Chrome for Android. - [Proton Mail Launches Post Quantum Encryption](https://www.privacyguides.org/news/2026/05/07/proton-mail-launches-post-quantum-encryption.md) - Proton Mail now offers post-quantum encryption to protect against future threats from quantum computers. - [FTC to Ban Data Broker From Selling Location Data](https://www.privacyguides.org/news/2026/05/07/ftc-to-ban-data-broker-from-selling-location-data.md) - Under the proposed settlement, Kochava would be required to implement a slew of oversights and allow consumers to have more control over their data. - [Disneyland California Rolls Out Facial Recognition](https://www.privacyguides.org/news/2026/05/06/disneyland-california-rolls-out-facial-recognition.md) - The company surprisingly emphasizes reduced fraud instead of visitor safety. - [Apple Confirms RCS E2EE Will Ship with iOS 26.5](https://www.privacyguides.org/news/2026/05/05/apple-confirms-rcs-e2ee-will-ship-with-ios-26-5.md) - 9to5mac spotted in the release notes of iOS 26.5 RC confirmation that the long-awaited RCS end-to-end encryption feature will ship with iOS 26.5. - [Fedora Sealed Bootable Container Images, Possibly Opening the Door to a “Fully Verified Boot Chain”](https://www.privacyguides.org/news/2026/05/04/fedora-sealed-bootable-container-images-possibly-opening-the-door-to-a-fully-verified-boot-chain.md) - Fedora 44 has released, and with it comes a new offering: sealed bootable container images, which “include all the components needed to create a fully verified boot chain.” - [OpenAI Introduces Advanced Account Security](https://www.privacyguides.org/news/2026/05/02/openai-introduces-advanced-account-security.md) - OpenAI has introduced new security protections for ChatGPT accounts called Advanced Account Security, to protect users against account takeover. - [Every Linux Distribution Shipped Since 2017 Vulnerable to New Copy.Fail Exploit](https://www.privacyguides.org/news/2026/05/02/every-linux-distribution-shipped-since-2017-vulnerable-to-new-copy-fail-exploit.md) - A new exploit called copy.fail has emerged that can root just about any Linux distribution shipped since 2017 using just an unprivileged user account. - [Is Ubuntu Becoming the New Windows?](https://www.privacyguides.org/livestreams/2026/05/01/is-ubuntu-becoming-the-new-windows.md) - This Week in Privacy #51 - [Data Breach Roundup (Apr 24 - 30 2026)](https://www.privacyguides.org/news/2026/05/01/data-breach-roundup-apr-24-30-2026.md) - A security company, two medtech companies, a video streaming service, and an older attack we missed last week compromise this week's data breach headlines. - [Firefox Quietly Adds Brave’s Rust-Based Adblocker](https://www.privacyguides.org/news/2026/04/24/firefox-quietly-adds-braves-rust-based-adblocker.md) - Firefox has bundled adblock-rust, Brave’s memory-safe content blocker, into Firefox in version 149, although disabled by default. - [Would You Pay $60 For A Browser? (ft. Firewalls Don’t Stop Dragons)](https://www.privacyguides.org/livestreams/2026/04/24/would-you-pay-60-for-a-browser-ft-firewalls-dont-stop-dragons.md) - This Week in Privacy #50 - [Data Breach Roundup (Apr 17 - 23, 2026)](https://www.privacyguides.org/news/2026/04/24/data-breach-roundup-apr-17-23-2026.md) - A popular app-infrastructure provider, an important French government agency, a watchmaker, and a cosmetics giant make up this week's confirmed data breaches. - [Fingerprint.com Discovers Vulnerability That Can Link Your Tor Browsing Together](https://www.privacyguides.org/news/2026/04/24/fingerprint-com-discovers-vulnerability-that-can-link-your-tor-browsing-together.md) - The fingerprinting company fingerprint.com discovered a vulnerability affecting “all Firefox-based browsers” that would allow a “stable process-lifetime identifier” during a browsing session, including after pressing the “New Identity“ button in Tor browser. - [Apple Releases Patch for the Signal Notification Issue That Allowed Recovery of Deleted Messages](https://www.privacyguides.org/news/2026/04/23/apple-releases-patch-for-the-signal-notification-issue-that-allowed-recovery-of-deleted-messages.md) - Apple has released iOS 26.4.2, which fixes the notification bug that allowed the FBI to extract Signal messages from a defendant’s iPhone. - [Mozilla Used Mythos to Fix 271 Firefox Bugs](https://www.privacyguides.org/news/2026/04/22/mozilla-used-mythos-to-fix-271-firefox-bugs.md) - Regardless of your feelings on AI (and Mozilla), it seems Mozilla has at least found one good use for it. - [Madison Square Garden Facial Recognition Surveillance Used to Ban and Track People Around](https://www.privacyguides.org/news/2026/04/22/madison-square-garden-facial-recognition-surveillance-used-to-ban-and-track-people-around.md) - According to WIRED, Madison Square Garden’s incredibly invasive facial recognition system has been used to ban critics of the stadium and even track a trans woman around who did nothing wrong. - [Maryland Set To Ban Surveillance Pricing](https://www.privacyguides.org/news/2026/04/22/maryland-set-to-ban-surveillance-pricing.md) - The bill would be the first of it's kind but is not without controversy. - [Does everyone have the "Parents Decide Act" wrong?](https://www.privacyguides.org/videos/2026/04/22/does-everyone-have-the-parents-decide-act-wrong.md) - We break down the backstory of age verification laws, decipher what good could actually come out of H.R. 8250, and issue a warning about the potential dangers that this act could create in our future. - [Brave Launches Paid, Bloat-Free "Brave Origin"](https://www.privacyguides.org/news/2026/04/21/brave-launches-paid-bloat-free-brave-origin.md) - Is this a sustainable, fair business model or paywalling what should be the free version? - [Interview with Carissa Véliz, Author of "Privacy is Power" and "Prophecy"](https://www.privacyguides.org/videos/2026/04/19/interview-with-carissa-veliz-author-of-privacy-is-power-and-prophecy.md) - We sat down with Carissa Véliz, author of 'Privacy is Power' and Oxford AI Ethics professor, to talk about how predictive AI will make a 'meritocracy' impossible, how lifelike chat bots are designed to deceive you, and the importance of privacy in the digital age. - [Tracking Opt-Outs Are Useless, Cal.com's Closed Source Chaos, Both Good & Bad Political News, and More!](https://www.privacyguides.org/livestreams/2026/04/17/tracking-opt-outs-are-useless-cal-coms-closed-source-chaos-both-good-bad-political-news-and-more.md) - This Week in Privacy #49 - [HackerOne Pauses Internet Bug Bounty](https://www.privacyguides.org/news/2026/04/17/hackerone-pauses-internet-bug-bounty.md) - Hacker One says that the rise of AI bug reports is overwhelming projects, meaning the bug bounty system needs to be rethought. - [Data Breach Roundup (Apr 10-16, 2026)](https://www.privacyguides.org/news/2026/04/17/data-breach-roundup-apr-10-16-2026.md) - This week saw yet another breach from Booking.com, education giant McGraw-Hill, freelancing job board Fiverr, and many more. - [India Drops Proposal to Require Biometric ID App After Strong Opposition](https://www.privacyguides.org/news/2026/04/17/india-drops-proposal-to-require-biometric-id-app-after-strong-opposition.md) - Reuters reports that the Indian government has decided it won’t go through with a proposal to require operating systems to preinstall the biometric ID app Aadhaar. - [Fiverr Exposes Private Information of its Users Publicly on Google Search Results](https://www.privacyguides.org/news/2026/04/16/fiverr-exposes-private-information-of-its-users-publicly-on-google-search-results.md) - A security researcher on Hacker News claims that sensitive documents like tax forms shared between Fiverr users in private messages ended up publicly indexed by search engines like Google. - [Mastodon to Get E2EE for Private Messages Thanks to Sovereign Tech Fund](https://www.privacyguides.org/news/2026/04/15/mastodon-to-get-e2ee-for-private-messages-thanks-to-sovereign-tech-fund.md) - Mastodon announced they were awarded a €614k service agreement by the Sovereign Tech Fund to fund the development of new features and improvements, including end-to-end encrypted private messages. - [Google Chrome Adding Protection Against Cookie-Stealing Malware](https://www.privacyguides.org/news/2026/04/14/google-chrome-adding-protection-against-cookie-stealing-malware.md) - Google announced on their security blog that Device Bound Session Credentials (DBSC), a protection against session theft, are shipping for Windows users on Chrome 146. - [Librarians Raise Privacy Concerns Over Age Verification Bill](https://www.privacyguides.org/news/2026/04/13/librarians-raise-privacy-concerns-over-age-verification-bill.md) - The Coalition of Alberta Public Libraries issued a letter raising privacy concerns over Bill 28, or the Municipal Affairs and Housing Statues Amendment Act, in Alberta, which requires age restrictions on library materials. - [Interview with EFF Executive Director Cindy Cohn: "I like to win."](https://www.privacyguides.org/videos/2026/04/12/interview-with-eff-executive-director-cindy-cohn-i-like-to-win.md) - Privacy Guides sat down with EFF Executive Director Cindy Cohn to reflect on her over 30 years of service defending privacy and digital civil liberties at the Electronic Frontier Foundation. - [Data Breach Roundup (Apr 3 - 9, 2026)](https://www.privacyguides.org/news/2026/04/12/data-breach-roundup-apr-3-9-2026.md) - It was a slow week, though we did still see a high-profile breach of a startup that provides training data for AI which likely continue to be talked about for a while. - [Microsoft Hates Security, "Surveillance Wages" Are a Thing Now, FBI Recovered Signal Messages From Notification History, and More!](https://www.privacyguides.org/livestreams/2026/04/10/microsoft-hates-security-surveillance-wages-are-a-thing-now-fbi-recovered-signal-messages-from-notification-history-and-more.md) - This Week in Privacy #48 - [Your Inbox Isn’t Private — Here’s How to Fix It](https://www.privacyguides.org/videos/2026/04/09/your-inbox-isnt-private-heres-how-to-fix-it.md) - Your email address is the key to your digital life, learning how to secure it properly is instrumental in protecting your privacy & security. ## Optional - [RSS Feed](https://www.privacyguides.org/rss/) - [Sitemap](https://www.privacyguides.org/sitemap.xml) - [Full content of pages and posts](https://www.privacyguides.org/llms-full.txt)