Data Breach Roundup (Jan 16 – Jan 22, 2026)
You have to admire the audacity of someone who posts on Instagram as "ihackthegovernment"
RSS Feed • Follow @PrivacyNews@mstdn.plus on Mastodon • Find more news on the forum
You have to admire the audacity of someone who posts on Instagram as "ihackthegovernment"
The first day of the Pwn2Own Automotive hacking competition has kicked off in Tokyo, Japan, with “a record 73 entries” showing that our vehicles are juicier targets than ever.
Mandiant, a cybersecurity firm and subsidiary of Google, has released a rainbow table for the outdated Windows NTLMv1 authentication protocol, allowing attackers to crack administrator passwords in under 12 hours using consumer hardware that costs less than $600.
OpenAI has announced it’ll be incorporating ads into ChatGPT for Free and Go users.
A data breach forum having a breach, an investment platform sweeping theirs under the rug, major shipping company ignoring disclosures, and more.
Researchers have discovered a vulnerability in Google Fast Pair, dubbed WhisperPair, that leaves affected accessories open to being fully controlled by an attacker.
By offering discounts to current users, Windscribe wants you to invest your money into specialists, not bundled ecosystems.
Security research and consulting firm Trail of Bits analyzed agentic AI in browsers and found vulnerabilites that resemble cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
Funded by private equity firm AFINUM Management since 2020, Threema has agreed to a secondary buyout from Comitis Capital.
Mention of the long-awaited RCS end-to-end encryption (E2EE) support in the iOS 26.3 beta was spotted by Tiion-X83 on X via a carrier bundle setting that would let carriers enable E2EE for RCS messaging.
Instagram users were sent password reset emails recently that they didn’t request, but Instagram says there was no breach of their system.
From cryptocurrency to healthcare, 2026 seems set to bring us more of the same breaches.
Logitech’s G HUB and Logi Options+ software stopped working, leaving users who relied on it for managing their mice and keyboards high and dry.
Illustrating the importance of threat models
Telegram has added support for passkeys, a secure and convenient sign-in method, replacing SMS verification codes.
Gnu Privacy Guard, a popular implementation of the OpenPGP standard, was found to have multiple vulnerabilities including modifying the plaintext shown to the user and modifying files on the user’s system.
The Connectivity Standards Alliance has launched their new standard for secure, interoperable smart locks called Aliro.
WIRED, crypto, and 2026's first candidate for "cascading data breach"
AI data centers are running up against the physical limits of copper for transmitting data, so radio is being considered as a replacement.
The Aflac breach affected 22.6 million customers. And this was a slow week.
Following multiple outages, Cloudflare outlines their plan to improve resilience of their network, titled “Code Orange: Fail Small.”