Data Breach Roundup (Sep 25 - Oct 1, 2026)
The US government has once again been breached, as well as a Japanese car-sharing app and a vibe-coding app platform.
The US government has once again been breached, as well as a Japanese car-sharing app and a vibe-coding app platform.
According to 404 Media, a company that makes devices to hack phones claims they can bypass iOS's automatic reboot feature and allow police to more easily access data on iPhones.
A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.
The Pentagon sent out letters to affected individuals explaining that their Defense Manpower Data Center (DMDC) was accessed by "unauthorized users," exposing the highly sensitive personal data of millions of military personnel.
Researchers at the Graz University of Technology Austria demonstrated a new attack that can track you via file change events "on all systems," allowing for various data leaks.
Meta announced in a blog post that its notorious smart glasses will soon use its Private Processing to protect your data as it's being processed in the cloud.
Researchers have demonstrated a way to break RSA encryption faster than before, allowing them to break (admittedly already deprecated) 1024-bit RSA in just five months on classical computers in an academic CPU cluster.
Tor has released updates for "all components" of Tor that include severe vulnerabilities and bugs from the "LLM report firehose" and recommends "upgrading as soon as possible."
This week's big story is a breach of the FBI exposing all employees and applicants.
Discord is rolling out a revised version of their age verification system, promising privacy improvements over the previous implementation.
The notorious hacker group ShinyHunters claims they breached the FBI's systems on Monday night, accessing the personal data of "almost all FBI agents/employees."
macOS security researcher Patrick Wardle discovered a flaw in Meta's new Muse AI assistant that an attacker can use to turn it into "the ultimate backdoor."
Revolut made headlines this week, but they weren't the only organization breached (as usual).
The UK is rolling out passkeys across GOV.UK One Login to provide more than 23 million people with a more secure way to log in.
Signal has officially announced signups without phone numbers on their community forum for the Android 8.28 beta version of the app.
X Chat, X's dedicated end-to-end encrypted messaging app, has disappeared from both Apple's App Store and the Google Play Store.
An investigation by the EFF found that cops treat mass surveillance as a joke, typing reasons for searches such as "LMAO," "LOL," and other non sequiturs or keyboard mashing in leu of an actual reason.
Revolut disclosed customers' passports, selfies, and full transaction histories to a fake government employee over email.
Two Trezor breaches, more healtcare companies, and more identification documents. This week was a mess.
Microsoft patched a record 973 vulnerabilities this September, beating their other records from earlier this year.
Apple today announced Siri Recap, a new feature in their upcoming Apple Watches that will allow it to generate a summary of conversations you have throughout the day.