Data Breach Roundup (July 24 - 30, 2026)
People's AI chats have once more been exposed online, multiple updates to previously reported data breaches, and more.
People's AI chats have once more been exposed online, multiple updates to previously reported data breaches, and more.
App developer/security researchers at Mysk discovered several leaks in Apple's Private Relay and all other browser proxies that allow websites to see your real IP address.
The Tech Trace reports that a WhatsApp representative has confirmed the messenger is testing out new age verification on some user accounts to comply with a new law in India.
Unit 42 released new research showing that in Google's synced passkey ecosystem, it's possible for an attacker to take over accounts protected by synced passkeys without user interaction.
A flaw in Coinkite's Coldcard hardware wallet firmware cost victims millions of dollars, all of whom believed they were investing in state of the art security
CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
In a blog post, Google announced it is working on a system in Chrome to apply updates without needing to restart the browser in order to keep up with a mountain of patches.
The Pokémon Company announced that they've implemented mandatory facial recognition in Japanese Pokémon stores to combat card scalpers.
The Treasury Inspector General for Tax Administration (TIGTA) found over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents.
Flock-style license plate reader vendor Leonardo announced a new system called SignalTrace that can fingerprint your wireless devices while you drive by and track you around without needing to see your license plate.
After last week's lack of news, the breaches are back with a vengeance.
Researchers Talal Haj Bakry and Tommy Mysk discovered a vulnerability in macOS that allows an attacker to replace already installed apps with malicious versions that look indistinguishable from the real app.
The Register received multiple reports of people being able to access features such as sending SMS or WhatsApp messages from the lock screen when Gemini is enabled.
404 Media says Apple has fixed a vulnerability in HideMyEmail that would allow anyone to find your real email address after knowing about the issue for over a year.
According to Cyber Security News, North Korean hackers are targeting developers with fake job interviews containing malicious code stored in SVG images.
Gamers Nexus tested an LG monitor and found it automatically installs an LG app on a Windows system without asking permission, which has access to "All System Resources" and includes McAfee ads.
This week was slow with only one breach (that we know of).
California AB 1856 has had its planned expansion of age checking to browsers and websites removed, leaving just closed-source operating systems on the hook for age checking.
Researchers at ESET discovered that secure boot on Linux and Windows could be bypassed using decade-old UEFI shim bootloaders still signed by Microsoft.
The next model of Meta's smart AI glasses will reportedly activate the onboard camera for AI features without notifying anyone via the camera indicator LED.
OpenAI's James Sun announced that their agentic AI browser, Atlas, launched just last October, will be discontinued.