Visualização normal

Ontem — 8 de Setembro de 2026Stream principal

Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids

8 de Setembro de 2026, 09:00
Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.

  • ✇Malwarebytes
  • Grindr settles HIV status data-sharing lawsuit for $35 million
    Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers. The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020. The claimants allege that Grindr shared personal and highly sensitive information with a
     

Grindr settles HIV status data-sharing lawsuit for $35 million

8 de Setembro de 2026, 09:51

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  • ✇Malwarebytes
  • LG TV flaws could let attackers listen in, even in standby mode
    Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR).  ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and co
     

LG TV flaws could let attackers listen in, even in standby mode

7 de Setembro de 2026, 10:34

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.

Our earlier guide to disabling ACR includes instructions for several popular TV brands.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Antes de ontemStream principal

ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years

4 de Setembro de 2026, 07:30
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.

Prediction Market Betting Is Getting People Banned and Arrested

3 de Setembro de 2026, 18:48
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents

Health data of more than 9.5 million people leaked from Aesto record system

2 de Setembro de 2026, 14:15
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.

  • ✇Malwarebytes
  • Your phone or computer may soon ask how old you are
    First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027.  Operatin
     

Your phone or computer may soon ask how old you are

3 de Setembro de 2026, 05:54

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be.

California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027.  Operating systems set up before that date in California will need to do the same by July 1, 2027.

Operating systems will categorize people into four age brackets: under 13, 13–15, 16–17, and 18+. They will then be able to send a non-identifying age signal to app developers. Developers must request that signal from the operating system provider or app store when someone downloads and launches an app. This makes them legally aware of the person’s age bracket.

California wants to stop children from doing things that could hurt them. Kids shouldn’t be able to download apps containing mature content meant only for adults, for example. Age assurance also goes hand in hand with social media restrictions, and Meta recently agreed to put time limits on kids’ social network use as part of a massive court settlement. Another California bill, AB1709, would restrict addictive social media features for children under 16. Measures like these need some form of age assurance to function.

This makes digital rights activists unhappy. The Electronic Frontier Foundation (EFF) isn’t a fan of age verification. It accused California of “outsourcing censorship to developers” through the DAAA rather than focusing on privacy.

The EFF was also uncomfortable with the effect of all this on open-source systems. Age verification requires time and effort from operating system developers. That’s fine if you’re Microsoft, Apple, or Google with a massive development budget. But it’s more problematic for operating systems developed by volunteers, such as Linux distributions. Those that don’t have the resources to comply, or don’t like the privacy implications, might prefer to avoid the Golden State altogether.

GrapheneOS, a privacy-focused mobile operating system that strips Android of its surveillance functions, took that option. In March, it said that it wouldn’t implement age verification, and would happily forego sales of devices running its software in certain regions, if necessary.

Assembly member Buffy Wicks, who introduced the original DAAA, has been listening. She tweaked the legislation with Bill AB1856, which would amend the law to exempt certain open-source operating system providers. California lawmakers passed the bill in late August, and it is now awaiting the governor’s decision.

AB1856 would exempt software that follows open-source rules, allowing it to be reused and built upon by others. This includes software distributed under common licenses such as GPL, MIT, BSD, and Apache. Not one single lawmaker voted against it.

California isn’t alone in mandating the collection of age brackets. Colorado’s SB26-051, now law, does something similar. Legislators there also added parallel open-source exemptions after lobbying by Linux hardware maker System76.  Illinois has also passed age assurance legislation, and New York has a bill in the works.

Exempting open-source operating systems from California and Colorado will please privacy-conscious users, but it’s worth noting that some Linux distributions are going ahead with age assurance anyway. Many have drawn a line in the sand, others, like Fedora, are reportedly planning to do it anyway.

In any case, those using more mainstream operating systems can expect a “How old are you?” or “What’s your birthdate?” question sometime soon. If you’d rather avoid that, consider an open-source operating system instead. Just check with your distribution’s maintainers to see what their plans are.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

  • ✇Malwarebytes
  • 153M+ driver’s licenses for sale on new dark web platform
    A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports. The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise
     

153M+ driver’s licenses for sale on new dark web platform

2 de Setembro de 2026, 07:03

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards.

The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports.

The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise.

The FBI’s New Orleans field office has opened an investigation into an apparent breach involving identity verification provider IDScan.net. The company said it was investigating.

IDScan.net advertises as follows:

“We provide simple, secure solutions to help dispensaries reduce liability and protect their licenses by validating IDs, including a customer’s age, in a matter of seconds.”

The allegedly exposed records were especially concerning because some included more than a basic photo of an ID. KrebsOnSecurity found records containing front-and-back images, as well as infrared and ultraviolet scans, with timestamps that appeared to align with the holders’ travel or car-rental activity.

That matters because a driver’s license is far more useful to an identity thief than a password. You can reset a password. You cannot easily replace your face, date of birth, address, or license number, particularly when they’re accompanied by high-resolution images of your government-issued ID.

The age-verification problem

Age verification has become a common justification for asking people to upload an ID, take a selfie, or submit both to a third-party identity verification provider.

We have previously warned about the privacy and security trade-offs in age-verification systems, particularly those that require people to submit copies of government-issued ID. Such systems can turn a request to access a website into a decision to share an enduring identity document with a company the user may never have heard of.

In our opinion, that is a disproportionate risk. Once someone uploads an ID, the service or its vendor can potentially link the visit to their identity. If the provider is breached, the consequences can extend well beyond unwanted marketing or an exposed email address.

The reported Nexus dataset illustrates a broader concern: Identity documents are collected in many places that people may not connect with one another. Each individual collection may be presented as routine, but together they create an ever-expanding ecosystem of organizations, contractors, software platforms, cloud services, and privacy policies.

Facial images and ID copies can be reused. Criminals may use them to make scams more convincing, pass weak identity checks, or assemble detailed victim profiles from records obtained from separate breaches. An attacker who knows your name, address, date of birth, email address, and license details has a useful foundation for fraud.

This is why “we only need to verify your age” should not automatically mean “please upload your driver’s license” or another form of ID.

How to stay safe

When an ID check is required to use an online service, ask a basic question: Why does this company need a copy of my identity document, and what happens to it afterward? The scale of the data reportedly offered through Nexus shows why the answer matters.

Consumers cannot always refuse an ID check, particularly where it is legally required or necessary for a regulated service. But you can reduce unnecessary exposure:

  • Ask whether an ID image is stored and, if so, for how long.
  • Check whether the company uses a third-party identity verification provider.
  • Prefer services that offer a privacy-preserving age check rather than requiring a full ID upload.
  • Avoid submitting identity documents to sites you do not trust or did not intend to use.
  • Do not email copies of IDs unless there is no safer alternative and you have independently verified the recipient.
  • Be alert for phishing, account-recovery scams, and fraudulent credit applications if you believe your ID may have been exposed.
  • Consider a credit freeze where available.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

  • ✇Schneier on Security
  • Wireless Routers as Motion Detectors Bruce Schneier
    Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity. Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected device
     

Wireless Routers as Motion Detectors

2 de Setembro de 2026, 07:22

Comcast has added motion detection as a feature to its wireless routers:

The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity.

Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance.

Sounds like a great surveillance tool. And also:

But the biggest privacy concern comes directly from Comcast’s own support page, which says information generated by WiFi Motion may be shared with third parties.

“Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena,” the page reads.

  • ✇Cybersecurity News
  • Android 17 Enables Encrypted Client Hello by Default to Hide Website Names Do Son
    Android 17 becomes the first major mobile OS to enable Encrypted Client Hello (ECH) by default, hiding visited website names from ISPs and network eavesdroppers. Related Posts: Android 17 Memory Limits: Stricter App Constraints Google Restricts Pixel Kernel Source Access, Ditching Public Git Repos Google Pixel 11 Pro Teaser Reveals Mysterious Spinning Light The post Android 17 Enables Encrypted Client Hello by Default to Hide Website Names appeared first on Daily CyberSecurity.
     

How an Atlanta Suburb Ended Up Sharing Flock Data With More Than 2,000 Organizations

28 de Agosto de 2026, 06:00
Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission. The reasons why show how vast—and invasive—the network has become.

A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend

27 de Agosto de 2026, 15:12
After an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.

  • ✇Malwarebytes
  • Flock wants privacy to meet surveillance halfway
    Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety. It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together. “When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise.” Langley call for compromise comes as the company faces intensifying resistance to its automated license plate reader (ALPR
     

Flock wants privacy to meet surveillance halfway

27 de Agosto de 2026, 12:15

Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety.

It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together.

“When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise.”

Langley call for compromise comes as the company faces intensifying resistance to its automated license plate reader (ALPR) network. The opposition has begun to affect Flock commercially and operationally, with agencies disabling cameras or canceling contracts.

The problem is that the public has already been doing the compromising: People’s movements have been routinely captured, stored, searched, and, in some cases, shared far beyond the communities that installed the cameras.

Flock’s ALPRs collect detailed records of where vehicles travel, then make that data available to law enforcement for investigations. Langley now says the company wants more regulation and accountability. Flock says it’s reducing its recommended default retention period to seven days and will require case codes for law enforcement and an audit tool designed to flag suspicious access by the end of the year.

Those are welcome concessions, but they do not resolve the underlying concern: A rapidly expanding, privately operated surveillance network can turn ordinary travel into searchable historical data.

The opposition has not faded; it has intensified. NPR reports that cameras have been vandalized in at least 36 states. Vandalism is neither a productive nor lawful answer, but its spread offers a useful measure of how profoundly many people feel excluded from decisions about surveillance in their communities.

A genuine compromise would not start with the assumption that widespread collection is inevitable and then negotiate the retention period. It would begin with democratic consent, strict limits on how the data can be used, independently enforceable access controls, public reporting, meaningful opt-outs where possible, and a clear requirement that surveillance be necessary and proportionate.

Calls to meet halfway are also harder to take seriously when the CEO has been accused by 404 Media of misleading police about the outlet’s reporting on an abortion-related case. According to 404 Media, his account is contradicted by court records and police reports. That accusation makes his public calls for compromise much harder to accept.

Flock is right about one thing: There needs to be accountability. But calling for “compromise” after the cameras are already up sharply limits the choices left to communities. Privacy is not a bargaining chip to be surrendered whenever surveillance vendors promise safety.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Do Smart Monitors Track You? What Buyers Should Know

26 de Agosto de 2026, 15:28

A smart monitor can do far more than display a PC. Built-in apps, ACR, and advertising systems can introduce additional privacy considerations.

The post Do Smart Monitors Track You? What Buyers Should Know appeared first on TechRepublic.

❌
❌