All CosmicBytez Labs articles tagged #Privacy, across news, security advisories, how-to guides, and projects.
California Attorney General Rob Bonta filed a lawsuit against 23andMe — now Chrome Holding Co. — over its failure to protect millions of customers'...
Deploy Pi-hole v6 as a network-wide DNS sinkhole backed by Unbound as a self-hosted recursive resolver — eliminating ads, trackers, and malware domains...
Microsoft is reversing course on a controversial Edge browser behavior that loaded all saved passwords into process memory in cleartext at startup — a...
The FTC will levy hefty fines and pursue investigations against platforms that fail to remove non-consensual intimate imagery, including AI-generated...
General Motors will pay $12.75 million to settle California allegations that it violated the California Consumer Privacy Act by collecting and selling...
General Motors has agreed to pay over $12 million to settle California privacy violations under the CCPA after sharing detailed driver behavior data —...
California regulators have issued a record $12 million settlement against General Motors for sharing OnStar driving behavior data with insurers without...
The European Commission has formally accused Meta of violating the Digital Services Act by failing to adequately protect children under 13 from accessing...
A high-severity Firefox vulnerability (CVE-2026-6770) exploits the internal ordering of IndexedDB database names to generate a stable 44-bit fingerprint...
Deploy a fully self-hosted, Bitwarden-compatible password manager using Vaultwarden on Docker with Caddy reverse proxy, automatic TLS, WebSocket...
Google removed over 8.3 billion policy-violating ads and suspended 24.9 million accounts in 2025, while simultaneously rolling out sweeping Android 17...
Citizen Lab has documented how an Israeli surveillance company called Cobwebs Technologies built an advertising-based global geolocation platform named...
ShinyHunters exploited compromised Okta SSO credentials to breach the Hims & Hers Zendesk customer support platform, exposing treatment category data for...
A critical unauthenticated information disclosure vulnerability in the Gardyn smart garden platform exposes all registered user account information via a...
Build a self-hosted WireGuard VPN server on Ubuntu for secure remote access — with NAT masquerading, DNS leak protection, QR-code client provisioning, and...
A Dutch court has ordered Elon Musk's xAI to stop generating nonconsensual nude images via Grok or face fines of €100,000 ($115,000) per day for...
The European Parliament voted 311 to reject an extension of CSAM scanning obligations for tech platforms, dealing a major blow to proposals that would...
This week's cybersecurity roundup covers supply chain attacks hitting CI/CD pipelines, long-running IoT botnets finally disrupted, the FBI's warrantless...
A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...
OpenAI confirmed that ChatGPT ads remain a U.S.-only pilot for Free and Go plan users, despite a global privacy policy update that alarmed international...
An unprotected MongoDB instance belonging to identity verification firm IDMerit left over 1 billion personal records — including SSNs, passport numbers,...
A 53MB source code leak from identity verification giant Persona reveals how routine age verification selfies feed into a surveillance system linking...
A misconfigured Google Firebase backend in the Chat & Ask AI app exposed 300 million private chatbot conversations from 25 million users, including...
The Netherlands' largest mobile network operator Odido has disclosed a data breach affecting 6.2 million customers, exposing names, addresses, bank...
The IRS faces legal action after improperly disclosing confidential tax information of 1.28 million individuals to DHS for immigration enforcement,...
South Korea's data protection authority has fined three LVMH luxury brands a combined $25 million for data breaches affecting millions of customers, with...
A hacker revealed 6.8 billion email addresses online on February 11, 2026, in one of the largest email database leaks in history, raising concerns about...
Set up a purpose-built OSINT workstation with Trace Labs VM, sock puppet management, browser isolation, VPN routing, and automated investigation workflows...
Substack CEO Chris Best disclosed a data breach on February 5 affecting approximately 700,000 users, after an unauthorized party accessed the platform...
Deploy Pi-hole for network-wide ad blocking and DNS security. Includes setup, configuration, upstream DNS options, and integration with encrypted DNS.
Telegram is investigating claims that a threat actor is selling data from 30 million users. The company denies any breach of its systems while the...
Deploy your own password manager with Vaultwarden (Bitwarden-compatible). Includes secure configuration, SSL setup, and backup procedures.