Browsing: Privacy & Personal Security
Guides, news, and tips to help you protect your data, digital identity, devices, and personal privacy online without the technical jargon.
The article discusses the ongoing privacy divide between the U.S. and Europe, particularly in the context of AI regulation. Europe is adapting its approach with a new digital omnibus package, which aims to simplify compliance and amend the GDPR. This shift highlights a fundamental difference in how personal data is perceived, with Europe emphasizing individual rights while the U.S. operates under a patchwork of state laws. This matters as the evolving AI landscape challenges existing privacy frameworks and user expectations.
Microsoft has confirmed a security flaw in its Copilot AI that allowed unauthorized access to users’ confidential emails, bypassing data loss prevention protocols. This vulnerability, tracked as CW1226324, has been present since late January and affects Microsoft 365 business customers. The issue raises concerns about the intersection of AI productivity tools and data privacy, as the AI continued to summarize emails marked as confidential.
In January, UpGuard researchers discovered an exposed database containing approximately 2.7 billion records of Social Security numbers and 3 billion email addresses and passwords. The data, hosted by Hetzner, likely compiled from multiple breaches, raises significant identity theft concerns. Notably, one in four Social Security numbers in a sample appeared valid, potentially affecting 675 million individuals, highlighting ongoing risks from past data breaches.
Betterment LLC, an investment advisor, reported a data breach in January 2026 where an attacker used social engineering to access a third-party platform. This incident compromised the personal and financial information of approximately 1.4 million customers, including sensitive details like retirement plan information and contact data. The ransomware group Shiny Hunters is now threatening to publish this stolen data, raising significant concerns about identity theft and targeted phishing attacks.
Generative AI tools like Claude, ChatGPT, and Gemini have been found to produce weak passwords that appear strong but are easily guessable. A study by Irregular revealed that these AI-generated passwords often follow common patterns, making them vulnerable to brute-force attacks. The estimated entropy of these passwords is significantly lower than that of truly random passwords, raising concerns about their security for sensitive accounts.
A bug in Microsoft 365 Copilot has been summarizing confidential emails since January 21, 2025, bypassing data loss prevention (DLP) policies. This issue affects the Copilot ‘work tab’ chat feature, which incorrectly processes emails in users’ Sent Items and Drafts folders. Microsoft is currently rolling out a fix and monitoring the situation, but has not disclosed how many users are affected.
Organizations are increasingly concerned that unrestricted access to AI tools may pose cybersecurity risks, particularly regarding data privacy and potential misuse. Blocking AI features can help prevent sensitive corporate data from being exposed or misused, especially in regulated industries like finance and healthcare. However, while this approach can enhance security, it may also limit the benefits AI tools can provide in detecting threats and automating responses.
A Spanish court has ordered NordVPN and ProtonVPN to block 16 websites that facilitate the piracy of football matches. This ruling, which applies to a dynamic list of IP addresses in Spain, was made without the defendants being present in court. LaLiga and its broadcasting partner, Telefónica, are also required to preserve digital evidence of the unlawful transmissions, marking a significant step in combating online piracy in Spain.
Non-Human Identities (NHIs) are crucial for cybersecurity, acting like machine passports that manage access and permissions in cloud environments. They help organizations reduce risks, ensure compliance, and improve operational efficiency. Industries such as finance and healthcare benefit significantly from NHIs by securing sensitive data and maintaining integrity, making their management essential in today’s digital landscape.
Chrome’s preloading feature anticipates user clicks and loads pages in the background, which can lead to unexpected block pages in Malwarebytes Browser Guard. This occurs because preloaded pages can still run code and contact servers, raising privacy concerns. Users can disable this feature to enhance their browsing privacy and avoid confusion from block pages.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.