Haruto Kimura discovered that NSS had incorrecty handled parsing PKCS#11
URI escape sequences. An attacker could possibly use this issue to cause
NSS to crash, resulting in a denial of service, or obtain sensitive
information.
WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]
It was discovered that SQLite incorrectly handled certain memory operations
in the FTS5 full-text search extension. An attacker could use this issue to
cause SQLite to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Learn what a VPN passthrough is, how it works with older protocols, and why most modern networks no longer need to use it.
The ruling is a victory for election advocates who say the evidence overwhelmingly shows that voter fraud is rare and not tied to mail voting in general.
The post Supreme Court approves mail-in ballots that arrive after Election Day appeared first on CyberScoop.
You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled today in Chatrie v. United States.
The case involved geofence warrant...
La Cour administrative suprême de Pologne confirme que l'obligation de tester régulièrement les mesures de sécurité s'applique depuis le premier jour d'application du RGPD, et que la notification d'une violation de données ne constitue pas une circonstance atténuante pour le calcul de l'amende.Faits...
L'Autorité de protection des données (APD) belge a publié son rapport annuel pour 2025, détaillant les changements internes, les dossiers marquants et les statistiques clés de l'année.L'année 2025 a vu le renouvellement du Comité de direction de l'APD, entré en fonction le 29 avril 2025, et l'élabor...
Dissenting justices who criticized the ruling said it would have “seismic” implications for the Fourth Amendment.
The post Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling appeared first on CyberScoop.
L'autorité estonienne de protection des données (AKI) rappelle les différentes bases juridiques applicables au traitement des données personnelles des employés dans le cadre de la relation de travail.Certains traitements sont justifiés par la nécessité d'exécuter le contrat de travail, notamment pou...
L'autorité croate de protection des données (AZOP) a initié une procédure de contrôle d'office à l'encontre de CARNET suite à une divulgation non autorisée de données personnelles d'élèves et d'enseignants.Cette procédure fait suite à la publication non autorisée de données personnelles, notamment d...
Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. [...]
The World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S., along with the help of U.S. broadcaster NBC Universal and other entities.
L'autorité espagnole sanctionne un média pour avoir diffusé une vidéo d'une agression entre jeunes avec leurs voix non modifiées, considérant que la publication de cette donnée personnelle n'était pas nécessaire à la finalité d'information du public et violait ainsi le principe de minimisation des d...
L'autorité espagnole sanctionne une entreprise d'une amende de 76 800 € pour ne pas avoir répondu à ses demandes d'information, entravant ainsi ses pouvoirs d'enquête.Faits et contexteL'Agence Espagnole de Protection des Données (AEPD) a aujourd'hui publié une décision de sanction à l'encontre de AE...
A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure.
The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog.
The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links t...
WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform.
The optional feature is designed to help users connect with someone on the service through usernames, as opposed to di...
The Supreme Court's decision to limit geofence warrants is a win for privacy advocates, who called their use unconstitutional but sought an outright ban.
Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild.
The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world...