Privacy
-
New AI Vulnerability Discovered in Microsoft 365 Copilot: ‘EchoLeak’
A new zero-click vulnerability known as ‘EchoLeak’ has been discovered in Microsoft 365 Copilot, enabling attackers to exfiltrate sensitive data without user interaction. While Microsoft has patched the flaw, experts advise businesses to enhance their cybersecurity measures to prevent future exploits.
-
Coordinated Cyber Attacks Target Tomcat Manager Interfaces
GreyNoise has warned of a surge in coordinated brute-force attacks targeting Apache Tomcat Manager interfaces, involving 295 unique malicious IP addresses. As attackers seek to exploit these vulnerabilities, experts recommend strengthening security measures to protect against unauthorized access.
-
Security Researchers Expose 40,000 Unprotected IoT Cameras, Raising Espionage Concerns
Researchers from Bitsight have exposed serious vulnerabilities in the security of around 40,000 internet-connected cameras globally, raising concerns over espionage and privacy for sensitive locations across the United States.
-
Texas Department of Transportation Reports Data Breach Affecting 300,000 Individuals
The Texas Department of Transportation has reported a data breach affecting approximately 300,000 individuals, with sensitive crash record information accessed by unauthorized actors on May 12, 2025.
-
Google Addresses Vulnerability Exposing Users’ Phone Numbers
A vulnerability in Google’s account recovery process allowed researchers to brute-force phone numbers linked to accounts, posing a significant risk of phishing and SIM-swapping attacks, now patched by the tech firm.
-
EU Launches DNS4EU to Enhance Digital Sovereignty and Security
The European Union has introduced DNS4EU, a privacy-focused DNS resolution service aimed at enhancing digital sovereignty and security across Europe. This new initiative offers a viable alternative to existing non-European DNS providers and emphasizes user privacy and local regulations.
-
Data Leak Exposes Personal Information of Over 3.6 Million Users
A recent data breach has exposed the personal information of over 3.6 million users associated with the app-building platform Passion.io, raising serious privacy and security concerns. Cybersecurity expert Jeremiah Fowler discovered the unsecured database containing sensitive data, prompting immediate action from the company.
-
Security Risks Emerge from Popular Chrome Extensions Transmitting User Data in Plaintext
Prominent Chrome extensions are under scrutiny as security experts highlight that several have been found transmitting sensitive data unencrypted over HTTP, raising significant privacy concerns. Users are urged to reconsider using these extensions until developers address security flaws.
-
Germany Imposes €45 Million Fine on Vodafone for Privacy Violations
Germany’s BfDI has fined Vodafone GmbH €45 million for privacy breaches linked to fraudulent contracts and security vulnerabilities, prompting the telecom giant to enhance its operational procedures and commit to future data protection efforts.









