VPN, privacy and cybersecurity news
Source-backed reporting on VPNs, privacy, scams, data breaches and online security—plus the practical steps worth taking next.
Latest reports
More from the newsroom
Clear summaries, visible dates and direct source links—without turning every security story into a VPN sales pitch.

Two Exploited Windows Flaws Make September Updates Urgent
CISA added two Windows privilege-escalation flaws to its Known Exploited Vulnerabilities catalog on 8 September. Home users and organisations should install Microsoft's current security updates rather than assume antivirus or a VPN closes the holes.
Read analysis
NCSC Warns That Shadow AI Can Expose Workplace Data
The UK's National Cyber Security Centre says staff using AI services outside approved company systems can weaken data control and create security blind spots. Its advice is to understand why people use the tools and provide safer alternatives, not pretend the behaviour can be banned away.
Read analysis
LG TV Research Raises Microphone and Network Privacy Concerns
Researchers testing several LG television models reported local-network discovery, viewing-data collection and security weaknesses that could increase the impact of a compromise. Some vulnerability details remain under responsible disclosure, so owners should update and narrow what the TV can reach.
Read analysis
Fake Copyright Claims Trigger Instagram Ransom Demands
Creators told the BBC that bogus copyright complaints are being used to suspend Instagram accounts before the claimants demand money to withdraw them. The scam exploits platform enforcement rather than stealing a password first.
Read analysis
BigBear Phishing Steals Microsoft 365 Sessions After MFA
CloudSEK says a live phishing-as-a-service operation used reverse-proxy pages to capture Microsoft 365 passwords and authenticated session cookies. Ordinary one-time-code or push MFA may not stop this kind of adversary-in-the-middle attack.
Read analysis
UK Gambling Sites Accused of Widespread Cookie-Consent Failures
A Swansea University study of 624 licensed British gambling websites found that 86% appeared to breach at least one GDPR requirement. The findings focus on tracking before consent, missing rejection choices and designs that steer visitors towards sharing more data.
Read analysis
Mathspace Data Breach Affects More Than One Million Users
Mathspace says attackers exploited an unpatched vulnerability in its self-hosted reporting software and downloaded account information belonging to 1,079,819 students, staff and parents or guardians in Australia and New Zealand.
Read analysis
Doda Orders a Two-Month Ban on VPN Use
An order dated 5 September prohibits VPN use across Doda district in Jammu and Kashmir for two months, according to Indian news reports. It covers individuals, institutions, cyber cafes, businesses and internet providers unless officially authorised.
Read analysis
Mullvad Is Closing Its Public Encrypted DNS Service
Mullvad will switch off the encrypted DNS servers it offers to the wider public on 2 November and sponsor the nonprofit Quad9 service instead. Most Mullvad VPN customers are unaffected, but manual DNS users need to change their settings.
Read analysis