LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
security

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.

zeroday.news · 3h ago

California has launched a new state-run portal, the Delete Request and Opt-out Platform (DROP), enabling residents to submit a single request to all registered data brokers to delete their personal information and opt out of its sale. The platform was established under California’s Delete Act, which mandates that data brokers register with the California Privacy Protection Agency (CPPA) or face penalties. Over 600 data brokers are currently listed in the registry.

Data brokers gather and sell extensive personal information, including financial details, online behaviors, and location data, often without explicit consent. DROP aims to address privacy and transparency concerns by providing a centralized mechanism for residents to manage their data.

Starting August 1, 2026, registered data brokers in California will be required to access DROP and will have 90 days to delete a person’s records after receiving a request through the platform.

To use DROP, Californians must provide at least one reachable email address or mobile phone number for identity verification and request tracking. Users will also need to supply basic personal data, such as their name, address, and contact details, which brokers are likely to possess and which DROP uses to match records.

The process involves navigating to the DROP portal, accepting the terms and conditions, and verifying California residency. Residency can be confirmed by manually inputting personal information or by authenticating through Login.gov, a federal identity verification service. If residency verification fails, users can request a review of their eligibility.

After successful residency verification, users create a deletion request by providing contact details and basic personal information. Upon submission, a unique DROP ID is issued, allowing users to track the status of their request online. A dedicated help site is available for assistance.

While California is currently the only state offering a centralized platform like DROP, other states such as Oregon, Texas, and Vermont also require data broker registration. Residents in these states can consult their attorney general’s website or privacy office for data broker registries and opt-out guidance, typically requiring direct requests to each broker.

For individuals outside of California, reducing data broker collection and sale of personal data generally involves more manual effort. This includes identifying brokers through privacy advocacy groups and submitting individual deletion and opt-out requests via web forms, email, or postal mail. When making such requests, it is advisable to provide only necessary information to match records (e.g., name, address, email, phone) and avoid oversharing sensitive data. Maintaining a spreadsheet to track requests, dates, and confirmations is also recommended, as most privacy laws specify response deadlines, often 30-45 days.

To minimize future data collection by brokers, strategies include using multiple email addresses, reserving one for critical accounts and using aliases or disposable emails for less sensitive interactions. Employing a VPN can encrypt internet traffic and mask IP addresses, making it harder for websites and analytics firms to link activity to a stable, location-based identifier. Additionally, for non-critical services, it is advisable to avoid providing full legal names, exact home addresses, or phone numbers if they are not strictly necessary, particularly for rewards and loyalty programs.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

The AI Act kicks into action, forces companies to be clear about AI chatbots

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.

ai

New Tool Traces AI Videos Back to Their Source

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

vulnerability

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

ai

AI slop pollutes the CVE pipeline with fake vulns

With NIST still buried under its backlog, expect AI-generated bogus reports to continue