LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
cloud

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million

The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.

zeroday.news ·

Grindr, the LGBTQ+ dating application, has agreed to a settlement of £26 million, equivalent to approximately $35.2 million, to resolve a UK lawsuit. The legal action alleged that the company shared sensitive user data, including HIV statuses, with advertisers.

The settlement was formalized in a regulatory filing with the Securities and Exchange Commission (SEC) on September 4, indicating that the payment will be made in two installments. The first payment is due by the end of December, with the second scheduled for the end of March.

The lawsuit, initiated by UK users in April 2024, claimed violations of the country's privacy laws. The alleged data sharing incidents occurred before early 2020, during a period when Grindr was under the ownership and management of a Chinese company, Kuntun.

While Grindr maintains that the settlement includes no findings or admission of liability, the company acknowledged in its SEC filing "the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period." The company spokesperson declined further comment, directing inquiries to the regulatory filing.

According to the filing, Grindr has "overhauled its privacy program with a keen focus on the unique needs of its community" since new ownership took over in 2020. The company stated it "is and remains a safe space for users, committed to transparency, user control, and responsible data practices."

In May 2024, Kelly Peterson Miranda, then Grindr's chief privacy officer, refuted the lawsuit's central claims. She stated that the company never sold health information, specifically HIV last-tested dates, for advertising purposes. She clarified that health-related information was never used for advertising.

Peterson Miranda explained that the information was shared with two service providers to facilitate the development of a new feature. This feature allowed users to include their HIV status in a dedicated profile field. She emphasized that the sharing was not a breach and was not done unknowingly, but rather in encrypted formats for the purpose of rolling out and monitoring the feature.

The lawsuit reportedly involved approximately 12,000 class members.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.