Data Privacy + Cybersecurity Insider
CYBERSECURITY
WhatsApp Patches Vulnerability That Facilitates Remote Code Execution
WhatsApp users should update the application for vulnerability CVE-2025-30401, which Meta recently patched when WhatsApp was released for Windows version 2.2450.6. Read more
ENFORCEMENT + LITIGATION
The FTC BOTS Act – Leveling the Ticketing Field
On March 31, 2025, President Trump signed an executive order (EO 14254) titled “Combating Unfair Practices in the Live Entertainment Market.” EO 14254 directs the Federal Trade Commission (FTC) to, amongst other provisions, rigorously enforce the Better Online Ticket Sales Act (BOTS Act or the Act) and address unfair ticket scalping practices. Read more
DATA PRIVACY
Yahoo ConnectID Faces Class Action Over Email Address Tracking as Alleged Wiretap Violation
Yahoo’s ConnectID is a cookieless identity solution that allows advertisers and publishers to personalize, measure, and perform ad campaigns by leveraging first-party data and 1-to-1 consumer relationships. ConnectID uses consumer email addresses (instead of third-party tracking cookies) to produce and monetize consumer data. A lawsuit filed in the U.S. District Court for the Southern District of New York says that this use and monetization is occurring without consumer consent. The complaint alleges that ConnectID allows user-level tracking across websites by utilizing the individual’s email address—i.e., ConnectID tracks the users via their email addresses without consent. The complaint further alleges that this tracking allows Yahoo to create consumer profiles with its “existing analytics, advertising, and AI products” and to collect user information even if a user isn’t a subscriber to a Yahoo product. Read more
Stall on Automated Decision-Making Technology Rules from the California Privacy Protection Agency
This week, the California Privacy Protection Agency (CPPA) board held its April meeting to discuss the latest set of proposed regulations, including automated decision-making technology (ADMT) regulations. Instead of finalizing these rules, the board continued its debate and considered further amendments to the draft regulations. Notably, some members proposed changing the definition of ADMT and removing behavioral advertising from ADMT and risk assessment requirements. The board also directed the CPPA to remove a selection of categories in scope for provisions covering significant decisions. The board conditionally approved these changes, but the final (we think) vote will occur at the next meeting. Read more
PRIVACY TIP #439
Government Officials’ Venmo Accounts Publicly Accessible
Wired has reported that several government officials involved in the Signal chat exposing sensitive national security plans have also exposed their Venmo accounts by not adjusting their account privacy settings to prohibit the information from being publicly accessible. This means that they “left not only their contact lists publicly visible but also their transactions, which are as recent as last autumn. These records reveal specific information” about who they paid, how much they paid, the date of the payment, and the reason for the payment. Not only is this quite concerning for national security, but it’s a reminder to be aware of privacy settings in all applications, including Venmo. Read more



