:

VENMO DEFAULTS TO PRIVATE POSTS IN PRIVACY OVERHAUL

SECURITY DESK1 MIN READ
MON, MAY 11, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Venmo is testing a major app redesign that will make new user posts private by default, marking a significant shift for the payment platform that previously exposed transaction data publicly.

The change sets new account holders' posts to be viewable only by friends rather than the general public. This addresses long-standing privacy concerns that have plagued the platform. In 2021, BuzzFeed News demonstrated the vulnerability by locating President Joe Biden's Venmo account and those of his associates through the app's public transaction feed. The incident exposed how Venmo's default settings made sensitive financial activity visible to anyone. Venmo users have historically been able to adjust privacy settings manually, but most relied on defaults. The redesign aims to reverse this by prioritizing privacy from the start. The new default represents a recognition that public transaction posting poses genuine security and privacy risks. The feature is currently in testing, with broader rollout expected pending the app redesign's completion. The update also reflects broader industry pressure on social platforms to strengthen privacy protections and reconsider data exposure policies.

■ SOURCES

The VergeEngadget

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

MAY 29Industry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

MAY 29Security Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

MAY 29Industry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

MAY 29Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.