After years of security failures and partner-spying marketing, pcTattletale’s founder has pleaded guilty in a rare US federal stalkerware case.

Linking your medical records to ChatGPT Health may give you personalized wellness answers, but it also comes with serious privacy implications.

Two actively exploited flaws—one brand new, one 16 years old—have been added to CISA’s KEV catalog, signaling urgent patching.

A smart toy doesn’t have to be a risky one. Lego’s Smart Bricks add sensors and sound without apps, accounts, or AI. We explain how it works.

We unpack a trojanized WinRAR download that was hiding the Winzipper malware behind a real installer.

The Crimson Collective claims to have stolen data on more than a million Brightspeed customers. The broadband provider is investigating.

Another well-crafted phishing campaign uses Google Cloud Integration Application infrastructure to bypass email filters.

The FTC is seeking a $10 million settlement over allegations that children’s privacy laws were violated through the mislabeling of kid-focused YouTube videos.

This week on the Lock and Code podcast, we speak with Will Freeman about Automated License Plate Reader (ALPR) surveillance.

Having generated content that may violate US child sexual abuse material laws, Grok highlights once again how ineffective AI guardrails can be.