Researchers found that Google API keys long treated as harmless can now unlock access to Gemini.

Disguised as a security check, this fake Google alert uses browser permissions to harvest contacts, location data, and more.

Attackers don’t always need custom malware. Sometimes they just need a trusted brand and a legitimate tool.

APT stands for Advanced Persistent Threat. But what does that actually mean, and how does it translate into the kind of threat you’re facing?

A third-party breach at Conduent now affects 25 million Americans—many never knew their data flowed through its systems.

Unsealed court records reveal Instagram executives discussed explicit messages to teens years before a blur feature was introduced.

A developer created an Android app that looks for nearby smart glasses. It’s not perfect, but it can help people in certian circumstances.

Ofcom and the Information Commissioner’s Office respectively fined a US porn company and Reddit for failing to protect children online.

Los Angeles County sued the online gaming platform Roblox for its alleged failure to protect children from danger.

A fake Zoom meeting page looks real, triggers a bogus “update,” and silently installs a legitimate commercial monitoring product.