Researchers have found that attackers are abusing OAuth to send users from legitimate Microsoft or Google login pages to phishing sites or malware downloads.

A list of topics we covered in the week of February 23 to March 1 of 2026

Researchers found that Google API keys long treated as harmless can now unlock access to Gemini.

This week on the Lock and Code podcast, we revisit an episode from 2025 in which we tried to answer: Is your phone listening to you?

Google’s Project Zero team found that WhatsApp can download a malicious media file without you doing anything at all.

This week on the Lock and Code podcast, host David Ruiz explains why he’s leaving behind Google Search… and what he’s replacing it with.

Google-owned AdMob allegedly collected kids’ data for ads without parental consent—including IP addresses, usage data, and exact locations.

This week on the Lock and Code podcast, we speak with Cory Doctorow about enshittification and its dangerous impact online and off.

Another well-crafted phishing campaign uses Google Cloud Integration Application infrastructure to bypass email filters.

Google will discontinue its dark web report early next year, prompting mixed reactions. How does dark web monitoring actually help keep you safe?