From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform. Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market. What we found A user in the UK […]
Read MoreA two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments. EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data […]
Read MoreChrome is rolling out an update for its desktop browser. The update includes 327 security fixes, ten of which address critical vulnerabilities. The stable channel has been updated to 152.0.7977.64/.65 for Windows and Mac, and 152.0.7977.64 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating is easy. […]
Read MoreThe vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers […]
Read MorePhishing pages don’t need to be sophisticated. They just need to look convincing enough to make you trust them. TikTok phishing often starts with an email or message designed to make you think you need to act on your account. It might claim your account has been suspended, reported, or hit with a copyright violation, […]
Read MoreSomeone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator. Take-Two Interactive, the publisher behind the […]
Read MoreA new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution. AI researchers describe “Cryptographic Context Injection”—an attack that hides malicious instructions inside encrypted data. The AI is then persuaded to decrypt that data using its own code-execution tool. As a result, the […]
Read MoreResearchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging […]
Read MoreAliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices. The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable […]
Read MoreThis week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out. As far back as 2007, Facebook was forced to reckon with mass grief when […]
Read More