Security

Hackers can exploit thousands of exposed Google API keys to access Gemini and steal data

Websites leak Google API keys. Apps leak Google API keys. Even code repositories are full of them. What used to be a nuisance is now letting attackers access your Gemini and sensitive data, security researchers warn.
Read more about Hackers can exploit thousands of exposed Google API keys to access Gemini and steal data

Chinese disinformation campaign targets Japan’s election and Donald Trump

In the days surrounding Japanese Prime Minister Sanae Takaichi's February election win, several dozen X accounts linked to a Chinese misinformation campaign attacked her deeply conservative views and hawkish approach to China, said a US research institute focused on national security and foreign policy.
Read more about Chinese disinformation campaign targets Japan’s election and Donald Trump

Former cybersecurity executive sentenced to 87 months in prison for selling zero-day exploits to Russia

Peter Williams, a former General Manager of US government defense contractor L3Harris’ cyber division Trenchant, has been sentenced to 87 months in prison for selling sensitive and protected zero-day exploits to a Russian cyber-tools broker.
Read more about Former cybersecurity executive sentenced to 87 months in prison for selling zero-day exploits to Russia

Massive Cisco flaw puts corporate networks at risk: CISA issues emergency order

Cisco has disclosed a maximum-severity zero-day vulnerability affecting its core network software, which threat actors have been exploiting since 2023. The US cyber authority CISA issued an emergency directive, urging agencies to secure their systems and report any unusual activity.
Read more about Massive Cisco flaw puts corporate networks at risk: CISA issues emergency order

Trump orders US diplomats to "counter unnecessarily burdensome regulations" and fight foreign data sovereignty laws

President Donald Trump's administration has ordered US diplomats to lobby against attempts to regulate US tech companies' handling of foreigners' data, saying in an internal diplomatic cable seen by Reuters that such efforts could interfere with artificial intelligence-related services.
Read more about Trump orders US diplomats to "counter unnecessarily burdensome regulations" and fight foreign data sovereignty laws

Cyberattack keeps University of Mississippi Medical Center offline through Friday

The University of Mississippi Medical Center (UMMC) will remain offline through at least Friday – and possibly longer – as a ransomware attack that has crippled seven hospitals and 35 clinics leaves patients struggling to reach care. Experts warn recovery could stretch for weeks., if not months.
Read more about Cyberattack keeps University of Mississippi Medical Center offline through Friday

Malicious NPM package racks up 50,000 infections in days, developers fully compromised

Security researchers are warning developers about a malicious npm package that mimics the popular JavaScript framework, Ember.js. In a few days, it was downloaded nearly 50,000 times, leading to complete system compromise for affected developers.
Read more about Malicious NPM package racks up 50,000 infections in days, developers fully compromised

One-click disaster: Microsoft’s Entra tokens can grant access to corporate emails, and that’s a problem

A single click could grant third-party apps permanent access to corporate email accounts without a password, putting organizations at risk of attacks.
Read more about One-click disaster: Microsoft’s Entra tokens can grant access to corporate emails, and that’s a problem

"We were breached, but the data’s gone:" Wynn Resorts attack sparks more questions than answers

Wynn Resorts has admitted a breach of its employee data, but says that the attackers deleted it. Does it mean that ShinyHunters just got paid?
Read more about "We were breached, but the data’s gone:" Wynn Resorts attack sparks more questions than answers

Google slays China's hacker dragons: state-linked spies disrupted

Google disrupted a Chinese-linked hacking group that breached at least 53 organizations across 42 countries, the company said Wednesday.
Read more about Google slays China's hacker dragons: state-linked spies disrupted

Gamers’ credit cards at risk after popular RPG Dungeon Crusher exposes data

A hit RPG game has accidentally exposed something far more valuable than loot. A misconfiguration in the game’s infrastructure left players’ purchase data accessible to anyone on the internet.
Read more about Gamers’ credit cards at risk after popular RPG Dungeon Crusher exposes data

“That’s on us:” Discord admits mistakes and hits pause after age verification fiasco

Following widespread backlash, Discord has admitted mistakes in its controversial age verification rollout and is delaying global expansion to the second half of 2026. Forced by regulations, Discord now plans to offer “multiple verification vendors,” passing on the choice to users.
Read more about “That’s on us:” Discord admits mistakes and hits pause after age verification fiasco

Cyber pros find vulnerability in Samsung Tizen OS

A vulnerability found in Samsung Tizen OS could allow users of Samsung smart TVs running that particular operating system to execute arbitrary code at an OS level on the devices, researchers say.
Read more about Cyber pros find vulnerability in Samsung Tizen OS

ShinyHunters leak 12.4M CarGurus records after ransom threat

The ShinyHunters extortion gang has released the personal records of 12.4 million CarGurus account holders – following what appears to be a failed ransom demand tied to a February 13th breach of the digital auto dealer.
Read more about ShinyHunters leak 12.4M CarGurus records after ransom threat

Ashley Madison pivots to shake cyberattack ghost, promises privacy this time

This once disgraced dating site sheds its scandalous branding in favour of privacy.
Read more about Ashley Madison pivots to shake cyberattack ghost, promises privacy this time

Hackers’ fake Zoom update drops same workforce analytics tool your boss uses – Malwarebytes report

Hackers can trick Windows users into joining fake Zoom meetings, downloading fake updates that silently install workforce analytics software used by companies to monitor staff activities, according to Malwarebytes. The security firm says it observed malicious activity attempts in the wild: not a single antivirus program flags it, while hackers can gain broad visibility.
Read more about Hackers’ fake Zoom update drops same workforce analytics tool your boss uses – Malwarebytes report

Is Verizon first among equals? New York exempts the company and other telecoms from following cybersecurity rules

Telecom companies, including Verizon and Optimum, have successfully pushed New York state regulators to exclude them from new cybersecurity rules. Experts are raising red flags, warning that this will leave the state unable to monitor and ensure the security of sensitive customer information. But how did the tech giants pull this off?
Read more about Is Verizon first among equals? New York exempts the company and other telecoms from following cybersecurity rules

Researchers reveal Russian hackers hijacked digital highways to "steal funds" from logistics giants

A Russian phishing crew hijacked the digital highways of US and EU logistics giants, exploiting trucking logins to steal funds. The investigation uncovered a well-organized crime infrastructure.
Read more about Researchers reveal Russian hackers hijacked digital highways to "steal funds" from logistics giants

Anthropic’s security tool made investors panic, but the cybersec industry should keep calm

Investors overreact every time a new AI tool or feature is announced these days. Last week was no different: when Anthropic launched Claude Code Security, a tool capable of autonomously finding and patching vulnerabilities, shares of elite cybersecurity companies plummeted in a flash. But is the risk of AI agents cannibalizing the market even real?
Read more about Anthropic’s security tool made investors panic, but the cybersec industry should keep calm

Scammers have the advantage: no one can reliably detect AI faces, study finds

Some people are just better at recognizing AI-generated faces, but even they fail 43% of the time, a new study has found. Synthetic faces can often be recognized because they “appear more human than real ones,” but no one can reliably predict.
Read more about Scammers have the advantage: no one can reliably detect AI faces, study finds