Spotify's Android app hides passkey setup code, surfacing months after a public tracker named it among major apps still missing passkey login.
Google's Agentic Defense pairs Gemini AI with its $32 billion Wiz deal, but its own 2026 Mandiant report blames human error for most 2025 breaches.
Brussels ordered Google to open Android to rival AI assistants, but the same rule forces enterprise security teams to rebuild a decade-old permission model.
India switched on a White Rabbit time network in Bengaluru to cut GPS dependence for markets, telecom and power grids amid a global jamming surge.
Hackers are exploiting a critical Gitea Docker authentication bypass, CVE-2026-20896, just weeks after Gitea patched it, leaving repositories exposed.
A Moroccan intelligence whistleblower says the DGST used Pegasus spyware since 2017 to target journalists, Spanish ministers and Guardia Civil officers.
xAI open-sourced Grok Build after a researcher found it uploading full Git repos, but the exfiltration code still sits in the binary.
A former Moroccan intelligence officer has confirmed Rabat's long-denied use of Pegasus spyware, revealing a wider arsenal used against journalists.
Block's $45 million settlement with 46 states pays state governments, not individual Cash App users, unlike a separate CFPB fund already mailing checks.
Jamf Threat Labs says CrashStealer malware used a notarized Apple developer ID to bypass Gatekeeper and steal Mac passwords and crypto wallets.