AI chats have a bigger audience than you think
Sharing an AI conversation with “anyone who has the link” might sound reasonably private. Unfortunately, links have legs — and some shared Claude chats and AI-generated documents are now showing up in Google searches.
People have found conversations containing everything from medical information and internal company documents to names and phone numbers associated with children. The chats weren’t hacked; users intentionally created sharable links, apparently without realizing those links could ultimately become searchable.
Find out why your “private” AI conversation might not be quite so private — and what to check before you share another chat.
You need to update your Zoom app
If you use Zoom, now’s a good time to make sure it’s updated — as newly disclosed flaws could let meeting attendees run malicious code on another participant’s device.
The “Zoomsday” vulnerabilities exploit the way Zoom handles shared annotation data. An attacker first needs to gain access to a meeting — potentially through an open or leaked meeting link or via a compromised account — but from there, the flaws could be used to target other attendees. Zoom has patched the problems in newer versions.
Check your Zoom version and get the fix before your next meeting gives an uninvited guest more access than anyone bargained for.
Scammers are turning phones into card readers
A nasty combination of Android malware could let hackers use your physical credit card for purchases — without the card ever leaving your hand.
In one attack, a scammer posing as a bank employee convinced a victim to install a malicious app, tap their credit card against their phone, and enter their PIN. The malware relayed the card interaction to the scammer in real time — while another malicious tool gave the attacker enough access to take out a loan in the victim’s name.
See how this particularly nasty phone scam works — and why a bank asking you to install an app or tap your card against your phone should set off every alarm bell you have. (And remember, too: With any malware like this, you’re ultimately the one who has to allow it to happen.)
That smartwatch might let strangers track your kid
Researchers found flaws in some inexpensive GPS watches geared toward children that could let hackers track a child’s location, access their microphone or camera, and alter emergency contacts.
TikTok just took a $400 million hit over kids’ privacy
The company agreed to a massive settlement with the U.S. Justice Department over allegations around child privacy violations. It’s also agreed to strengthen age controls, parental oversight, and privacy protections for younger users.
Hackers are discovering the untapped power of middle management
Ransomware crews are increasingly targeting managers with access to budgets, invoices, and other valuable data — not just CEOs. Apparently, the really useful passwords live a few rungs down the org chart.
Someone’s figured out a way to steal passkeys, but that doesn’t mean you need to ditch them
A new attack can lift the credentials from certain Windows systems — but, critically, only after malware has already compromised the computer. At that point, you’ve got bigger problems.
Your private photos are becoming prime hacking targets
The FBI says criminals are breaking into online accounts specifically to steal intimate images, then use them for extortion, harassment, or humiliation.
Spyware may be after your iPhone
Apple sent another round of warnings to people potentially targeted by mercenary spyware — highly sophisticated surveillance software typically used by governments or private contractors to secretly monitor high-level targets.
A financial breach comes with some serious interest
Hackers stole personal and financial information belonging to more than 1.2 million people, including Social Security numbers, IDs, bank account numbers, and birth dates.
WhatsApp is making your account harder to hack
The messaging app is beefing up two-step verification, letting users create stronger passwords instead of relying on six-digit PINs, and adding support for multiple passkeys.
A healthcare breach just keeps getting worse
CareCloud reported that roughly 350,000 people were impacted by a breach in which hackers stole loads of sensitive data, but that number has now climbed to more than 3.7 million.
Hackers are pirouetting into customer data
English National Ballet says customer contact info was exposed after hackers breached its customer-relations provider. No passwords or payment details were leaked, but beware that convincing phishing emails could be coming.