Android AI Apps Leaked 730TB: 72% Had Hardcoded Secrets
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
Tag
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
A tier-by-tier comparison of the top open-weight LLMs you can run locally, from 8GB laptops to 24GB gaming GPUs to Apple Silicon Macs.
Step-by-step guide to running a private, local AI chatbot that rivals ChatGPT - no subscription, no data collection, no internet required.
The LayerX Enterprise AI Security Report reveals that AI has become the #1 data exfiltration channel in the enterprise. 82% of those leaking data use personal accounts. Traditional DLP can't stop copy-paste.
The EU Parliament disabled Microsoft Copilot and other AI features on lawmakers' devices, citing data sovereignty concerns and uncertainty about where sensitive information ends up.
A 3.35B parameter multilingual model outperforms larger competitors on underserved languages - and runs locally on consumer hardware. Privacy-first AI for the rest of the world.
Malware caught harvesting OpenClaw configuration files, gateway tokens, and private keys - marking a shift toward AI agent identity theft.
Tennessee made it a felony to train AI chatbots that encourage suicide. Virginia is banning AI therapist impersonators. A dozen states have bills moving through legislatures right now.
ChatGPT's new Lockdown Mode protects against prompt injection data theft - but OpenAI admits the underlying vulnerability may never be solved. Here's what that means for agentic AI.
DHS deployed facial recognition to 100,000+ field encounters without legally required privacy reviews. Internal records show the agency knew the app couldn't verify identities.
Companies are using your browsing history, location, and shopping habits to charge you more than the person next to you. California just launched an investigation. Here's how it works.
Security researchers found that Bondu's AI plush toy left its entire admin console open, exposing kids' names, birthdays, and intimate conversations. A senator wants answers.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
Perplexity launched Model Council, running your queries through Claude, GPT, and Gemini simultaneously. Multi-model consensus could reduce hallucinations, but it triples your data exposure and costs $200 a month.
A Firebase misconfiguration exposed 300 million messages from 25 million users. A wider scan found data leaks across 196 of 198 AI apps.
Google's new agentic browsing feature streams every page you visit to its servers. Here's what that means for your privacy.
European regulators charged Meta with antitrust violations for blocking competing AI chatbots from WhatsApp's 3 billion users - while Meta AI gets exclusive access to the platform.
OpenAI started showing ads in ChatGPT conversations on February 9. Ad personalization is on by default, targeting uses your conversation topics, and opting out may cost you message limits. The era of ad-funded AI is here.
Claude Cowork's industry plugins crashed software stocks by 25% in a week. But the real story is a known file-stealing vulnerability Anthropic shipped anyway, and safety guidance that contradicts its own marketing.
GLM-5, Kimi K2.5, Qwen 3.5, Doubao 2.0, and MiniMax M2.2 arrive in the most concentrated wave of Chinese AI releases. Some are open-source. Here's what matters.
Tiiny AI says its 300-gram Pocket Lab runs 120B models locally. The design is plausible, but performance and privacy claims remain unverified.
Apple's deal to power Siri with Google's Gemini raises questions about where your data actually goes -- especially as the two CEOs contradict each other.
A DOJ task force challenges state AI laws while the administration threatens broadband funding. The fight isn't between companies -- it's between governments.
Three deals in one week -- including a startup that detects emotions from your voice. Google is assembling capabilities that should make privacy advocates nervous.