A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market.
36-year-old Michele Spagnuolo, an Italian citizen residing in Switzerland and a Google employee since 2014, appeared on Wednesday in the Southern District of New York.
In parallel, the Commodity Futures Trading Commission (CFTC) filed a separate civil complaint the same day, seeking restitution, disgorgement, civil monetary penalties, and trading and registration bans.
It should feel dated by now. It doesn’t. It feels like a prophecy.
Back in 2013, Dr. Ann Cavoukian sat down with me as the Information and Privacy Commissioner of Ontario and the mind behind Privacy by Design. She told me privacy was not dead. She told me security and freedom were not a trade-off. She told me metadata reveals more about you than the content ever could.
Then she said something I have never been able to shake:
“We have to protect privacy globally, or we protect it nowhere.”
Think about where we are now. Surveillance is the business model. Your data trains systems you will never see. The “nothing to hide” crowd got louder, and the borders she warned about got thinner. She saw all of it coming.
Engineers at the University of California San Diego have developed an optical device that reveals hidden images and changes colors in response to different levels of humidity. The technology, published in Light: Science & Applications, could lead to the development of new anti-counterfeiting labels, secure data storage, interactive displays, and environmental sensors.
The device works by displaying different images depending on moisture levels in the air. Under normal conditions or low humidity levels, one image (UC San Diego Triton logo) is visible. When humidity increases, a second image (UC San Diego library logo) emerges and conceals the first. This transition can be triggered even when a person breathes on the device. It happens in a fraction of a second and can be repeated many times.
“You can imagine using this as a built-in security feature with the environment acting like a key that unlocks different pieces of information,” said study first author Asad Nauman, an electrical and computer engineering postdoctoral researcher at UC San Diego. “One example would be something like a credit card security tag, where you can blow on it and reveal a hidden code. Another application would be an environmental sensor that changes color as the humidity changes.”
Anthropic appears to be preparing for the public rollout of “Mythos,” which was announced in April as a restricted model that poses major security risks to private and public software.
On April 7, Anthropic announced the Mythos in early preview and called it a new frontier model with strikingly advanced capabilities in computer security tasks.
Anthropic said the Mythos model shows major improvements in code reasoning and autonomy, far above its current flagship model, Opus 4.7.
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device.
The flaw was reported by security researcher Lyra Rebane and acknowledged as valid in December 2022, as per the thread on Chromium Issue Tracker.
An attacker could exploit the problem to create a malicious webpage with a Service Worker, such as a download task, that never terminates. Rebane says that this could allow an attacker to execute JavaScript code on the visitors’ devices.
Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure.
The vulnerability, now tracked as CVE-2026–9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is used in Drupal Core to validate queries and ensure they are sanitized against SQL injection attacks.
“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases,” it said. “This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.”