Zack Whittaker

Zack Whittaker

Zack is the author of ~this week in security~.
11
Jan
'26

this week in security — january 11 2026 edition

pcTattletale founder guilty, hackers breach New Zealanders' health data, Iran cuts off internet amid protests, Instagram data leak, Flock security lapse, and more.
9 min read
08
Jan
'26

ClickFix attacks are increasingly devious, dangerous, and can hack you in an instant

These attacks spoof Windows errors, CAPTCHAs, and real login pages to trick victims into hacking themselves with malware that skirts common cyber defenses.
11 min read
a screenshot of a blue-screen-style windows error, which is actually a ClickFix attack. the text has been slightly blurred for effect.
04
Jan
'26

this week in security — january 4 2026 edition

MongoBleed bug exploited globally, U.S. lifts sanctions on spyware executives, calls for digital independence from Silicon Valley, Kimwolf's huge botnet, and more.
9 min read
21
Dec
'25

this week in security — december 21 2025 edition

Mixpanel breach spreads to Pornhub; new Cisco zero-day under attack; French and U.K. governments hacked; TV makers sued for taking screenshots; and more.
10 min read
20
Dec
'25

Faced threats as a security researcher or journalist? Take our survey

Are you a security researcher or journalist? Working in partnership, this week in security and DataBreaches.net want to hear from you about your experiences facing or receiving legal demands and criminal threats as part of your research or reporting. We hope to learn more about how threats affect cybersecurity research and the journalism process.

Responses can be anonymous. Please take our survey (and please share!)

1 min read
19
Dec
'25

Apple nuking a customer's account over a bad gift card is a warning for everyone

One long-time Apple customer was left with no recourse after a bad gift card triggered a full account and device lock-out.
2 min read
a photo of an Apple MacBook's computer screen closer-up, displaying the dock on its desktop, in a slightly blue tinted light
14
Dec
'25

this week in security — december 14 2025 edition

U.S. wants travelers to submit social media history; Petco's lapses exposed data; tech giants patch zero-days; Coupang CEO resigns after breach; and more
10 min read
12
Dec
'25

Last-minute cybersecurity and privacy gifts your friends and family won't hate

Running out of gift ideas for the security or privacy buff in your life? Here are some thoughtful suggestions, including what tech you might want to avoid.
10 min read
Photo of a programmer's laptop with a red-backlit keyboard, with many energy drinks and holiday twinkly lights, in a darkened room.
07
Dec
'25

this week in security — december 7 2025 edition

India scraps mandatory phone app, Coupang breach rocks South Korea, critical React and Next.js bug under attack, Brickstorm malware warning, and more.
10 min read
06
Dec
'25

I've investigated 'stalkerware' for five years. Here's what I've learned

Stalkerware is a pervasive surveillance used by millions around the world, but these operations keep getting hacked and leaking victims' private phone data.
11 min read
a screenshot showing a Riverside film studio setup, with Zack Whittaker on the left and documentary journalist Daisy Maskell on the right.
30
Nov
'25

this week in security — november 30 2025 edition

Prolific hacker outed as Jordanian teen, Shai-Halud worm hacks thousands of devs, FCC warns of emergency alert hijacks, Mixpanel breach hits OpenAI, and more.
9 min read
26
Nov
'25

Banning TP-Link won't save America from its own terrible cybersecurity

TP-Link routers face a ban in the U.S. over the company's alleged links to China, but shoddy cybersecurity is the real insider threat to the United States.
6 min read
a photo of the back of a TP-Link wireless router