A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.

Google has begun implementing a new account recovery option that utilizes "selfie video" verification, allowing users to regain access to their accounts by submitting a video of their face. This feature is presented as an alternative for users who have lost their phone or forgotten their password.
To set up the feature, users navigate to the Security & sign-in section of their Google Account, select "Selfie video," and follow prompts to record a short video of their face and basic movements. This initial video is then stored by Google and used for comparison against subsequent videos submitted during sign-in or account recovery attempts.
While Google states that these videos are encrypted at rest, stored securely, and can be deleted through security settings, the introduction of this biometric data collection raises several security and privacy concerns. Users can reportedly opt out of allowing their video data to be used for improving Google's verification systems, implying that without opting out, the data may be used for this purpose. Google also asserts that the videos are not shared with third parties.
Critics of the feature highlight the inherent risks associated with using facial biometrics for high-privilege account recovery. Facial recognition systems, even top-tier ones, are not infallible, with evaluations by the US National Institute of Standards and Technology (NIST) indicating non-zero false positives and negatives, and performance degradation under varying conditions like lighting or camera quality. These systems do not store literal images but rather mathematical representations of facial features, which are then compared against new inputs.
The evolving sophistication of deepfake technology is another major concern. Research has shown that advanced deepfake attacks can achieve high success rates against some commercial facial verification systems in controlled environments, demonstrating the potential for such systems to be bypassed.
From a privacy standpoint, the collection of high-fidelity video recordings of users' faces and head movements for basic account management is seen as a significant long-term risk. Even with current privacy assurances regarding encryption, storage, and non-sharing, privacy policies and data usage practices can change over time. The mere existence of such a repository of sensitive biometric data makes it a potential target for data breaches.
Security experts advise against enabling this feature. Instead, they recommend using robust security practices such as strong, unique passwords managed by a password manager, enabling two-step verification with hardware security keys or passkeys (rather than SMS codes), maintaining secure offline backup codes, and regularly reviewing and updating recovery email addresses and phone numbers.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a