Trust

Keeping your account safe

Your account has no password. Your sign-in links are the key to it, so treat each one like a password you only use once.

How signing in works

When you sign in, we email you a link. Opening it signs you in on that device. Each link works once and expires 15 minutes after we send it. You stay signed in for up to 30 days of inactivity, and never longer than 90 days in a row. After that, we send you a new link.

Never share a sign-in link

Anyone who has your sign-in link can sign in to your account. The link itself is the proof that it's you, so:

  • Don't forward the sign-in email to anyone, including colleagues or IT support.
  • Don't paste the link into a chat, ticket, forum or AI assistant.
  • Don't share a screenshot that shows the link, or the address bar while it is open.
  • Open it yourself, on the device where you want to be signed in.

We will never ask you for a sign-in link, by email, phone, chat or social media. Anyone who asks for one is trying to take over your account.

Spotting fake emails

  • Our emails come from alerts@cybersecuritynews.us, and their links go to cybersecuritynews.us. Check the full address. Look-alike domains are a common trick.
  • We never ask for a password, payment details or personal information by email.
  • Got a sign-in email you didn't ask for? Ignore it. Nobody can sign in without opening that link. If it keeps happening, tell us.
  • Not sure if an email is real? Don't click it. Type cybersecuritynews.us into your browser and request a new link from there.

If something went wrong

If you shared a sign-in link by mistake, lost a device, or see activity you don't recognize, go to your account and choose Sign out of all devices. Every session ends immediately and any unused sign-in links stop working. Then request a fresh link for yourself.

Protect your email account

Whoever can read your email can sign in here. Use a strong, unique password and two-step verification (an authenticator app or a security key) on your email account.

API keys

If you use our Data API, your API keys are secrets too. Keep them out of code repositories, browser code and shared documents. Store them in a secrets manager or environment variable. If a key might have leaked, rotate or revoke it in the developer dashboard straight away.

Report a security problem

Suspicious emails that claim to be from us, a sign-in you didn't make, or a vulnerability in this site: email security@cybersecuritynews.us. We read every report.