Skip to main content

Tag: google

286 articles

Scientists gather around a futuristic workstation in a modern tech lab.

Tech Giants Unveil Advanced Cyber AI Models With Enhanced Safeguards

Google's Fairwind Program gives high-priority defenders, such as governments and healthcare providers, a critical edge in cybersecurity with early access to cutting-edge AI models that help them stay ahead of emerging threats. This proactive approach enables them to build stronger defenses and protect against new risks before they arise.

Analyst 207
Smartphone on a surface with blurred background and abstract web page on screen.

Android 17 Bolsters Privacy with OS-Wide Encrypted Client Hello Support

Android 17 just got a major boost to online privacy with OS-wide Encrypted Client Hello support, making it harder for snoops to see which websites you're visiting. This new standard teams up with private DNS to keep your browsing habits private, shielding the domain names you visit from prying eyes.

Analyst 207
Smartphone on a table with screen on, showing a blurred webpage in a minimalist room with soft daylight.

Android 17 Bolsters Browsing Privacy with ECH Support

Android 17 just got a major boost to browsing privacy with the addition of Encrypted Client Hello (ECH) support, which teams up with private DNS to keep your online activities under wraps by hiding the domain names you visit. This means you can say goodbye to being profiled by advertisers and hello to a more private browsing experience.

Analyst 207
Person using laptop outdoors in front of government or academic building.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns

Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

Analyst 207
Person sitting at a coffee shop table looks concerned while holding a smartphone, surrounded by blurred cafe patrons and a…

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts

Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

Analyst 207
Modern tech facility with blurred server infrastructure and unoccupied workstation.

AI API Flaw Exposes Secrets Across OpenAI, Anthropic, Google Models

A shocking security flaw in AI APIs has been uncovered, exposing sensitive secrets like API keys, passwords, and private keys across major models from OpenAI, Anthropic, and Google. Researchers decoded hundreds of thousands of "thinking" blocks, revealing a treasure trove of confidential data.

Analyst 207
Brightly-lit workspace with laptops and large windows, a single computer terminal on a clean desk in the foreground.

Agent Flaws in AWS, Google, Vercel Expose Tools to Forged Instructions

Critical flaws in AWS, Google, and Vercel's agent systems, dubbed CoreBreak, allow attackers to forge instructions by exploiting how tool calls are validated, potentially letting malicious data masquerade as authorized model commands. This vulnerability can be triggered even when the model hasn't run, posing a significant security risk.

Analyst 207
Professionals in business attire engaged in discussion around a conference table with laptops and notebooks.

US Wrestles with AI Safety as Models Break Free

As AI models continue to break free from their constraints, experts warn that traditional security measures are no match - even AWS Chief Security Officer Stephen Schmidt has a T-shirt that drives the point home. The White House is taking steps to address the issue, recently meeting with top AI labs to discuss voluntary guidelines for testing new models.

Analyst 207
Person sits at cluttered desk with laptop showing blurred chatbot conversation.

Google Exposes Anthropic's Claude Chats, Raising Privacy Concerns

A security researcher uncovered disturbing examples of sensitive data exposed through Anthropic's chatbot Claude, including private cryptocurrency wallet keys and personal info, despite the company's claims of prioritizing user privacy. This incident raises serious concerns about Claude's ability to safeguard user conversations.

Analyst 207
Cluttered developer workstation with GitHub repository on screen.

Google Disrupts AI Workflows Over GitHub Issue That Exposed Privileged Agent

Google just took a major step to protect its AI workflows after a security vulnerability was discovered in a public GitHub issue, allowing hackers to potentially manipulate its system. The issue was found in a workflow that automatically ran when a new issue was opened, using a privileged key to trigger a code-fixing agent.

Analyst 207
Cluttered home office desk with a laptop displaying a malware warning, surrounded by papers and everyday objects.

Malware Exploits Google Passkey Sync Flaws

Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Analyst 207
Laptop on a clean surface with a blank screen and coding materials nearby.

Google AI Dev Kit Exposes Supply Chain Vulnerability

Researchers at Pillar Security have uncovered a shocking vulnerability in the Google AI Dev Kit, exposing a supply chain weakness that could allow malicious AI agents to manipulate and wreak havoc on repository workflows. This game-changing exploit has already been downloaded over 90 million times, making it a potentially massive threat.

Analyst 207
A researcher's workspace with laptop, notes, and coding materials near a window with ambient daylight.

Google Leverages AI to Fix 1,072 Chrome Security Bugs

Google is supercharging Chrome's security with AI, and the results are staggering: a whopping 1,072 security bugs were squashed in Chrome 149 and 150, outpacing the total fixed in the previous 23 milestones combined. The tech giant is now using large language models to turbocharge its vulnerability management process, from sniffing out flaws to generating patches.

Analyst 207
Person working on laptop surrounded by threat intelligence screens and maps.

Google Unveils Unified Naming System for Hacker Groups

Say goodbye to memorization overload - Google's Threat Intelligence Group is shaking up threat tracking with a sleek, unified naming system for hacker groups, using simple two-word code names to make it easier to stay on top of cyber threats. This game-changing approach kicks off with dozens of high-priority groups and will keep expanding to make threat tracking a whole lot more intuitive.

Analyst 207
People work at desks in a neutral room, with a taxonomy chart displayed on a large screen in the foreground.

Google Unveils Cybercrime Taxonomy, Shakes Up Threat Naming Norms

Google is shaking up the world of cybercrime threat naming with a fresh approach, introducing a simple and streamlined taxonomy that's easy to map across different systems. The tech giant has teamed up with Mandiant to launch the Google Threat Intelligence Group, using a catchy two-word naming schema to identify cybercrime crews.

Analyst 207
Hand holding a smartphone with a blank screen on a neutral background.

Google Introduces Selfie-Based Account Recovery

Google just made account recovery a whole lot easier with its new selfie-based feature, allowing you to regain access to your account with a quick snap when other methods aren't an option. Simply record a short video on a device with a camera, and you're good to go!

Analyst 207
Smartphone screen prompts user to record selfie video on neutral background.

Google Introduces Selfie Video Sign-in for Locked Accounts

Say goodbye to account lockouts! Google's new selfie video sign-in feature lets you register a short video of yourself and use a fresh recording to regain access to your account if you get locked out.

Analyst 207
Researcher stands beside computer screen displaying code review interface in laboratory setting.

Google Unveils Gemini 3.5 Flash Cyber to Accelerate Vulnerability Detection

Meet Gemini 3.5 Flash Cyber, a game-changing AI model that supercharges vulnerability detection with lightning-fast speed and pinpoint accuracy. This lightweight powerhouse helps you discover, validate, and patch vulnerabilities quickly and efficiently, without breaking the bank.

Analyst 207
Smartphone on a neutral surface with blurred background and abstract screen pattern.

EU Orders Google to Open Android to Rival AI Assistants

Google is now required to open up Android to rival AI assistants, a move the company claims could compromise device security by giving external apps sensitive permissions. The European Commission's order, made under the Digital Markets Act, forces Google to grant third-party AI assistants access to Android sensors and system features.

Analyst 207
Hand reaches for Android smartphone with blurred lock screen on a flat surface.

Google scrambles to fix Android bug that lets Gemini bypass lock screen security

Google is racing to squash a newly discovered Android bug that allows sneaky users to bypass lock screen security and send SMS or WhatsApp messages using Gemini, all without entering the device PIN. A fix has already been implemented and is set to roll out this week.

Analyst 207
A laptop with a blank screen sits on a neutral surface, surrounded by development tools in a bright, clean tech lab setting.

Browser, Software Updates Fix Critical Flaws

Major tech players, including Adobe, Mozilla, Google, and Broadcom, have just rolled out critical security updates to fix dozens of vulnerabilities - and it's crucial to install them ASAP to avoid potential code execution and privilege escalation threats. Adobe alone is patching 88 flaws, including eight high-risk issues in ColdFusion that could lead to serious security breaches.

Analyst 207
Browser extension icon on a computer screen with a blurred history page in the background on a clean office workspace.

Google and Microsoft Remove ModHeader Extension Exposing Dormant Browsing History Collector

A shocking discovery was made about the popular ModHeader extension, used by 1.6 million Chrome and Edge users, which contained a hidden browsing history collector that thankfully remained dormant. Fortunately, both Google and Microsoft swiftly removed the extension from their stores after it was uncovered.

Analyst 207
A broken lock on a laptop screen amidst coding workspace symbolizes chatbot vulnerability.

Google Dialogflow Flaw Lets Rogue Agents Hijack Chatbots

A security flaw in Google Dialogflow, dubbed "Rogue Agent," allowed hackers to hijack chatbots, but thankfully, a fix was rolled out after Varonis reported the issue through Google's Vulnerability Reward Program. The flaw was cleverly exploited through custom Code Blocks in Dialogflow CX, highlighting the importance of robust security measures in chatbot development.

Analyst 207
Person holding smartphone with subtle phishing website in background, standing on city street.

Google Sues Chinese Scammers Over Gemini AI Misuse

Google is taking a stand against scammers, suing a group called Outsider Enterprise that uses its Gemini AI feature to create fake websites and scam people through text messages. The group, which operates on Telegram, offers phishing-as-a-service, making it easy for non-tech-savvy scammers to target victims.

Analyst 207