Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices
Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.
Google Chrome Updates Resolve 1,442 Security Flaws
Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.
Google AI Agent Uncovers 13-Year-Old Chrome Flaw
Google's AI agent harness identified a 13-year-old flaw in Chrome's codebase, highlighting AI's role in vulnerability research and Google's patching efforts.
AI-Powered Vulnerability Research: Google Patches 1,000+ Chrome Bugs
Google utilizes Big Sleep AI to identify and remediate over 1,000 security vulnerabilities in Chrome releases, signaling a shift in automated bug hunting.
Google Unified Threat Actor Naming: TAG and Mandiant Convergence
Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Google Threat Intel Adopts Unified Cryptonym Naming for Actors
Google Threat Intelligence Group (GTIG) rolls out a new two-word cryptonym-based naming schema for threat actors, standardizing tracking across platforms for enhanced…
Google Fined €890M: Evaluating Digital Markets Act Compliance Risks
Google faces a $1 billion EU fine for Digital Markets Act breaches. This report analyzes the technical compliance risks for search engines and app stores.
Google Gemini 3.5 Flash Cyber AI: Advanced Vulnerability Management
Google launches Gemini 3.5 Flash Cyber, a specialized AI for rapid vulnerability discovery, validation, and patching, available to governments via CodeMender.
Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control
Russian-speaking actor bandcampro utilized Google Gemini CLI to automate botnet control and password cracking across compromised dental healthcare systems.
Google Cloud Agentic Defense: Automating AI-Driven Security Response
Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.
EU Orders Android 18 to Open AI Hardware Access to Rivals
The EU orders Google to grant rival AI assistants deep hardware access in Android 18, raising concerns over microphone, camera, and screen data privacy.
Anthropic Claude Chrome Extension: Malicious AI Action Trigger
A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…
Google Gemini CLI Abused by 'bandcampro' for Botnet Operations
Russian-speaking threat actor 'bandcampro' is leveraging Google's Gemini CLI as a hacking agent and to command a small-scale botnet.
Exposed Cloud Functions: Hardening GCP Serverless Against LFI & RCE
Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.
ModHeader Extension Pulled Over Dormant Browsing Data Collector
ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.
Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws
Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.
Dialogflow CX 'Rogue Agent' Bug Enabled AI Conversation Hijacking
A 'Rogue Agent' vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…
Phishing Campaign Uses Nested Redirects to Hijack Google Accounts
Marketing professionals are being targeted by a sophisticated phishing campaign using nested redirects and fake job offers to compromise Google credentials.
Google Dialogflow CX: Critical Flaw Allows Agent Hijack
A critical flaw in Google Dialogflow CX allowed attackers with edit rights to one agent to hijack others in the same project, exposing user data.
Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service
Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.
Job Interview Phishing Targets Google Accounts of Marketing Professionals
A new phishing campaign impersonates 30+ major brands to lure marketing professionals into fake job interviews, aiming to steal their Google account credentials.
Google Disrupts NetNut Malicious Residential Proxy Network
Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.
NetNut (Popa) Residential Proxy Disruption: Impact & Defense
Google, FBI, and Lumen have disrupted NetNut (Popa), a vast residential proxy network, reducing its pool of compromised home devices by millions.