Google's €4.1B EU Fine Stands: Android Antitrust Implications
Google loses final appeal against its €4.1 billion EU antitrust fine concerning Android's dominance. Understand the compliance implications for tech giants.
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.
Falcon Cloud Security Expands Multi-Cloud Coverage for Azure, GCP
CrowdStrike Falcon Cloud Security's latest updates enhance multi-cloud protection across Azure and Google Cloud, improving visibility and threat detection.
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
AI Search Summary Liability: German Court Redefines Publisher Role
A landmark German court ruling declares Google liable for its AI search summaries, setting a significant precedent for AI content providers and data integrity.
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.
Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities
Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.
Google Update: New Search and Play History Privacy Controls
Google launches new privacy tools for Search and Play, allowing users to disable personalization and quickly delete recent activity to improve data privacy.
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.
GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments
An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments.
Google Privacy Pivot: IP Address Use for UK and EEA Ad Targeting
Google announces plans to utilize IP addresses from UK, EEA, and Swiss users for ad personalization and measurement starting August 2026, raising privacy concerns.
Google Vertex AI SDK Model Hijacking via Bucket Squatting
A Google Cloud Vertex AI SDK vulnerability allows attackers to hijack model uploads and achieve RCE through bucket squatting and malicious Pickle files.
Chinese Espionage: Google Workspace Rule Abuse in Research Sectors
China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.
China-Nexus Actor: Year-Long Espionage Against US Researchers
A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.
UNC6508: Chinese Cyberespionage Targets North American Research
Google's Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.
FBI and Google Dismantle Outsider Enterprise Phishing Service
Law enforcement and Google disrupt Outsider Enterprise, a massive Phishing-as-a-Service platform responsible for $1.9 billion in losses.
FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation
The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.
Chinese Smishing Network 'Outsider' Leverages Gemini AI for Phishing
Google sues a Chinese smishing network operating 'Outsider' PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026
Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.
CVE-2024-4947: Google Patches Fifth Chrome Zero-Day of 2024
Google addresses CVE-2024-4947, a high-severity V8 type confusion vulnerability in Chrome being exploited in the wild. Update to version 125.0.6422.60 now.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
Operation FlutterBridge: New FlutterShell Backdoor Targets macOS
Researchers discover Operation FlutterBridge, a malvertising campaign delivering the FlutterShell backdoor to macOS users via Google and YouTube ads.