Android CVE-2026-0073: Critical System RCE Patch Guidance
Google addresses a critical zero-click RCE vulnerability (CVE-2026-0073) in the Android System component. Learn how to mitigate this high-impact security flaw.
Google Android VRP 2024 Updates: $1.5M for Pixel Kernel Exploits
Google overhauls its Vulnerability Rewards Programs, increasing payouts for complex Android exploits while devaluing bugs easily identified by AI tools.
US DoD Partners with 7 Tech Giants for Classified AI Integration
The US Department of Defense secures deals with AWS, Google, and OpenAI to integrate AI into classified environments, focusing on operational decision-making.
AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet
A Vietnamese-linked operation dubbed AccountDumpling used Google AppSheet as a phishing relay to compromise 30,000 Facebook accounts for illicit resale.
Google Adjusts Bug Bounties: $1.5M Android Reward and AI Shift
Google updates its Vulnerability Reward Program, increasing Android zero-click payouts to $1.5 million while adjusting Chrome rewards amid an AI security surge.
Google Gemini CLI Host Code Execution: Securing AI Developer Tools
Critical security flaw in Google Gemini CLI allows host code execution and supply chain attacks via malicious configurations. Learn how to mitigate.
Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.
Malicious AI Prompt Injection Attacks: Google Red Team Insights
Google reports a surge in AI prompt injection attacks, highlighting low-sophistication attempts and strategies for mitigating indirect prompt injection risks.
CrowdStrike Falcon Cloud Security Expands Real-Time CDR to GCP
CrowdStrike enhances Falcon Cloud Security with real-time detection and response for Google Cloud, providing unified visibility and threat protection.
Google Antigravity RCE via Prompt Injection — Mitigation Guide
Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.
Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads
Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.
Google Deploys Gemini AI to Combat Malvertising and Brand Fraud
Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.
Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests
An audit reveals Google, Meta, and Microsoft frequently ignore California privacy law opt-out requests, posing significant compliance and data privacy risks.
Pushpaganda Scam: Detecting AI-Driven Ad Fraud in Google Discover
Researchers unmask Pushpaganda, a campaign using AI-generated content and SEO poisoning to trick users into enabling malicious browser notifications.
Pixel 10 Modem: Google Implements Rust-Based DNS Parser
Google integrates Rust-based DNS parsing in Pixel 10 modem firmware to eliminate memory-safety risks and prevent remote code execution at the baseband level.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
Google Workspace CSE: Securing Gmail on Android and iOS
Google introduces native client-side encryption for Gmail on Android and iOS, enabling enterprise users to control encryption keys on mobile devices.
Google Gmail Client-Side Encryption for Android and iOS — Deployment Guide
Google expands Gmail client-side encryption (CSE) to Android and iOS, giving enterprise users full control over encryption keys for mobile email communications.
Chrome DBSC: Securing Session Cookies with Device Binding — Analysis
Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.
Exposed Google API Keys in Android Apps Grant Gemini Access
Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.
TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity
Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.