Google DeepMind Research: Six Web Attack Vectors Against AI Agents
DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.
Google Accelerates Post-Quantum Cryptography Transition for 2029
Google announces a full migration to post-quantum cryptography by 2029 to ensure crypto-agility and defend against future quantum computing threats.
OAuth 2.0 Device Code Phishing Surge: Protecting M365 and Google
Device code phishing attacks have surged 37x this year. Learn how adversaries abuse the OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts.
Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses
Google researchers uncovered "Coruna," a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.
CVE-2026-5281: Google Dawn RCE via Use-After-Free — Mitigation Guide
CISA adds CVE-2026-5281 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in Google Dawn's WebGPU implementation.
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
Google Chrome Zero-Day Patch: Fourth In-the-Wild Exploit
Google has released an urgent security update for Chrome, patching the fourth zero-day vulnerability actively exploited in 2024. Update now to protect against…
Google Vertex AI Security: Mitigating AI Agent Weaponization
Google patches security flaws in Vertex AI after Unit 42 researchers demonstrated how to weaponize AI agents for unauthorized data access and exfiltration.
Google Drive Ransomware Protection Enabled by Default for Workspace
Google Workspace now enables AI-powered ransomware detection by default for paying users to identify and mitigate cloud-based encryption threats automatically.
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.
Google Vertex AI Over-Privilege: Data Theft & Cloud Intrusion Risk
Palo Alto Networks researchers found over-privileged AI agents in Google Vertex AI could be exploited for data exfiltration and access to restricted cloud infrastructure.
Google Gmail Address Migration: Security and Identity Implications
Google introduces Gmail address changes in the U.S., presenting new challenges for identity verification, account recovery, and phishing defense.
Android Developer Identity Verification: New Google Play Mandates
Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.
Vertex AI Permission Flaw Exposes Google Cloud Data — Mitigation Guide
Researchers uncover a security blind spot in Google Cloud Vertex AI, allowing attackers to weaponize AI agents for unauthorized data access and compromise.
Quantum Threat to Crypto: Qubit Requirements Reduced 20x
Google researchers demonstrate a 20x reduction in qubits needed to break Bitcoin and Ethereum encryption, accelerating the long-term quantum cryptographic threat.
Palo Alto Networks Recruiter Scam and Quantum Security Outlook
Threat actors are impersonating Palo Alto Networks recruiters to target security professionals, while Google sets a 2029 deadline for quantum computing.
Google Sets 2029 Deadline for Post-Quantum Cryptography Migration
Google establishes a 2029 deadline for quantum-safe cryptography to mitigate harvest-now-decrypt-later risks. Learn how to prepare for PQC migration.
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.
VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol
VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.
Google Play Protect Advanced Flow for Android Sideloading
Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.
Google Android Security: 24-Hour Wait for Unverified Sideloading
Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.
Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users
Researchers uncover 'Claudy Day', a trio of vulnerabilities in Anthropic's Claude AI that allow data theft through malicious Google search results.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.
Tech Giants Sign Industry Pact to Combat Online Scams and Fraud
Leading tech firms including Google, Meta, and Microsoft sign a collaborative pact to enhance cross-platform intelligence sharing and fight online scams.