CVE-2026-3909 & CVE-2026-3910: Actively Exploited Google Vulnerabilities
CISA added two Google vulnerabilities (Skia Out-of-Bounds Write, Chromium V8 unspecified) to its KEV Catalog due to active exploitation. Patch now.
Google Cloud Attacks: Exploitation Outpaces Patching Cycles
Vulnerability exploitation, not stolen credentials, is the primary initial compromise vector for Google Cloud environments, often bypassing patching efforts.
Google's $17M Bug Bounty: Insights on Chrome & Cloud Security
Google paid out $17 million in bug bounties in 2025, with major rewards for Chrome and cloud security flaws. Understand the implications for enterprise defense.
Google Patches Chrome Zero-Days CVE-2026-3909 in Skia and V8
Google addresses two high-severity Chrome zero-days, including CVE-2026-3909, exploited in the wild via Skia and V8. Learn how to secure your browser now.
Chrome 146 Patch: Two Exploited Zero-Days CVE-2025-0672 and CVE-2025-0673
Google addresses two actively exploited vulnerabilities in Chrome 146. CVE-2025-0672 and CVE-2025-0673 allow data manipulation and remote code execution.
CVE-2024-4947 and CVE-2024-4948: Google Patches Chrome Zero-Days
Google has patched CVE-2024-4947 and CVE-2024-4948, two high-severity Chrome zero-days exploited in the wild. Learn how to secure your browser environments.
Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities
Google's Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.
Wiz Joins Google Cloud: Strategic Implications for Cloud Security
Analyzes Google Cloud's landmark acquisition of Wiz, exploring the strategic impacts on cloud security posture, multi-cloud defense, and compliance for enterprises.
LeakyLooker: Google Looker Studio Cross-Tenant SQL Vulnerabilities
Discover how nine vulnerabilities in Google Looker Studio, dubbed LeakyLooker, allowed cross-tenant SQL queries and sensitive data exfiltration in GCP.
Google Cloud Security: Exploits Surpass Weak Credentials
Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.
Google Forecasts 90 Enterprise Zero-Day Exploits in 2025
Google predicts half of the 90 exploited zero-day vulnerabilities in 2025 will target enterprises. Understand attribution and proactive defense strategies.
Google Reports 90 Zero-Day Exploits in 2025: Enterprise Focus
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025, with nearly half targeting enterprise software and appliances.
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.
APT41-Linked Silver Dragon Targets Governments via Google Drive C2
APT41 sub-group Silver Dragon targets European and Southeast Asian governments using public-facing server exploits and Google Drive for C2 operations.
Google Chrome Two-Week Release Cycle: Reducing the Patch Gap
Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.
Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs
Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…
Phishing Campaign Leverages Fake Google PWA to Steal Credentials, MFA
A sophisticated phishing campaign uses a fake Google Security PWA to compromise accounts, steal MFA codes, and proxy traffic. Learn how to protect.
Chrome to Adopt Merkle Tree Certificates for Post-Quantum HTTPS
Google introduces Merkle Tree Certificates in Chrome to enable quantum-resistant HTTPS, addressing scalability issues found in traditional X.509 PQC signatures.
CVE-2026-0628: Chrome Gemini Panel Exploit Enables Privilege Escalation
A high-severity flaw in Google Chrome's Gemini side panel allowed malicious extensions to bypass security policies and access local files on target systems.
Google Gemini Side Panel Bug Enables Session Hijacking — Update Now
Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.
Chrome Gemini Live Hijacking: Malicious Extension Vulnerability
A vulnerability in Google Chrome’s Gemini Live AI assistant allowed malicious extensions to hijack sessions and steal user files. Learn more about the impact.
Google’s Path to Quantum-Safe Chrome HTTPS via Merkle Tree Certificates
Google is developing Merkle Tree Certificates (MTCs) for Chrome to transition the web toward post-quantum cryptography and enhance HTTPS certificate security.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.
Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies
All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.