Advertisement
Google Patches Chrome Zero-Days CVE-2026-3909 in Skia and V8
Google addresses two high-severity Chrome zero-days, including CVE-2026-3909, exploited in the wild via Skia and V8. Learn how to secure your browser now.
Chrome 146 Patch: Two Exploited Zero-Days CVE-2025-0672 and CVE-2025-0673
Google addresses two actively exploited vulnerabilities in Chrome 146. CVE-2025-0672 and CVE-2025-0673 allow data manipulation and remote code execution.
CVE-2024-4947 and CVE-2024-4948: Google Patches Chrome Zero-Days
Google has patched CVE-2024-4947 and CVE-2024-4948, two high-severity Chrome zero-days exploited in the wild. Learn how to secure your browser environments.
Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities
Google's Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.
Wiz Joins Google Cloud: Strategic Implications for Cloud Security
Analyzes Google Cloud's landmark acquisition of Wiz, exploring the strategic impacts on cloud security posture, multi-cloud defense, and compliance for enterprises.
LeakyLooker: Google Looker Studio Cross-Tenant SQL Vulnerabilities
Discover how nine vulnerabilities in Google Looker Studio, dubbed LeakyLooker, allowed cross-tenant SQL queries and sensitive data exfiltration in GCP.
Google Cloud Security: Exploits Surpass Weak Credentials
Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.
Google Forecasts 90 Enterprise Zero-Day Exploits in 2025
Google predicts half of the 90 exploited zero-day vulnerabilities in 2025 will target enterprises. Understand attribution and proactive defense strategies.
Google Reports 90 Zero-Day Exploits in 2025: Enterprise Focus
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025, with nearly half targeting enterprise software and appliances.
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.
APT41-Linked Silver Dragon Targets Governments via Google Drive C2
APT41 sub-group Silver Dragon targets European and Southeast Asian governments using public-facing server exploits and Google Drive for C2 operations.
Google Chrome Two-Week Release Cycle: Reducing the Patch Gap
Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.
Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs
Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…
Phishing Campaign Leverages Fake Google PWA to Steal Credentials, MFA
A sophisticated phishing campaign uses a fake Google Security PWA to compromise accounts, steal MFA codes, and proxy traffic. Learn how to protect.
Chrome to Adopt Merkle Tree Certificates for Post-Quantum HTTPS
Google introduces Merkle Tree Certificates in Chrome to enable quantum-resistant HTTPS, addressing scalability issues found in traditional X.509 PQC signatures.
CVE-2026-0628: Chrome Gemini Panel Exploit Enables Privilege Escalation
A high-severity flaw in Google Chrome's Gemini side panel allowed malicious extensions to bypass security policies and access local files on target systems.
Google Gemini Side Panel Bug Enables Session Hijacking — Update Now
Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.
Chrome Gemini Live Hijacking: Malicious Extension Vulnerability
A vulnerability in Google Chrome’s Gemini Live AI assistant allowed malicious extensions to hijack sessions and steal user files. Learn more about the impact.
Google’s Path to Quantum-Safe Chrome HTTPS via Merkle Tree Certificates
Google is developing Merkle Tree Certificates (MTCs) for Chrome to transition the web toward post-quantum cryptography and enhance HTTPS certificate security.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.
Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies
All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.
Insecure Google API Keys Expose Gemini AI and Private Data
Exposed Google API keys, once considered low-risk for services like Maps, now allow unauthorized access to Gemini AI models and sensitive project data.
Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches
Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.
GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally
Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.