Tag: google
-
ModHeader aus App-Stores verbannt: Inaktiver Spionagecode in HTTP-Tool entdeckt
Google und Microsoft haben die Erweiterung ModHeader mit 1,6 Millionen Downloads entfernt. Grund ist ein versteckter, inaktiver Daten-Sammler. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/modheader-aus-app-stores-verbannt
-
Google’s Gemini lets strangers send messages from your locked Android phone
Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/googles-gemini-strangers-messages-locked-android-phone
-
AI Hardware, App Store Shifts, and Security Scares Define This Week in Tech
Catch up on the week’s biggest tech news, including Google’s app store shakeup, Apple’s AI expansion, OpenAI’s hardware plans, and critical security threats. The post AI Hardware, App Store Shifts, and Security Scares Define This Week in Tech appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ai-hardware-app-store-shifts-and-security-scares-define-this-week-in-tech/
-
EU Orders Google to Open Android AI Features, Share Search Data With Rivals
EU rules will make Google share anonymized search data and give rival AI assistants broader access to Android features across Europe. The post EU Orders Google to Open Android AI Features, Share Search Data With Rivals appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-eu-google-android-ai-search-data-rules-emea/
-
Smartphone-Diebstahl: Betrüger locken mit Fake-SMS in Phishing-Falle
Smartphone-Diebstahl im Urlaub: Mit Fake-SMS locken Kriminelle Opfer in eine Phishing-Falle. So schützt du Apple-ID und Google-Konto. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/smartphone-diebstahl-fake-sms-phishing-falle-331552.html
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing.Google has to…
-
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
The City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls. First seen on wired.com Jump to article: www.wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores/
-
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/
-
Hacker missbraucht Googles Gemini CLI zur Botnetz-Steuerung
Ein russischsprachiger Cyberkrimineller hat Googles KI-Tool Gemini CLI als autonomen Hacking-Agenten zur Steuerung eines Botnetzes missbraucht. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-missbraucht-gemini
-
Google Makes Security Objections to EU Order Opening Android
EU Forces Google to Give Rival AI Services Android Access and to Share Search Data. Google sounded security alarms after the European Commission ordered it to open up deep Android functionality to rival artificial intelligence providers, and also to give third-party search providers access to Google Search data. The orders enforce the Digital Markets Act.…
-
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as >>bandcampro<< used a jailbroken Gemini CLI, Google's open-source terminal-based AI agent, to deploy and operate a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/
-
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt…
-
Phishing-as-a-Service Wenn Cyberkriminalität zum Abo-Modell wird
Mitte Juni hat das FBI im Rahmen der Operation Ghost-Hook gemeinsam mit Google und Black Lotus Labs die Plattform Outsider vom Netz genommen, einer der größten bislang bekannten Phishing-as-a-Service-Anbieter. Seit 2023 lieferte der Dienst Cyberkriminellen Phishing-Infrastruktur mit über 290 fertigen Vorlagen, die Banken, Behörden, Telekommunikationsanbieter und Einzelhändler imitierten. Die Ermittler nehmen an, dass seit der…
-
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/
-
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
ModHeader version 7.0.187.0.187.0.18, a popular Chrome extension used for modifying HTTP headers, contained dormant code capable of collecting and exfiltrating browsing history data from an estimated 900,000 users, according to research disclosed on July 13, 2026. Google removed the extension from the Chrome Web Store on Friday, July 10, following a responsible disclosure. Organizations should…
-
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version.The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single…
-
Zwei Millionen kompromittierte Geräte – Google und FBI zerschlagen NetNut-Proxy-Netzwerk
Tags: googleFirst seen on security-insider.de Jump to article: www.security-insider.de/google-fbi-zerschlagen-netnut-popa-proxy-netzwerk-a-36f87d3a47cfe5dff937edcd5ad8a16d/
-
Invited to a >>job interview<< with Netflix or OpenAI? Beware! Your Google password could be at risk
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/invited-job-interview-netflix-openai-beware-google-password
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
A newly disclosed vulnerability pattern known as >>GhostApproval<< is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. This issue demonstrates how attackers can exploit symbolic links (symlinks) to bypass workspace isolation and manipulate Human-in-the-Loop safeguards, potentially resulting in…
-
Google Chrome Update Patches 27 Security Vulnerabilities Including Critical UseFree Flaws
Google has released a critical security update for Chrome, upgrading the Stable channel to version 150.0.7871.114/.115 on Windows and macOS, and to version 150.0.7871.114 on Linux. This update addresses 27 vulnerabilities, including several critical use-after-free flaws that could potentially enable remote code execution. The update will roll out gradually over the coming days and weeks,…
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
Google pays $250k for Linux vulnerability allowing guest VM escapes
Both vulnerabilities allow untrusted users to gain root privileges. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/
-
Fake Job Offers Impersonate Netflix, OpenAI, and FIFA to Steal Google Credentials
A fake recruitment phishing campaign impersonates major brands and uses trusted HR platforms to steal Google account credentials. The post Fake Job Offers Impersonate Netflix, OpenAI, and FIFA to Steal Google Credentials appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-recruitment-phishing-google-credentials-2026/
-
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple.The models they tested through…
-
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple.The models they tested through…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…

