Tag: google
-
New Google Password Manager Attacks Can Hijack Synced Passkeys
Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/
-
Chrome to Block Policy-Abusing Extensions on Personal Devices
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chrome-extension-policy-abuse/
-
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
Tags: apple, credentials, cyber, data-breach, exploit, google, group, intelligence, iphone, login, risk, threatDarkSword’s leaked iOS exploit chain is now powering a fast”‘moving server cluster that marries one”‘click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to…
-
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that…
-
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users’ meeting information and potentially join calls. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
New Passkey attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
-
Google Warns Open-Source Attacks Will Reach New Heights
Google Says Open-Source Compromises Are Easier to Scale and Replicate. Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned Google. One of the largest open-source supply-chain attacks involved a North Korean threat actor. First seen on…
-
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap. The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-twice-weekly-security-updates/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
Google’s Cyber Threat Actor Naming System Ditches Jargon, Makes Intelligence More Actionable
A cyber threat actor by any other name”¦can probably be found in Google Threat Intelligence Group’s new taxonomy for tracking threat actors. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/googles-cyber-threat-actor-naming-system-ditches-jargon-makes-intelligence-more-actionable/
-
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories of the Week Hugging Face, Iranian ICS Attacks, EY, Hyundai, AI Agent Breaches
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 27August 1, 2026. The week’s throughline was AI on both sides of the fight: an autonomous agent escaped its sandbox and breached Hugging Face, a DeepSeek agent drove autonomous attacks, and Google […]…
-
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurrency wallets. The attack begins when victims search Google for >>how to install Claude on a Mac<< and click a sponsored…
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
ISMG Editors: A New Front in the Naming War
Also: The AI Spending Reality Check, Nvidia Takes on Closed AI. In this week’s panel, four ISMG editors discussed Google’s controversial new threat actor naming system and the need for standardization, whether the artificial intelligence boom is built on solid economic foundations, and the growing battle between open and closed AI models. First seen on…
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of…
-
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones combined. In a new report, the Chrome Security Team detailed how large language models are integrated throughout the vulnerability…
-
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-play-age-signals-api-global-rollout/
-
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies, like Microsoft and now Google, are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
-
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser’s two most recent releases as it expands its use of AI. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
-
Claude’s Shared Chats Surface on Google Search
Nearly 11 Months After a Similar Exposure, Sharing Guide Omits Search Risk. An unknown number of shared Claude chats and published Artifacts surfaced in Google results, including pages that reportedly contained medical, personal and company information. Anthropic’s chat-sharing guide does not warn that public links can become searchable. First seen on govinfosecurity.com Jump to article:…
-
Cloud-Monitoring als unverzichtbares Tool für IT-Teams
<>, kommentiert Jörg Hollerith, Produktmanager bei Paessler, die oft viel zu schnell gewachsenen […] First seen on netzpalaver.de Jump to article: netzpalaver.de/2026/07/28/cloud-monitoring-als-unverzichtbares-tool-fuer-it-teams/
-
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai…
-
Google Street View: Ab sofort Adressnachweis für Verpixelung notwendig
Tags: googleWer sein Haus bei Google Street View unkenntlich gemacht haben will, muss einen Adressnachweis erbringen. So soll Missbrauch vorgebeugt werden. First seen on golem.de Jump to article: www.golem.de/news/google-street-view-ab-sofort-adressnachweis-fuer-verpixelung-notwendig-2607-211350.html
-
Persönliche Daten geleakt: Unzählige Claude-Chats bei Google aufgetaucht
Claude-Nutzer können Links zu ihren Chats mit anderen Personen teilen. Die Unterhaltungen wurden bis vor kurzem aber auch bei Google gelistet. First seen on golem.de Jump to article: www.golem.de/news/persoenliche-daten-geleakt-unzaehlige-claude-chats-bei-google-aufgetaucht-2607-211338.html
-
Nvidia Launches Open-Source AI Security Alliance
Anthropic, OpenAI and Google Absent as 37 Firms Back Open AI Security Tools. Nvidia and 36 other technology giants launched the Open Secure AI Alliance to build and share open-source AI security tools, arguing open models are critical defensive assets – while Anthropic, OpenAI and Google, makers of the most capable closed models, are absent…
-
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure
-
PSA: Your Claude shared chats and Artifacts may have ended up on Google
Tags: googleThe issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/

