Advertisement
Top

Tag: Google


Access control, Security

Zenbleed: New Flaw in AMD Zen 2 Processors Puts Encryption Keys and Passwords at Risk

July 25, 2023

Via: The Hacker News

A new security vulnerability has been discovered in AMD’s Zen 2 architecture-based processors that could be exploited to extract sensitive data such as encryption keys and passwords. Discovered by Google Project Zero researcher Tavis Ormandy, the flaw – codenamed Zenbleed […]


Threats & Malware, Vulnerabilities

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

July 24, 2023

Via: The Hacker News

Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February 28, 2023, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, […]


Threats & Malware, Virus & Malware

Sophisticated BundleBot Malware Disguised as Google AI Chatbot and Utilities

July 21, 2023

Via: The Hacker News

A new malware strain known as BundleBot has been stealthily operating under the radar by taking advantage of .NET single-file deployment techniques, enabling threat actors to capture sensitive information from compromised hosts. “BundleBot is abusing the dotnet bundle (single-file), self-contained […]


Mobile, Mobile security

Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities

July 7, 2023

Via: The Hacker News

Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabilities have been identified as actively exploited in targeted attacks. One of the vulnerabilities tracked as CVE-2023-26083 is a memory […]


Application security, Security

Alert: Million of GitHub Repositories Likely Vulnerable to RepoJacking Attack

June 22, 2023

Via: The Hacker News

Millions of software repositories on GitHub are likely vulnerable to an attack called RepoJacking, a new study has revealed. This includes repositories from organizations such as Google, Lyft, and several others, Massachusetts-based cloud-native security firm Aqua said in a Wednesday […]


Cloud security, Security

Google Cloud Bug Allows Server Takeover From CloudSQL Service

May 25, 2023

Via: Dark Reading

Google has fixed a critical flaw in its Google Cloud Platform’s database service that researchers used to gain access to sensitive data and secrets, as well as escalate privileges to breach other cloud services, including potentially those in customer environments. […]


Mobile, Mobile security

Data Stealing Malware Discovered in Popular Android Screen Recorder App

May 24, 2023

Via: The Hacker News

Google has removed a screen recording app named “iRecorder – Screen Recorder” from the Play Store after it was found to sneak in information stealing capabilities nearly a year after the app was published as an innocuous app. The app […]


Mobile, Mobile security

Fleckpe Android Malware Sneaks onto Google Play Store with Over 620,000 Downloads

May 5, 2023

Via: The Hacker News

A new Android subscription malware named Fleckpe has been unearthed on the Google Play Store, amassing more than 620,000 downloads in total since 2022. Kaspersky, which identified 11 apps on the official app storefront, said the malware masqueraded as legitimate […]


Mobile, Mobile security

Apple and Google Join Forces to Stop Unauthorized Location-Tracking Devices

May 3, 2023

Via: The Hacker News

Apple and Google have teamed up to work on a draft industry-wide specification that’s designed to tackle safety risks and alert users when they are being tracked without their knowledge or permission using devices like AirTags. “The first-of-its-kind specification will […]


Mobile, Mobile security

Google Blocks 1.43 Million Malicious Apps, Bans 173,000 Bad Accounts in 2022

May 1, 2023

Via: The Hacker News

Google disclosed that its improved security features and app review processes helped it block 1.43 million bad apps from being published to the Play Store in 2022. In addition, the company said it banned 173,000 bad accounts and fended off […]


Access control, Security

Google 2FA Syncing Feature Could Put Your Privacy at Risk

April 27, 2023

Via: Dark Reading

After a 13-year-long wait, Google Authenticator has added a 2FA account-sync feature that allows its users to back up their 2FA code sequences into the cloud, after which they can restore them back into a new device. Though the process […]


Cloud security, Security

Google Cloud Introduces Security AI Workbench for Faster Threat Detection and Analysis

April 25, 2023

Via: The Hacker News

Google’s cloud division is following in the footsteps of Microsoft with the launch of Security AI Workbench that leverages generative AI models to gain better visibility into the threat landscape. Powering the cybersecurity suite is Sec-PaLM, a specialized large language […]


Threats & Malware, Virus & Malware

N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

April 21, 2023

Via: The Hacker News

The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophistication with North Korean threat actors. Google-owned Mandiant, which is tracking the attack event under […]


Threats & Malware, Vulnerabilities

Google Chrome Hit by Second Zero-Day Attack – Urgent Patch Update Released

April 19, 2023

Via: The Hacker News

Google on Tuesday rolled out emergency fixes to address another actively exploited high-severity zero-day flaw in its Chrome web browser. The flaw, tracked as CVE-2023-2136, is described as a case of integer overflow in Skia, an open source 2D graphics […]


Cyber-crime, Phishing

Google Uncovers APT41’s Use of Open Source GC2 Tool to Target Media and Job Sites

April 17, 2023

Via: The Hacker News

A Chinese nation-state group targeted an unnamed Taiwanese media organization to deliver an open source red teaming tool known as Google Command and Control (GC2) amid broader abuse of Google’s infrastructure for malicious ends. The tech giant’s Threat Analysis Group […]


Access control, Security

Google Launches New Cybersecurity Initiatives to Strengthen Vulnerability Management

April 13, 2023

Via: The Hacker News

Google on Thursday outlined a set of initiatives aimed at improving the vulnerability management ecosystem and establishing greater transparency measures around exploitation. “While the notoriety of zero-day vulnerabilities typically makes headlines, risks remain even after they’re known and fixed, which […]


Cyber-crime, Malware

Mandiant Also Links 3CX Supply Chain Attack to North Korean Hackers

April 12, 2023

Via: SecurityWeek

Google-owned Mandiant is investigating the breach and 3CX has released some information from the security firm’s initial analysis. “Based on the Mandiant investigation into the 3CX intrusion and supply chain attack thus far, they attribute the activity to a cluster […]


Cyber-crime, Phishing

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks

April 5, 2023

Via: The Hacker News

A North Korean government-backed threat actor has been linked to attacks targeting government and military personnel, think tanks, policy makers, academics, and researchers in South Korea and the U.S. Google’s Threat Analysis Group (TAG) is tracking the cluster under the […]


Threats & Malware, Virus & Malware

Microsoft squashes Windows bug exploited to inflict ransomware misery

March 14, 2023

Via: The Register

Criminals are exploiting a Microsoft SmartScreen bug to deliver Magniber ransomware, potentially infecting hundreds of thousands of devices, without raising any security red flags, according to Google’s Threat Analysis Group (TAG). TAG discovered the in-the-wild exploit, and reported it to […]


Email security, Security

Gmail launches a big security update, but you might not get it yet

December 19, 2022

Via: TechRadar

Google has become the latest company to roll out an encryption upgrade, revealing it Gmail email service is set to get full end-to-end encryption (E2EE) support, but not all users will be able to get it. In an update on […]