Reading view
Google's $15 Billion India Data Center Project Battles Water, Wildlife Concerns
Read more of this story at Slashdot.
Google Overhauls AI Leadership As DeepMind CEO Steps Aside
Read more of this story at Slashdot.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.
Google Blogger locks hundreds of blogs in malware false positive
Group of Teen Hikers Relied on Google Maps. It Was a Disaster.
Read more of this story at Slashdot.
Google Chrome may soon block New Tab hijacker extensions by default
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
Google's Gemini Can Now Stomp Around as a Humanoid Robot
Read more of this story at Slashdot.
Google Brings Its Age-Assurance Tech To Android Developers Worldwide
Read more of this story at Slashdot.
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google Shuts Down Its Nobel-Prize Winning AlphaFold Project
Read more of this story at Slashdot.
Google Adopts New Threat Actor Naming System
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word.
The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.
Google’s solution to hacker name confusion? Yet another naming system
If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest?
Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around memorable word pairs.
The company said in a blog post that the change merges two systems that had grown apart for years inside Google: Mandiant, the security firm Google bought in 2022, and its in-house Threat Analysis Group. Combining those units left Google with overlapping names for the same hacking groups, a problem the new system aims to fix.
“Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition,” the post reads.
Each tracked group will now get a two-word name. The first word is a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group. When no such name exists, researchers will generate one at random and have analysts check it before use. The second word sorts each group by category, such as country of origin or motive. In Google’s published examples, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state.
The approach echoes one CrowdStrike has long been known for. CrowdStrike pairs a specific term with an animal tied to a country or motive: PANDA for China, BEAR for Russia, SPIDER for cybercriminals, JACKAL for hacktivists. Google’s system swaps the animals for words like CASTLE and NEPTUNE but follows the same basic structure, down to the argument for why it works: A two-part name carries more information than a bare country label or number, and it can change as attribution is fine-tuned.
Microsoft took its own turn at a naming overhaul in April 2023, dropping a system built on chemical elements, trees and volcanoes in favor of weather terms. Under that system, Typhoon marked China, Blizzard marked Russia, Sandstorm marked Iran, and Tempest marked financially motivated cybercriminals. The switch produced names that drew as much attention for their sound as their substance, among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest. Industry experts bristled over the change, saying the names compared the groups to ice cream flavors or cocktails.
By 2025, the industry’s naming sprawl had become enough of a shared headache that two of the biggest players in it agreed to try to sort it out together. Microsoft and CrowdStrike announced a joint mapping effort in June of that year, pairing Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups, with Google, Mandiant and Palo Alto Networks Unit 42 also signed on to contribute. Both companies were careful to say the project was not an attempt to force the industry onto one naming system, just to make the existing ones easier to translate between.
Google‘s rollout starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will stay searchable within Google’s threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors.
The company says groups will keep carrying “UNC,” for uncategorized, if it is still too early to identify exactly where a group fits in this taxonomy.
The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.
Top Online Sites Debate Cutting Off Google's Crawlers
Read more of this story at Slashdot.
EU fines Google $1 billion for search, app store antitrust violations
Security researchers find stalkers abusing Chrome’s sync feature
Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.
Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.
As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.
“Emma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone,” wrote Certo co-founder Russell Kent-Payne. “What she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.”
The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certo’s research serves as “an important reminder that tech-enabled abuse isn’t just limited to stalkerware.”
Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account it’s syncing to, to protect users.
Google did not respond to multiple requests for comment about Certo’s findings.
But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.
“Modern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,” Kent-Payne wrote. “As a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain — just a quiet misuse of a feature the victim never knew existed.”
At the same time, Chrome is the world’s most popular browser, and this isn’t the first time security concerns have popped up about its sync feature, among other worries.
The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop.
Google Images Gets a Pinterest-Like Redesign Focused On Discovery
Read more of this story at Slashdot.
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek.
Google Search Hits All-Time Usage Record
Read more of this story at Slashdot.