Google's $15 Billion India Data Center Project Battles Water, Wildlife Concerns
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.
Read more of this story at Slashdot.
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word.
The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.
If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest?
Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around memorable word pairs.
The company said in a blog post that the change merges two systems that had grown apart for years inside Google: Mandiant, the security firm Google bought in 2022, and its in-house Threat Analysis Group. Combining those units left Google with overlapping names for the same hacking groups, a problem the new system aims to fix.
“Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition,” the post reads.
Each tracked group will now get a two-word name. The first word is a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group. When no such name exists, researchers will generate one at random and have analysts check it before use. The second word sorts each group by category, such as country of origin or motive. In Google’s published examples, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state.
The approach echoes one CrowdStrike has long been known for. CrowdStrike pairs a specific term with an animal tied to a country or motive: PANDA for China, BEAR for Russia, SPIDER for cybercriminals, JACKAL for hacktivists. Google’s system swaps the animals for words like CASTLE and NEPTUNE but follows the same basic structure, down to the argument for why it works: A two-part name carries more information than a bare country label or number, and it can change as attribution is fine-tuned.
Microsoft took its own turn at a naming overhaul in April 2023, dropping a system built on chemical elements, trees and volcanoes in favor of weather terms. Under that system, Typhoon marked China, Blizzard marked Russia, Sandstorm marked Iran, and Tempest marked financially motivated cybercriminals. The switch produced names that drew as much attention for their sound as their substance, among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest. Industry experts bristled over the change, saying the names compared the groups to ice cream flavors or cocktails.
By 2025, the industry’s naming sprawl had become enough of a shared headache that two of the biggest players in it agreed to try to sort it out together. Microsoft and CrowdStrike announced a joint mapping effort in June of that year, pairing Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups, with Google, Mandiant and Palo Alto Networks Unit 42 also signed on to contribute. Both companies were careful to say the project was not an attempt to force the industry onto one naming system, just to make the existing ones easier to translate between.
Google‘s rollout starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will stay searchable within Google’s threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors.
The company says groups will keep carrying “UNC,” for uncategorized, if it is still too early to identify exactly where a group fits in this taxonomy.
The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.
Read more of this story at Slashdot.
Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.
Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.
As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.
“Emma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone,” wrote Certo co-founder Russell Kent-Payne. “What she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.”
The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certo’s research serves as “an important reminder that tech-enabled abuse isn’t just limited to stalkerware.”
Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account it’s syncing to, to protect users.
Google did not respond to multiple requests for comment about Certo’s findings.
But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.
“Modern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,” Kent-Payne wrote. “As a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain — just a quiet misuse of a feature the victim never knew existed.”
At the same time, Chrome is the world’s most popular browser, and this isn’t the first time security concerns have popped up about its sync feature, among other worries.
The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop.
Read more of this story at Slashdot.
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek.
Read more of this story at Slashdot.
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

The NetNut homepage today was replaced by this seizure banner from the FBI.
On June 19, three different security firms issued similar findings: That NetNut is a residential proxy network which populates a botnet called Popa, and distributes software for devices commonly found in homes, such as smart TVs and streaming boxes. NetNut’s software turns those systems into always-on residential proxy nodes that are rented to others, who predominantly use them to relay abusive and intrusive Internet traffic, such as mass content scraping, advertising fraud, and account takeover activity.
Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure.
In a blog post published today, the Google Threat Intelligence Group (GTIG) said NetNut’s proxy network is widely resold and white-labeled by a number of third-party proxy providers, and that its services are heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic. The GTIG said that in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups.
“These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.”
Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs.
Omer Weiss, legal counsel for NetNut parent Alarum Technologies, said the company was aware of the FBI seizure and cooperating with investigators.
“Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Weiss said in a written statement.
Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies. Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.
Brundage said NetNut’s apparent demise is likely to be a great disadvantage for the cybercrime community, which was already reeling from legal actions by Google earlier this year that seized infrastructure for NetNut’s biggest competitor — IPIDEA.
“I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,” he said. “Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.”

NetNut’s infrastructure, in a nutshell. Image: Black Lotus Labs, Lumen.
The NetNut and Popa botnet takedown may have another added benefit, Brundage said: Lessening the impact of large distributed denial-of-service botnets that have been built on the backs of poorly configured residential proxy services. In January, Synthient revealed how cybercriminals had built the world’s largest DDoS botnet (Kimwolf) by tunneling through IPIDEA proxy connections into the local networks of TV box owners, and infecting other Android-based devices behind the victim’s firewall.
While many of the bigger proxy providers took steps to block this activity, resellers of the major proxy networks have been far slower to respond to the threat, Brundage said.
“In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there,” he said.
For its part, Google reckons today’s actions have caused “significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.” But the company warns that proxy networks can rebuild themselves by effectively reselling other proxy services, as IPIDEA has done over the past few months.
“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes. “While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers.”
As KrebsOnSecurity has warned repeatedly, most of the no-name TV streaming boxes for sale on the major e-commerce websites either come pre-installed with residential proxy software, or require the installation of proxy SDKs in order to use the device for its stated purpose (streaming pirated movies, sporting events and TV shows). Google’s advice here is sound: When it comes to TV boxes, stick to name brands from reputable manufacturers, and then be sparing and judicious with any apps you choose to install.
The sketchy TV boxes that are being commandeered by the Popa botnet and other threats all come with or require the user to install unofficial Android operating systems that do not operate within the confines of Google’s Official Play Protect store. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.
Even people without TV streaming boxes can find their smart TVs enrolled in residential proxy networks, just by installing one of thousands of apps available for download on Samsung and LG smart TVs. In a report released last month, the proxy tracking company Spur found 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.
Update, 4:24 p.m. ET: Included a statement shared post-publication from an attorney representing NetNut parent Alarum Technologies.
Update, July 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The company’s stock has taken a beating since the FBI action, and is currently trading at $2.62 a share, a roughly 67 percent decline over the past week.