Security News

Google Project Zero Announces 2021 Updates to Vulnerability Disclosure Policy
2021-04-16 10:47

Google's Project Zero cybersecurity research unit on Thursday announced that it's making some changes to its vulnerability disclosure policies, giving users 30 days to install patches before disclosing the technical details of a flaw. Project Zero has announced three major changes to its vulnerability disclosure policy in 2021, compared to 2020.

Google Broke Australian Law Over Location Data Collection: Court
2021-04-16 08:28

Google violated Australian law by misleading users of Android mobile devices about the use of their location data, a court ruled Friday in a landmark decision against the global digital giant. The federal court found that in 2017 and 2018 Google misled some users of phones and tablets featuring its Android operating system by collecting their personally identifiable location information even when they had opted out of sharing "Location History" data.

Google Chrome 90 released with HTTPS as the default protocol
2021-04-14 22:10

Google has released Chrome 90 today, April 14th, 2021, to the Stable desktop channel, and it includes security improvements, a new AV1 encoder, and the default protocol changed to HTTPS. Chrome 90 fixes 37 security bugs, including a zero-day used at the Pwn2Own competition and publicly released Monday on Twitter. Today, Google promoted Chrome 90 to the Stable channel, Chrome 91 as the new Beta version, and Chrome 92 will be the Canary version.

What the FLoC? Browser makers queue up to decry Google's latest ad-targeting initiative as invasive tracking
2021-04-14 19:33

Google's FLoC mechanism for ad personalisation, currently being trialled in the Chrome browser, has been rejected as privacy-invasive tracking by other browser makers including Vivaldi and Brave. FLoC is part of what Google calls the Privacy Sandbox initiative, a proposal to "Support business models that fund the open web in the absence of tracking mechanisms like third-party cookies," according to now-retired Chrome engineering director Justin Schuh and product manager Marshall Vale in January.

Second Google Chrome zero-day exploit dropped on twitter this week
2021-04-14 18:12

A second Chromium zero-day remote code execution exploit has been released on Twitter this week that affects current versions of Google Chrome, Microsoft Edge, and likely other Chromium-based browsers. A zero-day vulnerability is when detailed information about a vulnerability or an exploit is released before the affected software developers can fix it.

Vivaldi, Brave, DuckDuckGo reject Google's FLoC ad tracking tech
2021-04-14 15:59

Last month, Google announced plans to roll out a new privacy-focused feature called Federated Learning of Cohorts for the Chrome browser and ad serving websites. FLoC has been criticized by the Electronic Frontier Foundation and outright rejected by makers of Vivaldi and Brave browsers for its debatable claim of being a privacy-preserving technology.

100,000 Google Sites Used to Install SolarMarker RAT
2021-04-14 14:48

Hackers are using search-engine optimization tactics to lure business users to more than 100,000 malicious Google sites that seem legitimate, but instead install a remote access trojan, used to gain a foothold on a network and later infect systems with ransomware, credential-stealers, banking trojans and other malware. Attackers use Google search redirection and drive-by-download tactics to direct unsuspecting victims to the RAT-tracked by eSentire as SolarMarker.

Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs
2021-04-14 01:22

More than 100,000 web pages hosted by Google Sites are being used to trick netizens into opening business documents booby-trapped with a remote-access trojan that takes over victims' PCs and hands control to miscreants. Infosec outfit eSentire on Tuesday said it has noted a wave of so-called search redirection shenanigans, in which people Googling for business forms and the like are shown links to web pages published via Google Sites - a Google-hosted web service - that offer a download of whatever materials they were looking for.

Google Patches More Under-Attack Chome Zero-days
2021-04-13 22:46

As has become normal, Google did not provide any other details on the attacks or provide any IOCs to help organizations find signs of infection. So far in 2021, Google has rushed out fixes for at least three separate in-the-wild zero-day attacks.

Tax Phish Swims Past Google Workspace Email Security
2021-04-13 18:29

A W2 tax email scam is circulating in the U.S. using Typeform, a popular software that specializes in online surveys and form building. According to Armorblox, the campaign also bypasses native Google Workspace email security filters in the victims it examined.