Security News

Google Chrome Browser Bug Exposes Billions of Users to Data Theft
2020-08-10 19:43

The bug is found in Chrome, Opera and Edge, on Windows, Mac and Android - potentially affecting billions of web users, according to PerimeterX cybersecurity researcher Gal Weizman. CSP allows web admins to specify the domains that a browser should consider to be valid sources of executable scripts.

Android user chucks potential $10bn+ sueball at Google over 'spying', 'harvesting data'... this time to build supposed rival to TikTok called 'Shorts'
2020-08-07 12:23

The putative class-action suit, filed on Wednesday in the Northern district of California [PDF] also alleged that Google was gathering info from TikTok specifically in order to "Unfairly compete against TikTok [with a] competing video platform app called 'Shorts'." The suit further alleged that Lockbox worked "Through Google Mobile Services and allows Google employees to spy on how Android Smartphone users interact with non-Google apps. For example, Google is able to collect data on when and how often an Android smartphone user opens and runs non-Google apps and the amount of time spent in non-Google apps."

Tanium and Google Cloud partner to deliver security transformation
2020-08-05 00:00

Tanium has expanded its partnership with Google Cloud to help organizations accelerate the transformation to distributed business operations. "With Tanium and Google Cloud, customers don't have to make difficult tradeoffs between the quality, breadth, timeliness, or storage cost of their security telemetry," said Sunil Potti, General Manager and Vice President of Cloud Security at Google Cloud.

Google Cloud and AppViewX partner to secure digital identities
2020-08-04 23:10

AppViewX announced its partnership with Google Cloud to support its newly announced Google Cloud Certificate Authority Service with AppViewX's Certificate Lifecycle Management and Automation product, CERT+. This integration enables businesses to simplify deployment of private CAs, enabling end-to-end automation of enterprise infrastructure, DevOps and IoT. Google Cloud and AppViewX's integration primarily focuses on securing the growing number of digital identities with a robust and future-proof PKI system, allowing users to communicate with DevOps tools and CI/CD toolchains.

Google Patches Over 50 Vulnerabilities in Android With August 2020 Updates
2020-08-04 18:24

Google on Monday announced the August 2020 security updates for the Android operating system, with patches for a total of more than 50 vulnerabilities. The 2020-08-01 security patch level addresses 14 high-severity vulnerabilities in the Framework, Media Framework, and System components.

Google and Amazon most impersonated brands in phishing attacks
2020-08-04 16:30

Phishing attacks typically try to lure in victims by impersonating well-known companies, brands, and products. Released on Tuesday, Check Point's "Brand Phishing Report for Q2 2020" found that Google and Amazon were the most impersonated brands last quarter, each accounting for 13% of the brand phishing campaigns analyzed.

Google Updates Ad Policies to Counter Influence Campaigns, Extortion
2020-08-03 20:01

Google is making two changes in its advertising policy as the U.S. moves into the fall election season ahead of the presidential contest in November, in an attempt to thwart disinformation campaigns. For one, Google is updating its Google Ads Misrepresentation Policy to prevent coordinated activity around politics, social issues or "Matters of public concern," by requiring advertisers to provide transparency about who they are.

Google Analysis of Zero-Days Exploited in 2019 Finds 'Detection Bias'
2020-08-03 13:42

Google Project Zero last week released a report on the vulnerabilities exploited in attacks in 2019, and its researchers have drawn some interesting conclusions regarding the detection of zero-days. Google Project Zero has been tracking vulnerabilities exploited in the wild since 2014 and last year it made available a spreadsheet showing the flaws it has tracked.

We're suing Google for harvesting our personal info even though we opted out of Chrome sync – netizens
2020-07-28 19:40

A handful of Chrome users have sued Google, accusing the browser maker of collecting personal information despite their decision not to sync data stored in Chrome with a Google Account. The lawsuit [PDF], filed on Monday in a US federal district court in San Jose, California, claimed Google promises not to collect personal information from Chrome users who choose not to sync their browser data with a Google Account but does so anyway.

Australian Watchdog Accuses Google of Privacy Breaches
2020-07-27 12:11

Australia's consumer watchdog launched court action against Google on Monday alleging the technology giant misled account holders about its use of their personal data. The Australian Competition and Consumer Commission's action in the Federal Court is the latest litigation Google has faced around the world over allegations of privacy breaches.