Security News

Whizkids jimmy OpenAI, Google's closed models
2024-03-13 08:34

Boffins have managed to pry open closed AI services from OpenAI and Google with an attack that recovers an otherwise hidden portion of transformer models. "We thereby confirm, for the first time, that these black-box models have a hidden dimension of 1024 and 2048, respectively. We also recover the exact hidden dimension size of the gpt-3.5-turbo model, and estimate it would cost under $2,000 in queries to recover the entire projection matrix."

Google paid $10 million in bug bounty rewards last year
2024-03-12 16:00

Google awarded $10 million to 632 researchers from 68 countries in 2023 for finding and responsibly reporting security flaws in the company's products and services.Though this is lower than the $12 million Google's Vulnerability Reward Program paid to researchers in 2022, the amount is still significant, showcasing a high level of community participation in Google's security efforts.

YouTube stops recommending videos when signed out of Google
2024-03-10 22:16

YouTube is no longer showing recommended videos to users logged out of a Google account or using Incognito mode, making people concerned they are being bullied into always being signed into the service. This change, which is now rolling out, shows a simple YouTube homepage without any videos or tips on what to watch.

Google engineer caught stealing AI tech secrets for Chinese firms
2024-03-07 14:56

The U.S. Department of Justice has announced the unsealing of an indictment against Linwei Ding, 38, a former software engineer at Google, suspected of stealing Google AI trade secrets for Chinese companies. The allegedly stolen trade secrets involve crucial technology underpinning Google's advanced supercomputing data centers, which are essential for training and hosting large AI models capable of processing nuanced language and generating intelligent responses.

Ex-Google Engineer Arrested for Stealing AI Technology Secrets for China
2024-03-07 10:19

The U.S. Department of Justice (DoJ) announced the indictment of a 38-year-old Chinese national and a California resident of allegedly stealing proprietary information from Google while covertly...

Watch Out for Spoofed Zoom, Skype, Google Meet Sites Delivering Malware
2024-03-07 06:11

Threat actors have been leveraging fake websites advertising popular video conferencing software such as Google Meet, Skype, and Zoom to deliver a variety of malware targeting both Android and...

Lawsuit claims gift card fraud is the gift that keeps on giving, to Google
2024-03-07 01:15

A class action complaint [PDF], filed Tuesday in federal court for the District of Northern California, claims that "Over nearly a decade, Google has knowingly kept millions of dollars in stolen money from victims of gift card scams who purchased Google Play gift cards." Filed on behalf of Indiana resident Judy May, the suit alleges Google keeps funds from stolen Google Play gift cards - either by taking its 15-30 percent commission from payments to Google Play app developers made with fraudulently obtained gift cards, or by withholding all funds paid via scammed gift cards for its own benefit.

Chinese chap charged with stealing Google’s AI datacenter secrets
2024-03-07 00:37

The US Department of Justice on Wednesday revealed an indictment that charges a former Google employee with leaking the ad giant's AI tech to two Chinese companies - after easily defeating the Big G's security controls. The indictment names Linwei Ding, aka Leon Ding, and states that during his time at Google his job involved "Development of software that allowed GPUs to function efficiently for machine learning, AI applications, or other purposes required by Google or Google Cloud clients."

How to Find and Fix Risky Sharing in Google Drive
2024-03-06 09:48

Every Google Workspace administrator knows how quickly Google Drive becomes a messy sprawl of loosely shared confidential information. This isn't anyone's fault; it’s inevitable as your...

Banking Trojans Target Latin America and Europe Through Google Cloud Run
2024-02-26 09:51

Cybersecurity researchers are warning about a spike in email phishing campaigns that are weaponizing the Google Cloud Run service to deliver various banking trojans such as Astaroth (aka...