Security News

Google Chrome Beta Tests New DBSC Protection Against Cookie-Stealing Attacks
2024-04-03 13:07

Google on Tuesday said it's piloting a new feature in Chrome called Device Bound Session Credentials (DBSC) to help protect users against session cookie theft by malware. The prototype – currently...

Authy vs Google Authenticator: Two-Factor Authenticator Comparison
2024-04-03 13:00

Authy and Google Authenticator are two popular two-factor authentication tools that do just that. Another popular authenticator app is Google Authenticator.

Google bakes new cookie strategy that will leave crooks with a bad taste
2024-04-03 12:08

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Class-Action Lawsuit against Google’s Incognito Mode
2024-04-03 11:01

Google has agreed to delete "Billions of data records" the company collected while users browsed the web using Incognito mode, according to documents filed in federal court in San Francisco on Monday. The agreement, part of a settlement in a class action lawsuit filed in 2020, caps off years of disclosures about Google's practices that shed light on how much data the tech giant siphons from its users­-even when they're in private-browsing mode.

How Google plans to make stolen session cookies worthless for attackers
2024-04-03 05:30

Google is working on a new security feature for Chrome called Device Bound Session Credentials, meant to prevent attackers from using stolen session cookies to gain access user accounts. Session cookies are stored by browsers when a user logs into web resources.

Google agrees to delete Chrome browsing data of 136 million users
2024-04-02 17:07

Google has agreed to delete billions of data records collected from 136 million Chrome users in the United States, as part of a lawsuit settlement regarding alleged undisclosed browser data collection while in Incognito mode. Key elements of the Settlement include changes to Google's disclosures regarding its data collection practices, the deletion of billions of data records, implementing measures to curb the future accumulation of personal information, and eliminating mechanisms that enabled the tracking of users in Incognito mode without their knowledge.

Google to Delete Billions of Browsing Records in 'Incognito Mode' Privacy Lawsuit Settlement
2024-04-02 07:08

Google has agreed to purge billions of data records reflecting users' browsing activities to settle a class action lawsuit that claimed the search giant tracked them without their knowledge or...

Google now blocks spoofed emails for better phishing protection
2024-04-01 20:29

Google has started automatically blocking emails sent by bulk senders who don't meet stricter spam thresholds and authenticate their messages as required by new guidelines to strengthen defenses against spam and phishing attacks. Non-compliance may result in email delivery issues, including rejected emails or emails being automatically sent to recipients' spam folders.

Rust developers at Google are twice as productive as C++ teams
2024-03-31 16:33

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Zero-day exploitation surged in 2023, Google finds
2024-03-28 15:11

2023 saw attackers increasingly focusing on the discovery and exploitation of zero-day vulnerabilities in third-party libraries and drivers, as they can affect multiple products and effectively offer more possibilities for attack. Another interesting conclusion from Google's recent rundown of the 97 zero-days exploited in-the-wild in 2023 is that there's a notable increase in targeting enterprise-specific technologies.