Security News

Google’s monthly Android updates patch numerous “get root” holes
2022-04-05 18:44

If you go off-market, things can get much more dangerous, not least because there are many unofficial Android app stores out there where pretty much anything goes, including some app repositories that deliberately pitch themselves as a handy place to get at software that Google "Doesn't want you to have". As an aside, you might think that no one would deliberately seek out apps that clearly wouldn't be permitted on Google Play, or that have already been rejected by Google.

Mandiant shareholder sues to block $5.4b Google deal
2022-04-04 20:31

A Mandiant shareholder has launched a legal challenge to block Google's $5.4 billion takeover of the threat intelligence firm. According to a lawsuit filed in a New York federal district court by shareholder Shiva Stein, Mandiant made "Materially incomplete and misleading" statements to investors in financial documents filed with the US Securities and Exchange Commission about the planned acquisition.

Easily manage your Google activity with this handy tool
2022-04-04 15:46

Open your web browser and head to the Google My Activity site. Once you've verified it's you, you should see the full My Activity page, where you can begin managing your activity.

Google: Russian credential thieves target NATO, Eastern European military
2022-04-01 10:20

A Russian cybercrime gang has lately sent credential-phishing emails to the military of Eastern European countries and a NATO Center of Excellence, according to a Google threat report this week. One of these crews is Coldriver, which the Google team refer to as "a Russian-based threat actor." According to Leonard, Google hasn't seen attackers successfully compromise any Gmail accounts in its phishing campaigns.

Researchers Expose Mars Stealer Malware Campaign Using Google Ads to Spread
2022-03-30 20:09

A nascent information stealer called Mars has been observed in campaigns that take advantage of cracked versions of the malware to steal information stored in web browsers and cryptocurrency wallets. "Mars Stealer is being distributed via social engineering techniques, malspam campaigns, malicious software cracks, and keygens," Morphisec malware researcher Arnold Osipov said in a report published Tuesday.

Google: Russian phishing attacks target NATO, European military
2022-03-30 17:44

The Google Threat Analysis Group says more and more threat actors are now using Russia's war in Ukraine to target Eastern European and NATO countries, including Ukraine, in phishing and malware attacks. The report's highlight are credential phishing attacks coordinated by a Russian-based threat group tracked as COLDRIVER against a NATO Centre of Excellence and Eastern European militaries.

Google Chrome Bug Actively Exploited as Zero-Day
2022-03-30 16:14

Google has updated its Stable channel for the desktop version of Chrome, to address a zero-day security vulnerability that's being actively exploited in the wild. The bug, tracked as CVE-2022-1096, is a type-confusion issue in the V8 JavaScript engine, which is an open-source engine used by Chrome and Chromium-based web browsers.

North Korean threat actors target news outlets and fintechs with a Google Chrome vulnerability
2022-03-30 14:07

Threat actors from North Korea have been exploiting a vulnerability in Google Chrome to target certain users with remote code, particularly news outlets, software vendors and fintechs in the United States. On Feb. 10, Google's TAG team discovered two distinct threat actors using that vulnerability to target U.S.-based organizations spanning news media, IT, cryptocurrency and fintech industries.

Mars Stealer malware pushed via Google Ads and phishing emails
2022-03-30 13:12

Cybercriminals trying to foist the Mars Stealer malware onto users seemingly have a penchant for one particulat tactic: disguising it as legitimate, benign software to trick users into downloading it. In a recent campaign described by Morphisec malware researcher Arnold Osipov, the threat actor distributed the malware via cloned websites offering well-known software such as Apache Open Office.

Google Chrome 100 released with new features, icon, and more
2022-03-29 21:55

Google has released Chrome 100 today, March 29th, 2022, to the Stable desktop channel, and it includes a new logo, security improvements, development features, and more. Today, Google promoted Chrome 100 to the Stable channel, Chrome 101 as the new Beta version, and Chrome 102 will be the Canary version.