Search

Find merged stories by title or summary.

Privacy
Emerging1 src

Google’s top hacker hunter explains why hacking groups get codenames

Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.

Google
·TechCrunch Cybersecurity
Read →
Vendors & Market
Emerging1 src

Google says hackers are calling financial firm employees to hack and extort victims

Groups of hackers are breaking into large U. S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.

Google
·TechCrunch Cybersecurity
Read →
Vendors & Market
Emerging1 src

Still using Google Assistant? It’s time to look for a replacement - Cybernews

Still using Google Assistant? It’s time to look for a replacement Cybernews

Google
·Cybernews
Read →
Phishing
Emerging1 src

Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked. Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key? Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure but the software surrounding them still has weaknesses. What are passkeys? Passkeys are a password replacement based on public‑key cryptography. Instead of a secret you remember and type, each account gets a key pair where the private key never leaves your devices, and the website only ever sees the public key and signed challenges.

Google
·Malwarebytes Labs
Read →
Threat Actors & Campaigns
Emerging1 src

Malware on your device can access Google passkeys and use them as its own - Cybernews

Malware on your device can access Google passkeys and use them as its own Cybernews

Google
·Cybernews
Read →
Breaches & Ransomware
Emerging1 src

Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

On August 4, 2026, a malicious version of keyv was published to npm as keyv@6. 0. 0 , one of a number of npm packages affected across the Keyv and Cacheable ecosystem. The release follows the Mini Shai-Hulud pattern: a trojanized version of a heavily depended-on package, with an install-time hook that reaches cloud and CI credentials. It leaves the compiled library untouched and instead adds a preinstall hook and two files. The second of those files carries names and endpoints for AWS, HashiCorp Vault, Kubernetes, Google Cloud, Azure, npm, and GitHub Actions credentials, batched collection, and repository creation through GitHub’s own API. Technical analysis npm install └─ preinstall hook in package. json └─ setup. mjs └─ Math_Symbol. js, run under a downloaded Bun runtime Figure 1: The entry path, from a dependency install to the bundled file. What changed keyv@6. 0.

GoogleAws
·Mend.io Blog
Read →
Vendors & Market
Emerging1 src

Online backlash ends in Google rolling back Google Earth AI tool after a day

Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes. Google switched on the AI image generation feature inside Google Earth’s web version on July 30. It was available to everyone. The system used Google’s Nano Banana 2 image generator to create its images. That tool can already generate images from simple text input, but the advantage of doing it in Google Earth is that it can use the real satellite images as the basis for its deepfake versions. That makes it easier to make AI pictures with real, accurate building and landscape details. In its initial blog post on the launch, it said that students could use it to “bring history to life”, while realtors could use it to produce professional real estate plans. However, others warned that the system could be used to mislead people.

Google
·Malwarebytes Labs
Read →
AI Security
Emerging1 src

[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis

Hey there, I hope you’ve been doing well! 🤗 Hugging Face Incident It’s been… a week 😅 In case you haven’t heard, this week OpenAI published a blog post saying that the recent AI-powered attack on Hugging Face was in fact… GPT‑5.6 Sol and a pre-release model. I feel very fortunate to have been able to see things unfold behind the scenes and contribute to the blog. Unfortunately I can’t say more at this time, other than I am very impressed by my colleagues. Sponsor

Google
·TLDR Sec
Read →
AI Security
Emerging1 src

Google’s Gemini lets strangers send messages from your locked Android phone

Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.

Google
·Graham Cluley
Read →
AI Security
Emerging1 src

Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.

GoogleAdobe
·Graham Cluley
Read →
Vendors & Market
Emerging1 src

Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Meanwhile, "FortiBleed" sees 75,000 Fortinet firewalls thrown wide open - and the real damage is going to roll on for years. All this and more in episode 474 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Quentyn T

GoogleFortinet
·Graham Cluley
Read →
AI Security
Emerging1 src

[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security

Hey there, I hope you’ve been doing well! 🤔 New Job, Who Dis? TL;DR : I’ve joined OpenAI to lead their Cyber efforts. I’m joined by Mike Aiello , an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs. I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can. So here’s the short version. Why

GoogleAws
·TLDR Sec
Read →
Vulnerabilities & Patches
Emerging1 src

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the following developments: • Vulnerability Discovery and Exploit Generation: For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI.

Google
·Mandiant / Google TI
Read →
Phishing
Emerging1 src

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim’s inherent trust in several different enterprise software providers.

MicrosoftGoogleAmazonAws
·Mandiant / Google TI
Read →
Breaches & Ransomware
Emerging1 src

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany moved to the forefront of European data leak targets in 2025. Following a 2024 period where the UK led in DLS victims, this pivot reflects a resurgence of the intense pressure observed across German infrastructure during 2022 and 2023. This targeting is not a result of the overall number of companies within Europe, as Germany has fewer active enterprises than France or Italy.

Google
·Mandiant / Google TI
Read →
AI Security
Emerging1 src

Amp Code: Invisible Prompt Injection Fixed by Sourcegraph

In this post we will look at Amp, a coding agent from Sourcegraph. The other day we discussed how invisible instructions impact Google Jules . Turns out that many client applications are vulnerable to these kinds of attacks when they use models that support invisible instructions, like Claude. Invisible Unicode Tag Characters Interpreted as Instructions We have talked about hidden prompt injections quite a bit in the past , and so I’m keeping this short.

Google
·Embrace The Red (AI agent security)
Read →
AI Security
Emerging1 src

Google Jules is Vulnerable To Invisible Prompt Injection

The latest Gemini models quite reliably interpret hidden Unicode Tag characters as instructions . This vulnerability, first reported to Google over a year ago, has not been mitigated at the model or API level, hence now affects all applications built on top of Gemini. This includes Google’s own products and services, like Google Jules. Hopefully, this post helps raise awareness of this emerging threat. Invisible Prompt Injections in GitHub Issues When Jules is asked to work on a task, such as a GitHub issue, it is possible to plant invisible instructions into a GitHub issue to add backdoor code, or have it run arbitrary commands and tools.

Google
·Embrace The Red (AI agent security)
Read →
AI Security
Emerging1 src

Jules Zombie Agent: From Prompt Injection to Remote Control

In the previous post , we explored two data exfiltration vectors that Jules is vulnerable to and that can be exploited via prompt injection. This post takes it further by demonstrating how Jules can be convinced to download malware and join a remote command & control server. This research was performed in May 2025 and findings were shared with Google. Remote Command & Control - Proof Of Concept The basic attack chain follows the classic AI Kill Chain:

Google
·Embrace The Red (AI agent security)
Read →
Breaches & Ransomware
Emerging1 src

Google Jules: Vulnerable to Multiple Data Exfiltration Issues

This post explores data exfiltration attacks in Google Jules, an asynchronous coding agent. This is the first of three posts that will highlight my research on Google Jules in May 2025. All information provided was also shared with Google at that time. This first post will focus on data exfiltration, the lethal trifecta . But let’s first talk about Jules’ system prompt. Jules’ System Prompt and Multiple Agents To grab the system prompt I just asked it to write it into a file.

Google
·Embrace The Red (AI agent security)
Read →
AI Security
Emerging1 src

Mitigating prompt injection attacks with a layered defense strategy

Posted by Adam Gavish, Google GenAI Security Team With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or calendar invites that instruct AI to exfiltrate user data or execute other rogue actions. As more governments, businesses, and individuals adopt generative AI to get more done, this subtle yet potentially potent attack becomes increasingly pertinent across the industry, demanding immediate attention and robust security measures.

Google
·Google Online Security Blog
Read →
Vulnerabilities & Patches
Emerging1 src

Android 14 November security patch rolling out

With the November security patch, Google today is rolling out the first update to Android 14 since launch for the following Pixel devices: 4a 5G, 5, 5a, 6, 6 Pro, 6a, 7, 7 Pro, 7a, Tablet, Fold, 8, and 8 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 13 September security update rolling out for Pixel

Google is rolling out Android 13’s September update for the Pixel 4a 5G, 5, 5a, 6, 6 Pro, 6a, 7, 7 Pro, 7a, Tablet and Fold today. It comes two weeks after when Google usually releases monthly Pixel updates as we wait for Android 14 , and is just a security patch.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 13 August security patch rolling out: What’s fixed for Pixel

While we wait for the next major version of Google’s mobile OS to hit stable, the Android 13 August update for the Pixel 4a, 4a 5G, 5, 5a, 6, 6 Pro, 6a, 7, 7 Pro, 7a, and Fold is rolling out today.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Pixel Tablet July 2023 update rolling out with two fixes

With tablets, Google now has a third Pixel form factor following phones and watches. The Android 13 July 2023 security patch is rolling out today as the first monthly update for the Pixel Tablet.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Pixel April 2023 update is late, marking second delay in a row

Historically, Pixel security patches are released on the first Monday of the month at 10 a. m. PT. Following last month’s situation , Google has yet to release the April 2023 update for the Pixel 4a to 7 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

March Pixel Feature Drop with Android 13 QPR2 now rolling out

After a week-long delay, Google today is rolling out Android 13 QPR2 with the March security patch and the first Pixel Feature Drop of 2023.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 13 QPR1 for Google Pixel phones rolling out with December security patch

Android 13 sees Google continue with the concept of Quarterly Platform Releases and QPR1 is now rolling out to Pixel phones with the December security patch and Feature Drop .

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 13 with November security patch live, download Pixel OTA image now [U]

Google is rolling out the first update to the Pixel 7 and 7 Pro today with the Android 13 November security patch, while the supported devices list now starts with the Pixel 4a.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

The Pixel’s August update looks to have been delayed [U: New July patch for 6/Pro]

In most cases, Google rolls out the latest Android security patch to Pixel phones on the first Monday of every month. That did not occur this morning, and it looks like the August Pixel update has been delayed.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 July security patch rolling out to Google Pixel, factory images & OTAs live

The latest update of 2021 is rolling out today with the Android 12 December security patch for the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, Pixel 5a, Pixel 6, and Pixel 6 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 QPR3 June security patch rolling out to Google Pixel, factory images & OTAs live

After three months of testing , Android 12 QPR3 with the June security patch is rolling out today for the Pixel 4/XL, Pixel 4a, Pixel 4a 5G, Pixel 5, Pixel 5a, Pixel 6, and Pixel 6 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 April security patch rolling out to Google Pixel, factory images & OTAs live

Following last month’s launch of 12L , Android 12’s April security patch is rolling out to the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, Pixel 5a, Pixel 6, and Pixel 6 Pro today. It comes as Android 12 QPR3 is in beta and Android 13 is set to follow this month.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12.1 March security patch rolling out to Google Pixel, factory images & OTAs live

Android 12. 1 with the March security patch is rolling out today for the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, and Pixel 5a. [ Update : The Pixel 6 and Pixel 6 Pro will see SP2A. 220305. 013. A3 (Global build) OTAs “later this month.” ]

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Pixel 3 and 3 XL get final update with February security patch

Google today rolled out the final update for the Pixel 3 and 3 XL. This update was targeted for the first quarter of 2022 back in November.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 January security patch rolling out to Google Pixel, factory images & OTAs live

Following last month’s big update , the Android 12 January security patch is rolling out today for the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, and Pixel 5a. This update is not yet available for the Pixel 6 or 6 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 November security patch rolling out to Google Pixel, factory images & OTAs live

The first update to Android 12 is rolling out today with the November security patch for the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, Pixel 5a, Pixel 6, and Pixel 6 Pro.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 12 with October security patch live, download Pixel factory images & OTAs

Alongside the new phones , Google today is launching Android 12 for current Pixel devices. In addition to Material You, revamped Quick Settings, and a slew of other Android 12 additions, it features the October security patch. If it hasn’t rolled out to your device yet, Google just posted the official OTA and factory images.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

Android 11 October security patch rolling out to Google Pixel, factory images & OTAs live

Android 12 is not launching today . As such, we only have the October security patch with another Android 11 update for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), Pixel 5, and Pixel 5a.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

September security patch rolling out to Google Pixel, factory images & OTAs live

With Beta 4.1 , Android 12 is almost ready to launch, but until then Android 11 with the September security patch is now available for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), Pixel 5, and Pixel 5a.

Google
·9to5Google Security
Read →
Vulnerabilities & Patches
Emerging1 src

August security patch rolling out to Google Pixel, factory images & OTAs live

While the Android 12 Beta has improved in stability over recent releases, Android 11 still provides the most reliable experience. Google is now rolling out the August security patch for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), and Pixel 5.

Google
·9to5Google Security
Read →