Search

Find merged stories by title or summary.

Breaches & Ransomware
Emerging1 src

Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts

Socket identified a Firefox extension that ships with no hardcoded malicious code and fetches a remote payload after installation to silently automate Google account takeover, targeting Portuguese- and Spanish-speaking users since September 11, 2026. Socket's Threat Research team identified a malicious Firefox extension posing as a utility for identity verification before opening protected PDF documents. The extension, pdf-para-texto@extensao. local , was published to the Firefox Add-ons store on September 3, 2026, and its malicious functionality was first introduced in version 1. 4 on September 11, 2026. The extension does not have a significant user base, and the expected impact is fairly low.

·Socket Security Blog
Read →
Vendors & Market
Emerging1 src

[$] Ideas on modernizing the open-source desktop

Scott Jenson has been working on user interfaces (UIs) and user experience (UX) for many years at Apple, Google, and other companies. Now, he's trying to convince open-source projects to experiment more and drive the desktop beyond the age-old " windows, icons, menus, pointer " (WIMP) model. At Akademy 2026 , KDE's annual developer conference, he shared his complaints and ideas in a talk aimed at convincing those in attendance to take the lead on desktop design.

·LWN.net
Read →
Phishing
Emerging1 src

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.

·Dark Reading
Read →
Vulnerabilities & Patches
Emerging1 src

How One Kubernetes YAML Can Hand Over a GCP Organization

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Wednesday

Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.

·LWN.net
Read →
Phishing
Emerging1 src

Fake Claude Max giveaway hides a Google account phishing trap

Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach.

·Malwarebytes Labs
Read →
AI Security
Emerging1 src

The president has called for AI leadership. Here’s the mission.

America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control. President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear leadership, accountability and action inside the U. S. government. The question now is what that leadership should do. That question became more urgent last week when Google disclosed that its Gemini AI model gained unauthorized access to three real companies during testing. The incidents follow similar disclosures involving models from Anthropic, OpenAI and Meta.

·CyberScoop
Read →
Vulnerabilities & Patches
Emerging1 src

Google Chrome 154 Patches 108 Security Flaws Including 11 Critical Vulnerabilities

Google has rolled out Chrome 154 to the Stable channel for Windows, Mac, and Linux, delivering fixes for 108 security vulnerabilities. The update, version 154. 0. 8037. 57 for Linux and 154. 0. 8037. 57/. 58 for Windows and Mac, addresses one of the largest security patch batches Chrome has shipped in recent memory, including 11 flaws rated Critical severity The most severe issues affect Chrome’s graphics and rendering stack. Multiple critical bugs were found in ANGLE, Chrome’s cross-platform graphics abstraction layer, including buffer overflows. Google Chrome 154 Patches 108 Security Flaws Additional critical flaws hit the GPU process, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter components, with largely use-after-free and out-of-bounds write issues that could allow an attacker to achieve remote code execution or sandbox escape via a malicious web page.

·CyberPress
Read →
Threat Actors & Campaigns
Emerging1 src

Inside a multi stage toll fraud operation targeting Poland

CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking. Inside a multi stage toll fraud operation targeting Poland • CERT Polska

·Malware.news
Read →
AI Security
Emerging1 src

Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI

Claude Opus 5. 5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Built for long and complex tasks Opus 5. 5 is designed for codebase migrations, software audits, financial analysis, data collection and workflows involving several applications. Early testers used the model for engineering tasks that ran … More → The post Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

·The Hacker News
Read →
Threat Actors & Campaigns
Emerging1 src

New ClosedQuorum Windows malware uses AI for attack decisions

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [... ]

·BleepingComputer
Read →
AI Security
Emerging1 src

CAIRN – A New Tool to Track AI Malware That Operates Without Human Control

Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research Network searches for prompt templates, provider endpoints, API-key prefixes, jailbreak terms, and orchestration logic without downloading or executing binaries. The launch also revealed CLOSEDQUORUM, which Talos describes as the first publicly documented Windows implant to delegate tactical command-and-control decisions to artificial intelligence. Instead of awaiting instructions from a human operator or dedicated C2 server , the malware consults up to four commercial large language models—DeepSeek, Qwen, Mistral, and Google Gemini and uses plurality voting to choose its next action. Talos has not confirmed real-world deployment, and the public build is nonfunctional.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

Data Center Cyber Claims Rank Second. The Larger Exposure Is Invisible

The post Data Center Cyber Claims Rank Second. The Larger Exposure Is Invisible. appeared first on Silent Push . https://cyberinsurancenews.org/data-center-cyber-claims-allianz-accumulation/#google_vignette#new_tab?utm_source=rss&utm_medium=rss&utm_campaign=data-center-cyber-claims-rank-second-the-larger-exposure-is-invisible1post-1participantReadfulltopic

·Malware.news
Read →
Privacy
Emerging1 src

Google gets another $460 million fine for misusing user data

The Irish data privacy regulator found Google guilty misusing users' location history and web activity.

·Android Authority
Read →
Threat Actors & Campaigns
Emerging1 src

Beware these fake websites selling subscriptions to AI assistants

Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The sites impersonate AI products with solid reputations, including GPT-6 Astra , DaVinci Resolve , PixAI and OpenCut , in addition to some that no longer exist (such as Omegle, a chat service shut down in 2023) or are less reputable. All the fake websites were polished and incorporate genuine Google authentication elements inviting users to “Sign in with Google” to enhance credibility on the path to charging visitors’ payment cards anything from $10 a month to as much as $2,000 for a year’s access to the promised AI and software services. “The sites we examined did not use fake password forms or push malware downloads,” Malwarebytes researchers said in a blog post describing their discovery .

·CSO Online
Read →
Breaches & Ransomware
Emerging1 src

Webinar tomorrow: Inside real-world Google Workspace breaches

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [... ]

·BleepingComputer
Read →
AI Security
Emerging1 src

AI agents need boundaries, Google Cloud executive warns - Cybernews

AI agents need boundaries, Google Cloud executive warns Cybernews

·Cybernews
Read →
Vendors & Market
Emerging1 src

Samsung Studio is a solid video editor, but this open source Android alternative is better

One of my friends switched from the Samsung Galaxy ecosystem to the Google Pixel a few years ago, only to regret it later because of losing access to some of Samsung's excellent features.

·Android Police
Read →
Threat Actors & Campaigns
Emerging1 src

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details. The network includes sites that copy the names of existing products, among them GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. One site uses the name … More → The post Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions appeared first on Help Net Security .

·Help Net Security
Read →
AI Security
Emerging1 src

Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’

A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the May incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: Google, Anthropic, OpenAI and Meta. All four companies experienced agent misbehavior resulting in cybersecurity incidents, but of the four, only Google never publicly disclosed its agent’s activities. Indeed, it didn’t reveal the breaches at all until contacted by a WSJ reporter. Irregular described the incident in August, around the same time as Meta published its version and Anthropic and OpenAI revealed theirs .

·CSO Online
Read →
Breaches & Ransomware
Emerging1 src

A very real-world AI test.

Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn . CyberWire Guest Today we are joined by Matt Fredrikson , Carnegie Mellon University Associate Professor and CEO of Gray Swan AI, discussing OpenAI's Astra and real industry risks.

·The CyberWire
Read →
Privacy
Emerging1 src

Google Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after receiving complaints from several European consumer groups, including BEUC, about how Google handled location data. The investigation covered the period from 25 May 2018, when the GDPR came into force, to 4 February 2020. “The scope of the Inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy” between the date of application of the GDPR, 25 May 2018 to 4 February 2020.” reads the DPC’s press release .

·Security Affairs
Read →
Privacy
Emerging1 src

EU data regulator fines Google more than $460 million for location data violations

Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.

·The Record
Read →
Breaches & Ransomware
Emerging1 src

Google Hit With $463 Million Fine for EU Location Data Rule Breach

Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Google Wants Android Apps to Look Beyond the Security Patch Date - techrepublic.com

Google Wants Android Apps to Look Beyond the Security Patch Date techrepublic.com

·TechRepublic Cybersecurity
Read →
Policy & Regulation
Emerging1 src

Google Fined €403 Million Over GDPR Violations Tied to Location Data

Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which

·The Hacker News
Read →
Policy & Regulation
Emerging1 src

Google Fined €403 Million for GDPR Violations Over Users’ Location Data

Ireland’s Data Protection Commission (DPC) has fined Google Ireland Limited €403 million after concluding that the technology giant violated the General Data Protection Regulation (GDPR) while processing users’ location data . Announced on September 21, 2026, the decision also orders Google to bring the affected processing operations into compliance within six months. The enforcement action follows an own-volition inquiry opened in February 2020 after the regulator received complaints from several European consumer-rights organizations, including BEUC. Acting as Google’s lead supervisory authority in the European Union, the DPC examined location-data processing carried out from May 25, 2018, the date the GDPR became applicable, through February 4, 2020.

·Cyber Security News
Read →
Policy & Regulation
Emerging1 src

Ireland fines Google €403 million over location data processing

Ireland’s Data Protection Commission (DPC) has fined Google €403 million after finding that the company violated multiple GDPR requirements while processing users’ location data. The regulator also ordered Google to bring the affected processing practices into compliance within six months. The decision follows an own-volition inquiry launched by the DPC in February 2020 after complaints … The post Ireland fines Google €403 million over location data processing appeared first on CyberInsider .

·CyberInsider
Read →
Privacy
Emerging1 src

Google fined €403 million over location data privacy violations

Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [... ]

·BleepingComputer
Read →
Threat Actors & Campaigns
Emerging1 src

The fake sites using a cheap toolkit to sell $2,000 AI subscriptions

We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them. The sites we examined did not use fake password forms or push malware downloads. Instead, they used polished product pages and genuine Google sign-in screens before directing visitors to paid plans. Someone visiting an imitation site could believe they were buying from the genuine provider. With the unfamiliar brands, it is difficult to establish who is selling the subscription or independently verify the claims being made.

·Malwarebytes Labs
Read →
Policy & Regulation
Emerging1 src

Google Hit with €403m GDPR Fine Over Location Data Practices

The Irish DPC found that Google users were unaware that their location was being used to influence them with ads

·Infosecurity Magazine
Read →
AI Security
Emerging1 src

Gemini’s breach of real companies exposes an AI guardrail problem

Google says one of its Gemini models accessed systems belonging to three real companies during a cybersecurity evaluation in May. The model reportedly guessed credentials in one case, while finding exposed credentials in public repositories in two others. Google says Gemini stopped once it recognized that it had reached real infrastructure and that the affected organizations were notified. Gemini was participating in an evaluation run by Irregular, a third-party AI cybersecurity testing firm. Similar incidents involving models from Anthropic, OpenAI, and Meta have also been linked to the same underlying problems with evaluation environments that allowed the models to reach the public internet. But the news arrives at a particularly interesting moment.

·Malwarebytes Labs
Read →
AI Security
Emerging1 src

Google AI models broke out of sandbox, hacked three companies

The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta.

·Cybersecurity Dive
Read →
Vulnerabilities & Patches
Emerging1 src

Orphaned VMs: Running VMs Uninterrupted While Host Kernel Is Offline For Reboots/Updates

Here's some very intriguing work taking place by a Google engineer... With the hyperscalers and other cloud providers pushing for zero-downtime, a set of experimental patches for "Orphaned VMs" allow for the virtual machines to continue to run while the host kernel is offline for security updates or rebooting with the Live Update Orchestrator. The experimental patches and request for feedback from other Linux kernel stakeholders was sent out this weekend on Orphaned VMs...

·Phoronix
Read →
Breaches & Ransomware
Emerging1 src

Google Confirms Gemini AI Breached Three Firms

Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek .

·SecurityWeek
Read →
AI Security
Emerging1 src

BragJack Attack Lets Browser Extensions Hijack AI Agents Across Chrome, Edge and Comet

A newly disclosed BragJack is a browser-extension attack technique that can hijack built-in AI assistants across five AI-enabled browsers. The research demonstrates how a single malicious browser extension could allegedly abuse trusted communication paths between cloud-hosted AI models and privileged browser agents, enabling unauthorized commands, sensitive-data access, and browser-level actions. Forever Security researcher Gal Weizman reported that BragJack affected Gemini Live in Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. BragJack Attack Lets Browser Extensions Hijack AI Agents The vulnerabilities were disclosed to vendors through responsible channels and generated bounty awards from Google, Microsoft, Perplexity, Opera, and Anthropic. The findings include CVE-2026-0628 and CVE-2026-55945.

·CyberPress
Read →
AI Security
Emerging1 src

Google Gemini AI Autonomously Hacked Three Companies During Cybersecurity Test

Google has confirmed that a Gemini model accessed the systems of three real companies during a May cybersecurity evaluation, after an unintended internet connection let the agent move beyond its intended test environment. The incident is the first case in which a Google AI system autonomously compromised external organizations, though Google says it does not view the episode as model misalignment. Irregular, an independent AI-security evaluator, ran the assessment as a capture-the-flag exercise . Gemini had been instructed to obtain information from a fictional company within a simulated environment. Google Gemini AI Autonomously Hacked Three Companies However, the model could access the open internet, and the fictional entity’s name overlapped with that of a real organization.

·CyberPress
Read →
Threat Actors & Campaigns
Emerging1 src

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum Brevo Supply-Chain Attack Infected Over 100,000 Websites Gyazo Data Breach Exposes 23 Million User Records RatHat Turns Android Accessibility Into an Attack Weapon Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution OpenAI admits its models lie to cover their own mistakes Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown U. S.

·Security Affairs
Read →
Privacy
Emerging1 src

Samsung's AI privacy switch doesn't stop Google from collecting your data

Artificial Intelligence is a huge part of modern smartphones, so much so that many of the Google Pixel 11's differentiating features over its predecessor were AI features.

·Android Police
Read →