Security news

Latest security news

48 of 1,256 storiesGoogleClear all

Tue, 8 Sept 2026

  1. Attackers Use Multi-Hop Google Redirects for Phishing Campaign

    Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

    Dark ReadingGoogle
  2. Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

    The Hacker NewsGoogle
  3. Webinar: The forgotten Google Workspace access that can lead to a breach

    Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure.

    BleepingComputerGoogle
  4. AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

    Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks

    Infosecurity MagazineGoogle
  5. Extortion crews have their eyes on high-value AI data, Google warns

    Companies 'don't want their IP exposed, so they're willing to pay'

    The RegisterGoogle
  6. ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

    Cisco TalosGoogle, Cisco

Mon, 7 Sept 2026

  1. Your Cloud Security Checklist Doesn't Work the Way You Think It Does

    If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers

    The Hacker NewsGoogle, AWS
  2. JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

    The Hacker NewsGoogle

Fri, 4 Sept 2026

  1. Google security advisory (AV26-883) – Update 1

    Serial Number: AV26-883 Date: September 4, 2026 As of September 3, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.82 Google is aware that an exploit for CVE-2026-85046 exists in the wild. Update 1 On September 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Stable Channel Update for Desktop CISA KEV: CVE-2026-85046

    CriticalUsed in attacksCanadian Centre for Cyber SecurityGoogle, Chrome
  2. Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

    CriticalUsed in attacksThe Hacker NewsGoogle, Chrome

About this news

1,256
Stories
39
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets