Security news

Latest security news

48 of 1,256 storiesGoogleClear all

Today · Wed, 16 Sept 2026

  1. Webinar: What happens in the first hours of a Google Workspace breach

    The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse.

    BleepingComputerGoogle
  2. Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

    CriticalUsed in attacksThe Hacker NewsGoogle
  3. Google fixes actively exploited Android zero-day on Pixel devices

    Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.

    BleepingComputerGoogle, Android

Yesterday · Tue, 15 Sept 2026

  1. KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

    The Hacker NewsGoogle, Chrome
  2. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows

Mon, 14 Sept 2026

  1. Google’s new search redirects make links harder to check before you click

    Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.

    Malwarebytes LabsGoogle
  2. Webinar: How malicious OAuth apps can lead to Google Workspace breaches

    Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them.

    BleepingComputerGoogle
  3. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

    The Hacker NewsGoogle, Chrome, Firefox

Thu, 10 Sept 2026

  1. Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their

    The Hacker NewsGoogle, Android
  2. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.

    BleepingComputerGoogle, Microsoft, Windows

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets