10 Oct, 2026

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. The company’s OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings […]

3 mins read

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google’s Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. As spotted by TestingCatalog on X, Google is testing desktop control for Gemini, and there are references to a new hidden “Additional sandbox options” setting in the Gemini Desktop app. […]

2 mins read

Google fined €403 million over location data privacy violations

Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data. The agency launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations. It examined three Google features that were active during the GDPR application period from May 25, 2018, through […]

3 mins read

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The company began rolling out patched versions to Windows (153.0.8010.36), Mac […]

2 mins read

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal […]

2 mins read

Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly flag legitimate Google search links as malicious. The company first acknowledged the incident (tracked under MO1465962) at 10:30 AM UTC and says affected users are seeing “Opening this website might not be safe” warnings when trying to open the blocked hyperlinks. […]

2 mins read

Android 17 adds ECH support to make web browsing harder to track

Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users’ home networks. Android 17 adds support for Encrypted Client Hello (ECH), a new privacy standard that operates in conjunction with private DNS to hide profiling metadata, including visited domain names. ECH acts […]

2 mins read

How Anthropic plans to watermark Claude’s AI-generated text

It could soon become easier to identify AI-generated content, even if it’s not the usual “It’s Not X, it’s Y” type of post you’d come across on LinkedIn and other socials. As you may be aware, the EU now requires AI companies serving its market to mark their AI-generated content so it’s easier to identify. […]

9 mins read

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. In a new blog post, Google argues that notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests. To reduce the abuse, Google developed a “Swiss […]

2 mins read

Google Blogger locks hundreds of blogs in malware false positive

Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites actually deleted from the platform. The issue began on August 4, and it appears to affect many legitimate blogs that do not host malware or have malicious scripts. As seen by […]

2 mins read