Google says it blocks 18 million daily malware and phishing emails related to COVID-19 plus another 240 million daily spam messages related to the coronavirus pandemic.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Survey expressing anti-Microsoft sentiment was paid for in part and published by Google Cloud. It polled 2,600 currently employed residents of the US, 338 of these government employees.
Google Cloud will enforce mandatory MFA by the end of 2025 due to the sensitive nature of cloud deployments and phishing and stolen credentials being top attack vectors.
Google says initial access broker Exotic Lily targeted at least 650 organizations with about 5,000 phishing emails per day to obtain credentials for selling to ransomware gangs.
A long-term Chinese cyber espionage operation that has been active since at least 2017 and has a count of at least 53 victims has been substantially disrupted, according to the Google Threat Intelligence Group (GTIG) and Mandiant.
Pernicious botnet used for cryptojacking has taken a major blow thanks to Google. Glupteba has been operating for some months and was thought to be compromising thousands of people per day at its peak.
Google fixed the Gmail bug that allowed email spoofing, a few hours after a disgruntled researcher published the exploit code. Google had delayed solving the issue by 137 days.
The news of Google’s own Salesforce hack is also accompanied by a warning that there is now more clear evidence that ShinyHunters and Scattered Spider have formally joined forces, and that ShinyHunters is escalating to launching a leak site to put added pressure on its data breach victims.
Google has been issuing direct personal warnings to users that appear to have been targeted by a state-sponsored hacking group. The company has taken the unusual step of issuing a general public warning about an Iran-backed threat.
Google is now months behind its competitors in reporting its "rogue" AI models to the public, but says that its incidents came ahead of the Hugging Face attack and similar widely reported issues.










