Google is making passkeys the default sign-in option across its services for all users. User feedback found that at least 64% of users said passkeys were easier to use than passwords or two-factor authentication.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Roughly in keeping with numbers seen in recent years, the Google Play Store announced that it blocked 1.43 million bad apps and banned 173,000 malicious or policy-violating developer accounts in 2022.
Google says that Chinese SMS phishing campaigns have collectively yielded somewhere between 15 million and 100 million stolen credit cards in the US alone. The case names 25 individuals and believes the hackers produced over 100 different fraudulent websites that made use of Google branding.
The Scattered Spider ransomware gang has been grabbing headlines with a string of bold and high-profile cyber attacks. But researchers with Google's Threat Intelligence Group (GTIG) now believe that some of these attacks may have been misattributed, and that the similarly long-tenured ShinyHunters group may have instead been the culprits.
A new report from Google's Threat Intelligence Group (GTIG) finds that 75 zero-days were exploited in the wild last year, with a little over half involving spyware.
Google's report of novel AI-enabled malware in the wild is a game changer if these capabilities are now being picked up by sophisticated attackers. It identifies two specific new malware families, "PROMPTFLUX" and "PROMPTSTEAL," that are the first to incorporate a "just in time" dynamic function creation feature that draws on an LLM.
Google says it will start distrusting digital certificates issued by two certificate authorities due to, Chunghwa Telecom and Netlock, compliance issues and failure to address public incidents.
A ransomware gang that recently hit major UK retailers such as Marks & Spencer with cyber attacks is now setting its sights on US companies, according to a warning from Google's security team.
Google warns Salesforce customers about vishing attacks by hackers impersonating IT support to lure employees into connecting a rogue app, exfiltrate data, and demand ransom.
Google Threat Intelligence Group has warned about sophisticated cyber attacks on critical infrastructure by the Scattered Spider ransomware gang via VMware.










