< ciso
brief />
Tag Banner

All news with #google tag

714 articles · page 8 of 36

CJEU upholds €4.1B antitrust fine against Google

📢 The Court of Justice of the European Union has dismissed Google's final appeal against a €4.1 billion antitrust fine related to Android. The ruling affirms that Google used pre-installation, anti-fragmentation agreements, and certain revenue-sharing deals to strengthen its dominant position and restrict competition. Google contests the decision, noting changes to its practices since 2018 and arguing that market realities have shifted.
read more →

Google Disrupts Major Residential Proxy Network

🛡️ Today Google, working with the FBI, Lumen, and other partners, disrupted the NetNut (Popa) residential proxy network, building on earlier action against IPIDEA. Google disabled accounts used for NetNut C2, shared technical intelligence on SDKs and backend infrastructure, and ensured Play Protect warned users and disabled apps with NetNut SDKs. The disruption reduced NetNut’s available device pool by millions, though Google expects proxy operators to adapt and resell capacity.
read more →

Google’s June 2026 AI product and research updates

🧭 In June 2026 Google highlighted a broad set of AI advances spanning local models like Gemma 4 12B, Gemini 3.5 Flash integrations, new Android 17 and Pixel Drop features, and multimodal APIs for developers. The update covers consumer devices, developer tools, education and climate applications, as well as efforts to counter AI-enabled scams and support public services.
read more →

Context-Aware Polymorphic Schema Validation

🛠️ This post outlines an architecture using Google's ADK and Gemini Flash to replace static prompt-driven agents with a just-in-time, metadata-driven orchestration. It externalizes JSON schema descriptors to a Central Metadata Registry and employs a lightweight discovery prompt plus dynamic validation hooks (Cloud Run) to ensure deterministic, schema-compliant payloads. The pattern reduces context bloat, lowers token costs, and prevents attention diffusion in multi-agent workflows.
read more →

BigQuery Conversational Analytics Now Generally Available

🧭 Conversational Analytics in BigQuery is now generally available, enabling business and technical users to query data, run multi-step analyses, and produce visual reports using natural language directly where data resides. Built on Google’s Gemini models and BigQuery’s governed foundation, it offers inspectable answers, context citations, proactive disambiguation, and long-term memory. The feature integrates with Lakehouse sources, supports enterprise security and governance controls, and provides agentic workflows for scheduled monitoring and automated reports.
read more →

AirDrop and Quick Share weaknesses disrupt sharing

🔒 Two researchers disclosed six vulnerabilities in AirDrop and Quick Share that let a nearby attacker crash or manipulate file‑sharing sessions. The issues impact Apple and Samsung implementations and include a stack overflow in Apple's XML plist parser and a Windows memory bug in Google's Quick Share app. Apple, Google, and Samsung have begun issuing fixes and coordinating disclosures; users should update and restrict visibility settings.
read more →

Turner Industries’ secure cloud-first infrastructure

🔒 Turner Industries migrated to ChromeOS, Google Workspace, Chrome Enterprise Premium, and Cameyo to reduce costs and improve security. The shift extended device lifecycles, cut per-device costs by 40–50%, and saved an estimated $700,000 on new hardware plus $600,000 by converting existing devices with ChromeOS Flex. Faster deployments and simplified management freed IT to focus on strategic work while maintaining strong endpoint protection and legacy app access.
read more →

AI Liability and the Publisher–Carrier Distinction

📰 The German court found Google liable for AI-generated search summaries, rejecting defenses that users should verify AI output themselves. This ruling highlights the historical distinction between carriers and publishers and argues that AI summaries act like editorial content. Past cases, like Air Canada’s chatbot ruling, reinforce that organizations are responsible for their AI agents. The decision could force companies to improve AI accuracy or curtail certain commercial uses.
read more →

High‑Install Chrome Extension Enables Remote Script Injection

🛡️ An analysis of a widely installed Google Chrome extension, Adblock for YouTube (10M+ installs), revealed it can execute arbitrary JavaScript across websites. Researchers found a dormant, server‑controlled injection capability that could create elements without an extension update or store review. Although no evidence of active abuse was reported, the combination of all‑site access, prior ad‑injection SDKs, and related removed extensions raises significant privacy and security concerns.
read more →

Google expands privacy controls for Search and Play

🔒 Google announced new privacy controls that separate saved history and personalization for Search services and Google Play, rolling out in users' Google Accounts in the coming days. The update creates distinct Search Services History and Personalized Recommendations settings, and similarly splits Play History and Personalization in Play. If Web & App Activity is on, the new Search Services History and its Save Media subsetting will be enabled after transition, but users can disable or delete saved media later.
read more →

Open telco AI models accelerate network automation

📡 Modern telecom networks require domain-specific AI because general models lack the precise, vendor-specific context needed for mission-critical operations. GSMA’s Open Telco AI platform and AT&T’s OTel family—fine-tuned on Google’s open-source Gemma models—use curated telco datasets and RAG-based abstention to reduce hallucinations. The initiative produced 30 optimized models, demonstrated strong Gemma performance in AT&T tests, and already exceeded 18 million downloads.
read more →

Google expands EU financial advertiser verification

🔒 Google is expanding its financial services advertiser verification program to cover all EU and EEA member states, adding 24 countries to its rollout. The program builds on existing advertiser identity checks and Gemini-powered defenses to block harmful or unauthorized ads. Advertisers must complete verification against national registries within 30 days or face restrictions on financial ads. This aims to increase trust in online financial advertising and reduce scams.
read more →

Google enforces developer verification on Android

🔒 Google will begin enforcing Android developer verification on September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand. Certified devices from major OEMs will block normal installs of apps whose developers have not registered an identity with Google, affecting sideloaded and independent apps most. The Android Developer Verifier service rolls out to phones running Android 8+ starting June, with APIs and limited-distribution accounts arriving mid-year.
read more →

Attackers exploit trusted AI platforms and ads

🔐 Threat actors abused trusted services — Google Ads, GitLab Pages, and Claude’s shared-chat feature — to trick developers into executing malicious PowerShell and terminal commands via ClickFix social engineering. Researchers at TrendAI observed a six-wave campaign that funnelled over 2,000 victims from sponsored search results to malicious pages and then to weaponized Claude shared chats. By impersonating popular developer tools and brands, the attackers leveraged reputation stacking to make their lures appear legitimate and evade detection.
read more →

Google to use IPs for ad personalization in EEA, UK

🔒 Google has notified advertisers it will begin using IP addresses to identify devices for ad measurement and personalization across the EEA, UK and Switzerland on or shortly after August 3, 2026. The change repurposes IPs — already transmitted to route traffic and deliver ads — for purposes that trigger consent requirements under UK and EU law. Google will register for IAB Europe TCF Feature 3 and says it will rely on privacy-enhancing technologies while offering later user choices on its properties. Advertisers remain responsible for obtaining valid consent under Google’s EU User Consent Policy.
read more →

Google Vertex AI SDK bucket squatting enables RCE

🔒 A design flaw in the Vertex AI SDK for Python allowed attackers to hijack model staging buckets across projects by predicting bucket names derived from project ID and region. Unit 42 researchers called this class of issue Bucket Squatting, where global bucket name uniqueness enabled pre-creation and silent takeover. The flaw could lead to cross-tenant model poisoning and remote code execution via pickle deserialization. Google issued fixes in SDK versions 1.144.0 and 1.148.0 and users should upgrade.
read more →

Deploy a Remote MCP Server to GKE in 30 Minutes

🔧 This guide explains how to build and deploy a remote Model Context Protocol (MCP) server on Google Kubernetes Engine (GKE) using the Streamable HTTP transport. It covers prerequisites, creating a simple math MCP server with FastMCP, local testing, containerizing the server, and pushing the image to Artifact Registry. Finally, it details deploying to GKE Autopilot and exposing the server securely with the Kubernetes Gateway API and managed SSL.
read more →

Google Vertex AI SDK bucket-squatting flaw patched

🛡️ Palo Alto Networks Unit 42 disclosed a flaw in the Google Cloud Vertex AI Python SDK that let an attacker with only their own Google Cloud project and a victim's project ID hijack model uploads and execute code in Vertex AI serving containers. Google fixed the issue; users must update to google-cloud-aiplatform version 1.148.0 or later and explicitly set a staging_bucket. The bug arose from predictable default bucket names and lack of ownership checks, enabling an attacker to precreate the bucket, swap uploaded model files (often pickled), and run malicious code when Vertex AI loaded the model.
read more →

Looker Explore updates with AI and interface refresh

🔍 Google is updating Looker Explore with integrated AI assistants and a refreshed interface to help users surface insights faster. The release includes ad hoc Quick Starts powered by Gemini models, a Conversational Analytics-powered Insight Assistant for natural-language prompts, and automatic translation of user descriptions into Looker Expression syntax. The UI improvements include a resizable field picker, contextual data table menus, visual pivots, and a redesigned Merge Query workflow with smart joins and higher row limits.
read more →

Google Brazos: Rack Liquid Cooling for Legacy Racks

🔧 Google announces Brazos, a rack-mounted, closed-loop liquid-to-air cooling solution designed to enable high-density AI and HPC gear within traditional air-cooled data centers. Brazos separates the internal IT liquid loop from facility water, enabling one-rack-at-a-time deployment and avoiding costly chilled-water retrofits. The modular design features three cooling units, integrated rack manifolds, and hot-swappable FRUs for field serviceability, and it fits OCP ORv3 form-factor racks. Google plans to open-source Brazos specifications and encourage industry adoption through forums like the Open Compute Project.
read more →