LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

google

chromecritical

Chrome 150 Update Fixes 27 Security Flaws

Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

phishing

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

googlehigh

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

google

Google Is Suing Chinese Scammers Who Are Using Gemini

Google has filed a lawsuit against a Chinese criminal organization known as Outsider Enterprise. The group is accused of providing "phishing-as-a-service" through Telegram and allegedly leveraging Google's Gemini platform for their fraudulent operations.

threat intelligence

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.

bug bounty

VRP 2025 Year in Review

Google's Vulnerability Rewards Program (VRP) celebrated its 15th anniversary in 2025, awarding a record $17 million to over 700 researchers globally. The program saw significant growth, including the launch of a dedicated AI VRP and expanded reward categories for AI features within the Chrome VRP. Additionally, a new patch rewards program was introduced for the OSV-SCALIBR tool.