
Chrome 150 Update Fixes 27 Security Flaws
Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

Google Is Suing Chinese Scammers Who Are Using Gemini
Google has filed a lawsuit against a Chinese criminal organization known as Outsider Enterprise. The group is accused of providing "phishing-as-a-service" through Telegram and allegedly leveraging Google's Gemini platform for their fraudulent operations.

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.

VRP 2025 Year in Review
Google's Vulnerability Rewards Program (VRP) celebrated its 15th anniversary in 2025, awarding a record $17 million to over 700 researchers globally. The program saw significant growth, including the launch of a dedicated AI VRP and expanded reward categories for AI features within the Chrome VRP. Additionally, a new patch rewards program was introduced for the OSV-SCALIBR tool.