<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Google Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Google.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Updated Cyber Threat Actor Naming System</title><link>https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system</link><guid isPermaLink="false">cst-3186</guid><description>Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.</description><pubDate>Fri, 24 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Google gives developers an AI bug hunter that also writes patches</title><link>https://helpnetsecurity.com/2026/07/24/google-codemender-ai-agent-code-security</link><guid isPermaLink="false">cst-3155</guid><description>Google unveiled CodeMender, an AI agent designed to identify security vulnerabilities in code, verify their exploitability, and automatically generate patches for developer review. The tool aims to help defenders match the pace of attackers who are increasingly using AI to accelerate their operations.</description><pubDate>Fri, 24 Jul 2026 08:53:17 GMT</pubDate></item><item><title>Google’s newest sign-in method asks you to look at the camera</title><link>https://helpnetsecurity.com/2026/07/24/google-selfie-video-sign-in-verification</link><guid isPermaLink="false">cst-3156</guid><description>Google has introduced a selfie video sign-in method that verifies account owners are real people and prevents misuse by bots or automated programs. The recorded video is stored securely with user consent and can be deleted from the Google Account at any time. The feature is not yet available across all regions, accounts, or devices.</description><pubDate>Fri, 24 Jul 2026 08:33:58 GMT</pubDate></item><item><title>The automotive software vulnerabilities hiding in your dashboard</title><link>https://helpnetsecurity.com/2026/07/24/car-research-automotive-software-vulnerabilities</link><guid isPermaLink="false">cst-3146</guid><description>Modern vehicles contain substantial embedded software running operating systems like Android, Linux, QNX, and VxWorks across dashboard displays and safety-critical systems. Carmakers have transitioned to software-dependent architectures over the past decade, introducing potential vulnerability exposures in these systems. The article examines security risks inherent in automotive software stacks.</description><pubDate>Fri, 24 Jul 2026 06:30:41 GMT</pubDate></item><item><title>AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing</title><link>https://techcrunch.com/2026/07/23/aegisai-founded-by-former-google-security-execs-lands-36m-to-stop-ai-driven-spear-phishing</link><guid isPermaLink="false">cst-3128</guid><description>AegisAI, a startup founded by former Google security executives, raised $36 million in Series A funding led by Battery Ventures, bringing its total funding to $49 million. The company focuses on defending against AI-driven spear phishing attacks.</description><pubDate>Thu, 23 Jul 2026 18:38:34 GMT</pubDate></item><item><title>OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider</title><link>https://securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider</link><guid isPermaLink="false">cst-3107</guid><description>OpenAI patched a vulnerability that allowed attackers to create, insert, and remotely control covert autonomous AI agents within victim organizations. The flaw, termed AgentForger, could enable threat actors to establish persistent unauthorized access through AI systems.</description><pubDate>Thu, 23 Jul 2026 15:09:59 GMT</pubDate></item><item><title>ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories</title><link>https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html</link><guid isPermaLink="false">cst-3103</guid><description>This story appears to be a preview or teaser for a ThreatsDay Bulletin covering multiple threat categories including Android spyware, programmable logic controller (PLC) attacks, and artificial intelligence (AI) image prompt injection attacks among other threats.</description><pubDate>Thu, 23 Jul 2026 15:02:07 GMT</pubDate></item><item><title>EU fines Google $1 billion for search, app store antitrust violations</title><link>https://bleepingcomputer.com/news/google/eu-fines-google-1-billion-for-digital-markets-act-breaches-in-search-and-play-store</link><guid isPermaLink="false">cst-3083</guid><description>The European Commission issued a €890 million fine to Google for violating the Digital Markets Act, which regulates fair competition in digital markets. The penalty addresses breaches related to the company's search and app store practices.</description><pubDate>Thu, 23 Jul 2026 12:33:19 GMT</pubDate></item><item><title>Johnson Controls XAAP Android</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-02</link><guid isPermaLink="false">cst-3118</guid><description>Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</title><link>https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel</link><guid isPermaLink="false">cst-3081</guid><description>Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.</description><pubDate>Thu, 23 Jul 2026 10:00:38 GMT</pubDate></item><item><title>Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts</title><link>https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html</link><guid isPermaLink="false">cst-3086</guid><description>Google announced a new account recovery option allowing locked-out users to verify their identity through a selfie video. This method supplements existing recovery mechanisms like email and phone number verification. The feature expands user options for regaining account access when standard credentials are unavailable.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate></item><item><title>New msaRAT malware uses Chrome, Edge browsers to route C2 traffic</title><link>https://bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic</link><guid isPermaLink="false">cst-3068</guid><description>Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate></item><item><title>TAG-195 Upgrades MaaS Ecosystem with Modular Tools</title><link>https://recordedfuture.com/research/tag-195-evolves-maas-ecosystem</link><guid isPermaLink="false">cst-3132</guid><description>Insikt Group identified four new malware families associated with TAG-195, a financially motivated malware-as-a-service (MaaS) developer: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. These families demonstrate TAG-195's architectural evolution toward a modular, controller-and-plugin design that loads capability modules on demand rather than embedding all functionality in a single implant. The shift reflects both technical improvements in detection evasion and commercial incentives of the MaaS model, including selective capability provisioning and compartmentalization of risk across customers.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fake Bahrain Alert App Deploys Android Surveillance Malware</title><link>https://darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware</link><guid isPermaLink="false">cst-3051</guid><description>Cybercriminals distributed a fake alert application disguised as an official Bahrain warning tool, which delivered multi-stage Android spyware to victims. The malware was promoted through counterfeit Google Play storefronts and targeted civilians during a period of heightened tensions from Iranian missile strikes in the region.</description><pubDate>Wed, 22 Jul 2026 19:42:42 GMT</pubDate></item><item><title>Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</title><link>https://sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis</link><guid isPermaLink="false">cst-3045</guid><description>SentinelLabs evaluated frontier AI models on a multi-stage malware analysis benchmark based on their investigation of fast16, a 2005 sabotage implant, finding that only OpenAI's GPT-5.6 Sol completed the full eight-stage reverse-engineering task. The benchmark tested whether models could maintain investigative integrity as new evidence contradicted earlier conclusions, with successful completion requiring project-scale recovery including withdrawing incorrect conclusions and repairing technical artifacts. The researchers concluded that the strongest current use case is supervised investigative support where human analysts retain authority over objectives, quality control, and final publication.</description><pubDate>Wed, 22 Jul 2026 16:55:29 GMT</pubDate></item><item><title>Adobe Chrome extension flaw let sites access private WhatsApp chats</title><link>https://bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats</link><guid isPermaLink="false">cst-2996</guid><description>A vulnerability in the Adobe Acrobat extension for Chrome allowed unauthorized access to WhatsApp Web conversations and data without requiring authentication. The flaw exposed private messages and information that should have been protected, affecting users who had both the extension and WhatsApp Web open in their browser.</description><pubDate>Wed, 22 Jul 2026 13:22:20 GMT</pubDate></item><item><title>Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication</title><link>https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html</link><guid isPermaLink="false">cst-3013</guid><description>A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in open-source developer platform Windmill allows attackers to read arbitrary server files without authentication through the get_log_file endpoint. The flaw has entered active exploitation in the wild.</description><pubDate>Wed, 22 Jul 2026 12:36:36 GMT</pubDate></item><item><title>Shadow AI Is a Non-Human Identity Problem Wearing a Different Name Badge</title><link>https://reliaquest.com/blog/shadow-ai-non-human-identity-problem</link><guid isPermaLink="false">cst-3201</guid><description>Shadow AI integrated into engineering and data workflows presents a distinct security risk that differs from consumer chatbot usage. Tools connected to source code repositories, CI/CD pipelines, cloud environments, and production systems can operate through existing employee credentials without appearing as separate accounts in identity systems. Detection requires shifting focus from browser-based activity toward non-human identities and service accounts with privileged access.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities</title><link>https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html</link><guid isPermaLink="false">cst-2953</guid><description>Google DeepMind released Gemini 3.5 Flash Cyber, an AI model tailored to identify, validate, and remediate software vulnerabilities. The model is available in limited pilot form to governments and trusted partners through CodeMender.</description><pubDate>Tue, 21 Jul 2026 15:09:28 GMT</pubDate></item><item><title>AI agents tricked into recommending malicious GitHub repositories</title><link>https://helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents</link><guid isPermaLink="false">cst-2925</guid><description>Island researchers discovered approximately 7,600 malicious GitHub repositories, with over 800 masquerading as AI Skills or Model Context Protocol servers, peaking in April 2026. The FakeGit operation involved around 6,600 compromised accounts, roughly 1,400 of which targeted AI tools, agents, and workflows. These repositories offered fraudulent integrations spanning consumer and enterprise applications, including services like Gmail and WhatsApp.</description><pubDate>Tue, 21 Jul 2026 14:27:38 GMT</pubDate></item><item><title>Captive Portal Detection</title><link>https://isc.sans.edu/diary/rss/33172</link><guid isPermaLink="false">cst-2928</guid><description>This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.</description><pubDate>Tue, 21 Jul 2026 13:44:56 GMT</pubDate></item><item><title>Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness</title><link>https://tenable.com/blog/ai-coding-assistant-agent-harness-attacks</link><guid isPermaLink="false">cst-2912</guid><description>Attackers are poisoning AI coding assistant configuration files to achieve persistent access within developer environments by injecting malicious hooks into settings files used by tools like Cursor, GitHub Copilot, and Claude Code. These configuration files create a uniquely dangerous attack vector because they are trusted as developer settings, automatically executed by IDEs, and treated as authoritative instructions by large language models. The Mini Shai-Hulud worm, analyzed by Tenable, demonstrates this technique by scanning for and compromising AI tool configurations across npm and PyPI packages, enabling silent malware execution each time a developer starts a coding session.</description><pubDate>Tue, 21 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs</title><link>https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html</link><guid isPermaLink="false">cst-2899</guid><description>Researchers identified vulnerabilities in five open-source mobile AI agent frameworks that allow attackers to inject hidden instructions through Android apps with overlay and storage permissions, potentially escalating to code execution on connected host PCs. The attack chain leverages the AI agent's inability to distinguish between legitimate and malicious text, enabling a path from app-level manipulation to full host compromise.</description><pubDate>Tue, 21 Jul 2026 11:58:00 GMT</pubDate></item><item><title>Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes</title><link>https://bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes</link><guid isPermaLink="false">cst-2869</guid><description>Researchers demonstrated sandbox escape vulnerabilities in four AI coding tools: Cursor, Codex, Gemini CLI, and Antigravity. The attacks exploited a common pattern where AI agents write files that host tools subsequently execute, bypassing isolation mechanisms. Google patched Antigravity vulnerabilities and downgraded the severity of two findings.</description><pubDate>Mon, 20 Jul 2026 21:14:42 GMT</pubDate></item><item><title>From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab</title><link>https://rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis</link><guid isPermaLink="false">cst-2847</guid><description>Security researchers discovered an exposed server functioning as a malware delivery and testing laboratory containing over 1,000 artifacts used for weaponizing shortcut lures, WebDAV execution paths, and social engineering campaigns. The infrastructure revealed a systematic development workflow where attackers employed generative AI to bulk-generate phishing lures, create documentation, and automate QA testing of delivery methods. Analysis of the exposed directory showed the operator testing Unicode spoofing, filename obfuscation, signed binary execution, and alternative delivery containers to refine attack reliability.</description><pubDate>Mon, 20 Jul 2026 13:00:00 GMT</pubDate></item><item><title>20th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/20th-july-threat-intelligence-report</link><guid isPermaLink="false">cst-2835</guid><description>Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.</description><pubDate>Mon, 20 Jul 2026 12:18:41 GMT</pubDate></item><item><title>Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs</title><link>https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html</link><guid isPermaLink="false">cst-2817</guid><description>A Russian-speaking threat actor tracked as "bandcampro" leveraged Google's Gemini CLI to automate botnet operations, including password cracking and infrastructure setup, across eight compromised dental clinic computers. Analysis of 200 Gemini CLI session logs from March through April 2026 documented the actor's use of the open-source tool to streamline malicious activities.</description><pubDate>Mon, 20 Jul 2026 09:07:11 GMT</pubDate></item><item><title>Chrome 150 Update Patches Severe Memory Safety Bugs</title><link>https://securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs</link><guid isPermaLink="false">cst-2820</guid><description>Google released Chrome version 150, which addresses six critical and high-severity use-after-free vulnerabilities in the browser. These memory safety bugs posed significant security risks to users running earlier versions of Chrome.</description><pubDate>Mon, 20 Jul 2026 08:12:19 GMT</pubDate></item><item><title>Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security</title><link>https://helpnetsecurity.com/2026/07/20/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security</link><guid isPermaLink="false">cst-2812</guid><description>Check Point released ZoneAlarm Mobile Security, a mobile protection app that defends against phishing, malicious websites, and fraudulent links across iOS, Android, and Apple silicon Macs. The application features customizable content filtering and a Safari extension that checks websites before loading.</description><pubDate>Mon, 20 Jul 2026 04:30:34 GMT</pubDate></item><item><title>New North Korean campaign uses fake coding interviews to steal developer credentials</title><link>https://elastic.co/security-labs/contagious-interview-malware-svg-steganography</link><guid isPermaLink="false">cst-2774</guid><description>Elastic Security Labs discovered a North Korean-aligned campaign, tracked as REF9403, that uses fake job postings and coding challenges to distribute malware hidden in SVG image files via steganography. The trojanized code repositories appear functional but install a four-stage payload including credential and wallet stealers, file exfiltration, a Socket.IO-based remote access trojan, and clipboard stealing capabilities. The campaign demonstrates how threat actors target developers to establish initial access for downstream supply chain attacks.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Google Bets 'Agentic Defense' Strategy Can Outpace Attackers</title><link>https://darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers</link><guid isPermaLink="false">cst-2761</guid><description>Google Cloud has integrated Wiz capabilities into a platform designed to automate threat detection and remediation using agentic approaches. The integration aims to address emerging AI-driven attacks through automated defense mechanisms.</description><pubDate>Fri, 17 Jul 2026 11:50:25 GMT</pubDate></item><item><title>E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants</title><link>https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html</link><guid isPermaLink="false">cst-2752</guid><description>The European Commission has ordered Google to grant rival AI assistants the same access to Android hardware and functionality that Gemini currently enjoys, including camera, microphone, screen content, wake-word activation, and the ability to control other applications. Google must implement these changes in Android 18, with a compliance deadline of August 1, 2027.</description><pubDate>Fri, 17 Jul 2026 11:44:41 GMT</pubDate></item><item><title>San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores</title><link>https://wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores</link><guid isPermaLink="false">cst-2750</guid><description>San Francisco's City Attorney sent cease-and-desist letters to Apple and Google demanding they remove 13 face-swap applications from their app stores. The apps are designed to generate non-consensual intimate imagery targeting women and girls, generating revenue for the platforms hosting them.</description><pubDate>Fri, 17 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Claude can now sign into websites with 1Password without exposing your credentials</title><link>https://helpnetsecurity.com/2026/07/17/1password-anthropic-claude-integration</link><guid isPermaLink="false">cst-2748</guid><description>1Password has released a beta integration for Claude that allows the AI assistant to complete authentication-required browser tasks while keeping user passwords and secrets protected. The feature is available to paid Claude subscribers using Claude Desktop on macOS and compatible with 1Password individual, family, and business plan customers. The integration requires specific software components including Claude Desktop, the 1Password desktop app, and browser extension.</description><pubDate>Fri, 17 Jul 2026 09:17:44 GMT</pubDate></item><item><title>ACR Stealer: Two observed intrusion chains amid increased threat activity</title><link>https://microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity</link><guid isPermaLink="false">cst-2732</guid><description>Microsoft Defender Experts observed increased ACR Stealer activity from late April 2026 to mid-June 2026, identifying two distinct intrusion campaigns that use ClickFix social engineering to deliver information-stealing malware. Campaign 1 employs WebDAV-based payload delivery with Python loaders and blockchain-backed command-and-control, while Campaign 2 uses MSHTA and steganography for fileless execution. Both ultimately target browser credentials, authentication tokens, and sensitive enterprise documents.</description><pubDate>Thu, 16 Jul 2026 23:12:02 GMT</pubDate></item><item><title>Claude Chrome extension flaw lets malicious extensions trigger AI actions</title><link>https://bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions</link><guid isPermaLink="false">cst-2716</guid><description>A vulnerability in Anthropic's Claude Chrome extension allows malicious extensions to simulate user clicks and trigger predefined AI actions without explicit user consent. The flaw could be exploited to abuse Claude's access to connected services including Gmail, Google Docs, Google Calendar, and Salesforce.</description><pubDate>Thu, 16 Jul 2026 19:26:07 GMT</pubDate></item><item><title>ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories</title><link>https://thehackernews.com/2026/07/threatsday-game-cheat-spyware-24-hour.html</link><guid isPermaLink="false">cst-2694</guid><description>This week's security news covers multiple attack vectors including game cheat spyware, rapid ransomware deployment, and Chrome synchronization exploitation for surveillance. The stories highlight how attackers leverage seemingly legitimate tools, weak configurations, and straightforward attack paths to compromise systems and escalate damage.</description><pubDate>Thu, 16 Jul 2026 15:41:15 GMT</pubDate></item><item><title>Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management</title><link>https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management</link><guid isPermaLink="false">cst-2709</guid><description>Mandiant Consulting outlines a blueprint for safely integrating large language model agents into vulnerability management workflows, given that mean time-to-exploit has dropped to negative seven days. The guidance emphasizes establishing operational guardrails such as data security controls, zero data retention agreements with providers, workload isolation, and combining AI capabilities with deterministic controls and human oversight. Organizations deploying AI agents should extend existing security frameworks into the AI execution environment to manage architectural risks while accelerating vulnerability discovery and remediation.</description><pubDate>Thu, 16 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes</title><link>https://helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet</link><guid isPermaLink="false">cst-2684</guid><description>A Russian-speaking threat actor named bandcampro leveraged a jailbroken version of Google's Gemini CLI to build and manage botnet command-and-control infrastructure targeting a dental clinic. Over more than 200 sessions between March 19 and April 21, 2026, the attacker deployed malware across eight clinic computers and accessed the OpenDental database, accomplishing botnet reconstruction in approximately six minutes.</description><pubDate>Thu, 16 Jul 2026 12:08:46 GMT</pubDate></item><item><title>Security researchers find stalkers abusing Chrome’s sync feature</title><link>https://cyberscoop.com/google-chrome-sync-cyberstalking-exploit</link><guid isPermaLink="false">cst-2637</guid><description>Cyberstalkers are exploiting Google Chrome's sync feature to monitor victims' browsing history and access stored passwords by signing into a separate Google account on a target's phone. Researchers at Certo Software documented cases where attackers needed only brief physical access to enable sync, allowing surveillance from any device worldwide. The misuse reflects a shift toward exploiting legitimate app functionality as traditional spyware becomes harder to deploy on modern smartphones.</description><pubDate>Wed, 15 Jul 2026 20:42:37 GMT</pubDate></item><item><title>Google Gemini CLI abused as a hacking agent, malware botnet operator</title><link>https://bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator</link><guid isPermaLink="false">cst-2614</guid><description>A Russian-speaking threat actor identified as bandcampro leveraged Google's open-source Gemini CLI tool to conduct hacking activities and operate a botnet infrastructure. The actor demonstrated how the AI tool could be repurposed for malicious purposes including automated exploitation and command execution.</description><pubDate>Wed, 15 Jul 2026 18:33:48 GMT</pubDate></item><item><title>Understanding Claude Tag’s access model in Slack and how to configure it securely</title><link>https://tenable.com/blog/claude-tag-slack-access-model</link><guid isPermaLink="false">cst-2608</guid><description>Anthropic's Claude Tag is a Slack AI agent that operates using admin-configured shared credentials rather than individual user credentials, following a service-identity pattern similar to deploy bots and workflow automations. Access to connected services is controlled by admin-configured bundles at the workspace or channel level, with organization-wide controls governing who can direct the agent. Channel members can collaborate with Claude, but their participation does not grant new permissions beyond what the admin bundle defines.</description><pubDate>Wed, 15 Jul 2026 15:08:00 GMT</pubDate></item><item><title>The Risk of Exposed Cloud Functions and How to Harden</title><link>https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden</link><guid isPermaLink="false">cst-2607</guid><description>Mandiant security assessments identify publicly exposed serverless applications and functions lacking authentication that frequently contain vulnerabilities in custom code or third-party packages. Successful exploitation of application-level flaws like local file inclusion or command injection can grant attackers remote code execution and container-level access, which may lead to lateral movement and cloud environment compromise. The article describes attack scenarios and hardening strategies for securing serverless deployments that must remain publicly accessible.</description><pubDate>Wed, 15 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws</title><link>https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html</link><guid isPermaLink="false">cst-2594</guid><description>Mozilla released Firefox updates to patch two critical vulnerabilities in the JavaScript/WebAssembly and DOM/Navigation components with known public exploit code. Chrome, Adobe, and VMware also issued updates for multiple critical security flaws, though details on those vendors' patches are not provided in this incomplete summary.</description><pubDate>Wed, 15 Jul 2026 13:18:53 GMT</pubDate></item><item><title>Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates</title><link>https://securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates</link><guid isPermaLink="false">cst-2544</guid><description>Google Chrome 150 and Mozilla Firefox 152 were released with patches addressing critical vulnerabilities. Public exploit code exists for the Firefox flaws, though active exploitation in the wild has not been observed.</description><pubDate>Wed, 15 Jul 2026 07:24:52 GMT</pubDate></item><item><title>Microsoft releases Windows 10 KB5099539 extended security update</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update</link><guid isPermaLink="false">cst-2513</guid><description>Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.</description><pubDate>Tue, 14 Jul 2026 18:49:28 GMT</pubDate></item><item><title>Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar</title><link>https://securityweek.com/unpatched-claude-for-chrome-flaw-lets-extensions-read-gmail-calendar</link><guid isPermaLink="false">cst-2480</guid><description>A vulnerability in Claude for Chrome remains unpatched across eight updates, allowing malicious extensions to access sensitive user data including Gmail and Calendar contents. The flaw appears related to ClaudeBleed, a class of vulnerabilities affecting how the extension isolates data from other browser extensions.</description><pubDate>Tue, 14 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Google adds FIDO2 keys and phone passkeys to Windows login via GCPW</title><link>https://helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace</link><guid isPermaLink="false">cst-2487</guid><description>Google has begun rolling out support for FIDO2 physical security keys and phone passkeys as a second authentication factor for Google Credential Provider for Windows (GCPW) across all Google Workspace customers. GCPW enables Windows login using Google Workspace credentials, and the new capability allows administrators to enforce two-step verification with hardware security keys. The update strengthens account security by providing organizations with stronger multi-factor authentication options for Windows device access.</description><pubDate>Tue, 14 Jul 2026 10:35:48 GMT</pubDate></item><item><title>Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads</title><link>https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html</link><guid isPermaLink="false">cst-2463</guid><description>xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.</description><pubDate>Tue, 14 Jul 2026 09:02:48 GMT</pubDate></item><item><title>Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found</title><link>https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html</link><guid isPermaLink="false">cst-2433</guid><description>Google and Microsoft removed ModHeader, a browser extension with approximately 1.6 million installations, after security researchers discovered a dormant data collector embedded in the official store version. The collector remained inactive due to an empty allowlist and showed no evidence of having transmitted any user browsing data.</description><pubDate>Mon, 13 Jul 2026 17:17:24 GMT</pubDate></item></channel></rss>