Introducing DOM Snitch, our passive in-the-browser reconnaissance tool
Posted by Radoslav Vasilev, Security Test Engineer(Cross-posted from the Google Testing Blog)Every day modern web applications are becoming increasingly sophisticated, and as their complexity grows so does their attack surface. Previously we introduced…
Posted by Oliver Fisher, Google Anti-Malware TeamOver the past few months, Google’s systems have detected a number of bulk subdomain providers becoming targets of abuse by malware distributors. Bulk subdomain providers register a domain name, like ex…
Posted by Gary Illyes, Webmaster Trends Analyst(Cross-posted from the Webmaster Central Blog)Users are taught to protect themselves from malicious programs by installing sophisticated antivirus software, but they often also entrust their private inform…
Posted by Ben Laurie, Google Security TeamIn the wake of the recent Comodo fraud incident, there has been a great deal of speculation about how to improve the public key infrastructure, on which the security of the Internet rests. Unfortunately, this i…
Posted by Panayiotis Mavrommatis and Noé Lutz, Google Security TeamThe new version of Google Chrome is not only speedier and simpler but it also improves user security by automatically disabling out-of-date, vulnerable browser plugins.As browsers get …
Posted by Chris Evans, Robert Swiecki, Michal Zalewski, and Billy Rios, Google Security TeamWe’ve noticed some highly targeted and apparently politically motivated attacks against our users. We believe activists may have been a specific target. We’…
Posted by Nishit Shah, Product Manager, Google Security(Cross-posted from the Official Google Blog)Has anyone you know ever lost control of an email account and inadvertently sent spam—or worse—to their friends and family? There are plenty of examp…
Posted by Nishit Shah, Product Manager, Google Security(Cross-posted from the Official Google Blog)Has anyone you know ever lost control of an email account and inadvertently sent spam—or worse—to their friends and family? There are plenty of examp…
Posted by Matt Moore, Michal Zalewski, Adam Mein, Chris Evans; Google Security TeamAbout a week and a half ago we launched a new web vulnerability reward program, and the response has been fantastic. We’ve received many high quality reports from across…
Posted by Matt Moore, Michal Zalewski, Adam Mein, Chris Evans; Google Security TeamAbout a week and a half ago we launched a new web vulnerability reward program, and the response has been fantastic. We’ve received many high quality reports from across…
Posted by Chris Evans, Neel Mehta, Adam Mein, Matt Moore, and Michal Zalewski; Google Security TeamBack in January of this year, the Chromium open source project launched a well-received vulnerability reward program. In the months since launch, researc…
Posted by Chris Evans, Neel Mehta, Adam Mein, Matt Moore, and Michal Zalewski; Google Security TeamBack in January of this year, the Chromium open source project launched a well-received vulnerability reward program. In the months since launch, researc…
Posted by Adrienne St. Aubin, Public Policy AnalystIn the physical world, basic safety measures are second-nature to almost everyone (look both ways, stop drop and roll!). In the digital world, however, many of us expect security to be handled on our b…
Posted by Priya Nayak, Consumer Operations, Google AccountsLike many people, you probably store a lot of important information in your Google Account. I personally check my Gmail account every day (sometimes several times a day) and rely on having acce…
Posted by Priya Nayak, Consumer Operations, Google AccountsLike many people, you probably store a lot of important information in your Google Account. I personally check my Gmail account every day (sometimes several times a day) and rely on having acce…