Cybersecurity

Vulnerabilities, attacks, threats, security tools, cloud security, and identity.

40 Articles

Google: Indirect Prompt Injection Attacks Are Emerging on the Web but Remain Limited in Sophistication

Cybersecurity

Google: Indirect Prompt Injection Attacks Are Emerging on the Web but Remain Limited in Sophistication

A survey conducted by Google’s threat intelligence teams of public web content shows that various actors have begun experimenting with indirect prompt injection to target artificial intelligence systems, with the malicious category increasing by 32% between November 2025 and February 2026. Despite the limited sophistication of the observed attacks, Google expects their volume and complexity to grow as artificial intelligence systems become more capable and the cost of carrying out attacks declines.

2026-04-23

Google Integrates Rust into the Pixel 10 Modem to Strengthen the Security of the Cellular Connectivity Stack

Cybersecurity

Google Integrates Rust into the Pixel 10 Modem to Strengthen the Security of the Cellular Connectivity Stack

Google announced that the Pixel 10 series will be the first Pixel devices to integrate the memory-safe Rust language into cellular modem software by replacing the DNS resolver with a component written in Rust. The company says the move reduces an entire class of memory-safety vulnerability risks, although the component adds approximately 371 kilobytes to the software image.

2026-04-10

Google Expands Android Scam Protection to Samsung Devices and Adds Messaging Support in More Than 20 Countries

Cybersecurity

Google Expands Android Scam Protection to Samsung Devices and Adds Messaging Support in More Than 20 Countries

Google announced the expansion of its Scam Detection feature for scam calls to the Samsung Galaxy S26 series in the United States, along with enhanced detection of scam messages through an on-device Gemini model. The updates include support for more than 20 countries and several languages, while keeping call processing on the device and leaving the feature disabled by default.

2026-02-25

Google Prevents Publication of 1.75 Million Policy-Violating Apps and Bans More Than 80,000 Developer Accounts in 2025

Cybersecurity

Google Prevents Publication of 1.75 Million Policy-Violating Apps and Bans More Than 80,000 Developer Accounts in 2025

Google revealed the results of its Google Play and Android safety ecosystem in 2025, noting that it prevented the publication of more than 1.75 million policy-violating apps and banned more than 80,000 malicious developer accounts. Google Play Protect also expanded its protection against malware and fraud to 185 markets and more than 2.8 billion Android devices.

2026-02-19

How Can a “Sleeper Agent” Be Hidden Inside a Language Model and Awakened When a Specific Trigger Appears?

Cybersecurity

How Can a “Sleeper Agent” Be Hidden Inside a Language Model and Awakened When a Specific Trigger Appears?

A Hugging Face article presents an experiment in which a team transformed a Qwen3.6-27B model into an agent capable of behaving normally and then carrying out a malicious task upon detecting a specific semantic trigger. The experiment shows that isolation and behavioral safeguards reduce the risk, but they do not replace code review and the construction of secure runtime environments.

2026-01-14

How Google Is Building Security Layers for Agentic Browsing Capabilities in Chrome

Cybersecurity

How Google Is Building Security Layers for Agentic Browsing Capabilities in Chrome

Google explains a multilayered security architecture to protect Gemini’s agentic capabilities in Chrome from indirect prompt injection, data leakage, and unwanted action execution. The architecture includes an independent model for reviewing whether actions align with the user’s goal, sets that restrict the assets the agent is allowed to read or modify, as well as user confirmations and continuous testing.

2025-12-08