see the changes

  • [all]
  • [security.googleblog.com]
  • [RSS]
  • [Subscribe]

  • Google Online Security Blog 2022-05-18 16:22 UTC

    Privileged pod escalations in Kubernetes and GKE


    Posted by GKE and Anthos Platform Security Teams …
  • Google Online Security Blog 2022-05-11 20:32 UTC
    Last month, we also started rolling out a new Data safety section in Google Play to help you …
  • Google Online Security Blog 2022-05-11 19:27 UTC

    I/O 2022: Android 13 security and privacy (and more!)


    Posted by Eugene Liderman and Sara N-Marandi, …
  • Google Online Security Blog 2022-05-11 18:06 UTC

    Taking on the Next Generation of Phishing Scams


    Posted by Daniel Margolis, Senior Software …
  • Google Online Security Blog 2022-04-28 20:09 UTC

    The Package Analysis Project: Scalable detection of malicious open source packages


    Posted by Caleb …
  • Google Online Security Blog 2022-04-27 16:20 UTC

    How we fought bad apps and developers in 2021


    Posted by Steve Kafka and Khawaja Shams, Android …
  • Google Online Security Blog 2022-04-16 00:13 UTC

    How to SLSA Part 3 - Putting it all together


    Posted by Tom Hennen, software engineer, BCID & …
  • Google Online Security Blog 2022-04-07 16:14 UTC

    Improving software supply chain security with tamper-proof builds


    Posted by Asra Ali and Laurent …
  • Google Online Security Blog 2022-04-05 16:13 UTC

    Find and $eek! Increased rewards for Google Nest & Fitbit devices


    Posted by Medha Jain, Program …
  • Google Online Security Blog 2022-03-10 20:13 UTC

    What's up with in-the-wild exploits? Plus, what we're doing about it.


    Posted by Adrian Taylor, …
  • Google Online Security Blog 2022-02-23 20:13 UTC

    Mitigating kernel risks on 32-bit ARM


    Posted by Ard Biesheuvel, Google Open Source Security Team …
  • Google Online Security Blog 2022-02-14 20:13 UTC

    🌹 Roses are red, Violets are blue 💙 Giving leets 🧑‍💻 more sweets 🍭 All of 2022!


    Posted by Eduardo …
  • Google Online Security Blog 2022-02-10 20:15 UTC

    Vulnerability Reward Program: 2021 Year in Review


    Posted by Sarah Jacobus, Vulnerability Rewards …
  • Google Online Security Blog 2022-01-19 16:14 UTC

    Reducing Security Risks in Open Source Software at Scale: Scorecards Launches V4


    Posted by Laurent …
  • Google Online Security Blog 2021-12-24 08:13 UTC
    Editors Note:
    The below numbers were calculated based on both log4j-core and log4j-api, as both were …
  • Google Online Security Blog 2021-12-18 04:14 UTC

    Apache Log4j Vulnerability


    Like many other companies, we’re closely following the multiple CVEs …
  • Google Online Security Blog 2021-12-17 20:14 UTC

    Understanding the Impact of Apache Log4j Vulnerability


    Posted by James Wetter and Nicky Ringland, …
  • Google Online Security Blog 2021-12-17 00:14 UTC

    Improving OSS-Fuzz and Jazzer to catch Log4Shell


    The discovery of the Log4Shell vulnerability has …
  • Google Online Security Blog 2021-12-14 20:15 UTC

    Empowering the next generation of Android Application Security Researchers


    Posted by Jon Bottarini, …
  • Google Online Security Blog 2021-12-02 20:16 UTC

    Exploring Container Security: A Storage Vulnerability Deep Dive


    Posted by Fabricio Voznika and …
  • Google Online Security Blog 2021-11-11 20:14 UTC
    To learn more, check out the ClusterFuzzLite documentation . ClusterFuzzLite currently supports …
  • Google Online Security Blog 2021-11-11 12:16 UTC

    ClusterFuzzLite: Continuous fuzzing for all


    Posted by Jonathan Metzman, Google Open Source Security …
  • Google Online Security Blog 2021-11-02 00:18 UTC

    Trick & Treat! 🎃 Paying Leets and Sweets for Linux Kernel privescs and k8s escapes


    Posted by …
  • Google Online Security Blog 2021-10-30 01:58 UTC

    Protecting your device information with Private Set Membership


    Posted by Kevin Yeo and Sarvar …
  • Google Online Security Blog 2021-10-05 20:17 UTC

    Google Protects Your Accounts – Even When You No Longer Use Them


    Posted by Sam Heft-Luthy, Product …
  • Google Online Security Blog 2021-10-01 22:27 UTC

    Introducing the Secure Open Source Pilot Program


    Posted by Meder Kydyraliev and Kim Lewandowski, …
  • Google Online Security Blog 2021-09-28 16:15 UTC

    Announcing New Patch Reward Program for Tsunami Security Scanner


    Posted by Guoli Ma, Sebastian …
  • Google Online Security Blog 2021-09-28 08:13 UTC
    September 22, 2021
    $ cosign verify-attestation -key cosign.pub …
  • Google Online Security Blog 2021-09-22 16:18 UTC

    Posted by Priya Wadhwa and Appu Goundan, Google Open Source Security Team
    A few months ago we …

  • Google Online Security Blog 2021-09-21 20:16 UTC

    An update on Memory Safety in Chrome


    Adrian Taylor, Andrew Whalley, Dana Jansens and Nasko Oskov, …
  • Google Online Security Blog 2021-09-15 20:14 UTC

    Google Supports Open Source Technology Improvement Fund


    Posted by Kaylin Trychon, Google Open …
  • Google Online Security Blog 2021-09-09 20:13 UTC

    Introducing Android’s Private Compute Services


    Posted by Suzanne Frey, VP, Product, Android & …
  • Google Online Security Blog 2021-08-26 20:14 UTC

    Updates on our continued collaboration with NIST to secure the Software Supply Chain


    Posted by Eric …
  • Google Online Security Blog 2021-08-12 00:18 UTC

    AllStar: Continuous Security Policy Enforcement for GitHub Projects


    Posted by Mike Maraya, Google …
  • Google Online Security Blog 2021-08-10 08:22 UTC

    Simplifying Titan Security Key options for our users


    Posted by Christiaan Brand, Product Manager, …
  • Google Online Security Blog 2021-08-05 04:19 UTC

    Linux Kernel Security Done Right


    Posted by Kees Cook, Software Engineer, Google Open Source …
  • Google Online Security Blog 2021-07-27 16:16 UTC

    A new chapter for Google’s Vulnerability Reward Program


    Posted by Jan Keller, Technical Program …
  • Google Online Security Blog 2021-07-20 20:16 UTC

    Protecting more with Site Isolation


    Posted by Charlie Reis​ and Alex Moshchuk, Chrome Security Team …
  • Google Online Security Blog 2021-07-15 20:15 UTC

    Verifiable design in modern systems


    Posted by Ryan Hurst, Production Security Team The way we …
  • Google Online Security Blog 2021-07-01 16:14 UTC

    Measuring Security Risks in Open Source Software: Scorecards Launches V2


    Posted by Kim Lewandowski, …
  • Google Online Security Blog 2021-07-01 00:15 UTC
    SLSA 1 requires that the build process be fully scripted/automated and generate provenance. …
  • Google Online Security Blog 2021-06-25 00:17 UTC
    In recent months, Google has launched several efforts to strengthen open-source security on multiple …
  • Google Online Security Blog 2021-06-24 16:16 UTC

    Announcing a unified vulnerability schema for open source


    Posted by Oliver Chang, Google Open …
  • Google Online Security Blog 2021-06-18 16:15 UTC

    Get ready for the 2021 Google CTF


    Posted by Kristoffer Janke, Information Security Engineer
    Are you …
  • Google Online Security Blog 2021-06-16 16:15 UTC

    Introducing SLSA, an End-to-End Framework for Supply Chain Integrity


    Posted Kim Lewandowski, Google …
  • Google Online Security Blog 2021-06-09 04:15 UTC

    Rust/C++ interop in the Android Platform


    Posted by Joel Galenson and Matthew Maurer, Android Team …
  • Google Online Security Blog 2021-06-04 14:15 UTC

    Announcing New Abuse Research Grants Program


    Posted by Anna Hupa,  Marc Henson, and Martin Straka, …
  • Google Online Security Blog 2021-06-03 20:15 UTC

    New protections for Enhanced Safe Browsing users in Chrome


    Posted by Badr Salmi, Google Safe …
  • Google Online Security Blog 2021-05-26 18:13 UTC

    Introducing Security By Design


    Posted by Jon Markoff and Sean Smith, Android Security and Privacy …
  • Google Online Security Blog 2021-05-25 16:16 UTC

    Introducing Half-Double: New hammering technique for DRAM Rowhammer bug


    Research Team: Salman Qazi, …
  • Google Online Security Blog 2021-05-12 18:14 UTC
    Labels: android , android security , rust
  • Google Online Security Blog 2021-05-11 18:14 UTC

    Integrating Rust Into the Android Open Source Project


    Posted by Ivan Lozano, Android Team
    The …
  • Google Online Security Blog 2021-05-06 16:14 UTC
    Posted by Priya Wadhwa, Jake Sanders, Google Open Source Security Team Read More
    Posted by Priya …
  • Google Online Security Blog 2021-05-06 14:14 UTC

    Making the Internet more secure one signed container at a time


    Posted by Priya Wadhwa, Google Open …
  • Google Online Security Blog 2021-05-04 18:14 UTC

    Enabling Hardware-enforced Stack Protection (cetcompat) in Chrome


    Alex Gough, Engineer, Chrome …
  • https://security.googleblog.com/ 2021-04-30 04:13 UTC
    [Marking site as being monitored from now on]
  • Google Online Security Blog 2021-04-22 00:40 UTC

    How we fought bad apps and developers in 2020


    Posted by Krish Vitaldevara, Director of Product …