Cybersecurity

Chrome 118 Patches 20 Vulnerabilities

Google on Tuesday announced the release of Chrome 118 to the stable channel with fixes for 20 vulnerabilities, including 14 reported by external researchers. The most severe of the externally reported flaws is CVE-2023-5218, a critical bug described as a use-after-free issue in Site Isolation, Chrome’s component responsible for preventing sites from stealing other sites’ […]

Cybersecurity

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

Oct 10, 2023NewsroomServer Security / Vulnerability Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset. The layer 7 attacks were detected in late August 2023, the companies said in a coordinated disclosure. The cumulative […]

Cybersecurity

Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters

Enlarge Getty Images Incomplete information included in recent disclosures by Apple and Google reporting critical zero-day vulnerabilities under active exploitation in their products has created a “huge blindspot” that’s causing a large number of offerings from other developers to go unpatched, researchers said Thursday. Two weeks ago, Apple reported that threat actors were actively exploiting […]

Cybersecurity

California Settles With Google Over Location Privacy Practices for $93 Million

Search giant Google agreed to a $93 million settlement with the state of California on Thursday over its location-privacy practices. The settlement follows a $391.5 million settlement with 40 states, reached in November 2022, to resolve an investigation into how the company tracked users’ locations. The states’ investigation was sparked by a 2018 Associated Press […]