search

Sections

Cyber Security

2432 articles

Update: Ongoing Investigation and Continued Remediation
cybersecurity

Update: Ongoing Investigation and Continued Remediation

Open Source Security Advisory Update: Wednesday, April 1, 2026 Boston, MA 10:00 AM ET Over the past week, we have nearly finalized our investigation and are now in the final stages of documentation and review. There continues to be no indication that Aqua’s commercial products have been affected. As part of this process, we identified

Aqua ·
VRP 2025 Year in Review
cybersecurity

VRP 2025 Year in Review

In 2025, Google celebrated the 15th anniversary of its Vulnerability Reward Program (VRP), enhancing collaborations with the security research community. The program awarded over $17 million to more than 700 researchers globally, marking a 40% increase from the previous year. New initiatives included a dedicated AI VRP and a patch rewards program for open-source vulnerabilities. Significant bugSWAT events resulted in numerous reports and rewards. Looking ahead to 2026, Google plans to continue these efforts, fostering innovation and security enhancements.

Google Online Security Blog ·
The State of Trusted Open Source: March 2026
cybersecurity

The State of Trusted Open Source: March 2026

AI is accelerating software and CVE growth. Chainguard’s latest report shows rising risk in the long tail and how teams can stay secure at scale.

Chainguard: Unchained ·
Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
cybersecurity

Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here’s what happened, who’s affected, and how to check your exposure.

Blog RSS Feed | Snyk ·
The 5 Principles of Snyk’s Developer Experience
cybersecurity

The 5 Principles of Snyk’s Developer Experience

Discover the 5 principles behind Snyk’s developer experience. Learn how seamless workflows, actionable fixes, and AI-driven security help developers ship secure code faster without disrupting productivity.

Blog RSS Feed | Snyk ·
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
cybersecurity

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Google is addressing the imminent threats posed by quantum computing to digital security through the introduction of Post-Quantum Cryptography (PQC) in Android 17. This transition aims to safeguard essential digital systems currently reliant on public-key cryptography. Key upgrades include PQC integration in Android Verified Boot and Remote Attestation, which enhance foundational security, and updates to the Android Keystore for developers to utilize quantum-resistant cryptography. The approach also promotes hybrid signing for Google Play apps to ensure app authenticity against quantum-enabled signature forgery. This initiative, part of a broader plan initiated in 2016, aims to fortify the entire Android ecosystem against future quantum threats.

Google Online Security Blog ·