<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom"><id>https://news.reportstreambl.com/</id><title>ReportStream Newsroom</title><updated>2026-09-17T10:49:19Z</updated><link rel="self" href="https://news.reportstreambl.com/atom.xml"/><entry><id>urn:sha256:45f714b5200f754c748a</id><title>When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts</title><updated>2026-09-16T20:06:17Z</updated><link rel="alternate" href="https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/"/><summary>A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare&#x27;s machine learning models surface evasive client-side attacks for analyst investigation.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:cfa71c0e15bb22ba2292</id><title>Give every teammate and agent the right level of access to your Workers</title><updated>2026-09-15T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/workers-granular-authorization/"/><summary>You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:ad7845d189adc91f06a9</id><title>Have it both ways: stay discoverable in search while disallowing AI training</title><updated>2026-09-15T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/accountable-mixed-use-ai-crawlers/"/><summary>Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:1aad1ca56bc38dc65e5d</id><title>Introducing automatic remediation policies with Cloudflare CASB</title><updated>2026-09-11T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/casb-policies/"/><summary>Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:0c770e947d7bd7edd0b8</id><title>1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it</title><updated>2026-09-10T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/post-quantum-dnssec-1111/"/><summary>1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:41a2a0bd193ed0ae7774</id><title>How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility</title><updated>2026-09-09T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/workers-module-registry-nodejs/"/><summary>Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.meta, lazy compilation, shared code caches, and clearer errors.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:719d1de40dee9399b56e</id><title>Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)</title><updated>2026-09-08T13:10:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/automatic-key-exchange-for-origins/"/><summary>Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin supports it.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:0f3839e608e72b92f244</id><title>Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models</title><updated>2026-09-03T21:03:02Z</updated><link rel="alternate" href="https://blog.cloudflare.com/vulnerability-discovery-remediation/"/><summary>Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:8a83f875c00aa48b658e</id><title>How we could save petabytes of cache storage with Zstandard and Pingora</title><updated>2026-09-01T12:59:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/cache-transcoding/"/><summary>Could we get more cache space with the same hardware? We prototyped compression inside Cloudflare&#x27;s cache to find out.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:efee17a6b08fa65e1638</id><title>Introducing Adaptive Intelligence: Undermining the economics of every bot attack</title><updated>2026-08-31T12:59:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/introducing-adaptive-intelligence/"/><summary>Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare&#x27;s new Adaptive Intelligence engine flips this dynamic by autonomously learning from the meta-signals of live traffic and deploying disposable rules, making automated attacks too expensive to sustain.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:dcae496a047cb72a1be8</id><title>BotBase for Operators: A clearer path to joining Cloudflare&#x27;s directory of bots and agents</title><updated>2026-08-28T12:59:44Z</updated><link rel="alternate" href="https://blog.cloudflare.com/botbase-for-operators/"/><summary>Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately declare how their bots use content.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:6ded1bb74e8882bf7179</id><title>How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache</title><updated>2026-08-27T17:02:35Z</updated><link rel="alternate" href="https://blog.cloudflare.com/dns-cache-memory-optimization-1111/"/><summary>Five Rust-level memory optimizations to the DNS cache layout of Big Pineapple cut per-entry memory by 56%, freeing approximately 100 TB of memory across Cloudflare&#x27;s fleet.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:c59bd621ba0587c0d658</id><title>The Cloudflare Blog — brought to you by EmDash</title><updated>2026-08-24T19:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/cloudflare-blog-uses-emdash/"/><summary>We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:f347a6968dad80d769ac</id><title>Say it once: introducing Bot Preference Sync</title><updated>2026-08-21T23:19:57Z</updated><link rel="alternate" href="https://blog.cloudflare.com/bot-preference-sync/"/><summary>Cloudflare&#x27;s new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:b787c054dd296f843c7b</id><title>From all-or-nothing to task-based OAuth consent</title><updated>2026-08-20T17:03:03Z</updated><link rel="alternate" href="https://blog.cloudflare.com/task-based-oauth-consent/"/><summary>Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:de682fffa982d31e4771</id><title>A revisit of remote Spectre attacks on Cloudflare Workers</title><updated>2026-08-19T16:00:28Z</updated><link rel="alternate" href="https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/"/><summary>In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:f18fa69f7a979091eb65</id><title>BGP Role model: tracking the adoption of RFC 9234</title><updated>2026-08-18T15:21:32Z</updated><link rel="alternate" href="https://blog.cloudflare.com/rfc9234-bgp-role-model/"/><summary>RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:0da9efa14a20dfe7c25e</id><title>How Cloudflare detects MCP traffic and helps secure it</title><updated>2026-08-14T13:12:12Z</updated><link rel="alternate" href="https://blog.cloudflare.com/mcp-security-updates/"/><summary>Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for approved servers, and block direct connections on managed network paths.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:11596c7612a579251756</id><title>Secure all your internal vibe-coded applications — in one click</title><updated>2026-08-14T13:00:00Z</updated><link rel="alternate" href="https://blog.cloudflare.com/workers-protected-by-access/"/><summary>Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:61cd45ebf89d9cba6c02</id><title>Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal</title><updated>2026-08-13T19:58:01Z</updated><link rel="alternate" href="https://blog.cloudflare.com/total-eclipse-internet-traffic-iceland-spain-portugal/"/><summary>Cloudflare&#x27;s data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026.</summary><author><name>Cloudflare Blog</name></author></entry><entry><id>urn:sha256:3486ebb7e5dc053fd0ba</id><title>AI threats in the wild: The current state of prompt injections on the web</title><updated>2026-04-23T21:38:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html"/><summary>Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting this vector today – and if so, how? To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found. The threat of indirect prompt injection U…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:9e7da1ea6bca2362345b</id><title>Bringing Rust to the Pixel Baseband</title><updated>2026-04-10T15:12:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html"/><summary>Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on &quot;Deploying Rust in Existing Firmware Codebases&quot;, this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnera…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:b51c31027c63779f693c</id><title>Protecting Cookies with Device Bound Session Credentials</title><updated>2026-04-09T17:07:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html"/><summary>Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attack…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:4708b562b3075d8b81a4</id><title>Google Workspace’s continuous approach to mitigating indirect prompt injections</title><updated>2026-04-02T16:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/04/google-workspaces-continuous-approach.html"/><summary>Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user. IPI is not the kind of technical problem you “solve” and move on. Sophisticated LLMs with increasing use of agentic automation combined with a wide range of content create an ultra-dynamic and evolving playground for adversarial attacks. That’s why Google takes a sophisticated and comprehensive a…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:3e98a91279dd7843834e</id><title>VRP 2025 Year in Review</title><updated>2026-03-31T16:55:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html"/><summary>Posted by Dirk G ö hmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting their acceptance by the external research community, without which such programs cannot function. Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:a608567d1185c117c040</id><title>Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android</title><updated>2026-03-25T13:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/03/post-quantum-cryptography-in-android.html"/><summary>Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve &quot;impossible&quot; problems in drug discovery, materials science, and energy—tasks that even the most powerful classical supercomputers cannot handle. However, the same unique ability to consider different options simultaneously also allows these machines to bypass our current digital locks. This puts the public-key cryptography we’ve relied on for decades at risk, potentially compromising everything from bank transfers to trade secrets. To secure our future, it is vital to adopt the new Post-Quantum Cryptography (PQC) standards National Institute of St…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:342e58372a39661d1544</id><title>Cultivating a robust and efficient quantum-safe HTTPS</title><updated>2026-02-27T17:01:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html"/><summary>Posted by Chrome Secure Web and Networking Team Today we&#x27;re announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we’ve taken to address them in earlier blog posts. To ensure the scalability and efficiency of the ecosystem, Chrome has no im…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:ce5354251cc5b3ee3365</id><title>Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection</title><updated>2026-02-25T15:17:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html"/><summary>Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month 1. While that scale is significant, the true impact of these protections is best understood through the stories of the individuals they help keep safe every day. This includes people like Majik B., an IT professional in Sunnyvale, California. Despite his technical background, Majik recently found himself on a call that felt dangerously legitimate. While using his Pixel, he received a call that appeared to be from his bank…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:a516aac255e2b6326f04</id><title>Keeping Google Play &amp; Android app ecosystems safe in 2025</title><updated>2026-02-19T17:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/02/keeping-google-play-android-app-ecosystem-safe-2025.html"/><summary>Posted by Vijaya Kaza, VP and GM, App &amp; Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we’re focused on ensuring that apps do not cause real-world harm, such as malware, financial fraud, hidden subscriptions, and privacy invasions. As bad actors leverage AI to change their tactics and launch increasingly sophisticated attacks, we’ve deepened our investments in AI and real-time defenses over the last year to maintain the upper hand and stop these threats before they reach users. Upgrading Google Play’s AI-powered, multi-layered user protections We’ve seen a clear impact from these safety efforts on Google Play. I…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:2c2730a971234a784474</id><title>New Android Theft Protection Feature Updates: Smarter, Stronger</title><updated>2026-01-27T16:59:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2026/01/android-theft-protection-feature-updates.html"/><summary>Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team Phone theft is more than just losing a device; it&#x27;s a form of financial fraud that can leave you suddenly vulnerable to personal data and financial theft. That’s why we&#x27;re committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt. Today, we&#x27;re announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals. Stronger Authentication Safeguards We&#x27;ve expanded our security to protect you against an even wider range of threats. These updates are now available for…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:5ea3583178bac56647bb</id><title>HTTPS certificate industry phasing out less secure domain validation methods</title><updated>2025-12-10T20:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html"/><summary>Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical mail, phone calls, or emails, we are closing potential loopholes for attackers and pushing the ecosystem toward automated, cryptographically verifiable security. To…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:3ef6a9e7a5e08dd57715</id><title>Further Hardening Android GPUs</title><updated>2025-12-09T17:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/12/further-hardening-android-gpus.html"/><summary>Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google&#x27;s Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely, making them unreachable by restricting attack surface is another effective and often faster way to improve security. This post details our efforts in partnership with Arm to further harden the GPU by reducing the driver&#x27;s attack surface. The Growing Threat:…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:cbea07fe439ed39276fb</id><title>Architecting Security for Agentic Capabilities in Chrome</title><updated>2025-12-08T18:03:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/12/architecting-security-for-agentic.html"/><summary>Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing. The primary new threat facing all agentic browsers is indirect prompt injection. It can appear in malicious sites, third-party content in iframes, or from user-generated content like user reviews, and can cause the agent to take unwanted actions such as initiating financial…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:339a4af901754234c494</id><title>Android expands pilot for in-call scam protection for financial apps</title><updated>2025-12-03T16:59:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/12/android-expands-pilot-in-call-scam-protection-financial-apps.html"/><summary>Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust &amp; Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle. Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications. These efforts are making a real difference in the lives of Android users. According to a recent YouGov survey 1 commissioned by Google, Android users were 58% more likely than iOS users to report they had not received any scam texts in the prior week 2. But our work doesn’t stop there. Scammers are continuously evolving, using more sophisticated social engineering…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:8e3690964736a40c4c13</id><title>Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing</title><updated>2025-11-20T17:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/11/android-quick-share-support-for-airdrop-security.html"/><summary>Posted by Dave Kleidermacher, VP, Platforms Security &amp; Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy regardless of the phone they use. That’s why Android has been building experiences that help you stay connected across platforms. As part of our efforts to continue to make cross-platform communication more seamless for users, we&#x27;ve made Quick Share interoperable with AirDrop, allowing for two-way file sharing between Android and iOS devices, starting with the Pixel 10 Family. This new feature makes it possible to quickly share your photos, videos, and files with people you choose to communicate with, without worrying about the kind of pho…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:3c3eba3b1bc1e729643d</id><title>Rust in Android: move fast and fix things</title><updated>2025-11-13T16:59:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/11/rust-in-android-move-fast-fix-things.html"/><summary>Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in new code quickly yields durable and compounding gains. This year we look at how this approach isn’t just fixing things, but helping us move faster. The 2025 data continues to validate the approach, with memory safety vulnerabilities falling below 20% of total vulnerabilities for the first time. Updated data for 2025. This data covers first-party and third-party (open source) code changes to the Android platform across C, C++, Java, Kotlin, and Rust. This post is published a couple of months before the end of 2025, but Android’s industry-standard 90-day patch window means that these results are very likely close to f…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:749651a8fd96d8dd6987</id><title>How Android provides the most effective protection to keep you safe from mobile scams</title><updated>2025-10-30T16:59:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/10/how-android-protects-you-from-scams.html"/><summary>Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we’re focusing on one of today&#x27;s most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally. ¹ For years, Android has been on the frontlines in the battle against scammers, using the best of Google AI to build proactive, multi-layered protections that can anticipate and block scams before they reach you. Android’s scam defenses protect users around the world from over 10…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:c24594ff661dc8e348a1</id><title>HTTPS by default</title><updated>2025-10-28T17:01:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/10/https-by-default.html"/><summary>One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user&#x27;s permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security&#x27;s mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks on a link, the browser ends up where the user intended. When links don&#x27;t use HTTPS, an attacker can hijack the navigation and force Chrome users to load arbitrary, attacker-controlled resources, and expose the user to malware, targeted exploitation, or social e…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:2619725ec191f27d90fd</id><title>Accelerating adoption of AI for cybersecurity at DEF CON 33</title><updated>2025-09-24T18:42:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/09/accelerating-adoption-of-ai-for.html"/><summary>Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security Team Empowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle cybercriminals and keep users safe. To help accelerate adoption of AI for cybersecurity workflows, we partnered with Airbus at DEF CON 33 to host the GenSec Capture the Flag (CTF), dedicated to human-AI collaboration in cybersecurity. Our goal was to create a fun, interactive environment, where participants across various skill levels could explore how AI can accelerate their daily cybersecurity workflows. At GenSec CTF, nearly 500 participants successfully completed introductory challenges, with 23% of participants using AI for cybersecurity…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:848e09530aad710add40</id><title>Supporting Rowhammer research to protect the DRAM ecosystem</title><updated>2025-09-15T17:01:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/09/supporting-rowhammer-research-to.html"/><summary>Posted by Daniel Moghimi Rowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and enhance DRAM reliability. However, the resilience of those mitigations against sophisticated attackers remains an open question. To address this gap and help the ecosystem with deploying robust defenses, Google has supported academic research and developed tes…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:122969df806313d391e6</id><title>How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials</title><updated>2025-09-10T15:59:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/09/pixel-android-trusted-images-c2pa-content-credentials.html"/><summary>Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA Content Credentials in Pixel Camera and Google Photos. This announcement represents a series of steps towards greater digital media transparency: The Pixel 10 lineup is the first to have Content Credentials built in across every photo created by Pixel Camera. The Pixel Camera app achieved Assurance Level 2, the highest security rating currently defined by the C2PA Conformance Program. Assurance Level 2 for a mobile app is currently only possible on the Android platform. A private-by-design approach to C2PA certificate management, where no i…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:bae9b4d715d061a1852a</id><title>Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification</title><updated>2025-08-12T16:00:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/08/Android-pKVM-Certified-SESIP-Level-5.html"/><summary>Posted by Dave Kleidermacher, VP Engineering, Android Security &amp; Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. Supporting Next-Gen Android Features The implications for the future of secure mobile technology are profound. With this level of security assurance, Android is now positioned to securely support the next generation of high-criticality isolated workloads. This…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:5ddb4c3a4dd767c00a77</id><title>Introducing OSS Rebuild: Open Source, Rebuilt to Last</title><updated>2025-07-21T21:34:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html"/><summary>Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we&#x27;re excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers. The project comprises: Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/TS), and Crates.io (Rust) packages. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrat…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:472e2a493f2645ce69ed</id><title>Advancing Protection in Chrome on Android</title><updated>2025-07-08T17:36:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/07/advancing-protection-in-chrome-on.html"/><summary>Posted by David Adrian, Javier Castro &amp; Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most sophisticated threats. Advanced Protection acts as a single control point for at-risk users on Android that enables important security settings across applications, including many of your favorite Google apps, including Chrome. In this post, we’d like to do a d…</summary><author><name>Google Security Blog</name></author></entry><entry><id>urn:sha256:9c62c84e41b8955e90a8</id><title>Mitigating prompt injection attacks with a layered defense strategy</title><updated>2025-06-13T16:03:00Z</updated><link rel="alternate" href="http://security.googleblog.com/2025/06/mitigating-prompt-injection-attacks.html"/><summary>Posted by Adam Gavish, Google GenAI Security Team With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or calendar invites that instruct AI to exfiltrate user data or execute other rogue actions. As more governments, businesses, and individuals adopt generative AI to get more done, this subtle yet potentially potent attack becomes increasingly pertinent across t…</summary><author><name>Google Security Blog</name></author></entry></feed>
