Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Rivian gives RJ Scaringe new salary package worth up to $5 billion

GoWish shopping and wish list app has its biggest year yet

I tried Apple’s crossbody strap. It’s convenient, but if you remove the strap, it looks tacky.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google launches DBSC Open Beta in Chrome and increases patch transparency via Project Zero
Identity

Google launches DBSC Open Beta in Chrome and increases patch transparency via Project Zero

userBy userJuly 30, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 30, 2025Ravi LakshmananDevice Security / AI Security

Google has announced that it is creating a security feature called Device Bound Session Credentials (DBSC) in open beta to help users be protected against session cookie theft attacks.

First introduced as a prototype in April 2024, DBSC is designed to combine authentication sessions into devices to prevent threat actors from using stolen cookies to sign in to the victim’s account and gain unauthorized access from another device under their control.

“DBSC, available in the Chrome browser on Windows, helps to enhance security after logging in and bind session cookies (small files used by websites that remember user information) to your device,” said Senior Director of Product Administrator at Google Workspace.

DBSC is not just about protecting user accounts after authentication. It will be much more difficult for bad actors to reuse session cookies and improve session integrity.

Cybersecurity

The company also notes that PassKey support is now available to more than 11 million Google Workspace customers in general, as well as expanding its admin controls to audit registrations and limit PassKey to physical security keys.

Finally, Google will use the OpenID standard to deploy a Shared Signal Framework (SSF) receiver in a closed beta for selected customers to allow for near-real-time exchange of critical security signals.

“This framework acts as a robust system for the ‘transmitters’ to quickly notify ‘receivers’ of critical events, facilitating a coordinated response to security threats,” Wen said.

“Beyond threat detection and response, signal sharing also allows for general sharing of various properties, such as devices and user information, further strengthening the overall security attitude and joint defense mechanism.”

Google Project Zero releases transparency report

The development comes as Google Project Zero, a security team within the company tasked with hunting for zero-day vulnerabilities, announced a new testing policy reporting transparency to address what is described as upstream patch gaps.

Typically, a patch gap refers to the period when a fix is released due to a vulnerability and the time it takes for users to install the appropriate update, while an upstream patch gap indicates the time pan for upstream vendors to take advantage of the fix, while downstream customers have not yet integrated the patch and shipped to end users.

To close this upstream patch app, Google said it is adding a new step that is intended to publicly share vulnerability discoveries within a week of reporting to relevant vendors.

This information is expected to include a vendor or open source project when the report, the affected products, the date the report was submitted, and the 90-day disclosure deadline expires. The current list includes two Microsoft Windows bugs, a flaw in Dolby Unified Decoder, and three issues: Google Bigwave.

Cybersecurity

“The main goal of this exam is to reduce the upstream patch gap by increasing transparency,” said Tim Willis of Project Zero. “We can better inform downstream dependents by providing an early signal that vulnerabilities are being reported upstream. For our small set of issues, there is an additional source of information to monitor issues that may affect users.”

Google further said it plans to apply this principle to Big Sleep. It is an artificial intelligence (AI) agent launched last year as part of a collaboration between DeepMind and Google Project Zero, which enhances vulnerability detection.

Search Behemoth also emphasized that technical details, proof of concept code, or other information that could “substantially support” will be released until the deadline.

With a modern approach, Google Project Zero said it hopes to drive needles by releasing patches to devices, systems and services that end users rely on timely, enhancing the overall security ecosystem.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBritish Minister commits to green transportation and skilled work
Next Article When microgrids begin to talk to each other
user
  • Website

Related Posts

Samsung’s zero-click flaw is exploited to deploy LANDFALL Android spyware via WhatsApp

November 7, 2025

From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools

November 7, 2025

Logic bomb hidden in malware-laden NuGet package is set to explode several years after installation

November 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Rivian gives RJ Scaringe new salary package worth up to $5 billion

GoWish shopping and wish list app has its biggest year yet

I tried Apple’s crossbody strap. It’s convenient, but if you remove the strap, it looks tacky.

Samsung’s zero-click flaw is exploited to deploy LANDFALL Android spyware via WhatsApp

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.