Google Introduces Passkey Authentication

Supply chain security for Go, Part 1: Vulnerability management

Google Authenticator now supports Google Account synchronization

Announcing the deps.dev API: critical dependency data for secure supply chains

Google's OSS-Fuzz expands fuzz-reward program

Supporting the Use of Rust in the Chromium Project

Memory Safe Languages in Android 13

Use-after-freedom: MiraclePtr

The Open Sourcing of Paranoid's Library

DNS-over-HTTP/3 in Android

Retrofitting Temporal Memory Safety on C++

Improving software supply chain security with tamper-proof builds

Understanding the Impact of Apache Log4j Vulnerability

The Secure Open Source Pilot Program

An update on Memory Safety in Chrome

Google Online Security Blog: An update on Memory Safety in Chrome

Linux Kernel Security Done Right

AllStar: Continuous Security Policy Enforcement for GitHub Projects

A New Chapter for Google’s Vulnerability Reward Program

Verifiable Supply Chain Metadata for Tekton

Measuring Security Risks in Open Source

SLSA, an End-to-End Framework for Supply Chain Integrity

Rust/C++ interop in the Android Platform

Google's unified vulnerability schema for open source supports Rust on launch

Half-Double: New hammering technique for DRAM Rowhammer bug

Google banned almost 120k spam developer accounts in 2020 for the play store

Making the Internet more secure one signed container at a time

Integrating Rust into the Android Open Source Project

A New Standard for Mobile App Security

FFmpeg and a Thousand Fixes (2014)

More →