Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

7/31/2019
08:00 PM
100%
0%

Google Cloud Debuts New Security Capabilities

Updates include Advanced Protection Program for the enterprise and general availability of password vaulted apps in Cloud Identity and G Suite.

Google Cloud is getting a few new capabilities and updates intended to secure data in the cloud, alert administrators to cloud-based threats, and protect users from targeted attacks.

Google is bringing its Advanced Protection Platform, designed to boost security for high-risk individuals, to G Suite, Google Cloud, and Cloud Identity customers. Businesses can opt to enroll users at greatest risk for targeted attacks — for example, C-level execs, IT administrators, and employees in industries like finance or government, which are typically more security-sensitive.

For these employees, Google enforces an extra set of security policies. The program automatically blocks access to third-party apps not verified by the company and has more detailed scanning of incoming mail for phishing attacks or malware. Participants are also required to use a FIDO security key, or other compatible hardware, to block account takeover. Google says the Advanced Protection Program will be available in beta within the coming days.

On a related note, Google's Titan Security Key, which launched in the US last year, will be made available in Japan, Canada, France, and the United Kingdom on the Google Store starting today. The Titan key can be used on any device that supports FIDO security keys.

Starting today, anomaly detection will be available in beta for G Suite Enterprise and G Suite Enterprise for Education. G Suite Enterprise admins can automatically receive anomalous activity alerts in the G Suite alert center to learn about potential security risks, including data exfiltration or other policy violations related to suspicious external file sharing and downloads.

Support for password-vaulted apps will be generally available for Cloud Identity within the coming days. Cloud Identity and G Suite already allow single sign-on for apps using SAML and OIDC identity standards; now Google is bringing support for password-vaulted apps to Cloud Identity so businesses can continue supporting legacy apps that still require a username and password. The combination of standards-based and password-vaulted app support is intended to provide one-click access for users, as well as a single point of management and control for admins, Google officials explain in a blog post.

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
sophiapage
50%
50%
sophiapage,
User Rank: Apprentice
8/7/2019 | 1:58:01 AM
Re: Google cloud
Thanks for sharing such useful ideas.
Lathaa103
50%
50%
Lathaa103,
User Rank: Apprentice
8/1/2019 | 6:05:17 AM
Google cloud
Hi,

Thanks for the article which speaks on the new capabilities of the Google cloud. Before even planning to migrate the applications on the cloud it is good to go for <a href="https://www.cloudnowtech.com/services/cloud-consulting.html">cloud consulting services</a> providers to have an overall view of the services offered by different cloud providers.
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: "The truth behind Stonehenge...."
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25902
PUBLISHED: 2021-03-02
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class.
CVE-2020-1936
PUBLISHED: 2021-03-02
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
CVE-2021-27904
PUBLISHED: 2021-03-02
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the &quot;all org&quot; flag sometimes provided view access to unintended actors.
CVE-2021-27901
PUBLISHED: 2021-03-02
An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illumination. The LG ID is LVE-SMP-210001 (March 2021).
CVE-2021-21321
PUBLISHED: 2021-03-02
fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before version 4.0.2, by crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is &...