Categories: HackingSecurity

Project Zero – Google is hiring the hacking excellence to improve Internet security

Project Zero is the new initiative announced by Google. The company is hiring the top security experts to make the Internet a more secure place.

Google has publicly announced a new program called “Project Zero,” an ambitious project which involves a team of Star Hackers and Bug Hunters with the purpose to improve security of the Internet. Google company has always considered security a top priority for its products and services, and now it desires to promote the research to secure the Internet.
“Security is a top priority for Google. We’ve invested a lot in making our products secure, including strong SSL encryption by default for Search, Gmail and Drive, as well as encrypting data moving between our data centers. Beyond securing our own products, interested Googlers also spend some of their time on research that makes the Internet safer, leading to the discovery of bugs like Heartbleed.” states the official announcement from Google.
Google hired a team of top security researchers that will work to discover most severe security vulnerabilities in applications and services around the world and to fix them.
It is clear the intent of Google to support the research to mitigate the risks of exploitation of previously unknown flaws, also known as zero-day vulnerabilities, by the cybercrime, Intelligence agencies and state-sponsored hackers.
The real problem related to zero-day is the window of exposure that is the period in which hackers exploit the vulnerability before world wide security community respond applying needed countermeasures.

“You should be able to use the web without fear that a criminal or state-sponsored actor is exploiting software bugs to infect your computer, steal secrets or monitor your communications. Yet in sophisticated attacks, we see the use of “zero-day” vulnerabilities to target, for example, human rights activists or to conduct industrial espionage. This needs to stop. We think more can be done to tackle this problem.” wrote Chris Evans from Google’s Chrome security team, the expert that will lead Project Zero.

Project Zero is born to significantly reduce the number of targeted attacks which daily exploit flaws in the Internet systems and applications, for the success of the initiative Google is hiring “the best practically-minded security researchers“.
Ok, now you are thinking who are the members of the Project Zero team already hired?
Google has already recruited many experts, following the most popular hackers of the Project Zero team:
  • Ben Hawkes – an independent researcher from New Zealand which discovered dozens of bugs in many software, including Adobe Flash and Microsoft Office.
  • George Hotz – the hacker which become popular for the hack of Sony PlayStation 3, iPhone, Google’s Chrome browser and the recent Towelroot for mobile Android devices.
  • Tavis Ormandy – Information Security Engineer at Google and who discovered many zero-day software in many applications.
The team of Project Zero will work to discover zero-day vulnerabilities in popular softwares, once discovered the flaws, the hackers will report them to the vendors releasing the full vulnerability disclosure only when the a patch will be available. Every bug will be filed transparently in an external database.

We’ll use standard approaches such as locating and reporting large numbers of vulnerabilities. In addition, we’ll be conducting new research into mitigations, exploitation, program analysis—and anything else that our researchers decide is a worthwhile investment.” Chris Evans said.

Google is intentioned to provide an historical contribution to the Infosec Community … let’s hope that Intelligence agencies will not access to the work of the team.

Pierluigi Paganini

Security Affairs –  (Project Zero, zero-day)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Experts warn of an ongoing malware campaign targeting WP-Automatic plugin

A critical vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and…

13 hours ago

Cryptocurrencies and cybercrime: A critical intermingling

As cryptocurrencies have grown in popularity, there has also been growing concern about cybercrime involvement…

15 hours ago

Kaiser Permanente data breach may have impacted 13.4 million patients

Healthcare service provider Kaiser Permanente disclosed a security breach that may impact 13.4 million individuals…

15 hours ago

Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability. Over…

17 hours ago

Sweden’s liquor supply severely impacted by ransomware attack on logistics company

A ransomware attack on a Swedish logistics company Skanlog severely impacted the country's liquor supply. …

19 hours ago

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

1 day ago

This website uses cookies.