Agregátor RSS

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

The Hacker News - 9 Říjen, 2026 - 15:22
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with  Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

The Hacker News - 9 Říjen, 2026 - 14:59
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

The Hacker News - 9 Říjen, 2026 - 14:47
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost." Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

The Hacker News - 9 Říjen, 2026 - 14:47
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ten chlápek z IT přeskočil kritickou záplatu. Hackeři vysáli citlivé složky FBI, včetně domácích adres agentů

Živě.cz - 9 Říjen, 2026 - 14:45
Útočníci získali informace o tisících zaměstnanců FBI, a to včetně lidí pracujících se zdroji. Jejich domácí adresy, zdravotní či psychiatrické záznamy. Podrobnosti se dostaly do nepovolaných rukou. Potřebná záplata už byla dávno k dispozici...
Kategorie: IT News

Ten chlápek z IT přeskočil kritickou záplatu. Hackeři vysáli citlivé složky FBI, včetně domácích adres agentů

Zive.cz - bezpečnost - 9 Říjen, 2026 - 14:45
Útočníci získali informace o tisících zaměstnanců FBI, a to včetně lidí pracujících se zdroji. Jejich domácí adresy, zdravotní či psychiatrické záznamy. Podrobnosti se dostaly do nepovolaných rukou. Potřebná záplata už byla dávno k dispozici...
Kategorie: Hacking & Security

Max severity SonicWall SMA1000 flaw now exploited in attacks

Bleeping Computer - 9 Říjen, 2026 - 14:32
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
Kategorie: Hacking & Security

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The Hacker News - 9 Říjen, 2026 - 14:21
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google ode dneška omezuje Gemini. Za chytřejší AI v mobilu si musíte připlatit

Živě.cz - 9 Říjen, 2026 - 14:15
Používali jste v mobilu Gemini ke komplexním dotazům? Brzy o to přijdete • Google ode dneška zavádí omezení bezplatných uživatelů na model Flash-Lite • A první reakce? Základní model je jen na úrovni běžného AI vyhledávání od Googlu
Kategorie: IT News

Oblíbený rodinný tarif Microsoft 365 se podstatně mění. Už nebude mít 1TB OneDrive pro každého uživatele

Živě.cz - 9 Říjen, 2026 - 13:45
Poté, co loni předplatné Microsoft 365 kvůli zahrnutí AI funkcí Copilot výrazně zdražilo, tvůrci ohlašují další změnu. Týká se rodinných tarifů, které lze sdílet s až šesti členy domácnosti. Doposud platilo, že každý uživatel získal svůj vyhrazený 1TB prostor. U nově nabízených tarifů je však k ...
Kategorie: IT News

Citrix gives NetScaler admins another critical reason to patch

The Register - Anti-Virus - 9 Říjen, 2026 - 13:43
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration. Citrix's advisory lists the affected builds and required updates. Secure Private Access Hybrid deployments using NetScaler instances also need patching. Citrix classifies the flaw as CWE-119: improper restriction of operations within a memory buffer. Customers must update their own deployments. Citrix says it handles the necessary updates for its managed cloud services and Adaptive Authentication. Citrix did not say whether this vulnerability was already exploited as a zero-day before disclosure, but credited Michael Tucker, Chew Keong Tan, and Alex Bernier at JPMorgan Chase's XOR Team, along with Maxim Suhanov, for the discovery. Google researchers said a campaign exploiting CVE-2026-88772 had been underway since at least early September, with organizations in government, finance, legal, and education across North America and Europe likely affected. Citrix disclosed the flaw weeks later as part of a release that patched eight vulnerabilities. Citrix disclosed another exploited flaw, CVE-2026-88779, last Friday that carries a severity score of 8.7. Both that flaw and the newly disclosed vulnerability involve memory overflows affecting SAML configurations. The latter can also allow remote code execution, carries a higher severity score, and has not been identified by Citrix as exploited. ®
Kategorie: Viry a Červi

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

The Hacker News - 9 Říjen, 2026 - 13:30
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating [email protected]
Kategorie: Hacking & Security

Man admits to running network of 15,000 money mules for cybercriminals

Bleeping Computer - 9 Říjen, 2026 - 13:14
​A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. [...]
Kategorie: Hacking & Security

Hackeři z dětského pokojíčku děsili firmy po celém světě, přitom někteří ještě ani neměli řidičák

Zive.cz - bezpečnost - 9 Říjen, 2026 - 12:45
** Jordánsko zadrželo teenagera Reye, údajného šéfa skupiny ShinyHunters. ** Španělská policie zatkla šestnáctiletého Rumuna, hlavního operátora skupiny KillSec. ** Skupiny mladých hackerů útočily na firmy, univerzity i úřady.
Kategorie: Hacking & Security

Hackeři z dětského pokojíčku děsili firmy po celém světě, přitom někteří ještě ani neměli řidičák

Živě.cz - 9 Říjen, 2026 - 12:45
Jordánsko zadrželo teenagera Reye, údajného šéfa skupiny ShinyHunters. • Španělská policie zatkla šestnáctiletého Rumuna, hlavního operátora skupiny KillSec. • Skupiny mladých hackerů útočily na firmy, univerzity i úřady.
Kategorie: IT News

Česká armáda je v dronech dál, než si občas myslíme. Postavila polygon pro pozemní roboty a má za sebou velké cvičení

Živě.cz - 9 Říjen, 2026 - 12:39
Při pohledu na ohromující tempo vojenské robotizace v posledních několika málo letech si musí každý soudný člověk klást otázku, jak o dronech na zemi i ve vzduchu uvažuje naše vlastní armáda. Představy širší veřejnosti jsou v tomto směru občas zbytečně sebemrskačské. Ozbrojené síly nežijí v jakési ...
Kategorie: IT News

Microsoft: Outdated Windows devices will stop receiving security updates

Bleeping Computer - 9 Říjen, 2026 - 12:12
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation. [...]
Kategorie: Hacking & Security

Rotace klíče kořenové zóny již 11. října – zkontrolujte si své resolvery!

AbcLinuxu [zprávičky] - 9 Říjen, 2026 - 12:00
V neděli 11. října proběhne rotace klíče kořenové zóny. Podruhé v historii. Ondřej Filip na blogu CZ.NIC: "Pokud je pro Vás DNS protokol spíše výzva, ale přesto spravujete nějakou síť či DNS resolver, zkuste si jednoduchý test, který připravila firma Cloudflare na této adrese. Obzvláště zbystřit byste měli, pokud uvidíte nějaká červená políčka."
Kategorie: GNU/Linux & BSD

12 steps to smarter Google account security

Computerworld.com [Hacking News] - 9 Říjen, 2026 - 12:00

There are important accounts to secure, and then there are important accounts to secure. Your Google account falls into that second category, maybe even with a couple of asterisks and some neon orange highlighting added in for good measure.

I mean, really: When you stop and think about how much stuff is associated with that single sign-in — your email, your documents, your photos, your files, your search history, maybe even your contacts, text messages, and location history, if you use Android — saying it’s a “sensitive account” seems like an understatement. Whether you’re using Google for business, personal purposes, or some combination of the two, you want to do everything you possibly can to keep all of that information locked down and completely under your control.

And guess what? Having a password that you hastily set seven years ago isn’t enough. With something as priceless as your personal data, that single key is only the start of a smart security setup. And even it might be due for an upgrade.

Take 10 minutes to go through these steps, then rest easy knowing your Google account is as guarded as can be.

Part I: Reinforce your front door Step 1: Check up on your Google account password

We’ll start with something simple but supremely important — that aforementioned Google account password. Consider the following questions:

  • Is your Google password based on your name, the name of your partner or child, your birthday, your street address, or anything else someone could easily figure out by Googling you?
  • Does your Google password revolve around a common word or easily guessable pattern?
  • Is your Google password short — less than eight characters, at a minimum?
  • Do you use your Google password (or any variation of it) to sign into any other app, website, or service?

If the answer to any of those questions is yes, first, bop yourself firmly on the nose. Then use this link to go change your password immediately — preferably to something long, complex, and not involving any easily discoverable personal info, any common words or patterns, or anything you use anywhere else.

(And note: This is also where a reliable password manager — whether the basic Google Password Manager or a more fully featured third-party option — can make all the difference in the world.)

Got it? Good. Next:

Step 2: Give your Google account a second layer of protection

No matter how strong your Google account password is, there’s always still the chance someone could crack it — but you can exponentially reduce the risk of anyone actually getting into your virtual property by enabling two-factor authentication on your account.

With two-factor authentication, you’ll be prompted for a second form of security in addition to your password — ideally something that requires a physical object that’d only ever be in your presence. In its simplest effective form, that could be a prompt or a code generated by your phone. If you want to get really fancy, it could be a button pressed on an actual key you carry (which could be a special USB- or Bluetooth-based dongle or even something built into your phone) — sometimes even called a “passkey,” which is basically just a confusing and overcomplicated way to say the same thing. There’s also an option to have codes sent to you via text message, but that method is relatively easy to hijack and thus not generally advisable to use.

Whatever path you choose, having that second layer in place will make it incredibly difficult for anyone to get into your Google account, even if they do somehow know your password.

Two-factor authentication makes it significantly more difficult for anyone to get into your Google account.

JR Raphael / Foundry

If you don’t have it set up yet, go to Google’s 2-Step Verification page to get started.

Step 3: Make sure you’re prepared to prove your identity

If Google ever detects some sort of suspicious activity on your account, it might require you to verify your identity before it lets you sign in. And if you haven’t looked at your account verification settings in a while (or ever, for that matter), there’s a decent chance the necessary info might be out of date or missing altogether.

Take a minute now to open up Google’s account security site and look in the section labeled “How you sign in to Google.” There, among other things, you should see two options:

  • Recovery phone
  • Recovery email

If the value next to either option is not current and correct, click it and update it immediately.

And with that, we’re ready to move on to our next level of Google account protection.

Step 4: Give yourself a selfie-centric failsafe

Effective online security is all about an endless array of “what if”-style scenarios, and this next Google account security strengthener is no exception. Now that we’ve confirmed you’re ready to recover your Google account if you ever get locked out, it’s time to ponder an alternate path out of that nightmare — in case the usual steps for recovery for any reason ever aren’t working.

As of August 2026, Google offers the option to verify your identity for an individual, non-company-connected account via a sophisticated selfie video — a short several-second clip of yourself staring at the camera and turning your head in different directions. All you’ve gotta do is take two minutes to opt into the option and record an initial selfie video now. Then, if you’re ever unable to access your account, you can submit a new selfie video and let the system match it with your original to confirm your identity.

To get started, go to this page within the Google account settings site on any device with a camera and follow the prompts to add a selfie video. Google will walk you through creating the video and then confirm that it’s saved and active. And if all your other available sign-in methods ever fail you in the future, you’ll have the added option to verify your identity via that path.

You can read more about the selfie sign-in system and how it works in this primer.

Step 5: Get by with a little help from your friends

In addition to your own selfie video verification, you can now authorize a trusted friend or family member to step in and confirm your identity for you.

It’s something Google recently launched called Recovery Contacts, and it’s incredibly easy to set up:

The person you specify will have to acknowledge and accept the request within a week before they’re confirmed and active — but once that happens, if you’re ever locked out, they’ll be able to confirm a special one-time recovery code on their secured device to authenticate for you.

(In short: After failing to sign in, Google would allow you to select the contact, and you’d then see a random number on your screen. At the same time, your contact would receive three different numbers on their device. In order to confirm and authenticate, they would have to select which of those numbers matches the number you’re seeing and relaying to them — while communicating with you and thus verifying that the request was actually legitimate and triggered by you — in order to complete the authentication.)

Again, this would only come up if you were completely locked out of the account and unable to receive the same sort of code directly on your own. And your contact wouldn’t actually have access to any of your Google account info. They’d just be an extra pathway for you to confirm your identity and get back into your own account in a worst-case scenario.

Setting up a Recovery Contact is possible only on an individual Google account — not a company-managed Workspace account, since in that situation, your company’s admin would already be able to help facilitate any account recovery for you.

Part II: Clamp down on connections Step 6: Review the third-party services with access to your account

When you set up an app that interacts with Google in some way — on your phone, on your computer, or even within a Google service such as Gmail or Docs — that app gets granted a certain level of access to your Google account data.

Depending on the situation, that could mean it’s able to see some of your activity within specific Google services; it could mean it’s able to see everything in your Gmail, Google Calendar, or Google Drive; or it could mean it’s able to see everything across your entire Google account.

It’s all too easy to click through confirmation boxes without giving it careful thought — so look back now and see exactly what apps have access to what types of information. Visit Google’s third-party app access overview and look through the list of connected services. If you see anything there you no longer use or don’t recognize, click its line and then click the button to remove it.

Review your third-party app list and remove any items that no longer need access to your Google account.

JR Raphael / Foundry

Allowing apps you know and trust to access your account is perfectly fine, but you want to be sure to revisit the list regularly and keep it as current and concise as possible.

Step 7: Review the devices with access to your account

In addition to apps, you’ve almost certainly signed into your Google account on a variety of physical devices over the past several months (and beyond). And often, once you’ve signed in at the system level, a device remains connected to your account and able to access it — no matter how long it’s been since you’ve actually used the thing.

You can close that loop and take back control by going to Google’s device activity page. If you see any device there that you no longer use or don’t recognize, click the three-dot menu icon within its box and sign it out of your account right then and there.

Step 8: Look over app permissions on your phone

Another important app-related consideration: If you’re using Android, some system-level permissions — such as those connected to your contacts and calendar — can effectively control access to areas of your Google account data, since services such as Google Contacts and Google Calendar sync that data between your phone and the cloud.

Head into the Security & Privacy section of your phone’s system settings and look for the line labeled “Permission manager.” (Depending on your device, you might have to tap a line labeled “Privacy controls” before you see it.) If you can’t find it, try searching your system settings for the phrase permission manager instead.

Once you get there, you can look through each type of permission and see which apps are authorized to access it — and, with a couple more taps, revoke the permission from any apps where that level of access doesn’t seem necessary.

Android makes it easy to review and adjust an app’s permission, if you know where to look.

JR Raphael / Foundry

Step 9: Look over extension permissions in your browser

On the desktop, extensions added into Chrome or any other browser have the potential to expand your browser’s capabilities — but they also have the potential to put your privacy at risk.

Extensions could require access to anything from your complete browsing history to your system clipboard. They can often read and change data on sites you’re actively viewing, too — either any and all sites or only specific pertinent URLs, depending on the specific permissions requested.

None of this is necessarily bad, so long as the extension in question is reputable and requesting only the permissions it genuinely requires for the function it provides. But sometimes, even the most well-intending developers can get lazy and go with a broader permission than what their software actually needs. And in such an instance, an extension that does something as simple as enhancing the Gmail interface or allowing you to save articles for later could have access to everything you do in your browser — and the sort of broad data that’s typically kept under lock and key inside your Google account could be shared with external entities for no good reason.

So let’s do a quick little assessment, shall we? If you’re using Chrome, type chrome:extensions into your browser’s address bar. If you’re using another browser, look in its main menu to find the equivalent option for managing extensions or add-ons, as they’re sometimes also called.

Once you’re looking a list of all your installed extensions, click the “Details” or “Options” button for every extension on the page. Peek at the “Permissions” section within each one and then take a close look at the “Site access” section, in particular. Think carefully about the level of access that’s granted there and whether it’s genuinely needed — or whether it’d make sense to bring it down a notch and make it more limited in nature.

With Chrome and other Chrome-based browsers — like Microsoft Edge and Vivaldi — if the extension seems like it really only needs access to a specific site or domain and it’s requesting access to your activity on all sites, click the dropdown menu in that area and change its setting from “On all sites” to “On specific sites” (which lets you provide a specific, limited list of URLs on which the extension will have full visibility).

Chrome and other Chrome-based browsers make it easy to view and adjust the permissions for any browser extension you’re using.

JR Raphael / Foundry

Just remember that many extensions do legitimately need certain levels of access in order to operate — so make these changes cautiously and only after carefully thinking through the potential implications. Worst-case scenario, though, if you bring an extension’s access down and then find it’s no longer working as expected, you can always come back to this same area of your browser’s settings later and change it back.

Firefox, incidentally, doesn’t allow this level of granular permission-granting — so if you find an extension there is accessing more than you’re comfortable with, your only real option is to uninstall it entirely.

Speaking of which…

Step 10: Get rid of any mobile apps and browser extensions you don’t need

While you’re thinking about third-party add-ons for your computer and phone, take a moment to review everything you have installed on both fronts and consider how many of those programs you actually still use. The fewer cracked windows you allow on your Google account, the better — and if you aren’t even using something, there’s no reason to keep it connected.

And with that, we’re ready for our final two parts of account-protecting possibilities.

Part III: Plan for the worst Step 11: Set up or confirm your virtual Google will

Thinking about worst-case scenarios is never particularly pleasant — I’d much rather be eating crumpets, myself — but just as it’s important to have a plan in place for your physical and financial possessions, creating a virtual will for your Google account will make matters infinitely easier for your loved ones if and when you ever develop a mild case of death.

For company-managed Google Workspace accounts, someone at your organization would be able to take control of your account in the event that you were no longer able to access it. But with an individual Google account, no such system for passing along access exists.

Google has a simple system in place to manage this: Open up the Inactive Account Manager, and you’ll find tools for determining exactly what should happen if your account ever becomes inactive for a certain period of time. You can specify the number of months that must go by without any sign of your presence, along with the email addresses and phone numbers Google should use to contact you for confirmation. And then, you can give Google the email addresses of any people you want to be notified once it’s clear that you’re no longer available.

From there, you can specify exactly what types of information your chosen contacts will be able to access. You’ll even be able to leave a message for those people, if you want, and optionally create a broad autoreply that’ll be sent to anyone who emails you once your inactive period has begun (creepy!).

Google’s Inactive Account Manager is like a virtual estate planning tool for all of your account-associated data.

JR Raphael / Foundry

Even if you’ve gone through this process before, it’s worth going back in and revisiting your preferences occasionally to confirm the info is all still complete and accurate — not only in the specific contacts you have set to be notified but also in what specific areas of your account those people will be able to access, if this situation ever actually arises.

For that latter piece of the puzzle, be sure to click the email address of each person you have listed, then click the “Edit apps & services” option on the screen that comes up next. That’ll show you a list of account-related areas — everything from Contacts and Calendar to Google Chat, Google Photos, and even your location history (if you’re using a device that contributes to such a collection) — and let you both see which areas are currently selected and add or remove any areas you want from the list.

Virtually every time I’ve ever looked at that, I’ve found a handful of newer account-related areas weren’t selected to be shared — presumably because they didn’t exist when I had last reviewed the options. I had to manually check them all to be sure they’d be included in any post-consciousness account sharing.

Part IV: Turn your protection up to the max Step 12: Think about Google’s Advanced Protection Program

Last but not least is a step that won’t be right for everyone but could be hugely consequential for certain types of Google users. For anyone at a higher risk of a targeted attack, Google offers an elevated form of account security called the Advanced Protection Program.

The program is described as being appropriate for business leaders, IT admins, activists, journalists, and anyone else who’s in the public eye and likely to be sought out by someone looking to do damage. It puts a series of heavy-duty restrictions on your Google account to make it especially difficult for anyone else to gain access — but as a result, it also makes things a bit more difficult for you.

The core part of the Advanced Protection Program is a requirement to have a physical security key the first time you sign into your account on any new device. That means in addition to your password, you’ll need that specific form of two-factor authentication — either an approved key built into your phone or a standalone dongle — in order to access your email, documents, or any other area of your Google account.

As part of the added security, you also won’t be able to connect most third-party apps to your Google account — including those that require access to your Gmail or Google Drive in order to operate. That could create some challenges (such as signing into an Android TV device, curiously enough) and require some compromises (such as no longer being able to use most third-party email clients with Gmail). And if you ever can’t get into your account for any reason, you’ll have to go through an extra-involved, multiday recovery process in order to restore access. You can read more about what the Advanced Protection Program is like to live with in this thoughtful overview.

Ultimately, only you can decide if the added inconveniences are worth the extra assurance. If you want the utmost in security for your Google account, though — and particularly if you’re someone who’s at a higher-than-average risk of being targeted — it’s something well worth considering.

If you do want to make the leap and add this extra layer of intense security onto your Google account, head over to Google’s Advanced Protection Program website to get started. With a personal account, you’ll be able to get yourself up and running in a matter of minutes. With an account that’s part of a paid company Workspace plan, your plan administrator will have to enable Advanced Protection for the organization before you’re able to do it. Once you start the enrollment process, you’ll see pretty quickly if it’s already available for your account or not — and if not, you can contact your company admin to ask about the possibility of allowing it.

And with that, give yourself a pat on the back: Now that these 11 steps are behind you, your Google account security is officially in tiptop shape — and you shouldn’t have to devote an ounce of thought to this area again anytime soon.

Just set yourself a reminder to revisit this page and review the steps within it once a year for good measure. (I’ll continue to update and expand the specific instructions as needed over time.) Do the same with security smarts in other areas — like your Android security settings, if you’re using an Android device of any sort — and then rest easy knowing your most important digital info is as secure as it can possibly be.

This article was originally published in February 2020 and most recently updated in October 2026.

Kategorie: Hacking & Security

Google makes its most powerful AI models pay-for-play as AI services struggle to turn users into customers

Computerworld.com [Hacking News] - 9 Říjen, 2026 - 11:58

Half of all US consumers use AI services — but only a small fraction pay for them. Google is trying to shift the balance by giving users of its Gemini AI services reasons to become paying customers.

Users are certainly reluctant to dip into their pockets. A quarter of US consumers use AI daily, but only 4.5% have an active paid subscription to ChatGPT, Gemini or Claude, according to research from Andreesen Horowitz. The survey found, however, that consumers are extremely engaged and that the top 10% of spenders account for roughly half of all observed spending.

Now Google is changing the rules on who can use which Gemini models, limiting what users of its free service and its lowest-priced subscription tier can do.

Starting from October 9, those without a paid subscription will only be able to access the less powerful Gemini Flash Lite model; previously, they could use Gemini Flash and had variable access to Gemini Pro. Subscribers to the $4.99/month Google AI Plus plan will still be able to use Gemini Flash, but will lose access to Gemini Pro. Subscribers to the most expensive plans, AI Pro ($19.99/month) and AI Ultra (from $99.99/month) will retain access to Gemini Pro.

This is a clear change of direction for Google, looking to tap into the market for AI power users. The Andreessen Horowitz survey revealed that Claude had already overtaken Gemini among consumer users and Google now wants the higher end of the market. The question will be whether users are willing to pay that premium.

Kategorie: Hacking & Security
Syndikovat obsah