{"id":815,"date":"2025-04-01T09:47:18","date_gmt":"2025-04-01T09:47:18","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/815\/"},"modified":"2025-04-01T09:47:18","modified_gmt":"2025-04-01T09:47:18","slug":"googles-gmail-upgrade-good-and-bad-news-for-3-billion-users","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/815\/","title":{"rendered":"Google\u2019s Gmail Upgrade\u2014Good And Bad News For 3 Billion Users"},"content":{"rendered":"<p class=\"color-body light-text\" role=\"button\">New Gmail warning<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Just days after Google confirmed it is bringing its next AI upgrade to Gmail, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/24\/google-confirms-gmail-upgrade-3-billion-users-must-now-decide\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/24\/google-confirms-gmail-upgrade-3-billion-users-must-now-decide\/\" target=\"_self\" aria-label=\"with major privacy implications\" rel=\"noopener\">with major privacy implications<\/a>, there\u2019s more good and bad news for the 3 billion users relying on Google to deliver secure, spam-free email to their phones and computers. It turns out that a dangerous email attack has operated under the radar for years \u2014 until now.<\/p>\n<p>First to the good news. Google\u2019s tightening restrictions on the mass delivery of spam emails to your inbox is working and it\u2019s having a devastating impact on the industry spawned to plague you with marketing messages. \u201cOver the last year,\u201d website <a class=\"color-link\" href=\"https:\/\/martech.org\/apple-and-gmail-make-it-harder-for-email-campaigns-to-get-to-the-inbox\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/martech.org\/apple-and-gmail-make-it-harder-for-email-campaigns-to-get-to-the-inbox\/\" aria-label=\"MarTech\">MarTech<\/a> says the industry has seen \u201cengagement rates (open and click rates, especially) drop considerably. Their emails only show up in the inboxes of people already engaging with the brand. For most subscribers, the emails are getting flagged as spam.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/30\/nsa-warns-iphone-android-users-change-message-settings\/\" target=\"_blank\" aria-label=\"NSA Warning\u2014Change Your  iPhone, Android Message Settings\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/30\/nsa-warns-iphone-android-users-change-message-settings\/\">ForbesNSA Warning\u2014Change Your  iPhone, Android Message SettingsBy Zak Doffman<\/a><\/p>\n<p>This is having the desired effect, albeit \u201cfor many of these brands, this is the first time they have encountered this issue [and] for brands with a recent history of combatting spam labels, normal mitigation practices have either been unsuccessful or only effective in the short term.\u201d Bad for brands and marketeers, good for email users.<\/p>\n<p>Be warned, though, the industry is shaping new advice to bypass the new measures. \u201cEmail deliverability is more of an art than a science,\u201d says Martech. \u201cEnsure your team maintains an open dialogue about strategies to stay out of the spam folder, and test initiatives that have proven effective for similar brands.\u201d And it comes with a list of new tricks and techniques.<\/p>\n<p>Apple\u2019s own spam crackdown has had the same effect, but the Gmail impact is much greater. According to <a class=\"color-link\" href=\"https:\/\/www.statista.com\/chart\/34197\/share-of-us-respondents-use-email-providers\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.statista.com\/chart\/34197\/share-of-us-respondents-use-email-providers\/\" aria-label=\"Statista\">Statista<\/a>, \u201cGmail and related e-mail addresses given out by Google positively dominate the U.S. market,\u201d this despite the latest privacy warnings, with its new AI upgrade leaving \u201cmany users feeling anxious and appalled at the thought that a generative AI would be reading their personal emails.\u201d<\/p>\n<p>For its part, when asked about the new AI upgrade Google told me \u201cour priority is respecting our users\u2019 privacy while giving them choice and control over their data. To that end, this particular tool is one of the &#8216;smart features\u2019 that users can control in their personalization settings.\u201d You can read more about those privacy <a class=\"color-link\" href=\"https:\/\/workspace.google.com\/blog\/identity-and-security\/protecting-your-data-era-generative-ai\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/workspace.google.com\/blog\/identity-and-security\/protecting-your-data-era-generative-ai\" aria-label=\"settings\">settings<\/a>.<\/p>\n<p class=\"color-body light-text\" role=\"button\">Gmail versus the rest<\/p>\n<p>Statista<\/p>\n<p>But Gmail (and other) security restrictions are not bulletproof \u2014 far from it. <a class=\"color-link\" href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/a-phishing-tale-of-doh-and-dns-mx-abuse\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/blogs.infoblox.com\/threat-intelligence\/a-phishing-tale-of-doh-and-dns-mx-abuse\/\" aria-label=\"Infloblox\">Infloblox<\/a> warns it \u201crecently discovered a DNS technique used to tailor content to victims.\u201d This works by way of a \u201cphishing kit that creatively employs DNS mail exchange (MX) records to dynamically serve fake, tailored, login pages, spoofing over 100 brands.\u201d The attacks evade detection by exploiting the DNS over HTTPS (DoH) upgrade, and also a raft of mass emailing spam techniques.<\/p>\n<p>According to the research team, \u201cmost of the hyperlinks in the spam emails use domains related to compromised WordPress websites, URL shorteners, or free web hosting.\u201d This includes \u201cabusing legitimate adtech infrastructure to generate redirect links to the phishing webpages. They also exploit open redirect vulnerabilities on DoubleClick, an advertising network owned by Google.\u201d<\/p>\n<p>As <a class=\"color-link\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/phishing-as-a-service-operation-uses-dns-over-https-for-evasion\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.bleepingcomputer.com\/news\/security\/phishing-as-a-service-operation-uses-dns-over-https-for-evasion\/\" aria-label=\"Bleeping Computer\">Bleeping Computer<\/a> explains, the operation dubbed Morphing Meerkat \u201ccan impersonate more than 114 email and service providers, including Gmail, Outlook, Yahoo, DHL, Maersk, and RakBank, delivering messages with subject lines crafted to prompt urgent action like \u2018Action Required: Account Deactivation\u2019.\u201d<\/p>\n<p>One devious twist in these attacks is that after serving malicious email login pages to steal credentials, an attack then redirects to real email login pages to avoid suspicion and leave a user thinking they had mistyped their credentials. The days of passwords for account access must now come to an end. While two-factor authentication (2FA) helps, in its simplest forms it is vulnerable. All Gmail users should setup passkeys and ensure the strongest form of 2FA is is in place for passwords left in place as a backup.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/28\/googles-chrome-deadline-you-have-21-days-to-update-your-browser\/\" target=\"_blank\" aria-label=\"Google\u2019s Chrome Deadline\u2014You Have 21 Days To Update Your Browser\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/28\/googles-chrome-deadline-you-have-21-days-to-update-your-browser\/\">ForbesGoogle\u2019s Chrome Deadline\u2014You Have 21 Days To Update Your BrowserBy Zak Doffman<\/a><\/p>\n<p>Infoblox says \u201cthe threat actor behind the campaigns often exploits open redirects on adtech infrastructure, compromises domains for phishing distribution, and distributes stolen credentials through several mechanisms, including Telegram.\u201d Alarmingly this has operated under everyone\u2019s radar. \u201cAlthough there have been reports of individual instances related to this activity, we have not seen reporting on this PhaaS and MX record technique, despite it being in operation for years.\u201d<\/p>\n<p>All the more reason not to click, download or open unless you\u2019re absolutely sure. And yet another clear warning as to why <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/02\/11\/googles-gmail-upgrade-why-you-need-a-new-app\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/02\/11\/googles-gmail-upgrade-why-you-need-a-new-app\/\" target=\"_self\" aria-label=\"email with its archaic architecture needs a rethink\" rel=\"noopener\">email with its archaic architecture needs a rethink<\/a> rather than a series of security upgrades that leave core weaknesses untouched.<\/p>\n","protected":false},"excerpt":{"rendered":"New Gmail warning NurPhoto via Getty Images Just days after Google confirmed it is bringing its next AI&hellip;\n","protected":false},"author":2,"featured_media":816,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[635,634,636,632,633,53,16,15],"class_list":{"0":"post-815","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-email-warning","9":"tag-gmail-ai","10":"tag-gmail-gemini","11":"tag-gmail-warning","12":"tag-google-warning","13":"tag-technology","14":"tag-uk","15":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114262077804836380","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=815"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/815\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/816"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}