WP Engine Vs. Automattic: Rulings Preserve WP Engine’s Lawsuit via @sejournal, @martinibuster

The judge overseeing the legal battle between WP Engine versus Automattic and Matt Mullenweg issued a ruling that fully dismissed two of WP Engine’s claims, allowed several to proceed, and gave WP Engine the chance to amend others.

Nine Claims Allowed To Proceed – One Partially Survives

Counts 1 & 2

  • Count 1: Intentional Interference with Contractual Relations
  • Count 2: Intentional Interference with Prospective Economic Advantage

Those two counts survived the motion to dismiss. That means WP Engine can try to prove that Automattic/Mullenweg interfered with its contracts and business opportunities. This shows that the judge didn’t throw out WP Engine’s entire “you’re sabotaging our business” approach. If WP Engine wins on these counts they could be eligible to receive damages.

In total, the judge’s order allowed nine claims to proceed and one to partially survive.

These are the remaining claims that survived and are allowed to proceed:

  • CFAA Unauthorized Access (Count 19):
    Tied to allegations that Automattic and Mullenweg covertly replaced WP Engine’s ACF plugin with their own SCF plugin on customer sites without authorization.
  • Unfair Competition (Count 5)
    Connected to claims that Automattic’s conduct, including unauthorized plugin replacement and trademark issues, amounted to unlawful and unfair business practices under California law.
  • Defamation (Count 9) & Trade Libel (Count 10)
    Statements on WordPress.org alleging WP Engine offered a “cheap knock-off” of WordPress and that WP Engine delivered a “bastardized simulacra of WordPress’s GPL code.”
  • Slander (Count 11):
    Based on public remarks Mullenweg made at WordCamp US and in a livestreamed interview where Mullenweg described WP Engine as “parasitic” and damaging to the open-source community.
  • Lanham Act (Count 17: Unfair Competition) & Lanham Act (Count 18: False Advertising)
    Automattic and Mullenweg filed a motion to partially dismiss these counts but the motion was not granted, so these two counts move forward.

This is the claim that partially survived:

Promissory Estoppel (Count 6)
This is based on specific promises, such as free plugin hosting on wordpress.org, which the court found definite enough to proceed, while broader statements like “everyone is welcome” were too vague to support the claim.

Two Claims Dismissed With Leave To Amend

The judge dismissed two of the claims with “leave to amend,” which means the court found an issue with how WP Engine pleaded their claims. The claims were not legally sufficient, but the judge gave WP Engine the option to update its complaint to fix the problems. If WP Engine amends successfully, those claims can return to the case.

The two claims dismissed with leave to amend are:

1. Antitrust claims of monopolization, attempted monopolization, and illegal tying (Sherman Act & Cartwright Act).

On the antitrust claims, the Court found WP Engine failed to define a relevant market, stating:

“…consumers entering the WordPress ecosystem by electing a WordPress web content management system would know they were locked-in to WordPress aftermarkets. Mullenweg’s purported deception and extortionate acts did not change that fundamental operating principle of the WordPress marketplace.”

2. CFAA extortion claim (Count 3): WP Engine alleged Automattic threatened to block wordpress.org access and demanded licensing fees.

Regarding the extortion claims, WP Engine alleged that Automattic and Mullenweg violated the Computer Fraud and Abuse Act (CFAA) by threatening to block WP Engine’s access to wordpress.org and demanding licensing fees.

The Court dismissed this claim with leave to amend, finding the allegations did not sufficiently establish “extortion” under CFAA standards. The judge noted that merely threatening to block access, even coupled with demands for licensing, did not meet the statutory requirements as pled. However, WP Engine has been given time to amend the complaint (“with leave to amend”).

Two Claims Fully Dismissed

Two of WP Engine’s claims were fully dismissed:

  • Count 4: Attempted Extortion (California Penal Code)
  • Count 16: Trademark Misuse

Count 4
Count 4 was dismissed because the California Penal Code allows government prosecutors to bring criminal charges for attempted extortion, but it does not give private parties like WP Engine the right to sue under that statute. The dismissal was not about whether Automattic’s conduct could be considered extortion but about whether WP Engine had the legal authority to use that law in a civil case.

Count 16
The court dismissed Count 16 because trademark misuse is only recognized as a defense, not as a lawsuit that can be filed on its own. WP Engine may still raise trademark misuse later if Automattic tries to enforce trademarks against it.

The exact wording is:

“With no authority from WPEngine that authorizes pleading declaratory judgment of trademark misuse as a standalone cause of action rather than an affirmative defense, the Court GRANTS Defendants’ motion to dismiss Count 16, without prejudice to WPEngine asserting it as an affirmative defense if appropriate later in this litigation.”

Post By Matt Mullenweg About The Ruling

Automattic CEO and WordPress co-founder posted an upbeat blog post about the court ruling that offered a simplified summary of the court order, which is fine, but simplification can leave out details. He’s right that the decision narrows the case and that the attempted extortion claim is out for good.

He wrote:

“…the court dismissed several of WP Engine and Silver Lake’s most serious claims — antitrust, monopolization, and extortion have been knocked out!”

The attempted extortion under California Penal Code (Count 4) was indeed “knocked out.” But the Computer Fraud and Abuse Act (CFAA) extortion claim (Count 3) was dismissed with leave to amend, meaning WP Engine has the opportunity to try again.

The antitrust and monopolization claims (Counts 12–15) were also dismissed but with leave to amend, meaning they too are not permanently gone.

His post is technically correct.

But the simplification leaves out what the judge allowed to move forward:

Automattic’s motion to dismiss Count 1 (intentional interference with contractual relations) and Count 2 (intentional interference with prospective economic relations) were denied, and both will move forward, potentially making WP Engine eligible to receive damages if they win on these counts.

Then there are the others that are moving forward:

  • CFAA (Count 19): This is significant. It alleges Automattic covertly swapped WP Engine’s widely-used ACF plugin with its own SCF plugin on customer sites without consent. The court found these allegations plausible enough to move forward
  • Unfair Competition (Count 5): Connected to claims that Automattic’s conduct, including unauthorized plugin replacement and trademark issues, amounted to unlawful and unfair business practices under California law. (The court specifically pointed to the surviving CFAA and Lanham Act claims as the legal basis for letting this proceed.)
  • Defamation (Count 9) & Trade Libel (Count 10): Based on statements on WordPress.org alleging WP Engine offered a “cheap knock-off” of WordPress and that WP Engine delivered a “bastardized simulacra of WordPress’s GPL code.”
  • Slander (Count 11): Grounded in public remarks Mullenweg made at WordCamp US and in a livestreamed interview where he described WP Engine as “parasitic” and damaging to the open-source community.
  • Lanham Act (Count 17: Unfair Competition) & Lanham Act (Count 18: False Advertising): Defendants sought partial dismissal, but the court declined. Both counts remain live and move forward.

Featured Image by Shutterstock/Kaspars Grinvalds

https://www.searchenginejournal.com/wp-engine-vs-automattic-rulings-preserve-wp-engines-lawsuit/555928/




CERT-AGID 6-12 settembre: i ransomware mostrano una nuova tattica di ingegneria sociale


La scorsa settimana il CERT-AGID ha identificato e analizzato 75 campagne malevole nell’ambito italiano: 41 hanno preso di mira obiettivi nazionali, mentre 34 erano di carattere generico ma hanno comunque interessato il nostro Paese.

Agli enti accreditati ha messo a disposizione i 1.235 indicatori di compromissione (IoC) individuati.

I temi della settimana

Questa settimana i temi sfruttati per veicolare le campagne malevole in Italia sono stati venti.

In primo piano si sono viste le “Multe”: svariate campagne italiane, tutte via email, hanno abusato del brand PagoPA, con un caso che ha simulato comunicazioni del Ministero dell’Interno.

I messaggi hanno riprodotto false notifiche di sanzioni o avvisi di pagamento con l’obiettivo di sottrarre i dati delle carte; in un caso il link alla pagina malevola è stato inserito dentro un allegato PDF invece che nel corpo dell’email.

Pagamenti e banche nel mirino: phishing su PagoPA e ING, nove famiglie di malware e prevalenza di RAR/ZIP; colpite università e servizi INPS.

Sul fronte “Banking” si sono contate dodici campagne di phishing italiane, sempre via email, che hanno preso di mira ING, Intesa Sanpaolo, BPM, Fineco e, in un caso, anche PayPal.

Il tema “Ordine” è stato usato in nove campagne complessive, di cui sette generiche e due italiane: le prime hanno diffuso diversi malware, tra cui Formbook, AgentTesla, DarkCloud e Remcos, spesso attraverso archivi compressi contenenti eseguibili malevoli; le due campagne italiane hanno distribuito VipKeylogger e Remcos.

Gli “Aggiornamenti” sono comparsi in sei campagne, cinque generiche e una italiana. Nelle campagne generiche è stato diffuso principalmente il malware Lumma Stealer, veicolato tramite archivi ZIP con eseguibili malevoli, mentre la campagna italiana ha puntato su un phishing ai danni degli utenti Microsoft Outlook.

Il tema “Documenti” è stato sfruttato in cinque campagne, quattro generiche e una italiana: le generiche hanno diffuso AgentTesla, Remcos e Guloader, oltre a un’ulteriore campagna di phishing contro HSBC.

Quella italiana ha invece sfruttato il nome di INPS con finalità di phishing, confermando la frequenza con cui questo tema viene usato per frodi online. Il resto dei temi ha sostenuto ulteriori campagne di malware e

Tra gli eventi più rilevanti, sono emerse campagne di phishing mirate contro personale e studenti di diversi atenei italiani, tra cui l’Università Politecnica delle Marche, l’Università di Verona, l’Università di Bari e l’Università di Chieti-Pescara.

Le operazioni, tutte correlate tra loro, hanno replicato graficamente i portali di accesso alle aree riservate per sottrarre credenziali istituzionali.

Guardando ai ransomware, invece, si è osservata una nuova tattica di ingegneria sociale. Il gruppo LunaLock ha dapprima rivendicato il furto e la cifratura dei dati di una piattaforma per artisti freelance.

Successivamente, oltre alla consueta minaccia di pubblicazione dei materiali sottratti, ha avvertito che in caso di mancato pagamento avrebbe consegnato le opere d’arte alle aziende di intelligenza artificiale per l’addestramento dei modelli.

Fonte: CERT-AGID

È stata inoltre rilevata una nuova campagna di phishing ai danni di INPS che ha sfruttato, con modalità simili a una precedente offensiva contro l’Agenzia delle Entrate, il brand del servizio di file sharing WeTransfer.

Gli attori hanno inviato email che simulavano notifiche di WeTransfer facendo apparire le comunicazioni come provenienti da un dominio istituzionale (pec.inps.it) per aumentarne la credibilità e indurre le vittime a scaricare presunti documenti previdenziali urgenti.

Il link malevolo ha reindirizzato dapprima a una finta pagina di WeTransfer e poi a una falsa pagina di accesso di Aruba, con l’obiettivo di sottrarre credenziali email.

Malware della settimana

Nel corso della settimana sono state individuate nove famiglie di malware che hanno interessato l’Italia.

FormBook ha riguardato sei campagne generiche a tema “Prezzi”, “Ordine”, “Contratti” e “Fattura”, veicolate via email con allegati RAR, TAR e Z. Remcos è comparso in una campagna italiana a tema “Ordine” e in cinque campagne generiche legate a “Ordine”, “Prezzi”, “Contratti” e “Documenti”, distribuite con email contenenti ZIP, RAR e TAR.

AgentTesla è stato rilevato in cinque campagne generiche che hanno sfruttato i temi “Pagamenti”, “Ordine”, “Documenti” e “Aggiornamenti”, con allegati GZ, LZH, Z e TAR.

Lumma ha sostenuto quattro campagne generiche tutte legate al tema “Aggiornamenti”, recapitate con allegati ZIP.

Fonte: CERT-AGID

VipKeylogger è emerso in una campagna italiana “Ordine” e in tre campagne generiche “Ordine” e “Fattura”, distribuite tramite email con allegati RAR e ZIP. XWorm è stato osservato in tre campagne generiche a tema “Fattura”, “Pagamenti” e “Preventivo”, inviate con allegati XLAM, talvolta racchiusi in archivi ZIP.

Copybara è stato diffuso in una campagna italiana a tema “Banking” tramite SMS che rimandavano al download di un APK malevolo. DarkCloud è comparso in una campagna generica “Ordine” distribuita con archivio 7Z.

Infine, Guloader è stato impiegato in una campagna generica “Documenti” recapitata con allegati HTML e MSI.

Phishing della settimana

In totale sono stati coinvolti diciannove brand nelle campagne di phishing della settimana, con una concentrazione particolare sui temi PagoPA e ING, che hanno registrato il maggior numero di tentativi fraudolenti.

Formati e canali di diffusione

Sul fronte dei vettori tecnici, è emersa la solita  prevalenza degli archivi compressi.

A fronte di tredici tipologie di file impiegate, il formato più utilizzato è stato il RAR con 10 campagne complessive, seguito dallo ZIP con 7 episodi, mentre XLAM e TAR sono comparsi 3 volte ciascuno.

Fonte: CERT-AGID

Più sporadico l’uso di altri formati, tra cui G, Z e PDF (2 volte ciascuno), e con un solo riscontro per APK, LZH, SHTML, 7Z, MSI e HTML.

Quanto ai canali di diffusione, le email hanno continuato a rappresentare il veicolo esclusivo scelto dai criminali informatici, risultando responsabili di tutte le 75 campagne registrate dal CERT-AGID.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/15/cert-agid-6-12-settembre-i-ransomware-mostrano-una-nuova-tattica-di-ingegneria-sociale/?utm_source=rss&utm_medium=rss&utm_campaign=cert-agid-6-12-settembre-i-ransomware-mostrano-una-nuova-tattica-di-ingegneria-sociale




L’IA diventa arma e vittima per il cybercrimine: il report di Crowdstrike


L’intelligenza artificiale diventa non solo un’arma per il cybercrimine, ma anche un allettante obiettivo: secondo il Threat Hunting Report di Crowdstrike, gli attaccanti stanno usando l’IA, in particolare la GenAI, per accelerare le operazioni, e al contempo stanno prendendo sempre più di mira gli agenti di IA autonomi delle aziende.

L’IA viene usata per automatizzare ogni fase degli attacchi, come nel caso delle campagne di Famous Chollima, gruppo legato alla Corea del Nord. I cyberattaccanti hanno usato la GenAI per creare curriculum falsi, condurre finti colloqui tramite deepfake ed eseguire compiti tecnici sotto false identità.

Altri esempi significativi sono quelli di Ember Bear, gruppo di matrice russa che ha fatto ampio uso dell’IA generativa per diffondere i propri ideali, e di Charming Kitten, gruppo legato all’Iran che ha sfruttato gli LLM per creare campagne di phishing efficaci contro entità statunitensi ed europee.

IA Crowdstrike

L’intelligenza artificiale viene usata anche per generare script e malware, soprattutto da attaccanti con un basso livello tecnico, in quanto riescono ad automatizzare compiti che prima richiedevano competenze specifiche. Tra i gruppi più attivi in questo senso troviamo Funklocker e SparkCat.

Secondo il report di Crowdstrike, l’IA è diventata anche la nuova superficie d’attacco, in particolare l’IA agentica: diversi cybercriminali hanno sfruttato le vulnerabilità presenti negli strumenti usati per costruire gli agenti autonomi per ottenere accesso senza autenticazione, stabilire persistenza, sottrarre credenziali e diffondere malware.

“L’era dell’AI ha ridefinito il modo in cui le aziende operano e il modo in cui gli avversari attaccano. Stiamo vedendo i criminali usare l’AI generativa per ampliare le attività di social engineering, accelerare le operazioni e abbassare la barriera d’ingresso per le intrusioni manuali” ha affermato Adam Meyers, head of counter adversary operations, CrowdStrike. “Allo stesso tempo, gli avversari stanno prendendo di mira proprio i sistemi di AI che le aziende stanno implementando. Ogni agente AI è un’identità sovrumana: autonoma, veloce e profondamente integrata, che li rende obiettivi di alto valore. Gli avversari trattano questi agenti come fossero infrastrutture, attaccandoli allo stesso modo in cui prendono di mira le piattaforme SaaS, le console cloud e gli account privilegiati. Proteggere la stessa AI che alimenta il business è il nuovo terreno su cui si sta evolvendo la guerra cibernetica oggi“.

Dal report è emerso inoltre che Scattered Spider ha incrementato i suoi attacchi cross-domain basati sull’identità, diventando più aggressivo e veloce. Scattered Spider ha usato il vishing per attaccare gli ambienti SaaS e cloud e diffondere ransomware.

Infine, i cyberattaccanti legati alla Cina hanno fatto registrare un aumento significativo di attacchi al cloud: le intrusioni di matrice cinese sono incrementate del 136% rispetto al precedente report.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/12/l-ia-diventa-arma-e-vittima-per-il-cybercrimine-il-report-di-crowdstrike/?utm_source=rss&utm_medium=rss&utm_campaign=l-ia-diventa-arma-e-vittima-per-il-cybercrimine-il-report-di-crowdstrike




Report Acronis: il ransomware rimane la minaccia principale grazie a phishing basato su IA


Il ransomware continua a dilagare e rimane la minaccia principale per le aziende di medie e grandi dimensioni, soprattutto grazie al phishing e al social engineering basati su IA: a dirlo è l’Acronis Cyberthreats Report H1 2025, analisi sui principali vettori di attacco, gruppi cybercriminali più attivi e settori più colpiti della prima metà del 2025.

Il report di Acronis evidenzia che il numero di vittime dei ransomware è aumentato del 70% nel primo semestre dell’anno rispetto allo stesso periodo del 2024.

Acronis ransomware

Tra i gruppi più attivi figurano Cl0p, Akira e Qin, ma anche gruppi minori si stanno facendo strada nel panorama delle minacce grazie a un uso più diffuso dell’IA. L’utilizzo di tecnologie deepfake e automazioni consente ai cybercriminali di impersonare in maniera convincente le figure chiavi aziendali e velocizzare le campagne di phishing. Questo cambiamento si riflette nei dati presentati da Acronis: gli attacchi di social engineering sono passati dal 20% al 25,6% tra gennaio e maggio 2025 rispetto allo stesso periodo del 2024.

“Sebbene la diffusione del ransomware rimanga l’obiettivo finale dei criminali, le modalità con cui vi arrivano stanno cambiando. Oggi anche gli attaccanti meno esperti possono accedere a funzionalità AI avanzate, generare attacchi di social engineering e automatizzare le proprie attività con uno sforzo minimo” ha affermato Gerald Beuchelt, CISO di Acronis. “Il risultato è che MSP, produttori, ISP e altri operatori sono costantemente esposti ad attacchi sempre più sofisticati, come i deepfake evoluti, e basta un solo errore per compromettere le prospettive future delle aziende. Per affrontare questo scenario ed evitare le pesanti conseguenze di un attacco ransomware, è fondamentale adottare una strategia di cyber protection olistica che integri funzionalità avanzate di rilevamento, risposta e ripristino“.

Anche il phishing è legato a numeri significativi: stando al report, rappresenta il 25% di tutti gli attacchi registrati e ben il 52% di quelli contro gli MSP, registrando un aumento del 22% rispetto al 1° settembre 2024.

Riguardo i settori, il più colpito risulta essere il manifatturiero con il 15% di tutti i casi registrati nel primo semestre dell’anno, seguito dal retail, dal food&beverages e da telecomunicazioni&media.

Guardando infine ai Paesi più colpiti da malware, l’India risulta essere al primo posto, seguita da Brasile e Spagna. Per quanto riguarda l’Italia, il nostro Paese è rimasto in cima alla classifica, alternandosi tra il quinto e sesto posto nel corso degli ultimi mesi.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/11/report-acronis-il-ransomware-rimane-la-minaccia-principale-grazie-a-phishing-basato-su-ia/?utm_source=rss&utm_medium=rss&utm_campaign=report-acronis-il-ransomware-rimane-la-minaccia-principale-grazie-a-phishing-basato-su-ia




Amazon Experiences Drop In Google Search Visibility via @sejournal, @martinibuster

New data from the Audience Key content marketing platform indicates that Amazon’s visibility has suffered a significant drop. The decline follows two changes Amazon made to its presence in Google Shopping, although it is uncertain whether those changes are direct or indirect causes.

The first change was the discontinuation of its paid Shopping ads, and the second was the consolidation of its three merchant store names (Amazon, Amazon.com, and Amazon.com – Seller) into a single store identity, “Amazon.” These changes appear to have had a measurable effect on how often Amazon product cards appear in Google’s organic Shopping results.

Audience Key is a content marketing platform that fills a gap in competitive intelligence by tracking and reporting on Google’s organic product grid rankings at scale. This is a new product that has recently rolled out.

According to Audience Key:

“Across 79,000+ keywords, Audience Key’s first-of-its-kind tracking showed the effects of Amazon’s changes to its merchant feed — the approach initially wiped out 31% of its organic product card rankings. Weeks later, Amazon has now disappeared completely — creating a seismic shift that is immediately reshaping e-commerce SERPs and freeing up prime shelf space for rivals.”Tom Rusling, founder of Audience Key notified me today that Amazon has subsequently completely dropped out of the organic search results, beginning on August 18th.

Anecdotally, I’ve seen Amazon completely dropped out of Google’s organic product grids, including for search queries I know for certain they used to rank for and are now completely gone from the search engine results pages (SERPs).

Overall Impact

The most immediate change was the overall scale of Amazon’s presence. Before July 25, Amazon’s listings appeared in 428,984 organic product cards. After the change, that presence dropped to 294,983.

  • Before July 25: 428,984 product cards
  • After July 25: 294,983 product cards

Net change: -134,001 cards (31% decline)

This shows that Amazon’s move was not just a brand consolidation but also a large reduction in visibility. It is possible that the brand consolidation triggered a temporary drop in visibility because it’s such a wide-scale change.

Category-Level Changes

The reduction was not spread evenly. Some product categories were hit harder than others. Apparel had the steepest losses, while categories like Home Goods and Laptop Computers also fell sharply.

Smaller categories such as Tires and Indoor Decor declined more moderately, but all showed the same downward trend.

Apparel Category Experiences The Largest Declines

Apparel stands out as the category where Amazon saw the steepest reductions, with its presence cut by more than half across several tracked segments.

Below is the data I currently have, I’m waiting for clarification from Audience Key about whether the following apparel categories are more specific:

  • Apparel: 4,571 → 1,804 (-60%)
  • Apparel: 4,503 → 1,859 (-59%)
  • Apparel: 31,852 → 13,632 (-57%)
  • Apparel: 6,932 → 3,029 (-56%)

Several Other Major Categories Affected

The losses were also large in high-volume categories. Home Goods, Laptop Computers, and Outdoor Furnishings all saw reductions, while Business Supplies and Technology products also suffered visibility declines.

  • Business Supplies: 12,510 → 9,786 (-22%)
  • Home Goods: 133,717 → 73,833 (-45%)
  • Laptop Computers: 30,520 → 19,615 (-36%)
  • Outdoor Furnishings: 58,416 → 41,995 (-28%)
  • Scientific and Technology: 58,880 → 50,666 (-14%)

Smaller Categories Also Affected

Even niche verticals were affected, though the percentage losses were less severe than in Apparel or Home Goods. These declines show Amazon’s reductions were spread across both major and smaller categories.

  • Structures: 6,241 → 4,229 (-32%)
  • Tires: 3,063 → 2,609 (-15%)
  • Indoor Decor: 23,634 → 19,789 (-16%)
  • Indoor Decor (variant): 6,626 → 5,926 (-11%)

Merchant Store Consolidation

Another change came from how Amazon presented itself in Shopping results. Before July 25, the company appeared under three names: Amazon, Amazon.com, and Amazon.com – Seller. Afterward, only the unified “Amazon” label remained.

  • Total before consolidation (all three names): 428,984 product cards
  • After consolidation (single “Amazon”): 294,980 product cards

This simplified Amazon’s presence by unifying it under one name, but it also coincided with a decline in overall coverage.

Where Amazon Is At Today?

Even with the July drops in visibility, Amazon remained the most visible merchant in Google Shopping, with smaller visibility than before. But that’s not longer the case, the situation for Amazon appears to have worsened.

Audience Key speculated on what is going on:

“We thought the first chapter of this story was complete, but just as we prepared this study for publication, everything changed. Again. Our latest U.S. search data reveals a stunning shift: Amazon vanished from the organic product grids.

Whether this is a short-term anomaly or a more permanent new normal, only time will tell. We will continue to monitor and report on our findings. The sudden removal leaves us — and the industry — asking one big question: WHY???

That is certainly a topic for speculation.”

Audience Key speculates that Amazon may be withholding their product feed from Google or that this is a technical or strategic change on Amazon’s part.

One thing that we know about Google organic search is that large-scale changes can have a dramatic impact on search visibility. Audience Key has a unique product that is focused on tracking Google’s product grid, something that many ecommerce companies may find useful. They are apparently well-positioned to notice this kind of change.

Read Audience Key’s blog post about these changes:

Beyond Paid: The Hidden Organic Shockwave from Amazon’s Google Shopping Exit

Featured Image by Shutterstock/Sergei Elagin

https://www.searchenginejournal.com/amazon-experiences-drop-in-google-search-visibility/555729/




Google Retiring Core Web Vitals CrUX Dashboard via @sejournal, @martinibuster

Google has announced that the CrUX Dashboard, the Looker Studio-based visualization tool for CrUX data, will be retired at the end of November 2025. The reason given for the deprecation is that it was not designed for “wide-scale” use and that Google has developed more scalable alternatives.

Why The CrUX Dashboard Is Being Retired

The CrUX Dashboard was built in Looker Studio to summarize monthly CrUX data. It gained popularity as Core Web Vitals became the de facto standard for how developers and SEOs measured performance.

Behind the scenes, however, the tool struggled to keep up with demand. According to the official Chrome announcement, it suffered “frequent outages, especially around the second Tuesday of each month when new data was published.”

The Chrome team concluded that while the dashboard showed the value of CrUX data, it was not built on the right technology.

Transition To Better Alternatives

To address these issues, Google launched the CrUX History API, which delivered weekly instead of monthly data, allowing more frequent monitoring of trends. The History API was faster and more scalable, leading to adoption by third-party tools.

In 2024, Google introduced CrUX Vis, which was more scalable and faster. Today, in 2025, CrUX Vis receives four to five times more users than the CrUX Dashboard, showing that users are increasingly moving to the newer tool.

What the Change Means for Users

Chrome will shut down the CrUX Connector to BigQuery in late November 2025. When this connector is removed, dashboards that depend on it will stop updating. Users who want to keep the old dashboard will need to connect directly to BigQuery with their own credentials. The announcement explains that the CrUX Connector infrastructure is unreliable and requires too much monitoring to maintain, which is why investment has shifted to the History API and CrUX Vis.

Some users have asked Google to postpone the shutdown until 2026, but the announcement makes it clear that this is not an option. Although the dashboard and its connector will be retired, the underlying BigQuery dataset will continue to be updated and supported. Google stated that it sees BigQuery as a valuable, longer-term public dataset.

Check out the CrUIX Vis tool here.

Read the original announcement:

CrUX Dashboard deprecation

https://www.searchenginejournal.com/google-retiring-core-web-vitals-dashboard/555714/




Google AI Max For Search Goes Global In Beta via @sejournal, @MattGSouthern

Google’s AI Max for Search campaigns is now available worldwide in beta across Google Ads, Google Ads Editor, Search Ads 360, and the Google Ads API.

AI Max packages Google’s AI features as a one-click suite inside Search campaigns. New built-in experiments allow you to test the impact with minimal setup.

Image Credit: Google

What’s New

One-Click Experiments

AI Max is positioned as a faster path to smarter optimization inside Search campaigns.

New one-click experiments are integrated in the campaign flow, so you can compare performance without rebuilding campaigns.

Availability spans all major surfaces, including the API for teams that automate workflows.

How The Built-In Experiments Work

AI Max experiments are run within the same Search campaign by splitting traffic between a control (with AI Max off) and a trial (with AI Max on).

Since the test doesn’t clone the campaign, you’ll avoid sync errors and can ramp up faster. Once the experiment ends, review the performance and decide whether to apply the change or discard it.

Controls You Can Tweak During A Test

By default, your experiment starts with Search term matching and Asset optimization enabled, but it’s easy to customize these settings.

You can choose to turn off Search term matching at the ad group level or disable Asset optimization at the campaign level if that better suits your goals.

For more control over your landing pages, consider using URL exclusions at the campaign level and URL inclusions at the ad group level.

Brand controls are also available for added flexibility: you can set brand inclusions or exclusions at the campaign level, and specify brand inclusions within ad groups.

The “locations of interest” feature at the ad group level offers more geographic targeting precision.

Reporting Surfaces

Results appear under Experiments with an expanded Experiment summary.

AI Max also adds transparency across reports. These include “AI Max” match-type indicators in Search terms and Keywords reports, plus combined views that show the matched term, headlines, and landing URLs.

Auto-Apply Option

If you want, you can set the experiment to auto-apply when results are favorable. Otherwise, apply manually from the Experiments table or enable AI Max from Campaign settings after the test concludes.

Setup Limits To Know

You can’t create an AI Max experiment via this flow if the campaign:

  • Has legacy features like text customization (old ACA), brand inclusions/exclusions, or ad-group location inclusion already configured
  • Targets the Display Network
  • Uses a Portfolio bid strategy
  • Uses Shared budgets

Coming Soon: Text Guidelines

Google is working on a feature that will provide text guidelines to help AI create brand-safe content that meets your business needs.

This will be available to more advertisers this fall for both AI Max and Performance Max. In the meantime, stick to your usual brand approvals and policy checks.

Getting Started

Google recommends checking out a best-practices guide and Think Week materials if you’re interested in getting started with AI Max.

If you’re already handling Search at scale, the API support simplifies standardizing experiments and comparing results to your existing setup.

Looking Ahead

Expect more controls around creative and safety as text guidelines roll out. Until then, low-lift experiments let you measure AI Max without committing your entire account.

https://www.searchenginejournal.com/google-ai-max-for-search-goes-global-in-beta/555683/




Google Ads Rolls Out New Creative & Omnichannel Tools via @sejournal, @MattGSouthern

Google is rolling out creative and omnichannel updates across Ads and YouTube.

The tools are designed to help you keep assets fresh, connect store and online demand, and plan spend across key shopping windows.

What’s New

Creative: Asset Studio, Product Studio, And Imagen 4

A new suite of generative tools is coming to Asset Studio, with asset generation in Performance Max and Demand Gen powered by Imagen 4.

In Product Studio, you’ll be able to swap product scenes at scale, replace backgrounds, turn images or text into short videos, and get proactive campaign concept suggestions.

See an example of a campaign concept suggestion below:

Image Credit: Google

Google says the new tools can speed up testing while keeping brand direction intact.

Omnichannel & YouTube

Demand Gen can now optimize for total sales across online, in-app, and in-store conversions. You can also use local offers to show nearby shoppers in-store promotions.

On YouTube, a Creator partnerships hub is meant to simplify brand-creator collaborations, and the YouTube Masthead is now shoppable so you can feature specific products tied to your goals.

Insights And Budgets: Plan 3–90 Day Bursts

New AI-powered insights in Google Merchant Center aim to surface actionable tips. Google is also expanding campaign total budgets from Demand Gen and YouTube to include Search, Performance Max, and Shopping.

You can set a start date, end date, and a total budget for periods between 3 and 90 days, and Google’s systems will pace spend to match peaks in demand.

Loyalty: Member-Only Offers

Google is introducing loyalty features that let you display member-only pricing and shipping benefits, with retention goals available in loyalty mode for Performance Max or Standard Shopping.

Looking Ahead

If your holiday plan spans multiple bursts, these tools can help you keep creative fresh, capture store demand, and avoid end-of-month pacing surprises.

Start by aligning product feeds and assets, then test omnichannel optimization and short budget windows around your key dates.

https://www.searchenginejournal.com/google-ads-rolls-out-new-creative-omnichannel-tools/555659/




Google e la privacy: sanzione multimilionaria per informazioni fuorvianti


Google dovrà pagare una multa salata da 425 milioni per informazioni vaghe e fuorvianti sulle proprie politiche di privacy: lo ha deciso la Corte distrettuale del distretto settentrionale della California, come riporta Malware Bytes.

Il caso è iniziato nel 2020 quando Anibal Rodriguez, un utente della compagnia, aveva intentato una causa contro il gigante tech accusandolo di aver confuso volontariamente gli utenti con le impostazioni “Attività web e app”. L’azione legale è diventata in seguito una class action.

Idealmente modificando queste impostazioni Google permetteva agli utenti di preservare la propria privacy disabilitando la raccolta di informazioni; in realtà, la compagnia non smetteva di raccogliere i dati, ma si limitava ad anonimizzarli. 

google privacy

Nel dettaglio, queste informazioni venivano raccolte tramite Firebase, un database per il monitoraggio delle attività che opera in maniera indipendente da “Attività web e app”. I dati venivano raccolti da applicazioni quali Uber, Shazam, Duolingo, Instagram e molte altre, con 98 milioni di utenti ignari di questa operazione.

I legali di Google si sono opposti all’accusa chiarendo che, modificando le impostazioni di privacy, viene mostrato all’utente un popup di conferma dal quale è possibile navigare su un dettaglio dei dati raccolti, e che quindi l’operato dell’azienda è trasparente.

I giudici, però, non hanno condiviso questa visione e hanno sottolineato che la compagnia dovrebbe essere più chiara nelle comunicazioni, soprattutto considerando che gli utenti spesso sono “superficiali” non dei lettori attenti; un dettaglio che, per quanto possa far sorridere, evidentemente ha avuto un certo peso nella decisione finale.

“Questa decisione fraintende il modo in cui funzionano i nostri prodotti” ha affermato Jose Castaneda, Policy Communication Manager presso Google. “I nostri tool per la privacy danno alle persone il controllo sui loro dati, e quando disabilitano la personalizzazione, noi rispettiamo quella scelta“.

In merito al caso, il giudice Richard Seeborg ha affermato che “Le comunicazioni interne di Google indicano che la compagnia sapeva di essere ‘intenzionalmente vaga’ sulla distinzione tecnica tra i dati raccolti da un account Google e quelli ottenuti al di fuori di esso perché la verità ‘sarebbe potuta sembrare allarmante per gli utenti’“.

Google ha comunicato l’intenzione di fare ricorso.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/10/google-e-la-privacy-sanzione-multimilionaria-per-informazioni-fuorvianti/?utm_source=rss&utm_medium=rss&utm_campaign=google-e-la-privacy-sanzione-multimilionaria-per-informazioni-fuorvianti




The State Of SEO 2026: How To Survive

Two-thirds of SEO professionals say original content creation is their secret weapon, but there’s a problem nobody talks about.

While content creation drives the best results, it’s also the hardest thing to scale. Over 40% of professionals say it takes more time than any other SEO task.

Our fifth annual State of SEO report shares insights from 371 SEO professionals in 52 countries. It highlights what’s working in SEO today and where the industry is headed.

Find out how professionals are responding to AI disruption, which tactics are most effective, and where teams plan to invest resources. Most respondents have four or more years of experience, so these insights come from people who have lived through many changes in the industry.

Download the report to learn about:

  • Which SEO activities deliver the strongest return on investment (ROI) right now.
  • How teams are using AI in their workflows.
  • The biggest challenges holding SEO back.
  • Investment priorities.
  • Why professionals are concerned about AI but stay optimistic about budgets.

Get the information you need to plan your SEO strategy for 2026.

Three Paths Are Emerging In SEO

As teams navigate AI disruption, the data reveals three distinct strategies forming across the industry:

  • AI-Heavy Adopters (22%) are betting on scale through automation.
  • Authority Builders (49%) are doubling down on E-E-A-T (Experience, Expertise, Authoritativeness, and Trustworthiness) and human expertise.
  • Hybrid Strategists (58%) are finding the middle ground, using AI to enhance human-created content.

Each path has merit, but the data shows clear patterns about what’s working now.

Original Content Creation Still Drives SEO Success

When we asked what had the most positive impact this year, original content creation topped the list at 66%. Content updates came second at 42.6%. Technical SEO improvements were close behind at 42.3%.

This shows that original content remains key to SEO success. However, as stated earlier, it takes significant time.

The industry has found a solution. Most teams (the 58% Hybrid Strategists) plan to create human-written content with AI support. They want quality over quantity, using AI to save time while maintaining human oversight.

Interestingly, cross-department collaboration currently shows the lowest impact at just 9%, yet 37% of companies plan to increase it. This gap represents a major opportunity for teams willing to break down silos.

Activities with the greatest positive impact

Download the full State of SEO 2026 report to see how successful teams manage their content work.

AI Tools Are A Competitive Necessity And Threat

The tools data tells us a lot about how SEO has changed. Analytics and reporting tools are most popular with respondents, leading at 56%. AI writing assistants have jumped to fourth place at 42.3%. That’s the same use as technical SEO tools.

Cross-functional platforms also scored high at 51.2%. Teams want all-in-one solutions instead of many separate tools.

While teams use AI, it also concerns them. A notable 77% worry that AI answers will reduce website clicks. That’s their biggest concern about the future.

This puts SEO professionals in a tough spot. They need AI to compete, but they see it as their biggest threat.

most critical seo tools and platforms

E-E-A-T Is The Industry’s Answer To AI Disruption

Almost half of respondents (49%) plan to invest in E-E-A-T next year.

This focus on Experience, Expertise, Authoritativeness, and Trustworthiness shows how the industry plans to fight back against AI threats. The thinking makes sense: AI can summarize existing information, but it can’t replicate real-life experience or original research. By focusing on E-E-A-T, teams build defenses that AI can’t break through.

This explains why topical authority and content architecture also rank high at 33% of investment plans. Teams want to become the go-to experts in their fields.

Algorithm changes remain the top challenge at 59%. Content workflow problems come second at 32%. But teams aren’t waiting around; they’re preparing through AI training (42% of companies) and better collaboration between departments (37%).

This strategic shift requires continued investment, which brings us to an encouraging finding about budgets.

[Chart: Future Investment and Innovation Plans]

SEO Budgets Stay Strong Because Results Remain Solid

Despite AI concerns and algorithm chaos, SEO investment stays strong. Only 43% of companies cut any SEO spending last year. And 65% expect no cuts next year.

Why this confidence? The results speak for themselves. When we asked about outcomes, 60% reported more organic traffic. Another 34% saw more leads and conversions. These results explain why companies keep investing even as the landscape shifts.

Teams also focus more on business impact when measuring success. Organic traffic leads at 74%, while qualified leads and sales rank second at 60%. Teams are moving past vanity metrics to prove real business value.

This combination of proven results and strategic adaptation explains the industry’s resilience.

[Chart: Recent SEO Investment Reductions]

Building Your 2026 SEO Strategy

The data paints a clear picture: SEO faces real challenges from AI disruption and constant algorithm changes. Technical problems affect 28% of teams, while 26% struggle with leadership support.

But the industry is responding strategically. About 42% of companies are training staff on AI. Another 36% are teaching current best practices. Teams that combine AI efficiency with human expertise and E-E-A-T principles are positioning themselves to thrive.

Whether you see yourself as an AI-Heavy Adopter, Authority Builder, or Hybrid Strategist, this report gives you the roadmap for 2026 planning. It includes insights from professionals managing SEO in every major market.

Download the State of SEO 2026 report now. Use it as your planning guide for the year ahead. Get complete analysis of tool adoption, scaling challenges, measurement methods, and expert advice on handling the AI transition.

The industry faces real challenges. But the data shows a strong community that’s finding ways to succeed.State of SEO 2026


Featured Image: Paulo Bobita/Search Engine Journal

https://www.searchenginejournal.com/the-state-of-seo-2026-how-to-survive/555368/