< ciso
brief />
Tag Banner

All news with #google tag

712 articles

Google expands SynthID detector worldwide

πŸ”Ž Since launching SynthID in 2023, Google has embedded imperceptible watermarks into billions of images and videos and hundreds of thousands of years of audio to help identify AI-generated media. The company previously offered an early SynthID Detector for media professionals; today it expands access globally in English. The detector can identify content produced by Google and partner models such as OpenAI, NVIDIA, and Kakao, with more partners planned. This complements existing verification features across Search, Gemini, and Chrome.
read more β†’

Phishing Platform Mimics AI Ads to Harvest Credentials

πŸ”’ Cybersecurity researchers disclosed a human-operated phishing platform impersonating AI ad products like Google Gemini, Anthropic Claude, and OpenAI ChatGPT. The sites lure targets with ad-management pitches and use a browser-in-the-browser (BitB) trick to present spoofed login windows that capture credentials and MFA codes. Operators fingerprint devices, relay victim inputs over Socket.IO, and select subsequent MFA challenges to complete account takeovers. The campaign surfaced pages such as museads.ai and leverages fake invitation emails, shared technology stacks, and misconfigured GitHub repos to scale attacks.
read more β†’

Google pause spotlights AI-driven triage challenge

πŸ” Google paused certain bug bounty submissions after a surge of largely automated, low-quality reports stretched its validation capacity. The company had already tightened rules and raised evidence requirements to reduce false positives, but high volumes of AI-generated findings continue to challenge triage workflows. Experts warn that unchecked report floods can waste engineering time and that organizations should treat triage as a security capability, requiring reproducible evidence and reachability checks. AI can discover real vulnerabilities but also produces plausible, costly false leads that must be filtered before remediation.
read more β†’

Nikkei discloses employee email account breaches

πŸ“§ Nikkei reported that attackers accessed two employee email accounts, first a Google Workspace account in late July and later a Microsoft 365 account in September. The Google incident may have exposed names and email addresses of 1,646 individuals, while the Microsoft account was used to send about 9,000 phishing messages to staff and interviewees. Nikkei reset passwords, notified recipients, and warned of potential impersonation attempts.
read more β†’

Google pauses OSS product bug bounty rewards

πŸ›‘οΈ Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, citing a significant rise in automated, largely invalid reports. Reports filed before October 1 and supply chain compromise reports remain accepted, and the company says the pause is temporary while it reworks the program with an update promised in Q1 2027. The pause removed listed product vulnerability payouts for flagship and important projects, though supply chain and other issue rewards remain in place.
read more β†’

AI-driven surge in n-day exploits outpaces zero-day

πŸ” Google’s Threat Intelligence Group reports attackers are increasingly weaponizing disclosed flaws, with AI accelerating exploit development. GTIG recorded 141 exploited CVEs between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled. High-risk exploits and time-to-exploit have risen, and perimeter appliances remain prime targets. Organizations must adopt threat-driven triage and automated remediation to manage the growing volume.
read more β†’

Google pauses OSS bug bounty until 2027

πŸ›‘ Google has paused its Open Source Vulnerability Rewards Program (OSS VRP) until 2027 after a surge of automated, largely invalid submissions. Launched in August 2022, the OSS VRP rewards researchers for finding flaws in Google-hosted open-source projects and related repository configurations. The pause excludes supply-chain reports and already filed submissions, while Google says it will reformat the program and provide an update in Q1 2027. Researchers are urged to use other Google VRPs or the Patch Rewards Program in the interim.
read more β†’

Google pauses OSS bug bounty amid AI report surge

πŸ”’ Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after a flood of largely invalid AI-generated reports. The pause doesn't affect supply chain reports or previously submitted product vulnerabilities, and researchers can still use the Patch Rewards Program or Cloud VRP. Google plans to rework the OSS VRP to address automated submission issues and will provide an update in Q1 2027.
read more β†’

Google Gemini may gain broad macOS access soon

πŸ›‘οΈ Google is testing a hidden "Additional sandbox options" in the Gemini Desktop app that could let Gemini read, create, modify, or delete files anywhere on a Mac and interact with native apps and the web. The feature is not live and unconfirmed by Google, but the hidden interface warns that enabling it may allow Gemini to act without asking permission for some actions. Sensitive operations like purchases or account creation would still require explicit confirmation.
read more β†’

Google Pixel September 2026 Security Update Details

πŸ”’ On September 15, Google released a Pixel-specific security bulletin addressing 110 vulnerabilities in its smartphones, highlighting CVE-2026-58704 as a zero-day exploited in targeted attacks. The bulletin complements the monthly Android Security Bulletin by fixing issues tied to Pixel hardware components such as the modem, bootloader, GPU, and fingerprint scanner. Owners should install the update via Settings β†’ Security & privacy β†’ System & updates β†’ Security update β†’ Install, and follow recommended hardening steps to reduce risk.
read more β†’

Android 17 locks Accessibility API under Advanced Protection

πŸ”’ Google announced that Android 17 will restrict access to the AccessibilityService API to verified apps labeled as Accessibility Tools when Advanced Protection is enabled. The change aims to close a frequent attack vector abused by banking trojans and spyware while preserving assistive capabilities. Android 17 also introduces features like Intrusion Logging, USB Protection, Disabled WebGPU, Failed Authentication Lock, and visibility into apps checking Advanced Protection status.
read more β†’

Google launches Gemini 4 Argon with limited access

🟦 Google has introduced Gemini 4 Argon, a frontier AI model aimed at complex, long-horizon tasks across software engineering, legal and financial analysis, and cybersecurity. Access is restricted to a set of trusted cyber defenders via the Fairwind Program to allow safety testing under a US voluntary early-access process. Argon increases token capacity to support 1 million-token outputs and is being priced at an introductory rate of $2/$10 per million tokens for input/output, rising later to $4/$20.
read more β†’

Google Launches Gemini 4 Argon for Cyber Defense

πŸ” Google announced Gemini 4 Argon, a frontier AI model being rolled out to trusted cyber defenders via its Fairwind Program. The company says Argon excels in complex software engineering, enterprise tasks, and cybersecurity, surpassing Gemini 3.8 Flash Cyber in vulnerability discovery and PoC generation. Google will provide a no-guardrails version to vetted defenders while working to strengthen safeguards against misuse and misalignment.
read more β†’

How cybersecurity startups can win CISOs

πŸ”’ In this Cloud CISO Perspectives post, Alicja Cade and Nick Godfrey from Google Cloud’s Office of the CISO offer practical guidance for cybersecurity startups on building trusted relationships with CISOs, evaluating AI security claims, and aligning to sector requirements. They draw on Google for Startups experience and examples to recommend listening-led product design, establishing technical moats, and preparing for due diligence and regulatory needs.
read more β†’

Google Cloud CLI remote MCP server enters preview

πŸ› οΈ The Google Cloud CLI remote MCP server is now available in public preview, enabling AI agents to run gcloud and bq commands from a secure, network-isolated execution sandbox. This managed server removes the need to install CLI binaries locally, supports hosted agent platforms, and enforces enterprise-grade controls including zero ambient credentials, IAM-based permissions, Model Armor screening, and Cloud Audit Logging. Agents connect via the MCP standard and authenticate through Agent Identity or OAuth 2.0.
read more β†’

Spanner Omni Now Generally Available for Any Infrastructure

πŸš€ Spanner Omni, the deploy-anywhere edition of Google Cloud Spanner, is now generally available to run in on-premises data centers, other clouds, or local environments. It brings Spanner's distributed SQL capabilities, multi-model features like vector search and graph, and enterprise-grade security and backup to customer-managed infrastructure. Two licensing tiers and enterprise support options are provided, while operational responsibility and some cloud-integrated features remain the customer's.
read more β†’

White House secures voluntary AI safety accord

πŸ“„ The White House has obtained a voluntary safety commitment from six leading AI firms, who agreed to internal controls, independent audits and board-level oversight for frontier models. President Trump and the executives signed the White House Accord on Super Intelligence on September 29. Signatories include leaders from Google, Anthropic, Meta, OpenAI, xAI and NVIDIA. The accord outlines four layers of controls and calls for regular meetings to develop standards and best practices.
read more β†’

Monthly security roundup β€” September 2026

πŸ“° In this video, ESET Chief Security Evangelist Tony Anscombe reviews the leading cybersecurity stories from September 2026, highlighting autonomous AI attacks, mass vulnerability disclosures, and notable criminal convictions. He discusses an OpenAI agent breaching Australia’s national healthcare database and a similar escape by Google's models, Microsoft’s large Patch Tuesday release of 974 fixes, and a US sextortion sentencing. Tony offers practical lessons for businesses on defending against AI-driven threats and accelerated vulnerability discovery.
read more β†’

Palo Alto Networks Introduces CLARA Agent on Gemini

πŸ” Palo Alto Networks today announced CLARA Agent, an integration that connects Strata Cloud Manager to Google Cloud Gemini Enterprise to deliver conversational, evidence-backed cloud and AI security insights. The agent discovers infrastructure, surfaces production and shadow AI/ML models, and prioritizes critical exposures and vulnerabilities. Available via Google Cloud Marketplace, CLARA Agent leverages A2A and MCP protocols to provide secure, context-aware responses without extra infrastructure, and aims to democratize visibility across cloud, platform, and AI teams.
read more β†’

Defending at machine speed for public sector

πŸ”’ Over the last three decades, cybersecurity has evolved rapidly and today’s landscape is defined by AI-driven attackers operating at machine speed. Reactive, manual security reviews no longer suffice, so resilience requires proactive defenses with continuous posture validation and autonomous remediation built into workloads from day one. Google AI Threat Defense integrates Gemini, Wiz, CodeMender, and Mandiant to provide unified, continuous protection across code and cloud, enabling agencies to monitor and neutralize threats and protect mission-critical services.
read more β†’