< ciso
brief />
Tag Banner

All news with #google tag

714 articles · page 10 of 36

Google June 2026 Android security updates

🔒 Google released June 2026 security patches addressing 124 Android vulnerabilities, including a high-severity Framework flaw tracked as CVE-2025-48595 affecting Android 14–16 and 16 QPR2. This privilege escalation bug can be exploited without user interaction and is reportedly under limited targeted exploitation. The June updates arrive in two batches, with the latter adding kernel and chipset fixes from MediaTek, Qualcomm, Unisoc, and others.
read more →

Google issues June 2026 Android security patches

🔒 Google released the June 2026 Android security updates fixing 124 vulnerabilities, including one actively exploited Android Framework zero-day (CVE-2025-48595) affecting devices running Android 14 and later. The company warned of limited, targeted exploitation and urged users to update to the latest Android versions. Two patch bundles (2026-06-01 and 2026-06-05) were issued; Pixel devices will receive updates immediately while other vendors may delay. Google also addressed 18 critical flaws across System, Framework, and Qualcomm components, and previously patched other zero-days this year.
read more →

Modeling a digital twin with BigQuery Graph

📈 BigQuery Graph enables building a digital twin of interconnected systems like supply chains and restaurant networks by creating a Graph View over existing tables. The approach maps items, recipes, locations and dependencies into nodes and edges, enabling targeted queries for issues such as recalls, weather disruptions, or procurement leaks. It emphasizes keeping relational data for metrics while using graphs for structure, cleaning keys, and capturing edge properties for richer modeling.
read more →

AlloyDB Remote MCP Server Now Generally Available

🛡️ The Remote Model Context Protocol (MCP) Server for AlloyDB is now generally available, providing a secure HTTP endpoint that lets AI agents access real-time operational data. This fully managed service simplifies production deployments by centralizing discovery, offering fine-grained IAM-based authorization, audit logging, and integration with Model Armor for prompt and response protection. Developers can join AlloyDB operational data with analytics in BigQuery and use built-in AI functions for low-latency agentic experiences.
read more →

GKE standby buffers lower autoscaling latency and cost

🚀 Google announces GKE standby buffers to complement active buffers, providing low-cost suspended node capacity that resumes faster than cold node provisioning. Standby buffers store node state to disk, releasing compute and memory costs while keeping persistent disk and IP charges, enabling near-instant scheduling with only a small single-digit percent overhead. Together, active and standby buffers reduce pod scheduling latency, replace manual balloon-pod workarounds, and help balance performance and cost for spiky workloads.
read more →

Analyze BigQuery Data Directly in Google Sheets

📊 Connected Sheets removes CSV exports and turns Google Sheets into a live, secure interface to BigQuery, enabling business users to analyze petabytes of governed data without SQL. Admins retain security and governance by provisioning table or view access while preventing data alteration from Sheets. End users gain immediate agility using familiar tools like pivot tables, charts, and formulas to analyze billions of rows and create refreshable reports and hybrid models. Connecting requires a Google Workspace account and a billing-enabled Google Cloud project, with connections established either from Sheets or the BigQuery UI.
read more →

Building an AI-Ready Security Program for Public Sector

🛡️ This Cloud CISO Perspectives post by Usman Chaudhary, Field CISO for Google Public Sector, outlines a pragmatic roadmap for public-sector CISOs to adopt AI-driven security. It emphasizes immediate quick wins in the first 90 days, tactical actions within six months, and strategic initiatives for months six to 12, combining internal automation, commercial AI capabilities, and vendor solutions like Gemini for Government. The guidance targets threat triage, talent augmentation, posture elevation, and governance to reduce toil and accelerate proactive defense.
read more →

AlloyDB Hot Standby: Faster Failovers and Reliability

🚀 AlloyDB for PostgreSQL introduces a Hot Standby HA architecture that keeps the standby node actively replaying WAL records, reducing failover time and preserving cache warmth. This change eliminates standby database startup delays and minimizes post-failover performance degradation, improving RTO and stabilizing application throughput. Hot Standby is rolling out for PostgreSQL 18 and will reach earlier versions in months, with no extra cost and retention of the 99.99% SLA.
read more →

Chrome rolls out device‑bound session cookie protection

🔒 Google has made the Chrome Device Bound Session Credentials (DBSC) feature generally available and is rolling it out to all users to prevent account takeovers. DBSC, in beta since April 2024, cryptographically binds session cookies to device hardware such as TPM and Secure Enclave, ensuring stolen cookies cannot be reused. The feature will be enabled by default for Google Workspace customers and cannot be disabled by administrators. DBSC aims to block previously exploited techniques that restored or reused expired authentication cookies.
read more →

UCO and Google accelerate forensic case analysis with AI

🧭 This collaboration between Google Public Sector and the University of Central Oklahoma (UCO) Forensic Science Institute uses Google’s NotebookLM to rapidly analyze complex criminal case documents and construct timelines. Originating from an AI hackathon co-led by UCO’s CIO Sonya Watkins, the project leverages Gemini to prioritize high-impact prototypes and has reduced multi-month analyses to days in early trials. UCO instructors ensure AI outputs are forensically sound and reliably cited.
read more →

How Google SRE Uses Agentic AI to Improve Operations

🤖 Google SRE describes how agentic AI augments traditional Site Reliability Engineering across the software lifecycle, from design and deployment to incident response and postmortems. The team applies AI agents for anomaly detection, playbook maintenance, alert enrichment, and automated mitigation while enforcing strong controls for security, explainability, and business continuity. Their approach pairs Gemini-based models and internal platforms with existing observability and governance practices.
read more →

Nano Banana 2 and Nano Banana Pro reach general availability

🖼️ Google Cloud announced Nano Banana 2 (Gemini 3.1 Flash Image) and Nano Banana Pro (Gemini 3 Pro Image) are generally available via the Gemini Enterprise Agent Platform, offering enterprise-grade image generation and editing. Nano Banana 2 now supports video files as input in preview, enabling deep video understanding to generate context-aware images. 1K and 2K outputs are GA while 4K remains in preview. The models are integrated by partners like Adobe, WPP, Shopify, URBN, and Magnopus to scale creative workflows and production pipelines.
read more →

Frontier AI models more vulnerable under iterative attacks

🔍 Cisco researchers found that popular frontier LLMs from OpenAI, Anthropic, Google, xAI, and Amazon exhibit substantially higher risk when subjected to multi-turn adversarial attacks than when assessed with single-prompt safety benchmarks. The team ran tens of thousands of single-turn and multi-turn attacks across 15 models and multiple configurations, revealing wide gaps in attack success rates (ASRs) and configuration-dependent safety behavior. They urge improved benchmarks, transparency on configuration impacts, and publication of paired single- and multi-turn ASRs to better inform procurement and governance decisions.
read more →

AppSheet-phishing: attackers abusing Google-linked emails

📧 Recent phishing campaigns exploit Google’s AppSheet platform to send convincing emails from a legitimate noreply{@}appsheet.com address, making them likely to bypass filters. Attackers craft personalized messages — urgent warnings or enticing job offers — to trick victims into submitting identity details on clone sites, then harvest credentials and data. The compromises can lead to account takeover, device control, and secondary targeted attacks using the stolen information.
read more →

Researchers Disrupt Glassworm's Resilient Botnet C2

🛡️ CrowdStrike, Google, and The Shadowserver Foundation coordinated to disrupt the Glassworm botnet by simultaneously takedown of four resilient C2 channels. The threat abused Solana blockchain memo fields, the BitTorrent DHT, Google Calendar events, and traditional VPS-hosted servers to persist and evade mitigation. Active campaigns targeted developers via malicious OpenVSX and VS Code extensions and later poisoned GitHub and npm artifacts. Infected hosts now beacon to a CrowdStrike-controlled IP and YARA rules have been published to detect compromise.
read more →

Google launches AI Threat Defense for enterprises

🔒 Google announces AI Threat Defense, an integrated, automated security system that uses Gemini, Mandiant, Wiz, and CodeMender to detect, prioritize, and remediate AI-powered threats. The platform combines multi-model scanning, live exposure mapping, and AI agents to validate exploitability, generate fixes, and accelerate remediation. It emphasizes machine-speed monitoring, autonomous response, and consolidated visibility across development and runtime environments to reduce attack surface and speed patching.
read more →

Google’s Network Strategy for the AI Era

📡 Google details how its global network and new data center fabrics are being redesigned for AI workloads, describing a vertically integrated stack anchored by an AI Hypercomputer. The post highlights Virgo Network, campus-scale and WAN innovations, and AI-native Cloud Interconnect to meet extreme bandwidth, low latency, and burst tolerance requirements. It emphasizes co-design with accelerators, autonomous reliability features, and global footprint benefits for inference and cross-site training.
read more →

Chinese PhaaS Grow More Sophisticated, Live Theft

🛡️ Google researchers report a rapid rise in Chinese phishing-as-a-service (PhaaS) operations that have shifted from static password harvesting to real-time credential interception and tokenization. These services use encrypted messaging protocols like RCS and iMessage to deliver convincing lures and employ live admin panels to capture OTPs and bypass MFA. Platforms also monetize stolen payment details via digital wallet provisioning and increasingly leverage AI to generate unique phishing pages and evade detection.
read more →

Google integrates CodeMender into enterprise agent platform

🔒 Google is folding CodeMender into its broader Agent Platform strategy, expanding the AI-powered security agent from standalone vulnerability remediation toward an integrated, governed enterprise agent ecosystem. Launched in October 2025 to autonomously identify and patch vulnerabilities using Gemini models, CodeMender reportedly upstreamed dozens of fixes but lacks published performance metrics on accuracy and regressions. The integration emphasizes governance, observability, and identity, positioning CodeMender as a controlled participant in AI-native development and security pipelines rather than an unsupervised remediation tool.
read more →

Chromium leak exposes unfixed persistent JavaScript flaw

🛡️ Google inadvertently published details of an unfixed Chromium vulnerability that allows JavaScript to continue running after the browser is closed, enabling remote code execution via persistent Service Workers. Reported by researcher Lyra Rebane in December 2022, the issue affects all Chromium-based browsers and was marked fixed in February 2024 but a patch was not shipped. The bug tracker entry was briefly made public on May 20, revealing the exploit still works in Chrome Dev 150 and Edge 148, making attacks stealthier and increasing risk until an emergency fix is released.
read more →