< ciso
brief />
Tag Banner

All news with #google tag

714 articles · page 16 of 36

Customers Achieve Scale and Flexibility with Spanner

🚀 Google Cloud Spanner’s interoperable multi-model capabilities are being adopted by customers to run relational, graph, vector, and full-text workloads together at global scale. Real-world examples across fraud detection, recommendation engines, hybrid search, and autonomous network operations show consolidation of database sprawl, elimination of ETL, and improved real-time analytics. Customers such as DANA, Palo Alto Networks, Target and Inspira highlight Spanner’s global consistency, native graph and vector search, and high availability as enablers of simpler, future-proof architectures.
read more →

Spanner's Multi-Model Advantage for Agentic AI in Production

🔍Spanner positions itself as a unified, globally consistent database designed for agentic AI by combining relational, key-value, graph, vector and full-text search capabilities in one platform. The post argues this interoperable multi-model approach reduces data silos, removes brittle synchronization logic, and improves governance, availability, and development velocity. Google highlights features such as GQL graph support, a Cassandra native endpoint for lift-and-shift, and ScaNN-based ANN vector search. The customer example of MakeMyTrip illustrates significant operational simplification and faster AI feature delivery.
read more →

Google VRP 2025 Year in Review: Growth and Milestones

🛡️ In 2025 Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary and awarded over $17 million to more than 700 researchers worldwide — a 40%+ increase versus 2024. The year introduced a standalone AI VRP, extended Chrome rewards for AI features, and launched a patch rewards program for OSV-SCALIBR. Multiple bugSWAT events and the ESCAL8 conference generated hundreds of reports and significant payouts. Google reaffirms its commitment to collaboration, transparency, and continued events in 2026.
read more →

AI-Driven Sustainability Reporting and Infrastructure

⚙️ Google and partners are applying generative AI to streamline environmental reporting and infrastructure. Internally, Google used Gemini to auto-validate claims against policies and NotebookLM to convert static reports into an interactive, cited knowledge base. Equinix built a Sustainability Data Lake on BigQuery, ingesting data from 240+ sites to shift from manual spreadsheets to on-demand insights. The approach pairs serverless architecture and carbon-intelligent infrastructure to cut cost, compute waste, and reporting cycle time.
read more →

Evolving Expectations of What's Possible with AI in Privacy

🔒 Kent Walker, Google's President of Global Affairs, outlined how rapidly evolving user expectations are shaping AI development at the IAPP Global Summit 2026. He highlighted Personal Intelligence in Search and the Ukraine national assistant Diia.AI as examples of context-aware, task-oriented assistants. Google’s rollout approach emphasizes trusted testers, staged expansion, continuous feedback, and clear controls over agents’ access, while applying guardrails such as Gemini avoiding proactive assumptions. Walker urged investment in privacy-enhancing technologies, new transparency models, and global standards to align data protection with these innovations.
read more →

Google Warns: Quantum Threat to Encryption by 2029

🔒 Google warns that advances in quantum computing could render widely used public-key cryptography vulnerable as early as 2029, increasing the risk of store-now-decrypt-later attacks. The company points to progress in quantum hardware, error correction and factoring resource estimates that compress migration timelines. To reduce exposure, Google will include post-quantum digital signature protection in Android 17, aligned with NIST recommendations. It urges organizations to treat post-quantum cryptography migration as an immediate operational priority rather than a distant compliance task.
read more →

Google Accelerates Post-Quantum Migration Deadline to 2029

🔒Google announced it is accelerating its post-quantum cryptography migration, setting 2029 as the new target to phase out quantum-vulnerable algorithms and prioritizing PQC for authentication services. The company cites rapid improvements in quantum hardware, error correction and algorithmic estimates that drastically reduce the qubit requirements to break common asymmetric encryption. Google urged other engineering teams and hyperscalers to follow suit, warning that adversaries may already be collecting encrypted data for future decryption.
read more →

ThreatsDay Bulletin: PQC Push, AI Bugs, Pirated Backdoors

🔔 This week’s ThreatsDay Bulletin captures a quieter, sneakier cadence: big-picture progress on cryptography and AI set against a steady churn of pragmatic abuse. Google accelerated a PQC migration to 2029 and GitHub is bringing AI-powered detections into the PR workflow, while threat actors keep innovating around trust — using pirated ISOs, fake extensions, firmware implants and clever phishing to scale backdoors, credential theft and fraud. The common thread is operational efficiency: takedowns and disruptions are temporary, but the workflows keep returning.
read more →

Android 17 Adopts NIST Post-Quantum Standards Platform

🔒 Google is introducing post-quantum cryptography support in Android 17, integrating NIST’s lattice-based standards into boot, keystore, and app signing to establish a quantum-resistant chain of trust. The release adds ML-DSA to Android Verified Boot and migrates KeyMint certificate chains and Remote Attestation toward PQC compliance. Developers gain native support for ML-DSA-65 and ML-DSA-87 via the KeyPairGenerator API, and Google Play will offer hybrid APK signing with keys managed by Google Cloud KMS to preserve compatibility during migration.
read more →

Google Sets 2029 Timeline for Post-Quantum Migration

🔐 Google announces a company-wide timeline targeting 2029 for migration to post-quantum cryptography (PQC) to protect against future quantum threats. The timeline reflects advances in quantum hardware, error correction, and factoring estimates, and prioritizes PQC for authentication services to guard digital signatures. Google cites ongoing integrations — including Android 17 using ML-DSA, Chrome support, and Cloud offerings — as concrete commitments and urges other teams and organizations to accelerate their own migrations.
read more →

Five Ways Chrome Enterprise Strengthens Browser Security

🔒 Chrome Enterprise outlines five enhancements aimed at reinforcing browser security for organizations, addressing modern risks from session theft to malware-driven credential theft. Highlights include Device Bound Session Credentials to prevent session hijacking, cache encryption to protect data at rest, and App-bound encryption to block unauthorized apps from reading browser-stored secrets. Administrators also get tighter download controls and deeper integrations with partners such as Citrix and Okta to improve access decisions and incident response.
read more →

Kubernetes as AI Infrastructure: llm-d Joins CNCF Sandbox

🚀 Google Cloud and partners announced that llm-d has been accepted into the CNCF Sandbox to promote open, accelerator-agnostic standards for distributed LLM inference. As a founding contributor alongside Red Hat, IBM Research, CoreWeave, and NVIDIA, Google emphasizes running any model on any accelerator in any cloud without vendor lock-in. GKE Inference Gateway now integrates the llm-d Endpoint Picker (EPP) to enable model-aware routing that optimizes for KV-cache hits, inflight requests, and queue depth, yielding concrete production gains in Vertex AI tests. Complementary work on the Kubernetes LeaderWorkerSet (LWS) API and vLLM extensions for Cloud TPUs targets scalable multi-node orchestration and up to 5x throughput improvements.
read more →

GKE and OSS Innovation Highlights at KubeCon EU 2026 Updates

🚀 Google Cloud previews GKE and open-source innovations at KubeCon Europe 2026, focusing on making Kubernetes the best platform for AI and agentic workloads. Autopilot compute classes can now be enabled per workload on Standard clusters, and GKE Cluster Autoscaler will be open-sourced to advance vendor-neutral provisioning. GKE is certified for the CNCF Kubernetes AI Conformance program, and projects like llm-d, DRA drivers for TPUs, and DRANET aim to standardize inference and resource management. Features such as the Model Context Protocol, Kubernetes Agent Sandbox, and GKE Pod Snapshots target secure, fast startup and manageability for agents.
read more →

Google Authenticator: Hidden Mechanics of Passkeys Design

🔐 This Unit 42 analysis examines how Google implements synchronized passkeys using a cloud-based authenticator embedded in Chrome and Google Password Manager. The author documents an enclave service (observed connecting to enclave.ua5v[.]com), hidden onboarding flows, and TPM-backed identity and user-verification keys that bind devices and gate access. The post explains the Security Domain Secret, device wrapping keys, the GPM PIN recovery mechanism, and the Noise/WebSocket transport used to protect device-to-cloud communications, emphasizing a novel attack surface in passwordless deployments.
read more →

Bringing Dark Web Intelligence into the AI Era with Google

🛡️Google Threat Intelligence introduces a new dark web intelligence capability powered by Gemini that analyzes millions of dark web events daily and elevates only threats relevant to your organization. Using autonomous organizational profiling, it reduces manual keyword configuration and filters noise to surface actionable risks early in the attack lifecycle. Internal tests report approximately 98% accuracy, and GTIG analysts add human context to ground AI findings.
read more →

RSAC '26: Supercharging Agentic AI Defense with Threat Intel

🔒 Google Cloud outlined a coordinated set of AI-driven security advances at RSAC ’26, anchored by the completed acquisition of Wiz and new agentic defense capabilities. The company highlighted Mandiant's M-Trends 2026 findings on rapid adversary operations and published guidance on AI risk and resilience. Previewed offerings include Google Security Operations with autonomous triage agents, dark web intelligence powered by Gemini, and expanded protections across model, data, and network security.
read more →

Google halts AI-generated bug reports for OSS program

🛑 Google will no longer accept AI-generated bug reports for the Open Source Software Vulnerability Reward Program it funds, citing a rising number of low-quality submissions that often contain hallucinated exploit paths or issues with minimal security impact. To reduce triage overhead, some reward tiers will now require higher-quality proof such as an OSS-Fuzz reproduction or a merged patch. Google says this will help teams focus on high-impact, verifiable vulnerabilities. Separately, the company is contributing to programs that use AI constructively to strengthen open-source security.
read more →

Five Ways Google Helps You Avoid Tax Season Scammers

🔒Google outlines five practical defenses to help users spot and avoid tax‑season scams. It describes on‑device AI protections on Pixel phones including Call Screen and optional real‑time Scam Detection alerts, plus text‑vetting with Circle to Search and Lens. The post highlights real‑time Safe Browsing, high‑visibility Gmail warning banners and security steps like Passkeys and 2‑Step Verification to reduce fraud risk.
read more →

Darksword iOS Exploit Used in Wide Infostealer Attacks

🔒 Darksword is a newly discovered iOS exploit kit targeting iPhones running iOS 18.4–18.6.2 and used to harvest credentials, photos, messages, and cryptocurrency wallet data. Researchers from Lookout, Google Threat Intelligence Group, and iVerify linked the framework to the actor behind the Coruna chain and say Apple has patched the exploited flaws. Victims should update to iOS 26.3.1 and consider enabling Lockdown Mode if at high risk.
read more →

DarkSword: Full-Chain iOS Exploit Targeting iOS 18.4–18.7

🔒 Google Threat Intelligence Group (GTIG) disclosed a JavaScript full-chain iOS exploit named 'DarkSword,' observed since November 2025, that chains six vulnerabilities to fully compromise devices running iOS 18.4–18.7. Multiple operators — including commercial vendor PARS Defense and suspected state actors (UNC6748, UNC6353) — used DarkSword to deploy implants GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Apple has issued patches (culminating in iOS 26.3); GTIG recommends updating immediately or enabling Lockdown Mode if updates are not possible.
read more →