< ciso
brief />
Tag Banner

All news with #google tag

642 articles · page 2 of 33

Google credits AI for surge in Chrome vulnerability fixes

🔒 Google reports that AI has enabled Chrome to patch 1,072 security bugs across Chrome 149 and 150, exceeding the total fixed in the prior 23 milestones combined. The company uses large language models across the vulnerability lifecycle—from discovery and repro to patch generation and testing—and has developed multi-agent systems like Naptime and Big Sleep. Google is also accelerating updates with tighter release cycles and exploring dynamic patching to reduce the window between fix commit and user update.
read more →

Gemma 4 now on Amazon Bedrock in GovCloud

🔒 The Gemma 4 family from Google DeepMind is now available on Amazon Bedrock in AWS GovCloud (US-West). The offering includes three variants—Gemma 4 31B, Gemma 4 26B-A4B, and Gemma 4 E2B—covering dense and MoE architectures with support for multimodal inputs, native function calling, and a 256K-token context window on the 31B variant. Bedrock enhancements target price performance, tool calling, structured output, reasoning, and streaming responses to support reliable generative AI workloads.
read more →

Google Chrome fixes 370 vulnerabilities in update

🔒 Google’s Chrome team released version 151 (Windows, Mac and Linux) addressing 370 vulnerabilities, including seven critical flaws. The critical issues include several use after free bugs across Compositing, Views, Skia and Ozone, plus validation flaws in Dawn and ANGLE and a race condition in the Updater. These were reported between 18 May and 14 June 2026. The update also patches 71 high, 170 medium and 122 low severity issues, with researchers awarded $58,500 via the bug bounty.
read more →

Google Cloud Introduces Borderless Lakehouse

🧭 Today at Next Tokyo, Google Cloud announced enhancements to its borderless Lakehouse built on Apache Iceberg, enabling cross-cloud, zero-copy analytics and federated catalogs. The platform lets Gemini Enterprise and conversational agents query and act on live data across on-prem, AWS, Azure, and major SaaS systems without heavy ETL. New features include catalog federation (preview), Cross-Cloud Interconnects with predictable pricing, intelligent caching, and integration with Knowledge Catalog for unified governance and context.
read more →

Google Cloud Gemini Enterprise Agent Platform Updates

🧭 Google Cloud announces broader availability of key features in the Gemini Enterprise Agent Platform, including Agent Memory Bank, Agent Runtime, Agent Identity, Agent Gateway, and Agent Registry. These additions enable long-running, personalized agents with enterprise-grade security, governance, and centralized discovery. The platform also adds unified observability and evaluation tools to monitor agent behavior and performance in production.
read more →

Looker adds agentic workflows for data monitoring

🤖 Looker introduces Agentic Workflows in preview to automate metric monitoring and root-cause analysis using intelligent background agents. Users can create continuous monitoring routines via the Conversational Analytics chat by prompting the agent to watch metrics and set thresholds. When a threshold is crossed, the agent runs Key Driver Analysis to identify drivers of the change and delivers a diagnostic summary to Slack or email. Administrators retain centralized oversight while business users can manage their own monitors.
read more →

Automate agent lifecycles with Gemini Enterprise

🛠️ This deep dive shows how to build a production-ready agent using the Agents CLI and Gemini Enterprise. It walks developers through six stages—Setup, Build, Deploy, Govern, Evaluate, and Publish—using an Industry Watch agent that reconciles press coverage with SEC filings. The tutorial emphasizes deterministic tools, managed runtime, memory, identity controls, and automated evaluations to prevent hallucination and ensure grounded, auditable results.
read more →

Enterprise resilience and toolchain security insights

🔐 Mandiant and Google research show that most successful intrusions still stem from human and systemic failures, with exploits as the top initial vector and voice phishing rising. The blog urges shifting from prevention-only approaches to an operating model that assumes compromise, emphasizes containment, and uses intelligence-led feedback to build resilience. It highlights risks to recovery paths, the need for executive and extended ecosystem protection, and the role of immersive training and disciplined AI integration in defense.
read more →

Google GTIG launches unified threat actor names

🔐 Google’s Threat Intelligence Group (GTIG) is introducing a unified cryptonym-based naming schema to standardize threat actor tracking across platforms and reports. The system uses two-word names: a unique memorable term and a second word denoting motivation, origin, or activity type to aid defenders. Several dozen active groups will be renamed initially, with prior aliases and MITRE ATT&CK mappings preserved for continuity. The approach aims to simplify mapping across vendor taxonomies while acknowledging visibility differences.
read more →

Preparing Infrastructure for the Agentic Data Cloud

🚀 In the agentic era, organizations must move from passive data stores to proactive systems of action by providing AI agents with trusted business context. Google introduces the Agentic Data Cloud to unify data, models, and operational databases on an AI-native stack, leveraging BigQuery, Spanner, and open standards like Apache Iceberg. The approach reduces latency, operational overhead, and integration gaps that hinder production-grade agentic AI.
read more →

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

EU fines Google €890M for Digital Markets Act breaches

📰 The European Commission fined Google €890 million for violating the EU's Digital Markets Act, finding the company favoured its own services in Google Search and restricted app developers on Google Play. Google was designated a DMA gatekeeper in September 2023 and investigated from March 2024. The fine splits into €460 million for search favouritism and €430 million for app store steering, and Google must comply within 60 days or face further penalties.
read more →

Google adds selfie video account recovery option

📹 Google introduced an opt-in selfie video sign-in method to help users recover access when they cannot use their usual phone or computer. Users set up a short guided video with head movements to capture their face from multiple angles; later recordings are compared to the saved video to confirm identity. The feature stores videos encrypted at rest, is not available for Workspace, Child, or Advanced Protection accounts, and can be deleted or toggled for service improvement.
read more →

Google introduces selfie video sign-in option

📸 Selfie video sign-in provides a new option to access your Google Account when you’re locked out or lack your usual device. Setup involves a short guided head-movement video captured and stored securely with your consent; you can delete it anytime. The system compares a fresh selfie video to the stored one and requires live movements to prevent spoofing. Encryption at rest and existing security measures are applied to protect against impersonation and suspicious sign-in attempts.
read more →

Google phone verification and RCS privacy risks

📱 Google’s phone number verification notifies users when their SIM is confirmed and links that number to all Google accounts on the device. The feature supports RCS messaging and fraud protection but can surface hidden verification SMS or metadata collection. Verification runs by default, may use carrier APIs or hidden SMS, and can attach identifiers like ICCID/IMSI. Users can opt out per account but may lose RCS and risk re-enablement.
read more →

Google launches enterprise-ready CodeMender agent

🛡️ Google has made CodeMender available as a fully managed AI code security agent for enterprise customers via the Gemini Enterprise Agent Platform and AI Threat Defense. Originally a DeepMind research project, CodeMender now builds and runs PoC exploits in sandboxes, proposes tested fixes into pipelines, and offers multiple Gemini model options for cost and coverage balance. Features include secure traffic routing, data isolation, zero code retention and integrations with tools like VS Code and Antigravity.
read more →

Google unveils Gemini 3.5 Flash Cyber for security

🔒 DeepMind has released Gemini 3.5 Flash Cyber, a lightweight AI specialized in rapid vulnerability discovery, validation, and patching. The model is available only to governments and trusted partners via the CodeMender pilot program and is designed for high-speed, low-cost scanning of code paths. DeepMind reports it outperforms other Gemini variants and rival models in finding unique, confirmed issues across complex projects.
read more →

CodeMender brings AI-driven code scanning and remediation

🛡️ CodeMender is a managed code security agent now available in preview, offering automated scanning and remediation using Google DeepMind–tuned models via the Gemini Enterprise Agent Platform or as part of AI Threat Defense. It prioritizes fixes by exploitability, runs proof-of-concept exploits in customer-managed sandboxes, and generates validated patches that integrate into developer workflows. The agent supports multiple languages, integrates with CI/CD and IDEs, and enforces enterprise-grade governance and data controls.
read more →

Sandbox escapes impact major AI coding agents

🛡️ Security researchers demonstrated sandbox escape techniques against four popular AI coding agents—Cursor, OpenAI's Codex CLI, Google's Gemini CLI and Antigravity—by having the agent write files that trusted host tools later execute. Pillar Security reproduced the bypasses over months and published them as a daily series, identifying four failure modes including denylist limitations, executable workspace configs, permissive command allowlists, and privileged daemons. Most issues have been patched and vendor-acknowledged, though Google classified two Antigravity findings as lower-severity due to required social engineering.
read more →

OneDrive and Google Drive for Multi‑Session Fleets

📂 Amazon WorkSpaces Applications now supports Microsoft OneDrive for Business and Google Drive as persistent storage options for multi-session fleets. Users streaming on shared fleet instances can connect their cloud accounts to access, save, and sync files directly within sessions, alongside the existing S3-backed home folder. This feature is available in all AWS Regions where WorkSpaces Applications is offered and incurs no extra charge beyond standard streaming usage pricing.
read more →