< ciso
brief />
Tag Banner

All news with #google tag

713 articles · page 22 of 36

Agent Factory Recap: Antigravity and Nano Banana Pro

🛠 This episode of the Agent Factory podcast showcases Google’s new developer tools: Antigravity, an agent-first multi-window IDE, and Nano Banana Pro, the Gemini 3 Pro image model. Hosts Remik and Vlad demo building an agentic slide generator using the Agent Development Kit, Antigravity’s Agent Manager, and an MCP server, highlighting planning, testing, and high-fidelity image creation.
read more →

Filling Common Gaps in Google Workspace Security Posture

🔒 Security teams at fast-growing companies must secure collaboration platforms without slowing the business. This piece highlights common native gaps in Google Workspace—from BEC and targeted phishing to legacy protocol exposure and weak OAuth controls—and lists immediate hardening steps for Gmail, access, and data protection. It also outlines how Material augments Workspace with advanced email defense, context-aware account monitoring, and automated data protection.
read more →

Deploy Gemini 3 Apps Quickly with Google Cloud Run

🚀 This guide demonstrates how to create and deploy a public web app using Gemini 3 Flash Preview via Google AI Studio and Google Cloud Run. In Build mode you describe the application in natural language and let the model "vibe code" a complete app, which appears instantly in the Preview panel for testing. When satisfied, a single Deploy App action pushes the app to Cloud Run, exports your API key as an environment variable, and provides a shareable URL. Note that deployment requires a Google Cloud project with billing enabled.
read more →

Mastering Gemini CLI: Installation to Advanced Use Cases

📚 This free course from Google Cloud and DeepLearning.ai teaches practical use of Gemini CLI, guiding users through installation, context management, extensibility, and specialized workflows. It is designed for developers and non-developers who want to integrate the CLI into daily tasks such as data analysis, content generation, and personalized learning. The curriculum runs in under two hours and provides hands-on lessons covering GEMINI.md, memory features, MCP servers, and extensions.
read more →

Google: Gemini Won't Have Ads for Now as ChatGPT Tests Ads

📰 Google says Gemini will not include ads for now, a stance confirmed by DeepMind CEO Demis Hassabis at the Davos Economic Forum. Google AI leadership reiterated that it currently does not plan to monetize Gemini with advertising, although the company did not rule out future changes. Meanwhile, OpenAI has begun testing ads in ChatGPT in the U.S. for Free and Go users, with paid tiers expected to remain ad-free.
read more →

Gemini AI Trick Exposes Google Calendar Data via Invite

⚠️ Researchers at Miggo Security demonstrated that Google Gemini can be manipulated via malicious Calendar invites to exfiltrate private event data. By embedding natural-language prompt-injection payloads in an event description, attackers can cause Gemini to summarize private meetings and write that summary into a new event visible to participants. Miggo reported the issue and Google has implemented mitigations.
read more →

Firestore Enterprise launches advanced query engine

🚀 Firestore Enterprise introduces an advanced query engine with more than a hundred new pipeline operations available in preview. The update lets developers chain stages for aggregations, grouping, filtering and array unnesting, reducing reliance on mandatory indexes for many queries. It also adds precise index controls, query explain and query insights for deeper observability, and a clearer pricing model aimed at lowering read and storage costs.
read more →

Google Gemini exploited via calendar prompt injection

⚠️ Researchers disclosed an indirect prompt-injection flaw that allowed Google Gemini to bypass calendar privacy controls and exfiltrate meeting data. A crafted Google Calendar invite could hide a natural-language payload that Gemini later parsed, summarized, and wrote into new events whose descriptions leaked private meeting content. Miggo Security reported the issue and said it has been responsibly disclosed and addressed, highlighting how AI-native features increase the attack surface when assistants can read, summarize, and write into productivity services.
read more →

Google Chrome Tests Gemini 'Skills' to Automate Tasks

🤖 Google is testing new Skills for its Gemini AI in Chrome that enable the assistant to perform tasks automatically inside the browser. A hidden page, chrome://skills, has been identified and appears to let users add Skills with a name and instructions while the feature is being internally tested. Currently, Gemini in Chrome acts as a helper on desktop in the US, summarizing pages, explaining content, and combining information from multiple tabs. Google plans to evolve Gemini into an agent that will work more closely with apps like Calendar, YouTube, and Maps, though rollout timing is still unclear.
read more →

Google Chrome adds option to remove on-device AI models

🔒 Google Chrome now allows users to delete the local AI models that power the Enhanced Protection feature, which received AI upgrades last year. The device-hosted model performs real-time scans of sites, downloads, and extensions to flag potentially dangerous content. Researcher Leopeva64 spotted a new control in Chrome Canary; to remove the model, go to Settings > System and turn off "On-device GenAI." Google will roll the option to stable channels soon.
read more →

Google Vertex AI permissions raise insider threat risks

⚠️ XM Cyber disclosed privilege-escalation flaws in Google’s Vertex AI that let low‑privileged users manipulate Google-managed Service Agents to gain elevated project-wide permissions. Google told XM Cyber this behavior is "working as intended." Security experts warn that managed service identities and insecure defaults create invisible, structural risks. CISOs are urged to audit service identities, reduce authentication scope, and monitor agent activity like privileged users.
read more →

Google rolls out ability to change @gmail.com address

✉️ Google has begun rolling out an option that lets users change their primary @gmail.com address to a new @gmail.com address. When changed, the previous address becomes an alias and continues to receive mail; account data (photos, messages, and existing emails) is preserved and accessible. You can sign in with either the old or new address, revert to the prior address at any time, and Google limits creation of additional new addresses for the same account over a 12‑month period; the new address cannot be deleted.
read more →

BigQuery: Managed SQL-native Inference for Open Models

🚀 BigQuery now supports managed third‑party generative AI inference (Preview) for open models from Hugging Face and Vertex AI Model Garden, enabling SQL-native deployment and inference. With a single CREATE MODEL statement you can provision and configure compute, control lifecycle with endpoint_idle_ttl and ALTER MODEL, and run inference via AI.GENERATE_TEXT or AI.GENERATE_EMBEDDING. BigQuery automates resource cleanup and integrates cost controls to reduce operational overhead.
read more →

WhisperPair Flaw Lets Attackers Hijack Bluetooth Audio

🔒 Security researchers at KU Leuven disclosed a critical flaw dubbed WhisperPair (CVE-2025-36911) in the Fast Pair protocol that lets attackers forcibly pair with and control Bluetooth audio accessories. The issue stems from devices failing to enforce the Fast Pair requirement to ignore pairing requests when not in pairing mode, enabling silent hijacking and eavesdropping. Hundreds of millions of headphones, earbuds, and speakers from vendors including Google, Jabra, Sony, OnePlus, Xiaomi, and others are affected, and patches are being coordinated with manufacturers.
read more →

Critical Fast Pair Flaw Lets Attackers Hijack Headsets

🔒 Researchers disclosed a critical vulnerability in Google's Fast Pair protocol, tracked as CVE-2025-36911 and dubbed WhisperPair. The flaw stems from many accessories failing to ignore pairing requests when not in pairing mode, enabling attackers to pair without user consent. Exploits can hijack audio devices, enable eavesdropping and location tracking, and affect hundreds of millions of headsets from vendors including Google, Sony, Jabra, JBL, OnePlus. Only manufacturer firmware updates mitigate the risk; disabling Fast Pair on phones does not protect accessories.
read more →

Microsoft Tops Brands Imitated in Q4 2025 Phishing

🔒 In Q4 2025, Check Point Research found Microsoft to be the most impersonated brand in phishing campaigns, responsible for 22% of branded phishing attempts. Google followed with 13%, while Amazon rose to 9%, driven by Black Friday and holiday sales, displacing Apple. After a lengthy absence, Facebook (Meta) reappeared in the top ten at fifth, underscoring renewed interest in social media account takeover. The pattern reflects a multi-quarter trend of attackers abusing trusted enterprise and consumer brands to harvest credentials and gain initial access.
read more →

Google to Add Gemini Agentic Features to Chrome Android

🤖 Google is testing integration of Gemini into Chrome for Android, with Chromium source references indicating an agentic feature codenamed Glic. A Google engineer noted the browser binary increases because of the added support code, suggesting significant new functionality. The integration may provide contextual, agent-like actions such as page summaries and follow-up queries, similar to mobile copilots. No release timetable has been announced.
read more →

Google's Personal Intelligence Links Data to Gemini

🔐 Google is rolling out a new Personal Intelligence capability in Gemini that can access information from Gmail, Google Photos, Search, YouTube and other Google products to generate more personalized responses. The feature is opt-in, off by default, and users can choose which apps to connect, disconnect them, or turn the feature off at any time. Google illustrates uses such as pulling tire specifications from photos and emails or extracting a license plate from an image to confirm vehicle details. The functionality is launching as a U.S. beta for eligible subscribers, and Google warns that the model can still produce inaccuracies or over-personalization, inviting users to provide feedback.
read more →

Palo Alto Networks Automates DORs with Agentic AI Design

🤖 Palo Alto Networks automated creation of its internal Document of Record (DOR) using an agent built with Google's open-source Agent Development Kit (ADK) and hosted on Vertex AI Agent Engine. The agent leverages Vertex AI RAG Engine, Vertex AI Discovery Search, Gemini models, and Cloud Storage to retrieve and synthesize grounded answers to a standardized set of 140+ questions. A FastAPI webserver on GKE orchestrates parallel processing, manages state, and publishes completed DORs back to Salesforce via Cloud Pub/Sub, reducing manual effort and improving consistency.
read more →

Comments to SQL in BigQuery: Natural-Language Querying

🔎 Comments to SQL in BigQuery introduces an AI-driven way to write queries by placing natural-language expressions inside SQL comments. The system analyzes surrounding SQL context and translates plain English prompts into executable BigQuery SQL across SELECT, FROM, WHERE, GROUP BY and other clauses. It supports iterative refinement and aims to help both non-SQL users and experienced analysts move faster.
read more →