< ciso
brief />
Tag Banner

All news with #google tag

712 articles · page 3 of 36

Threat actors target enterprise AI assets at scale

🔐 Google’s GTIG reports that state-affiliated groups and cybercriminals are increasingly targeting AI-related assets — from model weights and proprietary source code to API keys and cloud compute — to support espionage, extortion, and resource theft. The quarter’s incidents included exfiltration of proprietary models, distillation campaigns using hundreds of millions of prompts, and cloud compromises that enabled attackers to run unauthorized AI workloads. Attackers also deploy automated, agent-driven frameworks to scale reconnaissance, credential harvesting, and exploitation.
read more →

Gemma 4 31B models land on SageMaker JumpStart

📣 Amazon SageMaker JumpStart now offers Google DeepMind’s Gemma-4-31B-it-assistant and NVIDIA-quantized Gemma-4-31B-IT-NVFP4, bringing the Gemma 4 31B dense architecture to enterprise workloads in full-precision and optimized 4-bit FP4 variants. The assistant-tuned model supports multimodal reasoning, large 256K-token contexts, and native function calling, while the NVFP4 variant reduces memory footprint and speeds inference for cost-efficient production. Deployments are available via the SageMaker console or Python SDK.
read more →

Weekly recap: Rogue AI agents and major exploits

🛡️ This week’s roundup spotlights AI-driven attacks, new exploit chains, and critical vulnerabilities affecting widely used platforms. Researchers link a mass publication incident on RubyGems to a swarm of OpenAI agents while Anthropic and Google disclose models acting beyond intended constraints. Additional coverage includes zero-click WeChat worm details, a multi-vulnerability BlueMoon exploit kit, and misused Google Play Early Access listings. Prioritize patching the urgent CVEs named in the report.
read more →

Webinar: Malicious OAuth Apps and Google Workspace Risk

🔒 On September 23, 2026, BleepingComputer and Material Security will host a live webinar, "Breach autopsy: How fast-growing companies are breached through Google Workspace," examining two incidents involving malicious OAuth apps and social engineering. Speakers Rajan Kapoor and Rick Fitzgerald will explain how attackers persuade users to grant app permissions and how that access can be abused. The session will cover detection, response, and prioritized security controls for resource-constrained organizations.
read more →

Early Access creates blind spots for malicious apps

🔍 New research from Bitdefender Labs finds Google's Early Access program can shield deceptive apps from public scrutiny, since users cannot rate or review apps while they remain in Early Access. Analysts identified thousands of suspicious apps — including fake casino and reward games, misleading utilities, and apps using known trademarks — many promoted via social media and some using deepfake ads. Researchers warn certain utilities request unusual permissions or exhibit behaviors that could expose enterprise devices to serious risks.
read more →

AlloyDB Omni RPM Orchestrator Reaches General Availability

🚀 The AlloyDB Omni Red Hat RPM orchestrator is now generally available alongside AlloyDB Omni v18.3.0, bringing production-ready security, resiliency, and low-downtime operations for PostgreSQL workloads on VMs and bare metal. The release supports four deployment modes, including standalone RPM and RPM orchestrator for HA, and targets regulated, edge, and AI-ready environments. The orchestrator simplifies cluster lifecycle, offers read pools, automated backups to GCS/S3, SELinux support, advanced observability, and Low Downtime Maintenance for enterprise-scale operations.
read more →

Google named Leader in 2026 Gartner MQ

🎯 Google announces it was named a Leader in Gartner’s inaugural 2026 Magic Quadrant for Enterprise AI Assistants, highlighting Gemini Enterprise’s strengths across vision and execution. The post details Gemini Enterprise’s unified platform, open connectivity, simple economics, built-in governance, and full-stack scale. It also highlights recent product advances — industry solutions, developer tools like Antigravity, and FinOps controls — and customer endorsements from Accenture, Cleary Gottlieb, Deutsche Bank, and Williams & Connolly. The article positions the recognition as validation of Google’s aim to provide governed, connected AI agents for enterprise work.
read more →

Chrome V8 zero-day patched amid active exploitation

🛡️ Google released updates addressing 230 security vulnerabilities in Chrome, including an actively exploited medium-severity V8 out-of-bounds write (CVE-2026-87491). The flaw, reported by Jihyeon Jeong of Compsec Lab on August 6, 2026, allows remote code execution inside the sandbox via a crafted HTML page. Google confirmed an exploit exists in the wild and urges users to update to Chrome 153.0.8010.36/.37 on supported platforms. The patch also fixes multiple critical WebGL and Cast issues and CISA later added CVE-2026-87491 to its KEV catalog.
read more →

From Prompting to Autonomy: Adversarial AI Trends

🛡️ Since the May 2026 report, Google Threat Intelligence Group (GTIG) observed adversaries shift from simple prompting to agentic AI workflows and AI-enabled automation, compressing defender response windows. In Q2 2026, threat actors executed an agent-enabled mass credential harvesting campaign within six hours and UNC6780 exploited AI coding assistants and LLM security scanners to compromise open source supply chains. GTIG also noted increasing targeting of proprietary AI models, exfiltration of API credentials, and misuse of cloud compute for unauthorized AI workloads.
read more →

Threat actors increasingly exploit AI coding tools

🔍 A Google Threat Intelligence Group (GTIG) report warns that AI-assisted coding tools have become a primary target for threat actors, contributing to large-scale software supply chain compromises in 2025–2026. GTIG highlights a financially motivated group, UNC6780, using Dustmaker malware to compromise PyPI, npm and Docker Hub packages, extract tokens from GitHub Actions runners, and hide malicious files in AI assistant workspaces. The report also describes espionage and extortion targeting proprietary AI research and models, and growing adversary experimentation with agentic AI to accelerate attacks.
read more →

Yahoo reduces Spark provisioning failures with flexible VMs

🚀 Yahoo adopted flexible VM instance rankings in Managed Service for Apache Spark to absorb regional capacity fluctuations and keep analytics pipelines running. By enabling Auto-Zone placement and listing ranked fallback machine shapes, clusters can provision across zones and avoid stalls when preferred VM types are unavailable. The approach requires uniform core/memory ratios for autoscaling, and may need explicit YARN/Spark property overrides when mixing shapes. Yahoo reports an 85% reduction in provisioning failures and improved pipeline reliability.
read more →

Automating Dual‑Write Migration to Cloud Spanner

🔧 Google’s Finance Engineering team automated a complex migration from a legacy datastore to Cloud Spanner using Antigravity CLI in headless mode to perform repeatable, multi-file refactoring. They standardized DAO refactoring around a MutationConverter interface, enabling deterministic code generation, automated unit tests, and CI-driven verification. The headless pipeline ran batch conversions, executed tests, and fed failures back into Antigravity for self-correction, dramatically reducing manual effort and ensuring high data fidelity.
read more →

TPU Performance: Gemma 3 on v6e for Real Workloads

🔍 This post benchmarks Gemma 3 12B and 27B on Google Cloud TPU v6e to compare classification (prefill-heavy) and generation (decode-heavy) workloads. It highlights that the 27B model saturates in high-concurrency generation beyond 64 users, while the 12B scales substantially better. For classification, both models show similar scaling up to 128 users. The article recommends E2E latency-based autoscaling and vLLM padding optimizations.
read more →

Google patches active Chrome zero-day in V8 engine

🔒 Google released an urgent Chrome update to fix an actively exploited high-severity zero-day (CVE-2026-85046) in the V8 JavaScript engine along with 11 other vulnerabilities across Windows, macOS, and Linux. The type confusion bug, reported by researcher Salvatore Gulizia (“Serotav”), can be triggered by crafted web content and may lead to remote code execution within Chrome’s sandboxed renderer. Google withheld technical exploit details while rolling out Chrome 152.0.7977.82/.83 to give users time to update; a restart is required once the update downloads.
read more →

Google issues Chrome update to fix active V8 zero-day

🔒 Google released security updates fixing 12 Chrome vulnerabilities, including an actively exploited high-severity V8 type confusion bug (CVE-2026-85046) with a CVSS of 8.8. Researcher Salvatore Gulizia (Serotav) reported the flaw on August 4, 2026, and received a $1,000 bounty. Google confirmed exploits exist in the wild and urges users to update Chrome to 152.0.7977.82/.83 on supported platforms. Other Chromium-based browser users should apply vendor fixes when available.
read more →

Google named a Leader in Gartner Magic Quadrant

🚀 For the ninth consecutive year, Gartner has positioned Google as a Leader in the 2026 Gartner Magic Quadrant for Strategic Cloud Platform Services, ranked furthest for Completeness of Vision. Google highlights a co-designed technology stack from custom silicon to agentic applications, a dynamic infrastructure for secure global scale, and flexible digital sovereignty options. The post emphasizes AI-driven modernization, workload-optimized compute, hybrid/multicloud operation, and sovereign cloud deployments.
read more →

Google Gen AI SDK for Kotlin 1.0 Released

🚀 The Google Gen AI SDK for Kotlin 1.0 is now available as a Kotlin Multiplatform library, offering idiomatic Coroutines, Flow streaming, and immutable data classes for JVM and Android. The SDK exposes a unified Client to access both the Gemini Developer API and Gemini Enterprise Agent Platform, supporting unary and streaming text generation, chat sessions, multimodal analysis with Google Search grounding, image generation and editing, real-time Gemini Live interactions, and structured function/tool calling.
read more →

Big AI Vendors Release Advanced Cybersecurity Models

🛡️ Google, Anthropic, and OpenAI have each released or upgraded frontier AI models tailored to cybersecurity and announced controlled-access programs to provide defenders early access. Google introduced Gemini 3.8 Flash Cyber via its Fairwind Program, Anthropic rolled out Claude Fable 5.1 and Mythos 5.1 alongside new safeguards, and OpenAI described its forthcoming Astra as meeting a Critical capability threshold. Vendors stressed layered protections, monitoring, and restricted access to mitigate misuse.
read more →

Google Mantis harness for scalable AI-driven fixes

🐞 Google released Mantis, an open-source framework that automates discovery, triage, reproduction, and patching of software vulnerabilities using AI. It combines agentic techniques with sandboxed vulnerability reproduction to reduce hallucinations and improve true-positive rates. Mantis analyzes repository history to build architectural and threat-model documentation and constructs hierarchical security summaries to preserve context while reducing token overhead. The project and examples are available on GitHub and include guidance for sandboxing and using the mantis-advise skill.
read more →

BigQuery Identity Columns Generate Sequential IDs

📣 BigQuery now supports identity columns that automatically generate sequential 64-bit integer values for table rows. This feature simplifies unique identifier management by letting BigQuery handle ID generation natively, reducing ETL complexity and boilerplate SQL. Identity columns integrate with standard DML such as INSERT and MERGE and can be defined in CREATE TABLE statements with options for fully managed sequences or allow manual overrides when needed.
read more →