< ciso
brief />
Tag Banner

All news with #google tag

712 articles · page 5 of 36

Research reveals practical weaknesses in passkey deployments

🔐 Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

Free Gemini Enterprise agent training pathway

🧭 This summer Google Cloud offers a free, hands-on training path powered by Gemini Enterprise Agent Ready (GEAR) to help developers and IT leaders move autonomous agents to production. The program includes sequential courses and skill badges covering agent fundamentals, multi-agent orchestration, ADK engineering, memory and state management, human-centered design, and operationalization on Google Cloud. Participants can earn credentials, access labs and prototypes, and join an All Things Agentic Hackathon with prizes to demonstrate real-world skills.
read more →

AWS, Google and Vercel Patch Agent Tool-Call Flaws

🛡️ Security advisories from Amazon Web Services, Google, and Vercel detail vulnerabilities in agent harnesses that allowed caller-supplied or forged tool-call data to reach execution without a verifying model turn. AWS patched its managed Bedrock AgentCore service, Google fixed ADK for Python in v2.5.0, and Vercel released fixes for its Codex and OpenCode harness packages. Each vendor's path differed in attack surface and required conditions, and mitigations focus on validating and binding tool invocations to authenticated model events.
read more →

Google ADK flaws show risks when agents trust messages

🔍 Security flaws in Google’s Agent Development Kit (ADK) workflows could let public-facing AI agents trigger higher-privilege automation, researchers at Pillar Security report. Malicious instructions in pull requests or issues induced agents to post commands that started trusted workflows, enabling actions like altering reviews and extracting tokens. Google removed the affected workflows and applied fixes after disclosure.
read more →

Data Commons on Spanner Graph Unifies Public and Private Data

🧭 Data Commons on Spanner Graph general availability and a preview of the Data Commons Platform simplify linking private enterprise data with Google's extensive public knowledge graphs. The platform consolidates standardized public datasets from over 100 providers into a unified graph with >400 billion observations and leverages Spanner Graph for native GQL support, incremental updates, and consistent snapshots. Organizations can deploy private instances to federate private and public knowledge graphs while retaining data isolation and enabling natural language query workflows.
read more →

Behind the scenes: scaling Google Agent Skills

🛠️ This article explains how the Google Agent Skills project was launched, structured, and governed to encode Google Cloud domain knowledge into agent-readable instructions. It outlines standardized repository layouts, a CI/CD pipeline with linters and link checkers, and continuous evaluations measuring accuracy and efficiency. The piece also describes ownership rules, internal authoring tools, and a parallel DevRel Skills initiative for internal workflows.
read more →

Chrome to block policy-installed new-tab hijackers

🛡️ Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged consumer devices. The change, spotted in Chromium Gerrit, would enable a feature flag by default to prevent extensions forced by local policies from overriding the New Tab or search settings. Chrome would cancel such installations, record the extension ID as blocked, and avoid repeated download attempts, while allowing administrators an escape hatch policy when needed.
read more →

Google introduces new threat actor naming scheme

🛡️ Google is rolling out a new two-word naming scheme from its Google Threat Intelligence Group (GTIG) to label cyber threat actors, replacing earlier TAG and Mandiant systems. The first word denotes motivation or activity type, while the second denotes the actor’s origin or status, such as "CASTLE" for China or "RELIC" for Russia, with non-state actors ending in "COMET." The move aims to standardize reporting but risks adding more confusion instead of unifying industry taxonomy.
read more →

Google fixes over a thousand Chrome vulnerabilities

🔒 Google disclosed fixes for 1,072 security bugs across Chrome 149 and 150, and an additional 370 in Chrome 151, including seven critical issues. The company attributes a surge in discoveries to AI-assisted techniques and is shifting to faster release cadences and automated tooling to shorten disclosure and patch windows. Google is also piloting dynamic patching, session-preserving restarts, and moves toward memory-safe languages like Rust to reduce entire classes of C++-origin vulnerabilities.
read more →

Google credits AI for surge in Chrome vulnerability fixes

🔒 Google reports that AI has enabled Chrome to patch 1,072 security bugs across Chrome 149 and 150, exceeding the total fixed in the prior 23 milestones combined. The company uses large language models across the vulnerability lifecycle—from discovery and repro to patch generation and testing—and has developed multi-agent systems like Naptime and Big Sleep. Google is also accelerating updates with tighter release cycles and exploring dynamic patching to reduce the window between fix commit and user update.
read more →

Gemma 4 now on Amazon Bedrock in GovCloud

🔒 The Gemma 4 family from Google DeepMind is now available on Amazon Bedrock in AWS GovCloud (US-West). The offering includes three variants—Gemma 4 31B, Gemma 4 26B-A4B, and Gemma 4 E2B—covering dense and MoE architectures with support for multimodal inputs, native function calling, and a 256K-token context window on the 31B variant. Bedrock enhancements target price performance, tool calling, structured output, reasoning, and streaming responses to support reliable generative AI workloads.
read more →

Google Chrome fixes 370 vulnerabilities in update

🔒 Google’s Chrome team released version 151 (Windows, Mac and Linux) addressing 370 vulnerabilities, including seven critical flaws. The critical issues include several use after free bugs across Compositing, Views, Skia and Ozone, plus validation flaws in Dawn and ANGLE and a race condition in the Updater. These were reported between 18 May and 14 June 2026. The update also patches 71 high, 170 medium and 122 low severity issues, with researchers awarded $58,500 via the bug bounty.
read more →

Google Cloud Introduces Borderless Lakehouse

🧭 Today at Next Tokyo, Google Cloud announced enhancements to its borderless Lakehouse built on Apache Iceberg, enabling cross-cloud, zero-copy analytics and federated catalogs. The platform lets Gemini Enterprise and conversational agents query and act on live data across on-prem, AWS, Azure, and major SaaS systems without heavy ETL. New features include catalog federation (preview), Cross-Cloud Interconnects with predictable pricing, intelligent caching, and integration with Knowledge Catalog for unified governance and context.
read more →

Google Cloud Gemini Enterprise Agent Platform Updates

🧭 Google Cloud announces broader availability of key features in the Gemini Enterprise Agent Platform, including Agent Memory Bank, Agent Runtime, Agent Identity, Agent Gateway, and Agent Registry. These additions enable long-running, personalized agents with enterprise-grade security, governance, and centralized discovery. The platform also adds unified observability and evaluation tools to monitor agent behavior and performance in production.
read more →

Looker adds agentic workflows for data monitoring

🤖 Looker introduces Agentic Workflows in preview to automate metric monitoring and root-cause analysis using intelligent background agents. Users can create continuous monitoring routines via the Conversational Analytics chat by prompting the agent to watch metrics and set thresholds. When a threshold is crossed, the agent runs Key Driver Analysis to identify drivers of the change and delivers a diagnostic summary to Slack or email. Administrators retain centralized oversight while business users can manage their own monitors.
read more →

Automate agent lifecycles with Gemini Enterprise

🛠️ This deep dive shows how to build a production-ready agent using the Agents CLI and Gemini Enterprise. It walks developers through six stages—Setup, Build, Deploy, Govern, Evaluate, and Publish—using an Industry Watch agent that reconciles press coverage with SEC filings. The tutorial emphasizes deterministic tools, managed runtime, memory, identity controls, and automated evaluations to prevent hallucination and ensure grounded, auditable results.
read more →

Enterprise resilience and toolchain security insights

🔐 Mandiant and Google research show that most successful intrusions still stem from human and systemic failures, with exploits as the top initial vector and voice phishing rising. The blog urges shifting from prevention-only approaches to an operating model that assumes compromise, emphasizes containment, and uses intelligence-led feedback to build resilience. It highlights risks to recovery paths, the need for executive and extended ecosystem protection, and the role of immersive training and disciplined AI integration in defense.
read more →

Google GTIG launches unified threat actor names

🔐 Google’s Threat Intelligence Group (GTIG) is introducing a unified cryptonym-based naming schema to standardize threat actor tracking across platforms and reports. The system uses two-word names: a unique memorable term and a second word denoting motivation, origin, or activity type to aid defenders. Several dozen active groups will be renamed initially, with prior aliases and MITRE ATT&CK mappings preserved for continuity. The approach aims to simplify mapping across vendor taxonomies while acknowledging visibility differences.
read more →

Preparing Infrastructure for the Agentic Data Cloud

🚀 In the agentic era, organizations must move from passive data stores to proactive systems of action by providing AI agents with trusted business context. Google introduces the Agentic Data Cloud to unify data, models, and operational databases on an AI-native stack, leveraging BigQuery, Spanner, and open standards like Apache Iceberg. The approach reduces latency, operational overhead, and integration gaps that hinder production-grade agentic AI.
read more →