❌

Vue lecture

Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses

Welcome to the first Cloud CISO Perspectives for September 2026. Today, Sandra Joyce shares the latest details on Google’s visibility into how attackers are using AI, and how we’re using AI to stop them.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8ab0250>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

‘Spellcheck for cybersecurity’ and beyond: How Google monitors AI threats and advances AI defenses

By Sandra Joyce, VP, Google Threat Intelligence

Sandra Joyce

Sandra Joyce, VP, Google Threat Intelligence

Anyone operating in security knows that speculation is a major liability during periods of technological disruption. While there is plenty of hype and understandable concern around how threats might use and target AI, a CISO’s AI security strategy has to be anchored in ground truth.

Google operates at a rare intersection as both a frontier AI lab and a security company with a frontline view of global incidents. This dual vantage point allows us to understand how AI is built, and exactly how AI is being targeted in the wild. To provide the operational realities that security and business leaders need in the AI era, Google Threat Intelligence Group (GTIG) recently released our latest AI Threat Tracker.

When we strip away the noise and look at the telemetry, the real threat landscape boils down to three structural shifts that CISOs must address:

  1. AI is reshaping how software is built. 

  2. AI is expanding the attack surface.

  3. AI is enhancing threat capabilities. 

Today, we’re sharing details on Google’s visibility into these three challenges, and our approach for solving them.

Building securely in the AI era 

AI has fundamentally altered software development velocity. Across the industry, autonomous agents and AI workflows now push code into production at unprecedented speed. This creates exciting opportunities for innovation, yet CISOs are faced with the difficult task of mitigating enterprise risk while maintaining business momentum. 

We’re seeing threat actors turn our greatest engineering shortcut against us by contaminating upstream packages that AI assistants are trained to suggest and trust. GTIG believes that malicious contamination of AI-assisted coding practices has been contributing to the significant growth in large-scale, open-source software supply chain compromises we observed in 2025 and early 2026.

The solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time 'spellcheck for cybersecurity.'

We’re also monitoring adversaries targeting agents. The financially-motivated threat actor TeamPCP (UNC6780) has implemented more than half a dozen methods to exploit AI tools and open-source software development practices, including hijacking AI toolkits, prompt injection, and blinding AI scanners with toxic prompts to obfuscate malicious payloads.

The solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time “spellcheck for cybersecurity.” 

Just as word processors underline typos without forcing the writer to stop, security controls must sit natively inside the developer’s editor and agentic workflows, instantly flagging poisoned packages, toxic prompts, and misconfigured toolkits. 

Crucially, this can’t stop at the editor. Traditional security suffers from context blindness: Code editors can’t see cloud configurations, delivery pipelines miss runtime exposure, and production teams can’t easily patch root-cause blueprints. 

Bridging this gap requires an integrated code-to-cloud approach — the exact design principle behind platforms like Wiz Code. The underlying approach is to ensure code is continuously verified against live cloud realities before it ships.

When organizations think about AI-driven code analysis, the default assumption is to pick one frontier model and point it at their repository. However, our research and telemetry show that single-model security creates a dangerous monoculture: No single AI model can discover every vulnerability, and threat actors are already testing inputs that can blind specific LLM safety filters and scanners.

To secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos... The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map.

To solve this, Google takes a deliberate multi-model approach. By orchestrating several foundation models — including Gemini, commercial, and open-source — we cross-validate findings, strip out false positives, remediate code, and identify complex logic flaws that a single model misses. We’re smarter with more than one “brain.”

Securing AI 

Securing the development lifecycle is only half the battle. We also need to prevent adversaries from exploiting AI attack surfaces and weaponizing over-privileged agents. Threat actors are targeting AI workloads with techniques that include: 

  • LLMJacking: Cybercriminals and state-sponsored groups target GPU access to support running their AI models and agentic workflows. In one notable intrusion Mandiant investigated in April, a threat actor gained initial access to a victim’s cloud environment from an exposed personal access token, and used it to deploy unauthorized AI infrastructure and scale high-performance compute resources, leaving the victim to absorb the hardware and platform costs.

  • Targeting of AI data and access: Cybercriminals now recognize that your custom prompts, agent instructions, and fine-tuned models represent high-value crown jewels. In Q2 2026, Mandiant investigated multiple data theft extortion operations where threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research. Demand is also surging for AI account credentials in underground marketplace forums, with some sellers offering steep discounts for consumer accounts at up to 99% off retail prices.

To secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos. Don’t treat agent access policies, model inventories (AI-BOMs) and shadow AI as separate challenges because these risks are deeply connected. The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map. 

Pioneered by the Wiz Security Graph, this approach serves as the contextual engine for Google AI Threat Defense (AITD) — our broader autonomous security framework that fuses the reasoning power of Gemini and other frontier models, the contextual risk prioritization of Wiz, the code remediation capabilities of CodeMender, and the frontline expertise of Mandiant to stay ahead of AI-driven attacks. Crucially, this context is not siloed; it directly feeds Google Security Operations, ensuring that security operations teams can continuously identify, prioritize, and sever toxic attack paths at machine speed.

Defending against AI threats

Threat actors are rapidly moving beyond simple prompt generation toward fully-automated, multi-agent attack pipelines.

Security in the AI Era

Cyber Defense Summit 2026: Security in the AI era

In one notable intrusion investigated by Mandiant, a financially-motivated actor compromised an organization's cloud infrastructure and deployed an autonomous agent framework. The threat actor used an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.

We’re also tracking adversaries using AI as an intelligent orchestrator across the entire attack lifecycle. GTIG recently observed a PRC-nexus espionage group experimenting with a tool called CC Switch to cycle across multiple accounts and swap AI models — like Claude, Codex, and Gemini — picking the best model for specific tasks, such as writing exploit scripts and drafting lures. While the underlying hacking tools aren’t new, AI turned what had been a disjointed manual process into a smooth and automated workflow.

To take advantage of your deep context, it’s imperative to shift from manual, human-scale incident response to machine-speed security operations. We can no longer rely on human analysts manually triaging endless backlogs of static alerts.

While these machine-speed attacks sound daunting, defenders actually hold an asymmetric advantage. Even when armed with autonomous AI, an attacker operates from the outside with limited context — probing in the dark, guessing connections, and hoping a compromised credential leads to a useful asset. 

Defenders, on the other hand, possess deep context that attackers don’t have. You know your code, cloud configurations, user identities, deployment realities, and internal architecture better than anyone. When you feed this rich, multi-dimensional internal observability into security models, AI defense becomes inherently faster and more accurate than AI offense.

To take advantage of your deep context, it’s imperative to shift from manual, human-scale incident response to machine-speed security operations. We can no longer rely on human analysts manually triaging endless backlogs of static alerts. 

By codifying our frontline threat intelligence directly into these AI models, these autonomous agents can continuously monitor for, investigate, prioritize, and remediate attacks.

How Google is helping defend the ecosystem 

As adversaries adopt AI, we have a unique opportunity to disrupt them at the source. As a major security and AI provider, we take this responsibility seriously, using multiple levers to stay ahead.

  • Disabling malicious infrastructure. If you use Google tools to facilitate an attack, you lose access to those tools. We proactively disable the projects, accounts, and assets of known bad actors.

  • Hardening our AI models and classifiers. We operate a continuous feedback loop for our AI models. By feeding threat intelligence directly back into product development, our models learn to recognize and refuse malicious requests before an attack can even be generated.

  • Automating vulnerability hunting and patching also disrupt adversaries. We are moving from manual patching to AI-driven hunting. Tools like CodeMender automatically fix critical vulnerabilities in the code itself.

  • Developing advanced defenses and threat models. Our teams at Google DeepMind are building specialized defenses for generative AI — deploying active monitoring across our entire ecosystem to identify misuse in real-time.

Securing the AI era can’t be achieved with the disconnected, manual tools of the past, and you can only defend against an AI-powered threat with an AI-powered defense. To tip the scales back in favor of defenders, we must transition to a continuous, machine-speed model of protection — and at Google, we are committed to building that secure future alongside you.

To learn more about our approach to securing the AI era, please check out our new Mandiant AI Risk and Resilience report.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8642ed0>), ('btn_text', 'Watch now'), ('href', 'https://x.com/googlecloud/status/2090213589558698309?s=20'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • A manufacturing blueprint for secure agentic AI: AI and agents have arrived on the factory floor. Today’s CISOs and business leaders must balance innovation with precision, physical safety, and operational resilience. Read more.
  • Proactive cyber defense for governments and enterprises: Our new Fairwind Program is a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities. Read more.
  • Getting started with the Mantis harness to find and fix bugs: Mantis is part of how Google finds and fixes vulnerabilities at machine-speed. The open-source AI harness creates a more effective repository analysis. Read more.
  • Breaking into Google's GFile for $100,000: Learn about how a vulnerability — that was not exploited and has now been patched — could have allowed attackers to chain unauthenticated, undocumented internal APIs with overly-permissive shared file libraries to achieve unrestricted data access across core infrastructure. Read more.
  • Introducing new session management tools with native, granular controls: New Google Cloud session controls are deeply integrated and a granular feature of Context-Aware Access. Here’s what you need to know. Read more.
  • How Blackline prevents data exfiltration with VPC Service Controls: We’re excited to share new policy intelligence capabilities in VPC-SC that help drive operational simplicity: Violation analyzer and violation dashboard. Read more.
  • Introducing Continuous Vulnerability Assessment: You can detect exposure to new vulnerabilities the moment they’re published with Wiz CVA. Read more.
  • How developers prevent production risk at the source: Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your software pipeline. Read more.
  • Wiz achieves GovRAMP High authorization: Delivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8640610>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • AI Threat Tracker: From prompting to autonomy: In the newest Google Threat Intelligence Group (GTIG) report on the adversarial misuse of AI, we’ve observed adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation, including threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. Read more.
  • Financially-motivated threat actor BREEZE COMET targets Brazil: Learn about BREEZE COMET’s tactics and toolkit, and our mitigation recommendations and detections to support organizations in defending against this active and developing threat. Read more.
  • JFrog Artifactory under attack: Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory. Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.
  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Nir Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Cloud CISO Perspectives: Tips on securing the water sector in the AI era

Welcome to the second Cloud CISO Perspectives for August 2026. Today, Chris Sistrunk and Stephanie Kiel detail the critical issues facing the water sector, and actionable steps that OT operators can take to secure their infrastructure.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc310>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Tips on securing the water sector in the AI era

By Chris Sistrunk, Practice Leader, OT, Mandiant Consulting, and Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud

ChrisSistrunk

Chris Sistrunk, Practice Leader, OT, Mandiant Consulting

Google Cloud’s threat intelligence teams have observed that threat actors are becoming bolder when targeting critical infrastructure amid geopolitical conflicts. Recently, we’ve seen increased targeting of water utilities' internet-connected programmable logic controllers in the U.S.

Stephanie Kiel crop

Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud

Historically, cyber incidents haven’t usually disrupted operations, in part because water utility operators have long had manual override capabilities and established water-quality checks that kick in before water reaches consumers. Pumps and pipes fail routinely for reasons that have nothing to do with cyber threats.

However, they do require our urgent attention and a commitment to stronger security hygiene. Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era. 

We recommend a threat-informed, risk-managed response. The current state of water sector security is indicative that additional action should be strongly considered in light of the unique operational resilience that keeps these systems safe.

Actions water and wastewater utilities should consider

For resource-constrained utilities, the most effective defense is to focus on cybersecurity fundamentals. By prioritizing these fundamental practices, you can significantly harden your systems and transform your organization into a far more challenging and resilient target, causing even well-resourced threat actors to look elsewhere. 

  • Inventory assets and assess exposure: Identify if your control systems are insecurely exposed to the internet, which often allows for the successful exploitation of vulnerabilities.

  • Basic security hygiene: Replace default credentials with strong passwords, and rigorously harden exposed access points, including firewalls.

  • Backups: Make sure that critical systems, including control systems, are safeguarded following the proven 3-2-1 backup rule (keep three copies of your data on two types of storage, with at least one copy stored off-site). Ensure critical spare equipment is on-hand to minimize downtime from cyberattacks.

  • Segmentation: Use network segmentation and multifactor authentication to ensure that remote access, when necessary, is strictly controlled. You should use read-only access where full control isn't required.

  • Emergency planning: Integrate cyber-incident planning into your existing all-hazards incident command system, including FEMA NIMS and Incident Command System for Industrial Control Systems, the same response structures you already use for physical pipe breaks, boil water alerts, and natural disasters.

  • Secure third-party and vendor access: As many water utilities do not manage their own IT or OT and rely on third-party system integrators, you should audit the remote connections used by the system integrators and maintenance contractors. You should ensure third-party vendors are held to rigorous access controls (such as MFA standards) and logging requirements.

These recommendations echo guidance from the American Water Works Association, the National Rural Water Association, the Water-ISAC, the Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI.

Recommendations for IT and OT leaders: Bridging the governance gap

IT and OT leaders must work together to build a unified governance framework and should focus on making cyber-physical systems more resilient over the long term, a collective effort that spans government agencies, private sector organizations, and individuals. The goal is to build a future where these systems are secure, adaptable, and capable of recovering quickly from disruptions.

Although PLCs almost always sit outside standard software development practices, a robust approach to the software your organization uses can significantly enhance your overall security posture, such as those outlined in NIST’s Secure Software Development Framework (SSDF). They’re also good examples of leading indicators that can help you gauge your resilience, and to help you get started we’ve published a guide to evaluate leading indicators.

Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.

As technology evolves, it is critical to modernize security, transitioning from a reactive, manual model to an AI-augmented approach that keeps human expertise central to decision-making. This approach offers an unique opportunity to be a force multiplier for lean security teams. 

To stay ahead of today’s threats, organizations must move beyond simple compliance checklists and adopt a more agile, threat-informed strategy that makes compliance a natural outcome of good security, rather than the primary goal.

The Mandiant Operational Technology (OT) Theory of 99 has become more relevant in the AI era. Although the funnel of opportunity has been significantly compressed, in intrusions that go deep enough to impact OT:

  • 99% of compromised systems will be computer workstations and servers

  • 99% of malware will be designed for computer workstations and servers

  • 99% of forensics will be performed on computer workstations and servers

  • 99% of detection opportunities will be for activity connected to computer workstations and servers

  • 99% of intrusion dwell time happens in commercial, off-the-shelf computer equipment before any Purdue level 0-1 devices are impacted

As a result, there is often a significant overlap across tactics, techniques, and procedures used by threat actors who target IT and OT networks. However, the Theory of 99 underscores a significant defender's advantage in the AI era. By using advanced AI capabilities to secure the 99% of intermediary infrastructure, organizations can proactively neutralize threats and ensure robust protection for the critical 1% of physical operational processes.

AI for cyber defense

As we have shared before, AI capabilities offer the opportunity to shift the balance in network security in the favor of defenders. The defender’s advantage becomes even more important as malicious actors increasingly use AI capabilities across the attack lifecycle. 

In the current threat environment, automating defenses can serve as a force multiplier for human security teams, enhancing decision-making and productivity to ensure critical exposures are addressed before they can be exploited. With careful planning, critical infrastructure providers can protect their physical assets while building a more resilient, threat-informed defense.

To effectively realize AI advantages for defense, you should integrate AI tools into systems in a structured, intentional way. It’s crucial that operators understand the unique vulnerabilities that AI introduces to physical processes, evaluate specific business uses that can benefit from security automation, and establish clear frameworks to continuously test and monitor. As part of our approach, we’ve developed the Secure AI Framework to help you achieve secure integration and deployment of AI capabilities, regardless of sector. 

Most importantly, human oversight must remain central — meaning that AI should support decision-making, and safety practices need to be embedded directly into incident response plans. 

What’s next for water security

Protecting water systems from malicious cyber threats is not just a technical challenge; it is a fundamental public safety imperative. Given that access to clean, reliable water is an essential service, we anticipate that federal, state, and local governments will increasingly shift from policy debate to decisive action to ensure the continuity of this critical public infrastructure in the face of cyber threats. 

For example, the Office of the National Cyber Director in partnership with the State of Texas has just launched a pilot program to help protect water infrastructure providers from cyberattacks, and U.S. senators have already introduced a new bill in response to recent events.

Google is committed to helping you protect your cloud and hybrid cloud OT environments. To learn more about Google guidance on securing critical infrastructure, please visit our CISO Insights Hub.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc370>), ('btn_text', 'Watch now'), ('href', 'https://x.com/googlecloud/status/2090213589558698309?s=20'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Empowering autonomous agents with advanced security governance: To be useful and secure, AI agents need access — and also guardrails. In our new State of AI infrastructure report, 79% of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference. Read more.
  • The state of cloud risk 2026: Most security findings aren’t real attacker opportunities: Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise. Read more.
  • Introducing Google Cloud Fault Injection Testing in preview: When databases fail and network paths falter, you still need your mission-critical cloud services to stay online. Fault Injection Testing (FIT) can help you automate failure testing to ensure predictable behavior during disruptions. Read more.
  • How Wiz built AI-powered data discovery: Inside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine. Read more.
  • Democratizing FinOps with Wiz: How the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value. Read more.
  • Defend against agent risks with layered protections in Google Workspace Studio: Studio incorporates layered defenses to mitigate risks from threat actors and robust observability tools to help organizations adopt agents safely. Built on Google’s secure-by-design architecture, Studio combines native threat defenses with deep ecosystem visibility to secure multi-step agentic workflows. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc3d0>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Distinct clusters target individuals of interest to Russia: Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace, governments, and think tanks across Europe and in the U.S. Read more.
  • Inside 90 days of attacks on AI infrastructure: Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft. Read more.
  • Version Control DFIR: A cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps: A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services. Read more.
  • Rust supply chain attack on arrayref: Significant overlap with DPRK campaigns: Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.
  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Cloud CISO Perspectives: Sticking to security fundamentals in the AI era

Welcome to the first Cloud CISO Perspectives for August 2026. Today, Chris Betz explains why the AI era makes it more important than ever to lean into security fundamentals.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef1880>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

How to stay strong with security fundamentals in the AI era

By Chris Betz, CISO, Google Cloud

Chris Betz Google-9779

Chris Betz, CISO, Google Cloud

As AI accelerates the capabilities of adversaries, foundational strength becomes the primary differentiator between resilience and vulnerability. It’s a dangerous and unfortunately common misconception that traditional security fundamentals are becoming obsolete. For CISOs, the challenge is to adopt new AI technology securely while scaling essential, effective defensive practices to move at the speed of the adversary.

For both attackers and defenders, AI has been a catalyst for optimization and innovation. While traditional automation has allowed us to perform repetitive tasks at scale, AI enables both sides to execute highly-specific, customized actions at massive scale and unprecedented speed.

Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

We can see the threat developing almost in real-time. Adversaries are deploying new malware with just-in-time AI that dynamically generates malicious scripts and obfuscates code mid-execution to evade detection. They use sophisticated vishing and deepfakes for identity theft and business email compromise. We even see unauthorized AI tools lead to the rise of shadow agents. 

Defending against AI powered security threats requires more than accelerating current security practices; it means stepping back and beginning with the security foundation and layered defenses. It’s critically important to build and use a layered defense with the right guardrails — foundational cybersecurity building blocks that we’ve been investing in for years.

Doubling down on this foundation: technologies like multi-factor authentication (MFA), Zero Trust frameworks, consistent system patching, and comprehensive detection and response. Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

Revolutionizing vulnerability management

In just a few short years, identifying and fixing vulnerabilities has evolved from a mostly laborious, manual process to one driven by AI tools discovering vulnerabilities at volumes never seen before. Further, the time to exploit window has essentially been eliminated.

However, it’s not enough to merely discover vulnerabilities, especially at today’s volumes. You still need to prioritize fixing those that have the most critical impact on your systems and networks first, and that necessitates an equally-rapid response in smart mitigation. 

Organizations use multiple models to scan for flaws and then suggest high-quality code fixes that engineers can quickly move into production, leveraging capabilities like AI Threat Defense. AI allows us to automate the entire software development lifecycle, from discovery to testing and deployment, ensuring that our defensive posture evolves faster than the threats targeting us.

Enhancing threat modeling

We’re also seeing the fundamental concept of threat modeling have an outsized impact. Doing threat modeling well requires bringing context together from your code, your cloud architecture, system design, and network pathways. 

While it isn’t easy, using AI can scale our ability to bring that data together into a coherent picture. Teams have been experimenting with multi-AI models to collect system information and enumerate threats. 

As I noted in June, engineering teams at Google Cloud now route product launches through an agent-based security review pipeline. High-risk indicators automatically get flagged for human review, while we’ve replaced static threat models with dynamic product dossiers that update in real-time.

The CISO as a strategic business leader

The most effective security leaders that I know today are more than just technologists: They are strategic business leaders. The intense global focus on AI vulnerabilities has brought cybersecurity to the forefront of boardroom and executive attention like never before.

This visibility is an opportunity to lead. We CISOs are expected to communicate with clarity, from the board to the C-suite to the security teams who look to them on a daily basis, demonstrating their ability as capable strategists who can navigate the complexities of AI while safeguarding the organization's growth. 

By aligning security fundamentals with business objectives and using AI to enhance defense, we can lead our organizations securely into the future.

To learn more about building and maintaining strong security foundations in the AI era, read our newest Defender’s Advantage: Cyber Snapshot Report.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef18e0>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Driving AI threat readiness with Wiz: Announcing new Wiz capabilities that can help organizations prepare for the AI era by expanding visibility and accelerating response, so your security teams can defend at machine speed. Read more.
  • PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap: We’ve long been actively working on and rolling out post-quantum cryptography in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029. Read more.
  • How Google Cloud detects, contains, and protects against emerging threats: Learn more about how Google Cloud empowers you with the tools, governance, and infrastructure you need to securely deploy workloads and maintain long-term trust. Read more.
  • Privacy-first medical AI with MedPerf and Google Cloud: Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation. Read more.
  • More cryptanalysis makes us all safer: Recent advances in frontier AI models do not signal the downfall of cryptography. Here’s why they’re best viewed as additional cryptanalysts. Read more.
  • How layered defenses harden Chrome against abusive notifications: Learn how Chrome Security has collaborated with Firebase Cloud Messaging (FCM) and Safe Browsing to significantly reduce notification abuse, and improve the security and quality of the web ecosystem for everyone. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef1940>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Staying ahead of adversarial AI through agentic source code review: To help defenders implement agentic approaches similar to our approach at Google Cloud, we are sharing the details of our Agentic Vulnerability Discovery Harness architecture for the first time. AVDH can also be used alongside CodeMender’s ongoing scanning to create a two-layered defense strategy. Read more.
  • Cloud threat highlights from the first half of 2026: In the first half of 2026, Wiz's Research and CIRT teams tracked threats affecting thousands of cloud environments. We saw a notable increase in the volume of activity, with supply-chain attacks running at a previously unseen scale and developer toolchains and AI infrastructure drawing serious attention. Read more.
  • Batten down your packages: Mitigation guidance for supply chain compromise: GTIG and Mandiant have tracked ongoing and increasing open source software supply chain compromise campaigns over the past several years. Here are our mitigation and hardening recommendations to secure software supply chains, including insights we have developed as a result of supporting customers. Read more.
  • Multi-brand vishing extortion targets financial services and enterprise cloud environments: Telemetry and infrastructure analysis reveal that UNC6671 has not disbanded. Instead, the threat group has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon and continues to rely on voice phishing to target enterprise employees. Read more.
  • Keyv and cacheable npm package hijacked in supply chain attack: Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. Read more.
  • Inside the Metabase SQLi: Exploited in the wild: Wiz has reverse engineered Metabase CVE-2026-72898 with AI to accelerate defense. Here’s what we learned. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline

Welcome to the second Cloud CISO Perspectives for July 2026. Today, Chris Betz, CISO, Google Cloud, and Alicja Cade, Senior Director, Office of the CISO, Google Cloud, explain what boards of directors need to know about AI security and how to prepare their organizations for security governance and business agility in the AI era.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699190>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Why AI Threat Defense is the new boardroom baseline

By Chris Betz, CISO, and Alicja Cade, Senior Director, Office of the CISO, Google Cloud

Chris Betz Google-9779

Chris Betz, CISO, Google Cloud

Modern security governance has become a critical part of the foundation for business agility. Often treated as an operational cost center, security is increasingly recognized as a primary business enabler, a runway that empowers your organization to move fast, adopt cutting-edge generative AI, and capture new markets securely.

In today’s environment, every major business initiative is an AI initiative, and every AI initiative requires a secure foundation. Ensuring your company is investing in the right technologies and using the right tools will be crucial in leading through the rapid AI transformation.

Alicja Cade headshot 2

Alicja Cade, Senior Director, Office of the CISO, Google Cloud

To operate against AI speed threats, boards of directors should encourage their CISOs and business leaders to transform their strategic approach for speed, scope, and scale. We need to emphasize risk and vulnerability management with a defensive strategy that’s AI native, agentic, and open.

By aligning defensive speeds with automated attack cycles, using deep internal business context, and integrating tools into unified platforms, AI-powered defense can help you confidently manage today’s threats at machine speed, and simultaneously greenlight aggressive innovation. Based on our learnings defending ourselves and our customers, Google developed AI Threat Defense (AITD) to help transition security from manual, reactive firefighting to an automated, continuous capability.

While directors don’t need to manage the execution of these technologies, they have to provide the governance frameworks that encourage operational modernization. To help guide your organization’s leadership team in this transition, we recommend focusing on these five strategic, constructive areas of inquiry.

For boards of directors, investing in these capabilities helps build the resilience required to drive business velocity.

Key questions for CISOs, business, and tech leadership

While directors don’t need to manage the execution of these technologies, they have to provide the governance frameworks that encourage operational modernization. To help guide your organization’s leadership team in this transition, we recommend focusing on these five strategic, constructive areas of inquiry.

1. Business enablement: When an enterprise transitions to automated threat defense, it is not just closing a security gap — it’s reclaiming engineering productivity and protecting operational continuity.

  • Ask your team: How will modernization investments speed up our business to deliver value to our customers? What additional resources do we need (if any) to create this business value more quickly, and create a competitive advantage? 

  • Governance objective: Ensure that any decisions about investments align with business strategy. Speed up time to market on new features. Create competitive agility advantage for security and shareholders.  

  • Expected operational standard: Consolidate business process, speed up execution and time to market.

2. Remediation cycle: By integrating business logic and context into defensive platforms, AI can help filter out the background noise that has historically overwhelmed security operations, and also keep you on top of the complex threat landscape.

  • Ask your team: How are we managing the organization’s risk in the era of fighting AI with AI? 

  • Governance objective: Expect a management plan with CISO input for balancing business operations, risk, and profitability with speed and reliability in an AI threat-driven world.

  • Expected operational standard: Your organizational mean time to remediate (MTTR) exposures and other desired changes into production goes down and to the right.

3. System consolidation: Boards should look beyond standalone AI features and point products to address systemic risk and truly enable business speed.

  • Ask your team: Are we moving toward a unified security platform, or maintaining a patchwork of point tools? 

  • Governance objective: Reduce visibility gaps and operational friction created by fragmented vendor environments.

  • Expected operational standard: Consolidate scanning, risk prioritization, and code remediation into an integrated workflow.

4. Contextual prioritization: Your organization knows exactly how applications are interconnected, where critical data assets reside, who has access privileges, and which workflows drive actual business logic. That deep context becomes the defender’s advantage when you are using AI powered defenses, including those in AI Threat Defense.

  • Ask your team: How are we using our deep business context to reduce security alert fatigue? 

  • Governance objective: Optimize engineering resources by ensuring teams are not consumed by false-positive alerts.

  • Expected operational standard: Direct AI systems to prioritize vulnerabilities based on actual reachability and business context.

5. AI safety and policy: Every AI conversation is a security conversation. Securing AI infrastructure starts with directing teams toward approved architectures with proper governance.

  • Ask your team: What frameworks do we have in place to secure our internal AI pipelines and monitor shadow AI? 

  • Governance objective: Protect intellectual property and maintain compliance as the enterprise adopts generative tools.

  • Expected operational standard: Implement clear runtime visibility, data egress controls, and secure development standards for AI.

Innovate with confidence

In a highly automated digital environment, passive oversight is no longer practical. Your teams should be looking at how they are using AI to accelerate security and respond to AI-driven threats at AI speed.

By steering the enterprise toward a platform-centered, context-driven security posture, boards can support long-term business resilience, protect asset value, and give the organization the confidence to innovate, scale, and lead in its next phase of growth safely.  Consider technologies like AI Threat Defense as part of your defenses in this new world.

For more insight, check out our Board of Directors hub here.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699220>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Now in preview: Find and fix software vulnerabilities with CodeMender: Our AI code security agent CodeMender can scan and fix software vulnerabilities, and is now available in preview through Agent Platform and AI Threat Defense. Read more.
  • Cyber Snapshot Report: Enterprise resilience key to toolchain success: Check out curated frontline insights and blueprints to turn potential crises into manageable events in the newest Cyber Snapshot Report. Read more.
  • Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS: TWe are extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA. Here’s why. Read more.
  • Atlas, Wiz's autonomous vulnerability-research agent, has been ranked #1 on CyberGym: See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit. Read more.
  • Best Buy scales AI workloads and secures access with Workforce Identity Federation: As Best Buy expanded its use of Google Cloud for advanced analytics and AI, its technology teams faced two significant scaling challenges: Mitigating risk and managing administrative friction when syncing thousands of backend users from Microsoft Entra ID. Here’s how Workforce Identity Federation helped them solve both problems. Read more.
  • The risk hiding behind exposed MCP servers: Learn how unauthenticated model context protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution. Read more.
  • Agentless threat detection: Illuminating cloud blind spots: Learn how Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks. Read more.
  • AlloyDB adds group authentication to secure enterprise scale and AI agents: We’re bringing identity-driven access control to your enterprise workloads through IAM group authentication for AlloyDB, now available in preview. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699040>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Updated cyber threat actor naming system: Google Threat Intelligence Group (GTIG) has begun rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Read more.
  • Demystifying AI exploits: A blueprint for AI-assisted vulnerability management: Concerned about how to safely integrate AI capabilities into vulnerability management workflows? Here’s actionable guidance from Mandiant Consulting on establishing operational guardrails for AI assisted vulnerability management, including detailed scenarios. Read more.
  • GhostApproval: A trust boundary gap in AI coding assistants: Learn how Wiz uncovered a category-level blind spot in modern AI coding assistants, and why the human-in-the-loop safety model fails against this classic threat. Read more.
  • The risk of exposed cloud functions and how to harden: Mandiant uses recent lessons from customer engagements to describe attack scenarios and provide actionable guidance on how to secure serverless environments. While this analysis focuses on hardening strategies for Google Cloud Run services and functions that must remain publicly accessible, these principles apply universally to any public serverless deployment. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: CISO tested, board approved: Noah Korba, vice-president, Digital Core, Cybersecurity, and Enterprise Architecture, General Mills, goes under the hood of Mills Collaborative Recovery, the company’s intensive, annual two-week drill that recovers 90% of their Google Cloud estate to test real-world cyber resilience. Listen here.
  • Cloud Security Podcast: Creating trust at global scale with local AI: Shuman Ghosemajumder, CEO, Reken, traces the evolution of automated fraud, from Gmail's early invite days to the origin of credential stuffing. Listen here.
  • Defender’s Advantage: Shadow LLMs, agentic identities, and securely integrating AI: Join Muhammad Muneer, technical manager, Incident Response, Mandiant, as he unpacks the stark realities of enterprise AI adoption. Listen here.
  • Behind the Binary: The challenges of reversing modern languages: Jae Young Kim from the Mandiant FLARE team discusses navigating how software has evolved, and what it actually takes to reverse engineer modern compiled languages like Go and Rust. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Cloud CISO Perspectives: How AI leverages deep context as the defender’s advantage

Welcome to the first Cloud CISO Perspectives for July 2026. Today, Francis deSouza, COO, Google Cloud and President, Security Products, explains the crucial role that deep context plays in creating an AI advantage for defenders.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7fb3607ecca0>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

How AI leverages deep context as the defender’s advantage

By Francis deSouza, COO, Google Cloud and President, Security Products

Francis DeSouza 2026

Francis deSouza, COO, Google Cloud and President, Security Products

Attackers are making headlines with AI, but defenders have a distinct and powerful advantage.

AI is rapidly transforming the cyberthreat landscape, driving unprecedented shifts in the scale, speed, and sophistication of attacks. Just recently, Google Threat Intelligence Group documented a critical milestone: the first known case of a zero-day exploit built entirely with AI. While we successfully disrupted their plans and got the vulnerability patched before launch, it highlights exactly what we are up against.

With AI agents, attacks are accelerating at machine speed. The handoff time between the first and second stage of an attack used to be eight hours; today, it takes just 22 seconds.

There’s an old saying in cybersecurity that adversaries only have to be right once, but defenders have to be right every time. That is the attacker’s advantage.

But AI is rewriting those rules, delivering a decisive defender's advantage built on deep context.

The AI Era: Attacker’s Profile vs. Defender’s Advantage

Aspect

Attacker's Profile

Defender's Advantage

Visibility

Limited to outside-in probing; little enterprise context upon entry.

Complete inside-out context; knows exact asset locations, application behavior, and team ownership.

Operational Speed

Executes multi-agent handoffs in 22 seconds.

Machine-speed defense; proactive mitigation in seconds (such as Morgan Stanley's 90-second resolution.)

Core Tactics

Multi-model phishing, deepfakes, AI-built zero-days, and model poisoning. 

Closed-loop defense; continuous exposure mapping and accelerated code patching.

The unified blueprint: Google AI Threat Defense

Previously, enterprise context data was fragmented across disconnected security tools. Now, AI empowers defenders to synthesize this rich data into a unified, always-on, autonomous defense.

We built Google AI Threat Defense to combine Google’s security capabilities into a single platform: the advanced reasoning of Gemini, the contextual cloud power of Wiz, the code-level remediation capabilities of CodeMender, and the frontline intelligence of Mandiant.

Our platform transforms vulnerability management across a continuous four-step framework:

Stage

Technology & Actions

Strategic Value to the Enterprise

1. Prepare 

Map exposed applications, APIs, identities, and runtime environments using Wiz. Simulate attack paths with the Wiz Red Agent.

Hardens the foundation to reduce internet reachability before vulnerabilities hit production.

2. Scan & Prioritize 

Run multi-model scanning — using lighter models for broad coverage and Gemini frontier models for deep-dive analysis of high-risk assets.

Replaces massive alert lists with deep, context-driven risk validation, including an optimal cost per token.

3. Remediate 

Deploy CodeMender inside developer IDEs/CLIs to auto-generate verified code fixes.

Replaces slow, manual patching with autonomous code-level remediation and memory-safe migrations.

4. Monitor 

Deploy AI agents tied to Wiz to hunt for vulnerabilities and anomalies across network, identity, and application telemetry.

Pair with Google Security Operations to rapidly hunt for unknown threats.

Establishes machine-speed runtime detection for zero-day response and threats against unpatchable environments. 

To stop vulnerabilities before they hit production, Morgan Stanley partnered with Google Cloud and Wiz, aligning their strategy with the core principles of the AI Threat Defense framework: prepare, scan, remediate, and monitor. By replacing fragmented tools with this unified blueprint, Morgan Stanley collapsed its mean time to detect threats by 99.9%, shifting from a reactive 45-minute window to proactive mitigation in 90 seconds or less.

Google Cloud x Morgan Stanley: Redefining Threat Defense in the AI Era

Google Cloud x Morgan Stanley: Redefining Threat Defense in the AI Era

Maintaining strategic human oversight

While human-speed execution cannot keep pace with automated threats, human management remains essential. We align autonomous AI agents directly with the human teams they support. In Wiz, for example, the Red agent automates penetration testing, the Blue agent drives threat investigations, and the Green agent accelerates cloud remediation.

Every AI conversation is a security conversation. That means securing AI infrastructure requires building from the ground up, and not bolting on.

This ensures autonomy under human supervision, empowering engineering and security teams to eliminate backlogs and secure the software development lifecycle without sacrificing speed.

What’s next: AI-native, agent-driven infrastructure

The foundation of your defender's advantage starts with protecting your environments — not just from outside threats, but from internal risks like shadow AI and unauthorized agents. When employees download models and deploy agents outside of IT oversight, they create silent logic breaches and data-poisoning risks.

The key to countering this is enforcing Zero Trust for AI, and directing teams toward approved architectures with proper governance. Every AI conversation is a security conversation. That means securing AI infrastructure requires building from the ground up, and not bolting on.

At Google, security is not just an added layer; it is our foundation. Our secure-by-default architecture automatically blocks nearly 15 billion unwanted emails and protects billions of users every day.

As the threat landscape matures, outperforming automated adversaries requires a platform built from the ground up to be AI-native and agent-driven.

Fight AI with AI. Learn more about how to secure your software lifecycle with Google AI Threat Defense.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7fb3607ecd30>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • FinOps for SecOps: How to optimize the agentic SOC for value: To be more resilient in AI adoption, CISOs should develop a disciplined "FinOps for SecOps" blueprint that maximizes threat disruption while keeping control over compute costs. Here's how. Read more.
  • New IDC study: How Mandiant transforms security into a competitive advantage: A new IDC Business Value White Paper found that you save an average of $4.3 million, driving a 268% three-year ROI, with Mandiant Consulting. Read more.
  • Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM: To help you match your real-world exposures with real-time adversary activity, we’ve begun integrating Google Threat Intelligence with Wiz Attack Surface Management. Read more.
  • Shift into high gear with agents: Securing the software-defined vehicle: To better support and secure SDVs, Google Cloud and Valtech have partnered to develop Nexus SDV, a highly-scalable, AI-enabled connected vehicle platform. Read more.
  • Meet the 33 cybersecurity startups joining the Gemini Startup Forum: Our flagship Google for Startups program, Gemini Startup Forum: Cybersecurity, has selected its first 33 trailblazing startups. Read more.
  • Introducing k8s-aibom on GKE for automated AI bills of materials: We’re open-sourcing k8s-aibom, a Kubernetes controller that continuously monitors environments to detect AI runtimes and generate standard ML-BOMs. Read more.
  • BGP route policies: Top 3 use cases by customer demand: We detail the three most impactful use cases for Cloud Router BGP route policies that have emerged since 2025. Read more.
  • Contributing to U.K. financial sector resilience as a critical third party: The U.K. Treasury has designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the CTP regime. Here’s how that helps you. Read more.
  • Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval: We understand that for the EU public sector, data protection is a prerequisite. We’re excited to reinforce this commitment with a major milestone. Read more.
  • Why IaC coverage belongs on your security dashboard: Rethinking infrastructure-as-code coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed. Read more.
  • Inside the ProdSec playbook: Operationalizing Wiz for end-to-end cloud security: Rethinking infrastructure-as-code coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed. Read more.
  • Build AI security agents with Wiz MCP: Power AI-driven security with trusted security context, Wiz AI Agents, and Wiz AI Skills. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7fb3607ecc40>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • A look at the drivers, dynamics, and applications of the pro-Russia influence ecosystem: Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. The interconnected nature of the ecosystem's disparate components makes it resilient to limited scope disruptions, a factor that defenders need to consider to mitigate pro-Russia influence threats. Read more.
  • Google’s continued disruption of malicious residential proxy networks: In coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Read more.
  • GhostApproval: A trust boundary gap in AI coding assistants: Learn how Wiz uncovered a category-level blind spot in modern AI coding assistants, and why the human-in-the-loop safety model fails against this classic threat. Read more.
  • The latest addition to Turla’s intelligence gathering apparatus: Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla, one of the oldest known cyber espionage groups, since at least December 2022. As part of our continued tracking of this group, we’re providing an overview of our STOCKSTAY analysis, a timeline of key developmental and operational observations, and detailed similarities to KAZUAR to contextualize this new capability in Turla’s arsenal. Read more.
  • Recovering active ADFS signing keys via Machine DPAPI: During a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. Here’s how to defend against it. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Building an AI-pilled, solo vibe-coded, Clickhouse-based SIEM: Dan Lussier, founder, Nano, unpacks how he vibe-coded an entire SIEM from scratch during his end-of-year holiday break. Listen here.
  • Cloud Security Podcast: Scaling lessons, from leading the NSA to defending the world: Morgan Adamski discusses how public-private partnerships and the shift to cloud infrastructure have transformed cybersecurity defense through improved intelligence sharing and collective trust. Listen here.
  • Cloud Security Podcast: Closest alligator to the canoe: How transforming the SOC became P0 for Lloyds Bank: Matt Row, chief security officer, Lloyds Bank, explains the bank's digital transformation strategy, highlighting how it modernized its security operations center to achieve a 20x reduction in human-reviewed alerts. Listen here.
  • Defender’s Advantage: Human-machine teaming and applying AI to frontline threat intelligence workflows: Jake Nicastro, AI lead, Frontline Intelligence Operations, GTIG, details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of human-machine teaming. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •