Google Cloud Threat Intelligence warns that adversaries are weaponizing AI agent workflows to automate attacks, including credential harvesting and supply-chain compromises, reducing defender response time.
Google’s threat intelligence unit reports three suspected Russian cyber espionage clusters targeting academics, defense officials, and diplomats across the U.S. and Europe via phishing and OAuth abuse, including new...
Google Cloud Threat Intelligence introduces the Agentic Vulnerability Discovery Harness (AVDH) to automate and enhance source code security analysis, combining AI agents with human expertise to identify vulnerabilities...
A threat group tracked as UNC6671 has rebranded from BlackFile to multiple extortion brands while continuing vishing attacks on financial and enterprise cloud targets, using AiTM phishing and MFA token theft to steal...
Google Cloud Threat Intelligence warns of a surge in open-source supply chain attacks, urging organizations to adopt multi-layered defenses amid rising threat actor activity in 2025–2026.
Google’s Threat Intelligence Group introduced a unified naming system for cyber threat actors, replacing fragmented historical labels with a standardized cryptonym format to improve clarity and operational efficiency...
Google Cloud Threat Intelligence outlines a framework for safely integrating AI agents into vulnerability management to counter rapidly exploited flaws, emphasizing structured controls, isolation, and human oversight.
Google Cloud Threat Intelligence warns that publicly exposed serverless functions without authentication pose significant cloud security risks, urging hardening measures to prevent full environment compromise.
Researchers found that misconfigured ADFS certificate rotations can expose active signing keys via Machine DPAPI, enabling adversaries to forge SAML tokens and bypass MFA in Microsoft environments.
Google, with the FBI and Lumen, disrupted the NetNut residential proxy network, disabling associated Google accounts and services used for malware command and control. The action follows a January 2026 disruption of the...
A Google Cloud Threat Intelligence report details the expansion and strategic reorientation of Russia’s pro-influence ecosystem, now leveraging generative AI and targeting global audiences beyond Ukraine.
Google’s threat intelligence team has detailed STOCKSTAY, a new .NET backdoor attributed to the Russian cyber espionage group Turla, active since late 2022 and targeting Ukrainian government and military entities as...