In a recent evaluation of AI models’ cyber capabilities, current Claude models can now succeed at multistage attacks on networks with dozens of hosts using only standard, open-source tools, instead of the custom tools needed by previous generations.
Google Cloud outlines a defense-in-depth view of AI security spanning application controls, data protections, and infrastructure isolation.
LiteLLM versions 1.82.7 and 1.82.8 were malicious PyPI releases available for about 40 minutes on March 24. A .pth file executed at Python startup and collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database secrets. CloudSEK's later dataset indicates broad exposure, but its organization and file totals are not confirmed victim counts or evidence that stolen credentials were used.
Wiz post on AI threat readiness and secure-by-default cloud operations in a faster vulnerability environment. The value for this library is the platform-security angle: AI-era systems need inventory, exposure reduction, posture management, and rapid remediation built into normal operating practice.
Play video
This AI Explained video reviews a major AI development through the lens of agentic workflows and tool-use risk. It is useful context for AI engineering, evaluation, governance, and operational risk.
Anthropic shares lessons from frontier red teaming and discusses where models are showing early-warning signs of higher-risk cyber and biology capabilities.
Play video
Conference talk on secure AI agents, focusing on how tool use, identity, and execution boundaries change when assistants can act across systems.
Google integrated computer use into Gemini 3.5 Flash so agents can act across browser, mobile, and desktop environments. Optional enterprise safeguards can require confirmation for sensitive actions or stop a task when indirect prompt injection is detected.
garak release with new generators, probe metadata, and evaluation workflow improvements. Relevant to maintaining repeatable LLM security testing coverage.
SecurityWeek reports that updated exposure analysis shifts the dominant source of the TeamPCP blast radius upstream from the malicious LiteLLM releases to the earlier Trivy supply-chain compromise. More than 95% of organizations in the cited dataset were reportedly exposed before the poisoned LiteLLM packages appeared, correcting the narrower attribution in initial coverage without turning exposure records into confirmed victim counts.
Frost & Sullivan names Microsoft a leader as cloud and application security converge into unified, runtime risk reduction.
AI models can now find high-severity vulnerabilities at scale. This is a moment to empower defenders. We're now using Claude to find and help fix vulnerabilities in open source software.
We’ve long been actively working on and rolling out PQC in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029.
Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation.
We are extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA. Here’s why.
Check out curated frontline insights and blueprints to turn potential crises into manageable events in the newest Cyber Snapshot Report.
Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.
Krebs reports that Microsoft’s July update fixed 570 flaws, including three exploited zero-days, as AI-assisted discovery accelerates patch volume. The release also addressed a high-severity Copilot flaw triggered through crafted prompts from a malicious webpage.
The U.K. Treasury has designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the CTP regime. Here’s how that helps you.
Our flagship Google for Startups program, Gemini Startup Forum: Cybersecurity, has selected its first 33 trailblazing startups.
Vendor guidance on operationalizing AI-enabled detection and response. Useful as an implementation signal for monitoring, containment, and response workflows around AI-influenced threats.
Anthropic and Verizon mapping of AI-enabled cyber activity to MITRE ATT&CK. Relevant to threat modeling, red-team scenario design, and structured reporting of AI-enabled operations.
OpenAI's opt-in Advanced Account Security applies to ChatGPT and Codex. It replaces password login with passkeys or FIDO security keys, disables email and SMS recovery, shortens sessions, adds login alerts and session management, and automatically excludes conversations from model training. The stronger recovery model also means support cannot restore access for an enrolled user.
Play video
This AI Explained video reviews a major AI development through the lens of agentic workflows and tool-use risk. It is useful context for AI engineering, evaluation, governance, and operational risk.