Google integrated computer use into Gemini 3.5 Flash so agents can act across browser, mobile, and desktop environments. Optional enterprise safeguards can require confirmation for sensitive actions or stop a task when indirect prompt injection is detected.
garak release with new generators, probe metadata, and evaluation workflow improvements. Relevant to maintaining repeatable LLM security testing coverage.
AI models can now find high-severity vulnerabilities at scale. This is a moment to empower defenders. We're now using Claude to find and help fix vulnerabilities in open source software.
We’ve long been actively working on and rolling out PQC in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029.
Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation.
We are extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA. Here’s why.
Check out curated frontline insights and blueprints to turn potential crises into manageable events in the newest Cyber Snapshot Report.
Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.
Krebs reports that Microsoft’s July update fixed 570 flaws, including three exploited zero-days, as AI-assisted discovery accelerates patch volume. The release also addressed a high-severity Copilot flaw triggered through crafted prompts from a malicious webpage.
The U.K. Treasury has designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the CTP regime. Here’s how that helps you.
Our flagship Google for Startups program, Gemini Startup Forum: Cybersecurity, has selected its first 33 trailblazing startups.
Vendor guidance on operationalizing AI-enabled detection and response. Useful as an implementation signal for monitoring, containment, and response workflows around AI-influenced threats.
Anthropic and Verizon mapping of AI-enabled cyber activity to MITRE ATT&CK. Relevant to threat modeling, red-team scenario design, and structured reporting of AI-enabled operations.
OpenAI's opt-in Advanced Account Security applies to ChatGPT and Codex. It replaces password login with passkeys or FIDO security keys, disables email and SMS recovery, shortens sessions, adds login alerts and session management, and automatically excludes conversations from model training. The stronger recovery model also means support cannot restore access for an enrolled user.
Play video
This AI Explained video reviews a major AI development through the lens of benchmarks and evaluation evidence. It is useful context for AI engineering, evaluation, governance, and operational risk.
Play video
This AI Explained video reviews a major AI development through the lens of agentic workflows and tool-use risk. It is useful context for AI engineering, evaluation, governance, and operational risk.
Play video
This AI Explained video reviews a major AI development through the lens of governance and responsible deployment. It is useful context for AI engineering, evaluation, governance, and operational risk.
OECD Due Diligence Guidance for Responsible AI helps businesses manage AI risks, meet global standards and build trustworthy AI value chains.
Play video
This AI Explained video reviews a major AI development through the lens of governance and responsible deployment. It is useful context for AI engineering, evaluation, governance, and operational risk.
Play video
This AI Explained video reviews a major AI development through the lens of agentic workflows and tool-use risk. It is useful context for AI engineering, evaluation, governance, and operational risk.
Play video
This AI Explained video reviews a major AI development through the lens of agentic workflows and tool-use risk. It is useful context for AI engineering, evaluation, governance, and operational risk.
Håkon Måløy demonstrates a cross-domain prompt-injection chain in Microsoft 365 Copilot for Word: hidden instructions in an external document alter a generated report and copy themselves into the output, which becomes a trusted carrier in later drafting sessions. Microsoft confirmed the behavior and deployed payload-specific mitigations, but Måløy reproduced the attack class after 144 days of coordinated disclosure; each hop still requires another Copilot drafting or editing operation.
OpenAI’s Enterprise and Edu release notes describe Codex updates including goal mode, browser improvements, locked computer use, app-window context, admin analytics, and plugin sharing status.
Explore how the EU is deploying trustworthy AI in healthcare, manufacturing, mobility and agriculture to boost competitiveness.