Advertisement
Google Cloud Post-Quantum Roadmap Targets 2029 Readiness
Google Cloud updates its roadmap for post-quantum cryptography (PQC) migration, aiming for full infrastructure readiness by 2029, addressing future quantum threats.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Google Cloud Agentic Defense: Automating AI-Driven Security Response
Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.
Exposed Cloud Functions: Hardening GCP Serverless Against LFI & RCE
Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.
Google Vertex AI SDK Model Hijacking via Bucket Squatting
A Google Cloud Vertex AI SDK vulnerability allows attackers to hijack model uploads and achieve RCE through bucket squatting and malicious Pickle files.
Google Vertex AI Security: Mitigating AI Agent Weaponization
Google patches security flaws in Vertex AI after Unit 42 researchers demonstrated how to weaponize AI agents for unauthorized data access and exfiltration.
Advertisement
Vertex AI Permission Flaw Exposes Google Cloud Data — Mitigation Guide
Researchers uncover a security blind spot in Google Cloud Vertex AI, allowing attackers to weaponize AI agents for unauthorized data access and compromise.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.
Google Cloud Attacks: Exploitation Outpaces Patching Cycles
Vulnerability exploitation, not stolen credentials, is the primary initial compromise vector for Google Cloud environments, often bypassing patching efforts.
Wiz Joins Google Cloud: Strategic Implications for Cloud Security
Analyzes Google Cloud's landmark acquisition of Wiz, exploring the strategic impacts on cloud security posture, multi-cloud defense, and compliance for enterprises.
Google Cloud Security: Exploits Surpass Weak Credentials
Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.
Insecure Google API Keys Expose Gemini AI and Private Data
Exposed Google API keys, once considered low-risk for services like Maps, now allow unauthorized access to Gemini AI models and sensitive project data.