<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Google Cloud</title><description>Cybersecurity articles tagged #Google Cloud on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Google Cloud Post-Quantum Roadmap Targets 2029 Readiness</title><link>https://runtimerebel.com/blog/google-cloud-post-quantum-roadmap-targets-2029-readiness</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-post-quantum-roadmap-targets-2029-readiness</guid><description>Google Cloud updates its roadmap for post-quantum cryptography (PQC) migration, aiming for full infrastructure readiness by 2029, addressing future quantum threats.</description><pubDate>Sat, 15 Aug 2026 08:16:44 GMT</pubDate><category>Post Quantum Cryptography</category><category>Google Cloud</category><category>Quantum Computing</category><category>NIST</category><category>Cryptographic Agility</category></item><item><title>Confused Deputy Flaws in Google Cloud &amp; Azure: Admin Bypass</title><link>https://runtimerebel.com/blog/confused-deputy-flaws-in-google-cloud-azure-admin-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/confused-deputy-flaws-in-google-cloud-azure-admin-bypass</guid><description>Analysis of &apos;Confused Deputy&apos; vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.</description><pubDate>Tue, 28 Jul 2026 02:40:00 GMT</pubDate><category>Confused Deputy</category><category>Google Cloud</category><category>Microsoft Azure</category><category>Privilege Escalation</category><category>Access Control Bypass</category><category>Cloud Security Posture Management</category></item><item><title>Google Cloud Agentic Defense: Automating AI-Driven Security Response</title><link>https://runtimerebel.com/blog/google-cloud-agentic-defense-automating-ai-driven-security-response</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-agentic-defense-automating-ai-driven-security-response</guid><description>Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.</description><pubDate>Fri, 17 Jul 2026 13:54:38 GMT</pubDate><category>Google Cloud</category><category>AI Security</category><category>Wiz</category><category>Agentic Defense</category><category>Mandiant</category></item><item><title>Exposed Cloud Functions: Hardening GCP Serverless Against LFI &amp; RCE</title><link>https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</guid><description>Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.</description><pubDate>Wed, 15 Jul 2026 17:23:18 GMT</pubDate><category>Google Cloud</category><category>Cloud Run</category><category>Serverless</category><category>LFI</category><category>Command Injection</category><category>RCE</category><category>WAF</category><category>Cloud Armor</category><category>IAM</category><category>Mandiant</category><category>Cloud Security Posture Management</category></item><item><title>Google Vertex AI SDK Model Hijacking via Bucket Squatting</title><link>https://runtimerebel.com/blog/google-vertex-ai-sdk-model-hijacking-via-bucket-squatting</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-vertex-ai-sdk-model-hijacking-via-bucket-squatting</guid><description>A Google Cloud Vertex AI SDK vulnerability allows attackers to hijack model uploads and achieve RCE through bucket squatting and malicious Pickle files.</description><pubDate>Tue, 16 Jun 2026 21:06:48 GMT</pubDate><category>Google Cloud</category><category>Vertex Ai</category><category>RCE</category><category>Unit 42</category><category>Bucket Squatting</category><category>Machine Learning</category></item><item><title>Google Vertex AI Security: Mitigating AI Agent Weaponization</title><link>https://runtimerebel.com/blog/google-vertex-ai-security-mitigating-ai-agent-weaponization</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-vertex-ai-security-mitigating-ai-agent-weaponization</guid><description>Google patches security flaws in Vertex AI after Unit 42 researchers demonstrated how to weaponize AI agents for unauthorized data access and exfiltration.</description><pubDate>Wed, 01 Apr 2026 08:39:46 GMT</pubDate><category>Google Cloud</category><category>Vertex Ai</category><category>AI Agent Security</category><category>Prompt Injection</category><category>Unit 42</category></item><item><title>Vertex AI Permission Flaw Exposes Google Cloud Data — Mitigation Guide</title><link>https://runtimerebel.com/blog/vertex-ai-permission-flaw-exposes-google-cloud-data-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/vertex-ai-permission-flaw-exposes-google-cloud-data-mitigation-guide</guid><description>Researchers uncover a security blind spot in Google Cloud Vertex AI, allowing attackers to weaponize AI agents for unauthorized data access and compromise.</description><pubDate>Tue, 31 Mar 2026 16:27:34 GMT</pubDate><category>Vertex Ai</category><category>Google Cloud</category><category>Unit 42</category><category>Cloud Security</category><category>AI Security</category></item><item><title>Native Launches Multicloud Security Control Plane for Policy Enforcement</title><link>https://runtimerebel.com/blog/native-launches-multicloud-security-control-plane-for-policy-enforcement</link><guid isPermaLink="true">https://runtimerebel.com/blog/native-launches-multicloud-security-control-plane-for-policy-enforcement</guid><description>Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.</description><pubDate>Fri, 20 Mar 2026 12:19:06 GMT</pubDate><category>Native Security</category><category>Multicloud Security</category><category>AWS Security</category><category>Azure Security</category><category>Google Cloud</category><category>Oracle Cloud</category></item><item><title>Google Cloud Attacks: Exploitation Outpaces Patching Cycles</title><link>https://runtimerebel.com/blog/google-cloud-attacks-exploitation-outpaces-patching-cycles</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-attacks-exploitation-outpaces-patching-cycles</guid><description>Vulnerability exploitation, not stolen credentials, is the primary initial compromise vector for Google Cloud environments, often bypassing patching efforts.</description><pubDate>Fri, 13 Mar 2026 16:21:51 GMT</pubDate><category>Google Cloud</category><category>Vulnerability Exploitation</category><category>Cloud Security</category><category>Threat Intelligence</category><category>Patch Management</category></item><item><title>Wiz Joins Google Cloud: Strategic Implications for Cloud Security</title><link>https://runtimerebel.com/blog/wiz-joins-google-cloud-strategic-implications-for-cloud-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/wiz-joins-google-cloud-strategic-implications-for-cloud-security</guid><description>Analyzes Google Cloud&apos;s landmark acquisition of Wiz, exploring the strategic impacts on cloud security posture, multi-cloud defense, and compliance for enterprises.</description><pubDate>Wed, 11 Mar 2026 16:30:37 GMT</pubDate><category>Wiz</category><category>Google Cloud</category><category>Cloud Security</category><category>Acquisition</category><category>CSPM</category><category>CNAPP</category><category>Multi Cloud</category></item><item><title>Google Cloud Security: Exploits Surpass Weak Credentials</title><link>https://runtimerebel.com/blog/google-cloud-security-exploits-surpass-weak-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-security-exploits-surpass-weak-credentials</guid><description>Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.</description><pubDate>Tue, 10 Mar 2026 00:32:06 GMT</pubDate><category>Google Cloud</category><category>Vulnerability Exploitation</category><category>Cloud Threat Intelligence</category><category>Patch Management</category></item><item><title>Google Cloud API Keys Exposed via Public Gemini Access</title><link>https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</guid><description>Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.</description><pubDate>Sat, 28 Feb 2026 12:12:17 GMT</pubDate><category>GCP</category><category>Google Cloud</category><category>Gemini</category><category>API Security</category><category>Truffle Security</category><category>Information Disclosure</category></item><item><title>Insecure Google API Keys Expose Gemini AI and Private Data</title><link>https://runtimerebel.com/blog/insecure-google-api-keys-expose-gemini-ai-and-private-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/insecure-google-api-keys-expose-gemini-ai-and-private-data</guid><description>Exposed Google API keys, once considered low-risk for services like Maps, now allow unauthorized access to Gemini AI models and sensitive project data.</description><pubDate>Fri, 27 Feb 2026 00:35:17 GMT</pubDate><category>Google Cloud</category><category>Gemini AI</category><category>API Security</category><category>Credential Exposure</category><category>Cloudflare</category></item></channel></rss>