惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
博客园 - 司徒正美
Last Week in AI
Last Week in AI
博客园 - 聂微东
Jina AI
Jina AI
月光博客
月光博客
爱范儿
爱范儿
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
T
Tailwind CSS Blog
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
罗磊的独立博客
小众软件
小众软件
雷峰网
雷峰网
IT之家
IT之家
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

Security & Identity

Using AI agents to secure Google infrastructure | Google Cloud Blog Google named a Leader in the External Threat Intelligence Service Forrester Wave™ | Google Cloud Blog Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses | Google Cloud Blog Introducing new session management tools with native, granular controls | Google Cloud Blog Getting started with the Mantis harness to find and fix bugs | Google Cloud Blog How Blackline prevents data exfiltration with VPC Service Controls | Google Cloud Blog Cloud CISO Perspectives: Tips on securing the water sector in the AI era | Google Cloud Blog Introducing Google Cloud Fault Injection Testing (FIT) in preview | Google Cloud Blog State of AI infrastructure report agent governance and security | Google Cloud Blog Announcing quantum-safe key import in Cloud KMS | Google Cloud Blog PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap | Google Cloud Blog How Google Cloud detects, contains, and protects against emerging threats | Google Cloud Blog Privacy-first medical AI with MedPerf and Google Cloud | Google Cloud Blog Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline | Google Cloud Blog AlloyDB adds group authentication to secure enterprise scale and AI agents | Google Cloud Blog Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS | Google Cloud Blog Best Buy scales secure AI access with Workforce Identity Federation | Google Cloud Blog Cyber Snapshot Report: Enterprise resilience key to toolchain success | Google Cloud Blog Now in preview: Find and fix software vulnerabilities with CodeMender | Google Cloud Blog Cloud CISO Perspectives: How AI leverages deep context as the defender’s advantage | Google Cloud Blog Introducing k8s-aibom on GKE for automated AI bills of materials | Google Cloud Blog Contributing to U.K. financial sector resilience as a critical third party | Google Cloud Blog Meet the 33 cybersecurity startups joining the Gemini Startup Forum | Google Cloud Blog Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM | Google Cloud Blog Shift into high gear with agents: Securing the software-defined vehicle | Google Cloud Blog New IDC study: How Mandiant transforms security into a competitive advantage | Google Cloud Blog Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval | Google Cloud Blog Cloud CISO Perspectives: How Google Cloud Security uses AI internally | Google Cloud Blog Securing agentic AI: What's new in VPC Service Controls | Google Cloud Blog Verifiable trust in the AI era: What’s new in Confidential Computing | Google Cloud Blog
Cloud CISO Perspectives: Sticking to security fundamental...
Chris Betz · 2026-08-22 · via Security & Identity

Welcome to the first Cloud CISO Perspectives for August 2026. Today, Chris Betz explains why the AI era makes it more important than ever to lean into security fundamentals.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

How to stay strong with security fundamentals in the AI era

By Chris Betz, CISO, Google Cloud

https://storage.googleapis.com/gweb-cloudblog-publish/images/Chris_Betz_Google-9779.max-2200x2200.jpg

As AI accelerates the capabilities of adversaries, foundational strength becomes the primary differentiator between resilience and vulnerability. It’s a dangerous and unfortunately common misconception that traditional security fundamentals are becoming obsolete. For CISOs, the challenge is to adopt new AI technology securely while scaling essential, effective defensive practices to move at the speed of the adversary.

For both attackers and defenders, AI has been a catalyst for optimization and innovation. While traditional automation has allowed us to perform repetitive tasks at scale, AI enables both sides to execute highly-specific, customized actions at massive scale and unprecedented speed.

Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

We can see the threat developing almost in real-time. Adversaries are deploying new malware with just-in-time AI that dynamically generates malicious scripts and obfuscates code mid-execution to evade detection. They use sophisticated vishing and deepfakes for identity theft and business email compromise. We even see unauthorized AI tools lead to the rise of shadow agents. 

Defending against AI powered security threats requires more than accelerating current security practices; it means stepping back and beginning with the security foundation and layered defenses. It’s critically important to build and use a layered defense with the right guardrails — foundational cybersecurity building blocks that we’ve been investing in for years.

Doubling down on this foundation: technologies like multi-factor authentication (MFA), Zero Trust frameworks, consistent system patching, and comprehensive detection and response. Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

Revolutionizing vulnerability management

In just a few short years, identifying and fixing vulnerabilities has evolved from a mostly laborious, manual process to one driven by AI tools discovering vulnerabilities at volumes never seen before. Further, the time to exploit window has essentially been eliminated.

However, it’s not enough to merely discover vulnerabilities, especially at today’s volumes. You still need to prioritize fixing those that have the most critical impact on your systems and networks first, and that necessitates an equally-rapid response in smart mitigation. 

Organizations use multiple models to scan for flaws and then suggest high-quality code fixes that engineers can quickly move into production, leveraging capabilities like AI Threat Defense. AI allows us to automate the entire software development lifecycle, from discovery to testing and deployment, ensuring that our defensive posture evolves faster than the threats targeting us.

Enhancing threat modeling

We’re also seeing the fundamental concept of threat modeling have an outsized impact. Doing threat modeling well requires bringing context together from your code, your cloud architecture, system design, and network pathways. 

While it isn’t easy, using AI can scale our ability to bring that data together into a coherent picture. Teams have been experimenting with multi-AI models to collect system information and enumerate threats. 

As I noted in June, engineering teams at Google Cloud now route product launches through an agent-based security review pipeline. High-risk indicators automatically get flagged for human review, while we’ve replaced static threat models with dynamic product dossiers that update in real-time.

The CISO as a strategic business leader

The most effective security leaders that I know today are more than just technologists: They are strategic business leaders. The intense global focus on AI vulnerabilities has brought cybersecurity to the forefront of boardroom and executive attention like never before.

This visibility is an opportunity to lead. We CISOs are expected to communicate with clarity, from the board to the C-suite to the security teams who look to them on a daily basis, demonstrating their ability as capable strategists who can navigate the complexities of AI while safeguarding the organization's growth. 

By aligning security fundamentals with business objectives and using AI to enhance defense, we can lead our organizations securely into the future.

To learn more about building and maintaining strong security foundations in the AI era, read our newest Defender’s Advantage: Cyber Snapshot Report.

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Driving AI threat readiness with Wiz: Announcing new Wiz capabilities that can help organizations prepare for the AI era by expanding visibility and accelerating response, so your security teams can defend at machine speed. Read more.
  • PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap: We’ve long been actively working on and rolling out post-quantum cryptography in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029. Read more.
  • How Google Cloud detects, contains, and protects against emerging threats: Learn more about how Google Cloud empowers you with the tools, governance, and infrastructure you need to securely deploy workloads and maintain long-term trust. Read more.
  • Privacy-first medical AI with MedPerf and Google Cloud: Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation. Read more.
  • More cryptanalysis makes us all safer: Recent advances in frontier AI models do not signal the downfall of cryptography. Here’s why they’re best viewed as additional cryptanalysts. Read more.
  • How layered defenses harden Chrome against abusive notifications: Learn how Chrome Security has collaborated with Firebase Cloud Messaging (FCM) and Safe Browsing to significantly reduce notification abuse, and improve the security and quality of the web ecosystem for everyone. Read more.

Please visit the Google Cloud blog for more security stories published this month.

Threat Intelligence news

  • Staying ahead of adversarial AI through agentic source code review: To help defenders implement agentic approaches similar to our approach at Google Cloud, we are sharing the details of our Agentic Vulnerability Discovery Harness architecture for the first time. AVDH can also be used alongside CodeMender’s ongoing scanning to create a two-layered defense strategy. Read more.
  • Cloud threat highlights from the first half of 2026: In the first half of 2026, Wiz's Research and CIRT teams tracked threats affecting thousands of cloud environments. We saw a notable increase in the volume of activity, with supply-chain attacks running at a previously unseen scale and developer toolchains and AI infrastructure drawing serious attention. Read more.
  • Batten down your packages: Mitigation guidance for supply chain compromise: GTIG and Mandiant have tracked ongoing and increasing open source software supply chain compromise campaigns over the past several years. Here are our mitigation and hardening recommendations to secure software supply chains, including insights we have developed as a result of supporting customers. Read more.
  • Multi-brand vishing extortion targets financial services and enterprise cloud environments: Telemetry and infrastructure analysis reveal that UNC6671 has not disbanded. Instead, the threat group has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon and continues to rely on voice phishing to target enterprise employees. Read more.
  • Keyv and cacheable npm package hijacked in supply chain attack: Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. Read more.
  • Inside the Metabase SQLi: Exploited in the wild: Wiz has reverse engineered Metabase CVE-2026-72898 with AI to accelerate defense. Here’s what we learned. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

Posted in