惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
月光博客
月光博客
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
人人都是产品经理
人人都是产品经理
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - Franky
The Cloudflare Blog
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
Jina AI
Jina AI
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
Last Week in AI
Last Week in AI

Security & Identity

Google named a Leader in the External Threat Intelligence Service Forrester Wave™ | Google Cloud Blog Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses | Google Cloud Blog Introducing new session management tools with native, granular controls | Google Cloud Blog Getting started with the Mantis harness to find and fix bugs | Google Cloud Blog How Blackline prevents data exfiltration with VPC Service Controls | Google Cloud Blog Cloud CISO Perspectives: Tips on securing the water sector in the AI era | Google Cloud Blog Introducing Google Cloud Fault Injection Testing (FIT) in preview | Google Cloud Blog State of AI infrastructure report agent governance and security | Google Cloud Blog Cloud CISO Perspectives: Sticking to security fundamentals in the AI era | Google Cloud Blog Announcing quantum-safe key import in Cloud KMS | Google Cloud Blog PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap | Google Cloud Blog Privacy-first medical AI with MedPerf and Google Cloud | Google Cloud Blog Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline | Google Cloud Blog AlloyDB adds group authentication to secure enterprise scale and AI agents | Google Cloud Blog Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS | Google Cloud Blog Best Buy scales secure AI access with Workforce Identity Federation | Google Cloud Blog Cyber Snapshot Report: Enterprise resilience key to toolchain success | Google Cloud Blog Now in preview: Find and fix software vulnerabilities with CodeMender | Google Cloud Blog Cloud CISO Perspectives: How AI leverages deep context as the defender’s advantage | Google Cloud Blog Introducing k8s-aibom on GKE for automated AI bills of materials | Google Cloud Blog Contributing to U.K. financial sector resilience as a critical third party | Google Cloud Blog Meet the 33 cybersecurity startups joining the Gemini Startup Forum | Google Cloud Blog Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM | Google Cloud Blog Shift into high gear with agents: Securing the software-defined vehicle | Google Cloud Blog New IDC study: How Mandiant transforms security into a competitive advantage | Google Cloud Blog Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval | Google Cloud Blog Cloud CISO Perspectives: How Google Cloud Security uses AI internally | Google Cloud Blog Securing agentic AI: What's new in VPC Service Controls | Google Cloud Blog Verifiable trust in the AI era: What’s new in Confidential Computing | Google Cloud Blog Choice, compliance, and collaboration: Europe’s path to open digital sovereignty | Google Cloud Blog
How Google Cloud detects, contains, and protects against ...
David Byrd, Salmaan Rashid · 2026-08-08 · via Security & Identity

At Google Cloud, securing your data and business systems is our foundational commitment. We empower our customers with the tools, governance, and infrastructure needed to securely deploy workloads and maintain long-term trust.

We approach security from a shared fate model, and we continuously work to proactively identify and mitigate potential threats before they can compromise your data and misuse your infrastructure.

Understanding the risk: How bad actors attempt to exploit cloud workloads

Hyperscale cloud platforms like Google Cloud offer massive compute capacity, high-speed networking, and cutting-edge AI engines, but these same core strengths also make us high-value targets for malicious actors seeking service disruption, financial gain, or exploit cloud resources.

By tracking active adversary techniques, Google’s specialist security teams actively monitor and defend across several areas.

  • AI workload exploitation: As organizations rapidly adopt AI tools and systems, including Gemini Enterprise Agent Platform, threat actors target unsecured API keys and leaked access tokens. Common attack patterns include using stolen credentials for unauthorized distillation attacks and reselling access tokens on third-party marketplaces. We track consumption rates, account standing, and access context to catch these anomalies early.

  • Cryptocurrency mining: Malicious actors often use stolen credentials to spin up virtual machines (VM) for illicit cryptomining. While Google Cloud respects customer privacy and does not inspect internal VM processes, we can accurately infer mining activity by analyzing infrastructure telemetry — such as distinctive CPU and memory utilization spikes and rapid VM creation rates.

  • Exfiltrated credentials and supply chain attacks: Developers occasionally commit secrets and API keys to public source repositories where automated scrapers harvest them in seconds. Exposed credentials also stem from supply chain attacks against local development environments or managed cloud workloads.

  • Account takeover (ATO): Adversary-in-the-middle (AITM) techniques — such as sophisticated phishing and session cookie theft — can grant unauthorized users administrative control. Once inside, adversaries establish persistence, move laterally, and execute downstream abuse like resource hijacking or data exfiltration.

Without proper containment, these attacks can lead to operational disruptions, compromised system integrity, and unchecked resource misuse — such as runaway costs — creating substantial friction for impacted users.

Mitigating risks: Tailored containment in action

Detecting a threat is only half the battle; maintaining business continuity by containing it without interrupting your legitimate operations is critical. Google Cloud deploys tailored mitigation strategies based on the nature of the threat.

  1. Granular containment and throttling: When anomalous traffic indicates AI abuse or cryptomining, we apply targeted throttling measures. This isolates malicious activity while preserving legitimate corporate traffic.

  2. Collaborative triage for complex workloads: In AI environments, malicious API calls are often interlaced with critical business operations. In these scenarios, our Cloud Abuse and Cloud Support teams collaborate directly to isolate and inspect specific traffic vectors.

  3. Localized identity isolation: To prevent lateral movement, localized containment protocols can be systematically applied across compromised user identities and Google Workspace domains.

  4. Targeted suspensions as a last resort: Our primary objective is to enforce containment at the most granular resource level possible. However, if platform integrity or customer financial exposure is severely threatened, we may temporarily suspend specific projects, backed by a clear appeal process.

Additionally, to stop attacks at the root, Google actively partners with public repository hosters through initiatives like GitHub Secret Scanning to catch exposed credentials immediately and trigger proactive warnings before exploitation occurs.

Communicating risk: Proactive transparency and log visibility

During a security event, time-to-awareness is everything. We provide a robust suite of tools and channels to ensure your key security stakeholders receives actionable visibility:

  • Cloud Abuse Event Logging: Provides a 30-day window into security and abuse notifications with resource-level granularity. These logs can be ingested directly into your SIEM product for automated orchestration and response.

  • Proactive support cases and abuse notifications: When critical abuse is detected, automated email notifications and high-touch support cases are generated to open an immediate channel for resolution and best-practice sharing.

  • Cloud Audit Logging and anomaly spending alerts: Audit logs monitor unexpected resource changes that point to an ATO, while automated billing alerts notify key stakeholders of sudden spend spikes driven by compromised workloads.

  • Essential Contacts: To ensure notifications reach the right people instantly, Google Cloud allows you to maintain a dedicated directory of designated contacts across security, billing, and operations.

Customer action plan: Hardening your environment

We handle the security of the underlying infrastructure, yet your organization remains resilient only through proactive hygiene on your side of our shared fate partnership.

To minimize risk exposure across your user accounts, service accounts, and API keys, we recommend implementing these foundational defenses.

  1. Mandatory identity protection: Enforce multi-factor authentication (MFA) and 2-Step Verification (2SV) across all user accounts and Google Workspace domains without exception to prevent AITM cookie theft and phishing attacks. Ensure that you use Device Bound Session Credentials (DBSC) for your Google Workspace accounts to bind a user's session to their specific device.

  2. Secure service accounts and API keys: Treat keys and tokens as top-tier secrets. Never embed API keys in source code or public repositories. Use keyless authentication where possible, rotate keys regularly, and follow strict governance for service account management.

  3. Enforce least privilege and perimeter defense: Use Identity and Access Management (IAM), VPC Service Controls (VPC-SC), and Context-Aware Access (CAA) to restrict access so identities only have the exact permissions required for their specific function.

  4. Configure Essential Contacts and billing alerts: Set up detailed billing alerts to identify unauthorized spending before costs rise, and conduct quarterly reviews to keep your Essential Contacts directory current.

  5. Regular resource hygiene: Conduct periodic audits of your organization to identify and decommission unused resources, legacy billing accounts, and dormant user accounts. Pay special attention to groups or service accounts with elevated permissions to ensure your attack surface remains as small as possible.

Continuous vigilance together

Google continuously monitors platform health to detect anomalous usage patterns before they impact your workloads. 

Ultimately, maintaining a secure environment is a partnership built on shared fate. While we take every precaution to prevent bad actors from gaining a foothold, protecting your organization requires equal dedication on your end. By applying robust access controls, staying vigilant, and adopting security best practices, together we can keep your workloads secure and resilient.

Explore key resources to harden your environment:

Posted in