The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation.
Browse entries 409–432 of 1576. Return to the first page to search and filter the complete collection.
Organizations need protection that operates in the gap between discovery and remediation.
In the AI era, we need to bolster security fundamentals more than ever. CISO Chris Betz explains why, and how Google Cloud can help you.
We’re excited to announce the preview of quantum-safe key import in Cloud KMS for software-based cryptographic keys, a pioneering BYOK capability.
We’ve long been actively working on and rolling out PQC in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029.
Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation.
We are extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA. Here’s why.
Check out curated frontline insights and blueprints to turn potential crises into manageable events in the newest Cyber Snapshot Report.
Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.
Krebs reports that Microsoft’s July update fixed 570 flaws, including three exploited zero-days, as AI-assisted discovery accelerates patch volume. The release also addressed a high-severity Copilot flaw triggered through crafted prompts from a malicious webpage.
The U.K. Treasury has designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the CTP regime. Here’s how that helps you.
Our flagship Google for Startups program, Gemini Startup Forum: Cybersecurity, has selected its first 33 trailblazing startups.
Anthropic and Verizon mapping of AI-enabled cyber activity to MITRE ATT&CK. Relevant to threat modeling, red-team scenario design, and structured reporting of AI-enabled operations.
OpenAI's opt-in Advanced Account Security applies to ChatGPT and Codex. It replaces password login with passkeys or FIDO security keys, disables email and SMS recovery, shortens sessions, adds login alerts and session management, and automatically excludes conversations from model training. The stronger recovery model also means support cannot restore access for an enrolled user.
Play video
This AI Explained video reviews a major AI development through the lens of benchmarks and evaluation evidence. It is useful context for AI engineering, evaluation, governance, and operational risk.
Play video
This AI Explained video reviews a major AI development through the lens of governance and responsible deployment. It is useful context for AI engineering, evaluation, governance, and operational risk.
Three METR staff spent two hours simulating how their research organization might work with agents capable of roughly 200-hour tasks. The exercise advanced through two hypothetical workdays and exposed choices about prioritization, delegation, context and review. Participants used present-day research needs but assumed future agent capabilities. The account is a planning exercise for identifying organizational constraints, not an experiment measuring productivity or evidence that such agents are available.
OpenAI announced plans to acquire Promptfoo, highlighting automated AI security testing, red teaming, and evaluation as core enterprise requirements.
In a collaboration with researchers at Mozilla, Claude Opus 4.6 discovered 22 Firefox vulnerabilities over the course of two weeks.
Play video
This AI Explained video reviews a major AI development through the lens of governance and responsible deployment. It is useful context for AI engineering, evaluation, governance, and operational risk.
A METR researcher tested Opus 4.6 on simplified terminal reimplementations of two existing games. Initial playthroughs found recognizable gameplay alongside missing or broken mechanics, without a predefined scoring rubric. A July follow-up uncovered additional problems that the original inspection missed. The tasks benefited from documented rules and reduced scope, and more complete versions failed on initial attempts. This is a qualitative study of deliverable inspection, not a measure of general game-development productivity.
METR explains why its follow-up developer experiment did not provide a reliable estimate of current AI productivity gains. Developers increasingly avoided participation or withheld tasks they did not want to perform without AI; lower compensation added another selection concern. Concurrent agent use also complicated time accounting. The raw results suggested possible speedups but had wide uncertainty and omitted important users and tasks, prompting changes to the study design.
METR’s January 2026 update expands its time-horizon suite from 170 to 228 tasks, repairs or removes problematic tasks, and moves evaluation infrastructure from Vivaria to Inspect. Re-estimated model results generally remain within earlier confidence intervals, but task composition changes the fitted recent trend. More long tasks improve coverage, yet only five of the 31 tasks estimated at eight hours or more have measured human baselines. The metric measures success against human task duration, not uninterrupted agent runtime.
Play video
This AI Explained video reviews a major AI development through the lens of governance and responsible deployment. It is useful context for AI engineering, evaluation, governance, and operational risk.
METR’s August 2025 follow-up contrasts algorithmic scoring with human review of repository work. It evaluated 18 tasks drawn from two projects using Claude 3.7 Sonnet and a basic agent scaffold. Automated scoring credited some solutions, while none of the 15 manually assessed submissions met the study’s holistic mergeability standard. Missing documentation, inadequate tests and other maintenance requirements help explain the gap. The selected tasks, limited elicitation and small sample prevent a general estimate of coding-agent usefulness; the manual assessment also was not a direct measurement of maintainers’ repair time.