From Google Cloud Blog · 40 stories
NVIDIA Launches Revenue-Sharing Model for AI Infrastructure and Agent Toolkit
NVIDIA has introduced a revenue-sharing model for AI cloud partners to access its infrastructure more affordably, enabling startups to pay a percentage of revenue in addition to hardware costs. Additionally, NVIDIA released an Agent Toolkit to facilitate the creation of specialized AI systems within business workflows. These initiatives aim to expand NVIDIA's AI technology reach and revenue sources.
Adobe Patches Critical ColdFusion and Campaign Classic Vulnerabilities Amid Exploits
Adobe released patches for critical vulnerabilities in ColdFusion and Campaign Classic, some of which are actively being exploited for remote code execution. These security flaws, including CVE-2026-48282, have CVSS scores of 10.0, marking them as maximum severity. The urgency of these updates highlights the importance of securing systems to prevent unauthorized access and potential attacks.
Researchers Reveal Security Flaws in AI Coding Agents and Open-Source Mobile Frameworks
Researchers from Hong Kong University have highlighted vulnerabilities in AI coding agents, notably OpenAI Codex and Claude Code, which can be bypassed using techniques like SKILLCLOAK. These techniques allow malicious AI add-ons and agents to evade current security scanners. These findings underscore the need for improved security measures in AI agent marketplaces and software, as current defenses are inadequate.
Strategic Frameworks and Systems Vital for Successful AI Integration in Enterprises
AI's integration in enterprises is moving beyond model development to focus on creating robust systems for execution and governance. This shift highlights the importance of developing adaptable frameworks to support AI's role across various functions such as finance, HR, and operations. It reflects a broader industry trend where the focus is on building the necessary infrastructure to ensure AI's ongoing, safe, and productive incorporation into real-world workflows, addressing the current challenges and limitations.
Meta Introduces Hybrid Asset Classification for Privacy-Aware Infrastructure
Meta has unveiled a hybrid asset classification strategy using large language models (LLMs) to handle ambiguous data in privacy-aware infrastructure while maintaining deterministic rules for enforcement. This method addresses the complexities of AI-native products with varied data inputs, ensuring compliance and effective data governance. It is a response to the challenges posed by the increasing speed and scale of AI innovations, and the approach aims to better manage privacy controls for evolving AI products.
Amazon Bedrock Enhances AI Capabilities with Security and Operational Features
Amazon Bedrock has introduced several updates to improve the security and operational management of AI applications, emphasizing capabilities for multi-tenant AI, data retention policies, and compliance with US government standards. Key features include resource-based policies, managed entitlements for model subscriptions, zero data retention enforcement, and AI model support in AWS GovCloud. These advancements aim to streamline AI adoption across diverse sectors while maintaining security and governance standards.
DeepSeek Launches Open-Source AI Agent Harness and Updates Flagship Model
DeepSeek has released DeepSeek Harness (dsh) in developer preview, an open-source AI agent runtime built with a plugin-based architecture under an MIT license. Concurrently, the company launched DeepSeek-V4-Pro, an updated flagship AI model optimized for agentic workloads, which is now available via API with new peak and off-peak pricing.
New AI Models for Long-Horizon Coding Tasks Introduced
Several AI models aimed at long-horizon tasks in coding and robotics have been released. GLM-5.2 by Hugging Face extends support for coding-agent scenarios with a 1 million token context. Cognition's SWE-1.7 enhances long-horizon asynchronous tasks with reinforcement learning. Xiaomi-Robotics-1 combines vast pre-training data for improved robotics capabilities. These releases highlight advances in scaling and reasoning capabilities.
Kubernetes Extends Reach to Desktop Infrastructure, Highlighting Database Management Challenges
Kubernetes is being considered for managing desktop infrastructure, traditionally separate from cloud-native models. This shift aims to unify operational practices and lower costs related to outdated virtual desktop systems. However, while Kubernetes simplifies deployment, it also exposes complexities in managing databases, requiring expertise beyond standard DevOps skills.
Google Expands Gemini Enterprise Agent Platform with Remote MCP Server
Google has enhanced its Gemini Enterprise Agent Platform by introducing a remote Managed Control Plane (MCP) server. This update allows developers to securely connect external AI agents with Google Cloud resources, facilitating agent development across various IDEs. The enhancements address developer feedback on building more efficient, production-ready AI agents.
Amazon Quick Enhances Efficiency for Finance, Sales, and Supply Chain Management
Amazon Quick, a generative AI assistant, enhances efficiency for AWS Finance, sales teams, Tradeshift, and supply chain operations. It streamlines data preparation, administrative tasks, and analytics processes, allowing organizations to improve productivity and response times across various sectors.
Supply Chain Attacks Target Open Source, Impacting Over 2,500 Organizations
Software supply chain attacks targeting open source repositories and CI/CD systems have increased significantly, with a recent incident impacting over 2,500 organizations and 430,000 CI/CD pipelines. This attack, attributed to TeamPCP, initially compromised Aqua Security's Trivy vulnerability scanner and subsequently affected projects like LiteLLM, leading to the exposure of terabytes of credentials from major companies.
Google DeepMind Introduces Gemini 3.8 Live Models for Voice Agents
Google DeepMind launched Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking, two new AI models designed to improve near real-time reasoning for voice agents. These models aim to make AI conversations more intuitive and intelligent, with Gemini 3.8 Live for scalable applications and Gemini 3.8 Live Extended Thinking for high-complexity tasks requiring multi-step reasoning.
Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA
Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.
Google Cloud Storage SDKs Enable End-to-End Checksums by Default for Data Integrity
Google Cloud Storage SDKs now enable end-to-end checksumming by default for all uploads and downloads. This change improves data integrity by protecting against bit flips during data transfer, even when applications do not explicitly provide checksums.
UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms
The UNC6671 extortion group has rebranded its operations under new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement of its previous BlackFile brand. The group continues to use voice phishing (vishing) to target enterprise employees, particularly in financial services, private equity, and professional services, leading to data theft from cloud environments like Microsoft 365 and Okta.
Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices
Google, the FBI, Lumen, and others disrupted the NetNut residential proxy network involving over 2 million devices used for malicious activities. The operation disabled command-and-control features, protecting home devices from being exploited. This action significantly reduces cybercriminals' ability to mask their activities using residential IPs.
Google Launches Faster AI Models for Image and Video: Nano Banana 2 Lite and Gemini Omni Flash
Google announced the launch of Nano Banana 2 Lite and Gemini Omni Flash, models designed to enhance multimedia processing efficiency. Nano Banana 2 Lite focuses on low-cost, fast image generation, while Omni Flash offers advanced video generation and editing. Available across Google platforms, these models aim to streamline creative workflows for developers and businesses using AI-generated content.
Google Cloud Managed Lustre Introduces Dynamic Tier for Lower Cost and AI/HPC Workloads
Google Cloud Managed Lustre now offers a Dynamic Tier priced at 6 cents/GB*month, allowing users to store all data in a single namespace. This aims to reduce costs and simplify data management for AI and HPC workloads by providing sub-millisecond latency for hot data and linear throughput scaling.
Google Cloud Releases Official Swift SDK for Server-Side Development
Google Cloud has launched official API Client Libraries for Swift, enabling server-side Swift applications to integrate with Google Cloud services. This SDK supports Swift 6.2+ and utilizes modern concurrency and networking features, allowing Swift developers to build high-throughput microservices for cloud environments.
2026 Public Sector M-Trends Report Highlights Alarming Cybersecurity Trends
The 2026 Public Sector Threat Landscape report reveals significant vulnerabilities in cybersecurity for the public sector, including a 22-second median hand-off to ransomware operators. These findings underscore an urgent need for rapid, machine-speed defenses amidst evolving attack methods that exploit trust boundaries.
Google Cloud C4N Instances Now Generally Available for High I/O Workloads
Google Cloud has announced the general availability of C4N, optimized for network and block storage I/O. This instance type offers up to 400 Gbps network bandwidth and 1M IOPS, addressing performance bottlenecks for enterprise applications, particularly in sectors requiring high data transfer rates.
Mandiant Identifies Vulnerability in ADFS Certificate Management
Mandiant discovered that improper manual rotation of ADFS certificates can expose active signing keys in Machine DPAPI. This vulnerability allows attackers to forge SAML tokens and bypass authentication mechanisms, posing significant risks to enterprise security.
Schrödinger accelerates molecular discovery by 4x using AlphaEvolve
Schrödinger partnered with Google Cloud to implement AlphaEvolve, enhancing their MLFF process by 4x. This advancement resolves the trade-off between speed and precision in molecular simulations, significantly impacting drug discovery and materials design.
Google open-sources Mantis, an AI-powered bug finding and fixing harness
Google has open-sourced Mantis, a framework designed to automate the discovery, triage, reproduction, and patching of software vulnerabilities using AI. Mantis aims to improve the effectiveness and scalability of vulnerability analysis by combining agentic techniques with sandboxed reproduction, offering a tool for developers to integrate AI into their security practices.
Google Threat Intelligence Group Identifies Three Russian Cyber Espionage Clusters Abusing Authentication Flows
Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters, UNC6293, UNC7005, and UNC5976, that are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. These groups employ persistent phishing and social engineering tactics to compromise accounts, often by tricking users into setting app passwords or abusing OAuth flows. This matters because these techniques exploit trusted authentication processes, making them harder for targets to recognize as malicious and posing a significant threat to sensitive information.
Malachyte Raises $10M Seed Funding to Bring Spotify-like AI Recommendations to E-commerce
Malachyte, a startup founded by former Spotify engineers Sidd Motwani, Ian Anderson, and Shivaditya Sinha, secured $10 million in seed funding to apply its AI-driven recommendation technology to e-commerce. The company aims to provide real-time, intent-aware shopping experiences, moving beyond traditional personalization methods based on past purchases or demographics. Its platform uses a "two-headed Vector AI" system, similar to Spotify's Vector AI which powers 90% of its recommendations, to predict shopper intent.
Mirendil Secures $100M+ Google Cloud Deal for Self-Improving AI Compute
AI lab Mirendil has signed a multi-year partnership with Google Cloud, valued at over $100 million, to acquire compute capacity for its self-improving AI research. This agreement provides Mirendil with access to Google's TPUs and Nvidia GPUs, enabling the startup to scale its work on AI systems that iteratively improve themselves.
Google Cloud Introduces AI Security Blueprint for Kubernetes Engine
Google Cloud has released a security blueprint for AI workloads on Google Kubernetes Engine (GKE). This strategic guide suggests a multilayered security approach to protect model weights and counter threats like prompt injection, advancing AI's transition from prototype to production. It matters as AI deployment security becomes crucial for enterprises.
Google Threat Intelligence Group Unifies Threat Actor Naming System
Google Threat Intelligence Group (GTIG) has introduced a new unified naming schema for tracking threat actors, replacing the previously separate systems used by Mandiant and Google's Threat Analysis Group (TAG). This change aims to standardize threat actor identification across platforms and public reporting, making it easier for defenders to understand and respond to threats.
Google's AlphaEvolve Released for General Use on Gemini Enterprise Platform
Google has announced that AlphaEvolve, an AI-driven code optimization service, is now generally available on the Gemini Enterprise Agent Platform. Featuring evolutionary algorithm techniques, it enables organizations to optimize their code within their own infrastructure boundaries, supporting diverse industries. This advancement signifies a robust approach to tackling optimization challenges across sectors like logistics and genomics.
Anthropic Launches Claude Apps Gateway for AWS and Google Cloud
Anthropic has launched the Claude apps gateway for both AWS and Google Cloud. This tool provides enterprises with centralized management of Claude Code, enhancing control over access, costs, and policy adherence. By streamlining developer credential management and spend tracking, the gateway eases administrative burdens for organizations operating at scale.
AWS & Google Cloud Designated as Critical Third Parties to UK's Financial Sector
HM Treasury has designated Amazon Web Services and Google Cloud as critical third parties to the UK financial sector. Under the Critical Third Party (CTP) regime effective January 1, 2025, these tech giants will be subject to oversight from UK regulators such as the Bank of England. This move aims to enhance the operational resilience of the financial sector amidst increasing reliance on cloud services.
AWS and Google Launch New Sandboxing Environments for Running Untrusted Code
AWS Lambda has introduced MicroVMs, a new serverless compute option offering VM-level isolation for running user-generated code. Concurrently, Google Cloud has launched Cloud Run sandboxes in public preview, enabling safe execution of AI-generated code and untrusted binaries. Both solutions aim to provide secure, isolated environments for a variety of applications.
Google's Spanner Omni, a deploy-anywhere distributed database, is now generally available
Google has made Spanner Omni generally available, allowing users to deploy the distributed, multi-model database in on-premises data centers or other cloud environments. This release provides the same core Spanner capabilities, including ACID compliance and horizontal scalability, outside of Google Cloud, enabling greater deployment flexibility for demanding workloads and AI applications.
Google Cloud Data Agent Kit is now Generally Available, adding BigQuery Graph, Bigtable, and Apache Spark support
Google Cloud's Data Agent Kit is now generally available, providing tools and agent skills for coding agents to interact with Google Cloud data products. This release adds support for BigQuery Graph, Bigtable, and Managed Service for Apache Spark, allowing agents to inspect schemas, run queries, and manage resources directly within the user's data environment.
Google Cloud announces general availability of M4N VM family for I/O and memory-bound workloads
Google Cloud has announced the general availability of its M4N virtual machine series, designed for I/O-intensive and high-memory workloads. This new VM family offers higher per-core IOPS and throughput, aiming to reduce total cost of ownership for applications like Oracle databases by optimizing memory-to-vCPU ratios.
Mandiant Details BREEZE COMET Threat Actor Targeting Brazilian Financial Services
Mandiant, part of Google Threat Intelligence Group, has identified BREEZE COMET (formerly UNC5669) as a financially motivated threat actor actively targeting Brazilian financial services, retail, and eCommerce organizations since early 2024. This group specializes in manipulating payment systems and banking software to conduct fraudulent transfers and is noted for using generative AI in malware development, potentially increasing the scale and sophistication of future operations.
Google Cloud Storage launches Storage Intelligence advisor and expands batch operations
Google Cloud Storage has released Storage Intelligence advisor into general availability and expanded capabilities for storage batch operations. These updates provide users with automated insights into storage changes and enable large-scale object management, addressing the complexity of managing growing data volumes.
Google Cloud's Memorystore for Valkey 9.1 achieves 3x QPS and microsecond latency
Google Cloud announced the general availability of Memorystore for Valkey 9.1, offering up to three times higher queries per second (QPS) and microsecond latency compared to Memorystore for Redis Cluster. This performance improvement is due to a redesigned lock-free, multi-queue messaging architecture that optimizes thread communication and dynamic work balancing.