{"slug": "cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses", "title": "Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses", "summary": "Google Threat Intelligence Group released its latest AI Threat Tracker, and VP Sandra Joyce said the threat landscape reduces to three structural shifts: AI is reshaping how software is built, expanding the attack surface, and enhancing threat capabilities. Joyce said the financially-motivated threat actor TeamPCP (UNC6780) has implemented more than half a dozen methods to exploit AI tools and open-source software development practices, including hijacking AI toolkits, prompt injection, and blinding AI scanners with toxic prompts. Google said malicious contamination of AI-assisted coding practices contributed to significant growth in large-scale open-source software supply chain compromises observed in 2025 and early 2026, and it is pushing in-editor guardrails as a real-time 'spellcheck for cybersecurity.'", "body_md": "Welcome to the first Cloud CISO Perspectives for September 2026. Today, Sandra Joyce shares the latest details on Google’s visibility into how attackers are using AI, and how we’re using AI to stop them.\n\nAs with all Cloud CISO Perspectives, the contents of this newsletter are posted to the [Google Cloud blog](https://cloud.google.com/blog/products/identity-security/). If you’re reading this on the website and you’d like to receive the email version, you can [subscribe here](https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup).\n\n*By Sandra Joyce, VP, Google Threat Intelligence*\n\nAnyone operating in security knows that speculation is a major liability during periods of technological disruption. While there is plenty of hype and understandable concern around how threats might use and target AI, a CISO’s AI security strategy has to be anchored in ground truth.\n\nGoogle operates at a rare intersection as both a frontier AI lab and a security company with a frontline view of global incidents. This dual vantage point allows us to understand how AI is built, and exactly how AI is being targeted in the wild. To provide the operational realities that security and business leaders need in the AI era, Google Threat Intelligence Group (GTIG) recently released our [latest AI Threat Tracker](https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai).\n\nWhen we strip away the noise and look at the telemetry, the real threat landscape boils down to three structural shifts that CISOs must address:\n\nAI is reshaping how software is built.\n\nAI is expanding the attack surface.\n\nAI is enhancing threat capabilities.\n\nToday, we’re sharing details on Google’s visibility into these three challenges, and our approach for solving them.\n\n**Building securely in the AI era** \n\nAI has fundamentally altered software development velocity. Across the industry, autonomous agents and AI workflows now push code into production at unprecedented speed. This creates exciting opportunities for innovation, yet CISOs are faced with the difficult task of mitigating enterprise risk while maintaining business momentum.\n\nWe’re seeing threat actors turn our greatest engineering shortcut against us by contaminating upstream packages that AI assistants are trained to suggest and trust. GTIG believes that malicious contamination of AI-assisted coding practices has been contributing to the significant growth in large-scale, open-source software supply chain compromises we [observed in 2025 and early 2026](https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise). \n\nThe solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time 'spellcheck for cybersecurity.'\n\nWe’re also monitoring adversaries targeting agents. The financially-motivated threat actor TeamPCP (UNC6780) has implemented more than half a dozen methods to exploit AI tools and open-source software development practices, including hijacking AI toolkits, prompt injection, and blinding AI scanners with toxic prompts to obfuscate malicious payloads.\n\nThe solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time “spellcheck for cybersecurity.”\n\nJust as word processors underline typos without forcing the writer to stop, security controls must sit natively inside the developer’s editor and agentic workflows, instantly flagging poisoned packages, toxic prompts, and misconfigured toolkits.\n\nCrucially, this can’t stop at the editor. Traditional security suffers from context blindness: Code editors can’t see cloud configurations, delivery pipelines miss runtime exposure, and production teams can’t easily patch root-cause blueprints.\n\nBridging this gap requires an integrated code-to-cloud approach — the exact design principle behind platforms like [Wiz Code](https://www.wiz.io/platform/wiz-code). The underlying approach is to ensure code is continuously verified against live cloud realities before it ships.\n\nWhen organizations think about AI-driven code analysis, the default assumption is to pick one frontier model and point it at their repository. However, our research and telemetry show that single-model security creates a dangerous monoculture: No single AI model can discover every vulnerability, and threat actors are already testing inputs that can blind specific LLM safety filters and scanners.\n\nTo secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos... The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map.\n\nTo solve this, Google takes a [deliberate multi-model approach](https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-next-26-why-we-re-multicloud-and-multi-ai). By orchestrating several foundation models — including Gemini, commercial, and open-source — we cross-validate findings, strip out false positives, remediate code, and identify complex logic flaws that a single model misses. We’re smarter with more than one “brain.”\n\n**Securing AI** \n\nSecuring the development lifecycle is only half the battle. We also need to prevent adversaries from exploiting AI attack surfaces and weaponizing over-privileged agents. Threat actors are targeting AI workloads with techniques that include:\n\n**LLMJacking**: Cybercriminals and state-sponsored groups target GPU access to support running their AI models and agentic workflows. In one notable intrusion Mandiant investigated in April, a threat actor gained initial access to a victim’s cloud environment from an exposed personal access token, and used it to deploy unauthorized AI infrastructure and scale high-performance compute resources, leaving the victim to absorb the hardware and platform costs.\n\n**Targeting of AI data and access**: Cybercriminals now recognize that your custom prompts, agent instructions, and fine-tuned models represent high-value crown jewels. In Q2 2026, Mandiant investigated multiple data theft extortion operations where threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research. Demand is also surging for AI account credentials in underground marketplace forums, with some sellers offering steep discounts for consumer accounts at up to 99% off retail prices.\n\nTo secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos. Don’t treat agent access policies, model inventories (AI-BOMs) and shadow AI as separate challenges because these risks are deeply connected. The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map.\n\nPioneered by the [Wiz Security Graph](https://www.wiz.io/lp/wiz-security-graph), this approach serves as the contextual engine for [Google AI Threat Defense](https://cloud.google.com/security/ai-threat-defense) (AITD) — our broader autonomous security framework that fuses the reasoning power of Gemini and other frontier models, the contextual risk prioritization of Wiz, the code remediation capabilities of CodeMender, and the frontline expertise of Mandiant to stay ahead of AI-driven attacks. Crucially, this context is not siloed; it directly feeds [Google Security Operations](https://cloud.google.com/security/products/security-operations), ensuring that security operations teams can continuously identify, prioritize, and sever toxic attack paths at machine speed.\n\n**Defending against AI threats**\n\nThreat actors are rapidly moving beyond simple prompt generation toward fully-automated, multi-agent attack pipelines.\n\nTo take advantage of your deep context, it’s imperative to shift from manual, human-scale incident response to machine-speed security operations. We can no longer rely on human analysts manually triaging endless backlogs of static alerts.\n\nIn one notable intrusion investigated by Mandiant, a financially-motivated actor compromised an organization's cloud infrastructure and deployed an autonomous agent framework. The threat actor used an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.\n\nWe’re also tracking adversaries using AI as an intelligent orchestrator across the entire attack lifecycle. GTIG recently observed a PRC-nexus espionage group experimenting with a tool called CC Switch to cycle across multiple accounts and swap AI models — like Claude, Codex, and Gemini — picking the best model for specific tasks, such as writing exploit scripts and drafting lures. While the underlying hacking tools aren’t new, AI turned what had been a disjointed manual process into a smooth and automated workflow.\n\nWhile these machine-speed attacks sound daunting, defenders actually hold an asymmetric advantage. Even when armed with autonomous AI, an attacker operates from the outside with limited context — probing in the dark, guessing connections, and hoping a compromised credential leads to a useful asset.\n\nDefenders, on the other hand, [possess deep context](https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-ai-leverages-deep-context-defenders-advantage) that attackers don’t have. You know your code, cloud configurations, user identities, deployment realities, and internal architecture better than anyone. When you feed this rich, multi-dimensional internal observability into security models, AI defense becomes inherently faster and more accurate than AI offense.\n\nBy codifying our frontline threat intelligence directly into these AI models, these autonomous agents can continuously monitor for, investigate, prioritize, and remediate attacks.\n\n**How Google is helping defend the ecosystem** \n\nAs adversaries adopt AI, we have a unique opportunity to disrupt them at the source. As a major security and AI provider, we take this responsibility seriously, using multiple levers to stay ahead.\n\n**Disabling malicious infrastructure**. If you use Google tools to facilitate an attack, you lose access to those tools. We proactively disable the projects, accounts, and assets of known bad actors.\n\n**Hardening our AI models and classifiers**. We operate a continuous feedback loop for our AI models. By feeding threat intelligence directly back into product development, our models learn to recognize and refuse malicious requests before an attack can even be generated.\n\n**Automating vulnerability hunting and patching also disrupt adversaries**. We are moving from manual patching to AI-driven hunting. Tools like [CodeMender automatically fix critical vulnerabilities](https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender) in the code itself.\n\n**Developing advanced defenses and threat models**. Our teams at Google DeepMind are building specialized defenses for generative AI — deploying active monitoring across our entire ecosystem to identify misuse in real-time.\n\nSecuring the AI era can’t be achieved with the disconnected, manual tools of the past, and you can only defend against an AI-powered threat with an AI-powered defense. To tip the scales back in favor of defenders, we must transition to a continuous, machine-speed model of protection — and at Google, we are committed to building that secure future alongside you.\n\nTo learn more about our approach to securing the AI era, please check out our new [Mandiant AI Risk and Resilience report](https://cloud.google.com/security/resources/ai-risk-and-resilience-2026).\n\nHere are the latest updates, products, services, and resources from our security teams so far this month:\n\nPlease visit the Google Cloud blog for more security stories [published this month](https://cloud.google.com/blog/products/identity-security).\n\nPlease visit the Google Cloud blog for more threat intelligence stories [published this month](https://cloud.google.com/blog/topics/threat-intelligence/).\n\nTo have our Cloud CISO Perspectives post delivered twice a month to your inbox, [sign up for our newsletter](https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup). We’ll be back in a few weeks with more security-related updates from Google Cloud.", "url": "https://wpnews.pro/news/cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses", "canonical_source": "https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-monitors-ai-threats-advances-ai-defenses/", "published_at": "2026-09-16 16:00:00+00:00", "updated_at": "2026-09-16 16:15:02.045335+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence", "ai-agents"], "entities": ["Google", "Google Threat Intelligence Group", "Sandra Joyce", "Google Cloud", "TeamPCP", "UNC6780", "AI Threat Tracker"], "alternates": {"html": "https://wpnews.pro/news/cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses", "markdown": "https://wpnews.pro/news/cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses.md", "text": "https://wpnews.pro/news/cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses.txt", "jsonld": "https://wpnews.pro/news/cloud-ciso-perspectives-how-google-monitors-ai-threats-and-advances-ai-defenses.jsonld"}}