🔎 Two indicators from a case we are actively investigating:
rezbackcup[.]blob[.]core[.]windows[.]net
frontend148[.]blob[.]core[.]windows[.]net
If you defend a network, hunt your logs for these now.
Seeing the same thing, or have additional context? Get in touch 👉 https://t.co/qkv4aEZ1Aq
‼️ Hugging Face built an interactive replay of the OpenAI agent that breached them. It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream and more.
https://t.co/y7dD9n8QTy
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face).
Link:
https://t.co/Qp41obmGBS
(+free download)
From @cloudsa, @SANSInstitute, @knosticai, @unpromptedconf, @OneRSAC, @FIRSTdotOrg
I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://t.co/HGr5lFuAZA
A decoy in your AI agent's MCP config can help spot an intrusion. Interactions with the honeypot MCP server are a high-confidence signal. Building this honeypot is pretty straightforward.
https://t.co/uH5C4frftB
@github We opened up AgentMesh for free. It’s like a VirusTotal but got extensions, skills, etc. (https://t.co/BcrPb9DUes) You can also check out how we secure coding agents if you like. Free up to 5 licenses. https://t.co/BsCxIZ8zQO
50+ Google-managed MCP servers are GA or in preview—with more on the way!
By pointing your AI agents toward Google-managed MCP endpoints, you’re plugging into the Google Cloud security stack without needing to make regional configuration changes → https://t.co/LmsfY3pMkV
Detect suspicious behavior in real time with Agent Anomaly Detection in Gemini Enterprise Agent Platform.
It uses statistical models and an LLM-as-a-judge framework to flag unusual reasoning. Learn more about governing your AI agents on Agent Platform → https://t.co/oJXEURVwoN
Our new Agent Registry in Gemini Enterprise Agent Platform provides a single source of truth for your enterprise.
It indexes every internal agent, tool, and skill—simplifying discovery and ensuring governed, approved assets are available to your users → https://t.co/5xcXkUmUCB
10 codelabs from #GoogleCloudNext to start building today:
1. Build rich agent experiences (ADK + A2UI).
Improve user interaction through intuitive, high-quality interfaces that allow users to interact with agentic systems seamlessly → https://t.co/21LvLJ7kDh
2. Build a multi-agent system.
Create the architecture required to make multiple agents work together to achieve a shared goal → https://t.co/MCv4mKifj0
3. Beyond the Simple SELECT: AlloyDB NL2SQL.
Democratize data access by building systems that allow users to query complex databases using natural language, supported by high-speed vector search → https://t.co/eqnxc8e6Ly
4. Beat fraud with an AI Shield (Spanner & BigQuery Graph).
Implement real-time reasoning with Spanner and BigQuery Graph databases. Analyze complex relationships in your data to prevent fraud at the point of transaction → https://t.co/L2c81fKTHH
5. Build secure agents by protecting access and data.
Protect the reasoning engine with Model Armor and IAM to manage agent access and ensure that sensitive data remains protected during execution → https://t.co/37nMd1FgNI
6. Ground agents with Google Maps Platform.
Use Geo-intelligent logistics to ground your agents in real-world location data to optimize field operations and logistics in real-time → https://t.co/NCb6LymayQ
7. Deploy and scale agents on Agent Engine.
Learn how to deploy agents as containerized microservices that scale dynamically with your workload → https://t.co/fY9WKYE2Xs
8. The ultimate guide to Cloud Run: from zero to production.
Achieve rapid deployment using this lab as a blueprint for moving from a local prototype to a production-ready, auto-scaling platform on Cloud Run → https://t.co/nZLRgEn7Vs
9. Developer Keynote: building agents with Skills.
Learn the ins and outs of AI agent development, including Agent Development Kit (ADK), prompting, Agent Skill usage, and MCP → https://t.co/fJ72HbFwgJ
10. General Keynote: forecasting with AI Agents.
Transform unstructured chaos into actionable business intelligence in seconds → https://t.co/iBBPXpoYoB
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
We’ll continue updating our coverage as more details are confirmed.
https://t.co/G0aakn8swq
The BBC has found a pattern of spikes in trades on financial markets ahead of public announcements by President Trump, including during the Iran war. 🎧 #GlobalNewsPod https://t.co/FaEezJpcNL
To check if your Google Workspace has been compromised by the same tool that compromised Vercel:
1. Go to https://t.co/TpuIOW5Fwg
- This is Google Admin Console > Security > Access and Data Control > API Controls > Manage app access > Accessed Apps
2. Filter by ID = https://t.co/uqJnCqp5Ah
- This is the ID of the compromised OAuth app
If you see an app after filtering, you have potentially been compromised
BREAKING: International Energy Agency Chief Fatih Birol says Europe has 'maybe six weeks of jet fuel left' and warns of possible flight cancellations
https://t.co/50LKUEGsnS
📺 Sky 501, Virgin 602, Freeview 233 and YouTube
> installed Claude Code 3 months ago
> never opened the security settings
> Claude reads your wallet seed phrases
> Claude reads your SSH keys
> Claude reads your AWS credentials
> can send data anywhere it wants
> one CLAUDE.md file in a cloned repo
> your data is already gone
> average damage - $8,000-$50,000 in one night
> 15 minutes to fix this
> you still haven't
GOOGLE BUILT A FOUNDATION MODEL THAT FORECASTS TIME SERIES WITHOUT TRAINING ON YOUR DATA
Every ML engineer I know has wasted weeks building these pipelines from scratch
custom models. feature engineering. hyperparameter tuning and it still breaks on new data
TimesFM is a pretrained foundation model for time series trained on a massive corpus of real-world data so you don't have to
plug in your historical numbers. get forecasts out
sales trends. energy consumption. demand signals. any sequential data with a timestamp
no training. no fine-tuning. no pipeline drama
200M parameters. 16k context window. quantile forecasts built in
Google liked it so much they shipped it inside BigQuery as an official product
the rest of us just got the open source version for free
https://t.co/4c2b0XlOgp
⚠️ New threat detected: [email protected] ⚠️
This dependency includes a severe supply-chain backdoor: it performs an automatic outbound request to a hardcoded external URL at module load time and executes JavaScript sourced from the response ...
https://t.co/sNWXzfHSj7