Detecting and containing AI-powered threats with Google Security Operations agents
Google has detailed how its Security Operations platform works with Google AI Threat Defense to detect, investigate, and contain attacks automatically, including threats from software a company does not control or cannot patch. The system relies on a set of AI agents that write detection rules, triage alerts, and hunt for hidden threats at machine speed. One agent has reduced a typical 30-minute alert review to 60 seconds and has worked through more than 5 million alerts.
Key Takeaways
- To defend against the growing range of AI-accelerated threat actors, organizations need to be able to respond faster to outpace the adversary.
Recently, we announced Google AI Threat Defense , an automated security system designed to help you continuously monitor for and stop AI-powered threats before they can impact your business.
- According to M-Trends 2026 , the exploitation of vulnerabilities has become the most common initial infection vector.
Notably, the report also indicates that the mean time to exploit has dropped to an estimated minus seven days, meaning exploitation frequently occurs even before a patch is officially released.
- The 2026 Verizon Data Breach Investigations Report underscores the magnitude of this challenge.
In a study encompassing over 13,000 organizations, only 26% of vulnerabilities identified on the CISA Known Exploited Vulnerabilities (KEV) list had been fully remediated.
- Results for illustrative purposes.
- To automatically find and fill coverage gaps tailored to your environment, the agent proactively builds new rules and validates them with synthetic events to help ensure your environment is covered before an exploit hits.
Stats & Key Facts
- #One agent has reduced a typical 30-minute alert review to 60 seconds and has worked through more than 5 million alerts.
- #In a study encompassing over 13,000 organizations, only 26% of vulnerabilities identified on the CISA Known Exploited Vulnerabilities (KEV) list had been fully remediated.

To defend against the growing range of AI-accelerated threat actors, organizations need to be able to respond faster to outpace the adversary. Recently, we announced Google AI Threat Defense , an automated security system designed to help you continuously monitor for and stop AI-powered threats before they can impact your business. Based on Google's own approach to today's threats and vulnerability management, it's centered on a four-step framework: Prepare, scan and prioritize, remediate, and monitor.
Today, we're sharing more details on how Google Security Operations works in concert with AI Threat Defense to monitor, detect, and respond to threats, particularly from code you do not own or can not patch. The remediation gap represents a critical vulnerability. According to M-Trends 2026 , the exploitation of vulnerabilities has become the most common initial infection vector.
Notably, the report also indicates that the mean time to exploit has dropped to an estimated minus seven days, meaning exploitation frequently occurs even before a patch is officially released. Google Security Operations delivers vital operational fabric to autonomously contain active attacks across your entire environment. Google Security Operations supports AI Threat Defense to monitor, detect, and respond to threats.
Together with Google AI Threat Defense , we're able to provide the autonomous platform you need to outpace AI-driven attacks. Continuous and autonomous coverage analysis and detection generation While proactive defense can identify vulnerabilities before they can be exploited, there will be applications that you can not patch, as well as potential gaps in the time it takes to remediate vulnerabilities. The 2026 Verizon Data Breach Investigations Report underscores the magnitude of this challenge.
In a study encompassing over 13,000 organizations, only 26% of vulnerabilities identified on the CISA Known Exploited Vulnerabilities (KEV) list had been fully remediated. Moreover, the median duration required to achieve full patching after detection stands at 43 days. Clearly, you still need continuous monitoring to detect threats in your environments.
Results for illustrative purposes. Results for illustrative purposes. Results for illustrative purposes.
The Detection Engineering agent in Google Security Operations can automatically translate new exploitation patterns of unpatched vulnerabilities into custom detections for your specific environment. Available in preview, it analyzes a diverse array of input sources to quickly and effectively recognize malicious activity, so you can uncover novel attack patterns evolving from new and unpatched vulnerabilities. The agent's sources include Google Threat Intelligence (such as emerging threat intelligence, new attack patterns curated by Mandiant, offensive tool repositories, red and purple team reports, autonomous malware analysis, open-source detection repositories and blogs), and internal security telemetry.
For more details please read the original article at Google Cloud AI.
Continue Learning
Comments
Comments appear only after moderation. Your email identifies your submission to the moderator and is never displayed here.
No approved comments yet.