Connect with us

News

Everyone is navigating AI security in real time — even Google

info

Published

on

GettyImages 2266466589.jpg

I recently had the opportunity to sit down with Francis de Souza, COO of Google Cloud, backstage at an event in Los Angeles. Amid the din around us, de Souza, who speaks in the calm, measured manner of a university professor, offered useful advice for companies navigating the AI security moment we’re all living through, noting that “there’ll be a transition period, and then I think we get to this better place.”

He wasn’t speaking about Google at that moment, but it’s clear that even Google is still figuring things out.

De Souza’s core message was one security professionals have been trying to get executives to internalize for years, now made urgent by AI: security can’t be an afterthought. “As companies embark on this AI journey, they need to take a platform approach,” he said. “Security is not something you can bolt on later, and it’s not something you can leave up to employees to do on their own.” He warned specifically about “shadow AI” — employees reaching for consumer tools without organizational oversight — and argued that companies need to demand security, governance, and auditability from their platforms from the start. “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”

Worth noting: he wasn’t pitching Google Cloud alone. When I observed that his advice sounded like a Google advertisement, he pushed back. Google, he said, is committed to a multicloud approach, and he made the case that companies that think they’re operating on a single cloud almost certainly aren’t. “Even if they pick a single cloud, they’re relying on SaaS applications, there are business partners that may be using different clouds,” he said. “It’s important for companies to have a security posture that is consistent across clouds, across models.”

He also made the case that the threat landscape has changed so fundamentally that old defensive models are too slow. He noted that the average time between an initial breach and the handoff to the next stage of an attack has dropped from eight hours to 22 seconds, and that the attack surface has expanded well beyond the traditional network perimeter. “In addition to your usual estate, you have models now. You have data pipelines used to train the models. You have agents, you have prompts. All of this needs to be protected.”

One threat de Souza flagged that doesn’t get enough attention: agents moving through a company’s internal systems can surface forgotten data repositories that nobody has thought about in years. “A lot of organizations have old SharePoint servers [and access controls] they haven’t really updated, but it didn’t matter because nobody really knew where they were. But agents roaming your enterprise will find those data assets and will expose the data on them.”

The answer, in his view, is to meet machine speed with machine speed. “We’re now seeing the emergence of an AI-native, fully agentic defense where organizations can run agents driving their defense,” he said. “Instead of having a human-led defense or even a human in the loop, you can now have humans overseeing a fully agentic defense.” He added that this has become a leadership issue, not just a technology one. “This is a board-level issue and an executive team issue. It’s not just a security team’s issue.”

But even as AI takes on more of the defensive workload, the people qualified to oversee it are in short supply — and the vulnerabilities that AI itself is introducing are multiplying faster than security teams can address them. “We’re going to need people to deal with the bug-pocalypse,” LinkedIn’s chief information security officer Lea Kissner told the New York Times this week, adding that she doesn’t expect the industry to understand AI security in any sustainable long-term way for at least several years.

Which brings us back to the platform providers themselves. The Register has published a series of reports over the past several weeks documenting a wave of Google Cloud developers hit with five-figure bills following unauthorized API calls to Gemini models — services many of them had never used or intentionally enabled. The cases followed a familiar pattern: API keys originally deployed for Google Maps, placed publicly per Google’s own instructions, had quietly become capable of accessing Gemini after Google expanded their scope without clearly disclosing the change.

Rod Danan, CEO of interview-prep platform Prentus, said his bill hit $10,138 in roughly 30 minutes after attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer whose account was similarly compromised, woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. What neither knew was that Google’s automated systems had upgraded their billing tiers based on account history, raising their effective ceilings to as high as $100,000 without explicit consent.

Google refunded both after The Register published its initial report. Still, Google told The Register it has no plans to change its automatic tier-upgrade policy, saying it prioritizes preventing service outages over enforcing users’ stated budget preferences.

In the meantime, there is the separate question of what happens when a developer tries to shut things down. The Register reported this week on research by security firm Aikido finding that even developers who catch a compromised key and immediately delete it may not be safe. According to Aikido’s findings, attackers can apparently continue using that key for up to 23 minutes because Google’s revocation propagates gradually across its infrastructure. Aikido researcher Joseph Leon told The Register that during that window, success rates are unpredictable — in some minutes over 90% of requests still authenticated — and attackers can use the time to exfiltrate files and cached conversation data from Gemini.

Leon also noted that Google’s own newer credential formats don’t appear to have the same problem: service account API credentials revoke in about five seconds, and Gemini’s newer AQ-prefixed key format takes about a minute. “Both run at Google scale,” he wrote in Aikido’s related paper. “Both suggest this is technically solvable for Google API keys, too.” In short, according to Leon, the 23-minute window isn’t an engineering constraint but a matter of priorities for the company.

That’s worth considering when reading de Souza’s advice, which is sound and should be taken very seriously. He’s not wrong, but there is currently a gap between the platforms are prescribing and how fast they are themselves adapating, and it’s good to be aware of this, too.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Imo senatorial aspirant, Nwachukwu drags NDC to court over ticket denial  

info

Published

on

By

Nwachukwu .jpg

A Senatorial Aspirant, Isaac Nwachukwu, has dragged Nigeria Democratic Congress, NDC, and the Independent National Electoral Commission, INEC, before a Federal High Court Sitting in Owerri, Imo State, over the fallout of the party’s National Assembly primaries.

Nwachukwu, in a suit filed through his Counsel, Cajethan Oguzie, accused the party of denying him the Imo North senatorial ticket after emerging a consensus candidate and paying N5m for the nomination form.

The suit also disclosed that Nwachukwu had paid N20m for the support of the party, but his support was unexplainably reduced to N10m when the list of those who supported the party was published.

The NDC Senatorial Aspirant, in his prayers before the court, demanded that a declaration should be made that he is the consensus candidate of the party in the state with regard to the Imo North Senatorial Zone in the 2027 General election.

“A declaration that the first defendant, NDC, be restrained from fielding another candidate except the plaintiff in the General election into the Imo North Senatorial Zone as he is the consensus candidate for the said election.

“A declaration that the second defendant, INEC, be perpetually restrained from recognising and accepting the candidacy of another person except the plaintiff in the Imo North Senatorial election pending the determination of the matter,” the suit stated.

In an affidavit supporting the originating summons, Nwachukwu stated that he purchased the expression of interest form to aspire for the position for Imo North senatorial zone, a copy of which is attached in the suit already filed.

The NDC Senatorial Aspirant added that upon the purchase of the form, he made a monetary contribution in support of the party’s growth in the tune of N20m into the party’s FCMB account number through his Counsel, receipt also attached in the suit as an exhibit.

“The first sign of irregularity and no compliance with the NDC constitution and electoral act came up when the N20m I paid for party support was allocated to one of the aspirants for my Senatorial District by the name Matthew Omegara, and the N10m that Matthew Omegara paid for party support was allocated to me by the Screening Committee headed by Sam Egwu and Buba Galadimma.

” In compliance with NDC’s directives, I participated in the NDC screening exercise and was successfully cleared as an aspirant to participate in the primary election.

After my consensus candidacy was ratified, my name was shortlisted as a Candidate for Imo North district. A copy of the result is hereby annexed as Exhibit 1U5,” the affidavit added.

Nwachukwu alleged that his name was substituted with Omegara after he had been declared the winner of the primary election.

The Imo North Senatorial Aspirant claimed that the National leader of the party, Seriake Dickson, had summoned him for a meeting telling him that his candidacy was affected after a party chieftain from his state said he didn’t know him.

Among other demands, Nwachukwu is asking the court to order NDC to issue him a certificate as its candidate for the Imo North Senatorial District.

Continue Reading

News

ADC raises alarm over alleged membership forgery in Zamfara

info

Published

on

By

ADC 2.jpg

Supporters and members of the African Democratic Congress, ADC, in Anka and Talata Mafara Local Government Areas of Zamfara State have alleged attempts to manipulate the party’s membership records and card numbers ahead of internal political activities.
The allegation was contained in a statement issued on Wednesday in Gusau by Nura Rabiu Cibiki, Director of Media and Strategy, Campaign and Mobilisation Committee for Abdulrahaman Yahaya, an aspirant for the House of Representatives seat representing Anka/Talata Mafara Federal Constituency.

The group warned against any attempt to alter or duplicate legitimate membership figures, saying such actions could deepen tensions within the party in the constituency.

“We strongly oppose any move to manipulate or duplicate legitimate membership figures, warning that such actions would only worsen existing tensions within the party and the Anka/Talata Mafara Federal Constituency,” the statement said.

The supporters maintained that ADC members in Anka and Talata Mafara were aware of the party’s authentic membership strength and were prepared to protect the integrity of the party’s records.

The statement added that while justice may be delayed, the truth could not be denied.

Meanwhile, Yahaya has filed a suit at the Federal High Court in Gusau challenging alleged irregularities in the party’s primary election process in the constituency.

The court has fixed June 23, 2026, for mention of the case.

Continue Reading

Trending