Skip to content

company

Google Threat Intelligence Group

Google's cybersecurity research unit tracking state-sponsored and criminal threat actors, publishing analysis on malware, phishing, and attacker infrastructure.

Known aliases

  • GTIG

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security4 publishers

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

Perspective Coverage

4 publishers
Builder
Builder 33%
Operator
Operator 61%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence65
security3 publishers

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption
Insufficient
Hype gap+18
Incentives40
Confidence60
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
security8 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 58%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+8
Incentives58
Confidence74
invest3 publishers

Anthropic's Alibaba distillation count rose fivefold while the accounts behind it shrank sevenfold

The September threat report puts 151 million Claude exchanges on 3,500 accounts Anthropic links to Alibaba, about 469 a day per account. The only figure denominated in money anywhere near it is a 2.7% share move.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 35%
Investor
Investor 37%

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence50
security3 publishers

A victim organization told Spain's AEPD an AI agent found the flaw and logged in by itself

Spain's AEPD published the account but has not yet verified it. In it, the agent scanned for flaws, logged in, altered personal data and opened invoices. The agency's own position is that AI adds speed and scale, not new threats.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence35
Adoption15
Hype gap+35
Incentives40
Confidence40

Earlier coverage

  1. A $10 limit stored as text on a Kinde token cut the agent off after four calls

    Build · September 22, 2026 · 1 publisher

  2. Google put an undercover analyst inside TeamPCP's inner circle during its 1,000-company campaign

    Security · September 21, 2026 · 1 publisher

  3. Google says an agent framework harvested thousands of third-party credentials in under six hours

    Security · September 17, 2026 · 1 publisher

  4. Attackers went from stolen cloud credentials to mass credential harvest in under six hours

    Leadership · September 16, 2026 · 2 publishers

  5. Mandiant's testers talked an internal AI assistant into pushing private repos to their own GitHub

    Security · September 16, 2026 · 1 publisher

  6. Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source

    Leadership · September 15, 2026 · 1 publisher

  7. IBM prices the AI-assisted breach at a million dollars more than the rest

    Invest · September 14, 2026 · 1 publisher

  8. An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud

    Build · September 12, 2026 · 1 publisher

  9. Four espionage crews picked up the same Chrome and Windows exploit chain within days

    Product · September 11, 2026 · 1 publisher

  10. A six-hour agent run harvested credentials from behind the victim's own cloud IPs

    Build · September 10, 2026 · 1 publisher

  11. Stealer logs now carry AI session tokens that replay straight past MFA

    Security · September 9, 2026 · 1 publisher

  12. Google clocks TeamPCP standing up a mass credential-harvesting campaign in under six hours

    Security · September 9, 2026 · 1 publisher

  13. Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks

    Security · September 8, 2026 · 1 publisher

  14. Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

    Security · September 8, 2026 · 3 publishers

  15. Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager

    Security · September 8, 2026 · 1 publisher

  16. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · 1 publisher

  17. TeamPCP poisoned more than 1,000 packages with tactics anyone can copy

    Security · August 28, 2026 · 1 publisher

  18. Every one of thirteen named 2025-26 incidents ran on a credential that still worked

    Build · August 31, 2026 · 1 publisher

  19. Three Russian clusters phish the grant, not the password, and MFA completion changes nothing

    Build · August 23, 2026 · 1 publisher

  20. Russia-linked crew keeps winning with app passwords and device codes

    Leadership · August 22, 2026 · 1 publisher

  21. Google: Russia-linked crews get targets to hand over app passwords, OAuth codes and WhatsApp devices

    Build · August 21, 2026 · 1 publisher

  22. The arrayref compromise turned cargo update into the delivery channel

    Product · August 21, 2026 · 1 publisher

  23. After Arup, a face on a video call is not a credential

    Product · August 21, 2026 · 1 publisher

  24. The extortion call now comes from your help desk, and the fix is a procedure you own

    Leadership · August 19, 2026 · 1 publisher

  25. UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones

    Leadership · August 19, 2026 · 1 publisher

  26. Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.

    Security · August 19, 2026 · 1 publisher