Google launches AI Threat Defense for faster vulnerability response

Google Cloud introduced AI Threat Defense, an automated security platform that finds, prioritizes, and helps patch software flaws using its Gemini models, Wiz, CodeMender, and Mandiant. The company says the system is built for a threat environment where attackers use AI to find and exploit weaknesses in hours or days.

Google launches AI Threat Defense for faster vulnerability response

Google Cloud has introduced AI Threat Defense, an automated cybersecurity platform that combines several of the company’s security products to find, prioritize, and patch software vulnerabilities faster. The company said the system is designed for enterprises facing attackers who now use AI to discover and exploit flaws in hours or days, shrinking response windows that used to be measured in weeks.

The platform brings together the Gemini family of models, the cloud security firm Wiz, the AI code-fixing agent CodeMender, and Mandiant’s threat intelligence and incident response expertise. Google Cloud said Wiz was acquired earlier and added to the security portfolio alongside Mandiant, which Google acquired in 2022.

⚡ New to this?

This matters because software flaws can be found and used very quickly now, especially when attackers use AI to scan for weaknesses. A SOC, or Security Operations Center, is the team and tools an organization uses to detect and respond to security incidents. Google is combining several products into one system to shorten the time between finding a flaw and fixing it.

🦞 OpenClaw angle

If you run self-hosted agents or automation pipelines, treat vulnerability response as a workflow, not a ticket. Map exposed services, APIs, identities, and containers first, then separate broad scanning from deeper checks on internet-facing or customer-facing systems. Also log which model or agent proposes each fix, generate tests before deployment, and tag patched dependencies so you have an audit trail when something breaks.

Google described AI Threat Defense as a four-stage workflow: Prepare, Scan and Prioritize, Remediate, and Monitor. In the Prepare stage, Wiz maps exposed applications, infrastructure, APIs, identities, and runtime environments so defenders can reduce what attackers can reach. Google said a built-in pen-testing agent in Wiz simulates attacks to identify which exposures are actually exploitable.

During scanning, the platform runs multiple AI models across the environment. According to Google, lighter models handle broad coverage across assets, while frontier models perform deeper analysis on internet-facing applications, customer-facing services, authentication logic, and other systems considered highest risk.

Google said it uses a multi-model approach because no single model finds every class of vulnerability. The company said performance varies across application logic, cloud configuration, binary analysis, and exploitability validation. Customers access those models through the Gemini Enterprise Agent Platform.

Once the system identifies a vulnerability, Mandiant provides response playbooks. Google said those playbooks include guidance for handling spikes in critical issues and retiring legacy products that may add risk.

The Remediate stage centers on CodeMender, a Google DeepMind agent that generates fixes inside a developer’s integrated development environment or command-line interface. Google said CodeMender works with Wiz and Antigravity to replace vulnerable code, rewrite older code in memory-safe languages, and analyze library dependencies so patches can be coordinated across components.

Before a patch reaches production, the platform generates tests to verify the fix. Google said patched libraries are tagged in source control and production to create an audit trail showing which model generated each fix and when. The company described the workflow as autonomy under human supervision.

The final Monitor stage uses agents connected to Google Security Operations, the company’s security operations center product. These agents handle detection, triage, investigation, and threat hunting across network, identity, and application telemetry.

Google also said the platform uses hardened container images that are built, signed, and verified daily to reduce runtime attack surface. Francis deSouza, COO of Google Cloud and president of Security Products, said Google’s secure-by-default architecture already blocks 10 million spam emails every minute and protects billions of users and customers across its portfolio.

Google framed the launch as part of its broader security work, including zero trust architecture, the Titan security chip, and Google Security Operations. DeSouza said the shrinking exploit window has made human-speed vulnerability management no longer viable for enterprise risk, and presented AI Threat Defense as Google’s answer to attackers who have automated reconnaissance and exploitation.

The product enters a market where many security vendors are adding AI features to existing tools. Google’s pitch is that AI Threat Defense connects vulnerability discovery, prioritized patching, Wiz risk context, CodeMender remediation, Gemini reasoning, and Mandiant operational guidance in one workflow.

Source: Help Net Security ↗

More from Security News