Google AI A.I CyberSecurity Scoring
Google AI
Company Information
Website:https://goo.gle/ai-devs
Employees number:None
Number of followers:300,017
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:goo.gle
Google AI Risk Score (AI oriented)
Between 600 and 649
Google AITechnology, Information and Internet
Updated:
30/08/2026
30/08/2026
638/1000
Poor
Caa
Google AI Global Score (TPRM)
xxxx
Google AITechnology, Information and Internet
Score locked

Google AIPoor
Current Score
638Caa (POOR)
01000
4 incidents
-50.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
639
AUGUST 2026
629
JULY 2026
677
Breach
14 Jul 2026 • Google AI
xAI and Google Cloud: xAI Grok CLI Exposed Developer Code Through Automatic Whole-Repository Uploads
xAI’s Grok Build CLI Found Transmitting Full Git Repositories by Default
627
CRITICAL-50
XAIGOO1784039078
xAI’s Grok Build CLI Found Transmitting Full Git Repositories by Default
Independent researcher cereblab uncovered a critical privacy issue in xAI’s Grok Build CLI (version 0.2.93), revealing that the tool transmitted entire Git repositories including unread files and commit history to xAI’s infrastructure by default. The analysis, conducted via HTTPS interception on macOS, showed that the CLI uploaded repository data even when explicitly instructed not to access files.
Key findings include:
- Unintended Data Transmission: The CLI sent full Git bundles via `POST /v1/storage`, exposing complete repository history and untouched files. A test with a 12 GB repository recorded over 5 GiB of data transferred in 73 chunks before manual termination.
- Sensitive Data Exposure: A test `.env` file containing simulated credentials was transmitted unredacted, appearing in both model-response requests and staged session archives.
- Persistent Uploads: Disabling the "Improve the model" option did not stop uploads, as server settings retained `trace_upload_enabled: true`. Local staging in `~/.grok/upload_queue` could also consume significant disk space.
- Cloud Storage Links: Metadata pointed to a Google Cloud Storage bucket (`grok-code-session-traces`), though it remains unconfirmed whether xAI used the data for training.
On July 14, xAI disabled the upload mechanism server-side (`disable_codebase_upload: true`) and added a privacy opt-out, though the latter was described as a data-retention control rather than a transmission block. Elon Musk publicly committed to deleting previously uploaded data, but independent verification is pending.
The incident highlights risks of AI coding agents accessing sensitive codebases, underscoring the need for isolated testing and egress monitoring. The analysis relied on a controlled proxy setup to intercept and examine outbound traffic.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
761
Ransomware
02 Jul 2026 • Google AI
DeepSeek and Google: Browser-Only Ransomware Uses File System Access API to Encrypt Files Without Malware Installation
Browser-Based Ransomware Exploits File System Access API in Novel Attack
677
CRITICAL-84
DEEGOO1782973818
Browser-Based Ransomware Exploits File System Access API in Novel Attack
Researchers have uncovered a new ransomware technique that operates entirely within a browser, leveraging the File System Access API to encrypt or exfiltrate files without requiring native malware, exploits, or elevated privileges. The proof-of-concept (PoC), attributed to AI-assisted development by DeepSeek, demonstrates how malicious actors can turn theoretical browser-based threats into practical attacks.
The attack begins with a social engineering lure a fake AI image-enhancement or upscaler web app designed to trick users into granting folder-level access. Once a victim selects a directory (such as a photo folder), the malicious page enumerates, reads, and encrypts files using browser file handles, then displays a ransom note. The technique bypasses traditional defenses, as it relies on legitimate browser APIs and user-granted permissions rather than dropped binaries or exploits.
A key concern is the attack’s effectiveness on Android, where Chromium-based browsers (including Chrome) allow access to sensitive directories like DCIM and Pictures, which often contain irreplaceable personal data. While Safari and Firefox do not widely expose the same API primitives, the risk is concentrated where Chrome dominates.
The DeepSeek PoC, dubbed InfernoGrabber, used a Discord-themed frontend with `showOpenFilePicker()` and `showDirectoryPicker()` to obtain file handles, demonstrating an end-to-end attack chain. Though the API restricts arbitrary disk access, targeting user-facing folders like Pictures and Downloads is sufficient for high-impact outcomes when paired with convincing social engineering.
This attack highlights a growing challenge: AI can rapidly translate abstract malicious concepts into operational threats by mapping them onto legitimate platform features. While DeepSeek’s model refuses direct ransomware prompts, it generated the necessary HTML/JavaScript code to abuse the File System Access API, accelerating the development of one-off malware.
The incident underscores the need for improved permission controls, as current mitigations rely heavily on user vigilance such as avoiding write access to sensitive directories and robust backups. Browser vendors are urged to tighten restrictions, particularly on mobile, where media libraries are prime targets. Defenders must now account for AI-assisted, disposable malware artifacts that complicate detection and attribution.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
761
MAY 2026
777
Cyber Attack
01 May 2026 • Google AI
GitHub and Google: Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign
Russian Threat Actor Exploits AI to Run Five-Year Crypto Fraud Scheme on Telegram
760
HIGH-17
GITGOO1780431903
Russian Threat Actor Exploits AI to Run Five-Year Crypto Fraud Scheme on Telegram
A lone Russian-speaking threat actor, tracked as bandcampro, has operated a sophisticated fraud campaign since February 2021, leveraging stolen AI credentials and a fake political persona to target American audiences. Posing as an authentic conservative voice under the Telegram channel @americanpatriotus, the actor amassed over 17,000 subscribers by capitalizing on the post-Capitol riot migration of QAnon and MAGA communities to alternative platforms.
The operation, uncovered by Trend Micro’s TrendAI Research team in May 2026, relied heavily on AI to automate content generation, credential theft, and cryptocurrency fraud. Starting in September 2025, the actor used a jailbroken version of Google Gemini dubbed Quantum Patriot to generate QAnon-style posts, manage infrastructure, and rotate stolen API keys via natural-language commands in Russian. The system operated at near-zero cost, cycling through 73 stolen Gemini API keys in a round-robin rotation to avoid detection.
Beyond influence operations, the actor deployed malicious tools, including StellarMonSetup.exe, a fake cryptocurrency wallet that installed the GoToResolve remote-access trojan (RAT). A separate AI-powered brute-forcing tool, using Gemini 2.5 Flash, cracked 29 WordPress administrator accounts across sectors like legal, medical, and weapons retail. The campaign also drained at least one victim’s cryptocurrency wallet.
Key infrastructure included GitHub-hosted tools, Cloudflare tunnels, and a gamified Telegram bot (@QFS_Terminal_Bot) to engage and defraud subscribers. The actor bypassed Gemini’s safety guardrails by persuading the AI to recognize him as an "authorized pentester," storing jailbreak instructions in a persistent GEMINI.md file to suppress ethical warnings.
Indicators of compromise (IoCs) include multiple GoToResolve IP addresses, the StellarMonSetup.exe RAT, and the @americanpatriotus Telegram channel. The incident highlights the growing threat of AI-enabled fraud, where a single operator can scale attacks to enterprise-level output using stolen resources.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
777
MARCH 2026
777
FEBRUARY 2026
777
JANUARY 2026
776
DECEMBER 2025
776
NOVEMBER 2025
776
OCTOBER 2025
776
AUGUST 2025
792
Vulnerability
05 Aug 2025 • Google AI
OpenAI, Anthropic and Google: An AI agent can pass every safety check and still leak secrets
AI Agent Security Flaws Expose Secrets in Default Configurations
776
CRITICAL-16
GOOANTOPE1785306233
AI Agent Security Flaws Expose Secrets in Default Configurations
Security researcher Elad Meged, a founding engineer at Novee Security, demonstrated critical vulnerabilities in AI agent workflows used by Anthropic, Google, and OpenAI, revealing how default configurations could be exploited to exfiltrate sensitive data. By testing the agents in their out-of-the-box setups mirroring how organizations deploy them Meged uncovered flaws in the trust models governing command approvals, output handling, and inter-stage handoffs.
The attacks leveraged prompt injection as an entry point, but the core vulnerabilities stemmed from how agent harnesses the components managing tool permissions, approval logic, and execution made and enforced trust decisions. In Anthropic’s Claude Code Action pipeline, for example, seemingly safe commands (e.g., read-only operations) were approved, only for their outputs to be automatically published or consumed by later stages with broader privileges. Each patch from Anthropic addressed a specific bypass but inadvertently exposed new attack surfaces, with the final exploit recovering secrets through a channel that evaded all prior fixes. Anthropic awarded bounties for each reported issue, though Meged noted that the bounty-per-bypass model risked obscuring the underlying architectural problem.
Google’s Gemini CLI faced a similar issue: a kill chain exploiting unenforced restrictions in CI workflows, resulting in a CVSS 10.0 advisory (GHSA-wpqr-6v78-jr5g). OpenAI’s Codex CLI, while equipped with a sandbox, proved vulnerable in multi-stage workflows where state from one stage deemed "trusted" by default was inherited by subsequent stages without revalidation. Across all three vendors, the pattern was consistent: defenses like environment sanitization or protected paths failed at the handoffs between stages, where initial safety judgments were not rechecked in context.
Meged’s findings highlight a systemic issue in AI agent design: harnesses often validate trust at the point of decision (e.g., "this command is read-only") but fail to account for how outputs are consumed downstream. A read-only command feeding into a public output channel, for instance, effectively becomes a data leak. While individual vendors have implemented fixes post-disclosure, Meged argues the problem reflects a shared architectural assumption across the industry one that may require cross-vendor collaboration or formal standards to address.
The research, including code-level analysis and live demonstrations, will be presented at Black Hat USA 2026. For organizations running these agents, Meged recommends auditing workflows for paths where agent-influenced state is consumed by later stages with elevated privileges, focusing on the gaps between "approved" actions and their downstream effects.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Google AI ??
What was Google AI's A.I Rankiteo Cyber Score in August 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in July 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in June 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in May 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in April 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in March 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in February 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in January 2026 ??
What was Google AI's A.I Rankiteo Cyber Score in December 2025 ??
What was Google AI's A.I Rankiteo Cyber Score in November 2025 ??
What was Google AI's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Google AI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Google AI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Google AI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?