Google Unveils New AI Security Tools Ahead of Black Hat and DEF CON
Google is advancing its AI-driven cybersecurity efforts with new tools, systems, and partnerships set to be showcased at Black Hat USA and DEF CON 33. From predictive AI agents to advanced anomaly detection, the tech giant is redefining how defenders secure digital infrastructure.
Big Sleep: AI That Finds Vulnerabilities Before They’re Exploited
One of Google’s most promising tools is Big Sleep, an AI agent developed by DeepMind and Google Project Zero. First announced last year, Big Sleep identifies unknown software vulnerabilities before they’re exploited. By November 2024, it discovered its first real-world threat — an achievement that marked a major milestone for AI-assisted security.
Since then, Big Sleep has uncovered several other vulnerabilities, most recently CVE-2025–6965 in SQLite — a flaw previously known only to threat actors. According to Google, this is the first known instance of an AI agent stopping an exploit before it was deployed. These proactive measures are helping secure both Google’s infrastructure and critical open-source projects.
The company emphasized that Big Sleep operates under strict safety guidelines. A white paper outlines its secure-by-design framework, prioritizing human oversight, transparency, and privacy safeguards.
Extending Agentic AI to Security Operations
Google is also introducing agentic capabilities to existing tools. This summer, the open-source forensic analysis platform Timesketch will be upgraded with Sec-Gemini integration. The update allows AI to conduct preliminary forensic investigations, reducing manual labor and enabling analysts to focus on high-priority threats.
At Black Hat USA, Google will demonstrate Timesketch’s log analysis features at booth #2240. In parallel, it will offer a live demo of FACADE (Fast and Accurate Contextual Anomaly Detection), which has been internally monitoring insider threats since 2018. Unlike traditional detection systems, FACADE uses contrastive learning to detect threats without relying on historical attack data.
At DEF CON 33, Google is partnering with Airbus to host a Capture the Flag (CTF) competition. Teams will collaborate with AI assistants to complete security challenges, showcasing how human-AI partnerships can enhance real-world threat detection.
Expanding Cybersecurity Through Public-Private Partnerships
Beyond tools, Google is scaling cybersecurity through collaboration. The company has helped launch the Coalition for Secure AI (CoSAI) to guide the safe use of AI systems. It will donate data from its Secure AI Framework (SAIF) to support CoSAI’s research in agentic AI and software supply chain defense.
DEF CON 33 will also mark the conclusion of the AI Cyber Challenge (AIxCC), a two-year competition with DARPA. Finalists will present AI tools designed to detect and patch vulnerabilities in open-source software, offering practical solutions for developers and defenders alike.
A Secure Future Requires AI Done Right
As AI transforms the cybersecurity landscape, Google stresses the importance of deploying these tools responsibly. “We believe this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild,” the company said, underscoring the potential for lasting impact.
With advancements in AI cybersecurity innovation accelerating, the focus now turns to real-world deployment. The coming months may determine whether these tools set a new standard for digital defense — or remain experimental.
