Cybersecurity

Google RSAC 2026: Agentic Defense Meets a 22-Second Threat

Google used RSAC 2026 to launch Gemini-powered dark web intelligence and SecOps AI agents; Mandiant's M-Trends 2026 found attackers now hand off access in 22 seconds.

Google RSAC 2026: Agentic Defense Meets a 22-Second Threat — article cover
On this page6 SECTIONS
  1. The 22-Second Threat: What M-Trends 2026 Says
  2. Dark Web Intelligence: From Keywords to Intent
  3. SecOps AI Agents and the MCP Ecosystem
  4. Wiz Closes, and Securing AI Itself
  5. What It Means for Developers and Security Teams
  6. Sources

On March 24, 2026, mid-RSA-Conference week, Google Cloud’s COO and president of security products, Francis deSouza, published the company’s RSAC playbook on the official blog: fold Google Threat Intelligence, Security Operations, and the freshly closed Wiz acquisition into a single “agentic defense” product line. The same day, Google’s Mandiant unit released its annual M-Trends 2026 report, built on more than 500,000 hours of incident investigations from 2025. Both documents point to one conclusion: attacks now move faster than a human SOC can follow, so defense has to move into the hands of agents.

The numbers are blunt. In 2025 investigations, division-of-labor attacks — one crew obtains access, then hands it to another to execute — showed a median time from initial compromise to hand-off of 22 seconds. In 2022 that figure was over eight hours. When stolen access becomes a commodity settled in seconds, automating defense with agents stops being marketing copy and becomes the only response speed that matches the threat.

The key numbers from the report:

  • Division-of-labor attacks appeared in 9% of investigations, up from 4% in 2022; median compromise-to-handoff collapsed from over eight hours to 22 seconds
  • Exploits led initial infection vectors for the sixth straight year at 32%; voice phishing climbed to second at 11%, while email phishing kept declining
  • Global median dwell time rose to 14 days, from 11 in 2024; ransomware accounted for 13% of investigations, with prior compromise now the top ransomware vector at 30%
  • Average time-to-exploit went negative: 63 days in 2018, minus 1 day in 2024, minus 7 days in 2025 — exploitation routinely starts before patches ship

The report also tracks 714 new malware families (over 6,000 total) and more than 660 new threat clusters. AI’s offensive role is judged incremental rather than transformative: QUIETVAULT harvests AI and developer tokens, while PROMPTFLUX and PROMPTSTEAL query LLMs mid-execution to aid evasion. But the companion AI risk report warns that adversaries have moved from experimenting with AI to autonomous agents capable of rewriting their own code in real time.

Dark Web Intelligence: From Keywords to Intent

Google’s headline launch is dark web intelligence inside Google Threat Intelligence. Built with the newest Gemini models, it scores 98% accuracy analyzing millions of daily external events in internal tests. The bigger shift is methodological: from keyword matching to intent-based analysis — when a threat actor deliberately avoids naming a victim’s subsidiary, the system can still connect the dots from context.

Michael Kosak, director of threat intelligence at LastPass, put the before-and-after in plain terms: the dark web tools he had used previously “averaged over 90% false positives,” while the new capability is “the difference between reacting to a fire and putting it out before the match is struck.”

SecOps AI Agents and the MCP Ecosystem

On the operations side, a Triage and Investigation agent entered preview in Google Security Operations: it autonomously investigates alerts, gathers evidence, and delivers verdicts with explanations, pairing adaptive AI with deterministic automation. Remote MCP server support — the plumbing for building enterprise-grade security agents on top of Google’s intelligence and tooling — is slated for general availability in early April 2026.

MCP here is not just an integration surface; it is also something to defend. Omdia principal analyst David Gruber supplies the demand-side numbers: 89% of CISOs are pushing to accelerate agentic security adoption, and over half of cybersecurity practitioners believe agentic AI offers a bigger advantage to defenders than to the adversary.

Wiz Closes, and Securing AI Itself

The other headline from the week: Google completed its acquisition of Wiz. Wiz immediately introduced an AI Application Protection Platform (AI-APP) plus red, blue, and green security agents, filling in exposure management for multicloud and AI workloads.

The second thread is securing AI itself. A CSA/Google survey found 72% of organizations lack confidence in their ability to execute a secure AI strategy. The product responses: AI Protection in Security Command Center now integrates with Vertex AI Agent Engine to detect agentic threats such as unauthorized access and data exfiltration by agents, and Model Armor integrates with Google MCP servers to mitigate prompt injection, data leakage, and tool poisoning.

What It Means for Developers and Security Teams

Three takeaways. First, threat intelligence is becoming model-consumable input: 98% filtering accuracy plus intent-based analysis means “reading the intel” moves from an analyst’s morning routine to a stage in the pipeline. Second, security agents need standard interfaces like MCP to compose into an ecosystem — the April GA date is worth tracking. Third, if your product runs agents, then agent permission boundaries, data exfiltration, and tool poisoning are your new threat model, and SCC and Model Armor point the direction. Agents reaching production is the defining theme of 2026 — we flagged it in our opening outlook for the year — and security is simply the part being squeezed hardest by the 22-second clock.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL