Your Browser Already Knows About Attacks Your SOC Doesn't. Here's How We Closed that Gap with Google Security Operations.

|
September 29, 2026
Menlo Security presentation banner for the Google Cloud Security Innovations Forum.

Your browser already sees the attack your security operations center (SOC) hasn't heard about yet. Now that we face an onslaught of highly adaptive, AI-powered threats, by the time a phishing page lands on a reputation list, it's often gone, and the alert that does reach your SOC still has to travel back out to whatever tool actually enforces the fix. That gap between what your team knows and what your tools can do about it is where damage happens.

AI agents are targets now, too. They browse, log in and open files on your behalf, and attackers have followed them there: prompt injection, credential theft and weaponized downloads. So you're not managing one gap, you're managing it twice: once for people and once for agents.

What's New: Google Security Operations  Administrators Can Now Seamlessly Instruct Menlo What to Do

Menlo HEAT Shield Agent inspects live page content with Google’s Gemini models and blocks zero-day phishing at the point of click, before any reputation feed has caught up. What changes today is what happens after the block. HEAT Shield Agent streams that detection straight into Google Security Operations , where a customer’s playbook can correlate it against existing telemetry and propose a response. Once a security operations  (SecOps) analyst approves it, Google Security Operations  executes the playbook and sends the instruction to Menlo's control plane, which carries out whatever the customer has built it to do, whether that's a policy change, a blocklist update, or a session containment, or any other action supported by Menlo API.

HEAT Shield Agent detects, your SecOps analyst decides, and Menlo enforces, all in one motion.

Your AI Agents Get the Same real-time Protection

Menlo Agent Runtime Security (MARS) runs every agent session inside the Menlo Cloud, never on the endpoint, so an agent reaches only the sites its task needs and every action is logged. MARS strips hidden prompt injection before an agent ever reads it, sanitizes files with Level 3 CDR instead of just blocking them, and enforces real-time DLP and masking so an agent can't leak what it shouldn't. When an agent hits a CAPTCHA, MFA prompt or login wall, a supervisor can clear it mid-session without the agent ever seeing the credential.

MARS detections can already stream into Google Security Operations  today, giving you the same visibility into agent activity that you have into browser activity, just like any other Menlo service.

Investigate and Act without Leaving the Conversation

Menlo Orchestrator Agent, included with HEAT Shield Agent and built on Google Cloud Gemini Enterprise, gives you a conversational way to run that same investigation and enforcement. Ask in plain language what happened, see who else was exposed, and apply the fix, without exporting a single log.

See It at Google Cloud’s Security Innovations Forum 2026

We're demonstrating the full detect, decide, enforce loop live at Google Cloud's Security Innovations Forum on September 29 in Sunnyvale. Stop by the Menlo kiosk for two live demos: HEAT Shield Agent and Google Security Operations closing the loop on a zero-day phishing attack, and MARS protecting an AI agent working through that same kind of attack in real time. 

Learn more at https://www.menlosecurity.com/menlo-security-google-cloud.

‍

Menlo Security

menlo security logo
linkedin logotwitter/x logoSocial share icon via eMail
See the Menlo Browser Security Platform in Action