Google Brings Calendar To Personal Intelligence In AI Mode via @sejournal, @MattGSouthern

Robby Stein, VP of Product, Google Search, says Personal Intelligence in AI Mode now connects to Google Calendar. He announced the update in a post on X, writing that Personal Intelligence in Search “now connects to Google Calendar.”

With this update, AI Mode can “add invites or other meetings to your Calendar directly,” and responses become more tailored because they consider what’s on your schedule.

Unlike Gmail and Photos, which only give AI Mode information to reference, Calendar is the first announced Personal Intelligence connection that can also create an entry directly.

Stein confirmed the connection is available now in the U.S., with more countries to come.

Background

Google previewed a Calendar connection for Personal Intelligence at I/O in May without saying when it would ship. The rollout follows comments from Google’s Nick Fox in December, when he said personal context features for AI Mode were “still to come.”

Personal Intelligence has rolled out in stages since then, starting with the launch in January for Google AI Pro and Ultra subscribers. It rolled out to free U.S. accounts in March.

By May’s I/O, Google had expanded Personal Intelligence to nearly 200 countries and 98 languages with no subscription required.

Why This Matters

Every connected app is another variable that can make the same query produce a different answer for different people. That’s already measurable: iPullRank’s May report found that connecting Gmail to Personal Intelligence changed which brands showed up in AI Mode responses, using identical prompts across test accounts.

Calendar adds a different kind of variable tied to timing rather than interests. Ask AI Mode for dinner spots and, with Calendar connected, the answer can account for whether tonight is already booked. Multiply that by however many apps Google eventually connects, and the old idea of a single results page for a given query gets harder to hold onto.

Two people typing the same words could reasonably land on two different answers, based on nothing more than what’s already sitting in their calendars.

Looking Ahead

Google hasn’t announced when the Calendar connection will expand beyond the U.S. The bigger question is how tracking will evolve as personalization grows: if AI Mode answers rely more on connected apps, there’s no single result to verify, only a range of answers influenced by the searcher’s connected apps.


Featured Image: FotoField/Shutterstock

https://www.searchenginejournal.com/google-brings-calendar-to-personal-intelligence-in-ai-mode/582409/




ChatGPT Calls Turn Into Leads More Often: Invoca Report via @sejournal, @MattGSouthern

According to a benchmark report published by Invoca on July 13, calls referred by ChatGPT are more likely to qualify as sales leads than calls from any other channel. However, once answered, these calls convert at approximately the average rate.

The report states that the lead rate for ChatGPT-referred calls is 49%, which is approximately 10 percentage points higher than the average of the seven channels tracked by Invoca and 6 points above Google Business Profiles at 43%. The conversion rate from these leads is 40%, compared to an all-channel average of 42%. Invoca considers this to be about average.

All figures represent averages from Invoca’s customer base, based on over 70 million calls and 600 million minutes of conversations across 10 industries. Invoca sells the call tracking and conversation analytics that generate this data.

Invoca says this is the first year it had enough data to measure calls driven by generative AI search at all.

What The Data Shows

Across all industries, approximately 56% of calls to businesses are answered by a person. If a call lasts more than 15 seconds, the answer rate increases to about 65%, and for calls over 30 seconds, it rises to around 71%. Out of the answered calls, roughly 38% qualify as leads, and about 42% of those leads convert during the call.

ChatGPT sits above that baseline on the first number and below it on the second.

Paid search continues to generate the most calls, leads, and conversions among paid channels in the dataset. For multi-location businesses, Google Business Profiles are the top organic source. Invoca emphasizes that channel efficiency and scale are different factors, and percentages alone don’t reveal which channel brings in the most business.

What The Report Doesn’t Say

Invoca does not publish how many ChatGPT-referred calls the 49% is calculated from, only noting thatInvoca does not publish how many ChatGPT-referred calls the 49% is calculated from, only noting that the overall volume attributable to generative AI remains very low. When a rate is derived from a small base, it tends to be less reliable compared to the same rate calculated from the significantly larger paid search volume.

The report doesn’t specify a measurement window. The methodology explains that the figures are based on calls tracked and analyzed on the Invoca platform across 10 industries and seven marketing channels, but it doesn’t mention a specific start or end date. Gemini, Claude, and Perplexity aren’t included in the channel breakdown. Invoca notes that this is a measurement limit rather than a comment on those assistants, mentioning that ChatGPT is the only large language model generating measurable call volume in their dataset.

How Invoca Attributes The Calls

Invoca labels calls as ChatGPT-referred, but the report lacks details on how this attribution works, such as whether callers clicked from ChatGPT, used tracked numbers, or contacted the business through other means. It only accounts for calls directly attributable to ChatGPT and not those from users who researched a business in an assistant and later called via untracked methods.

I covered a version of that boundary in June, when Similarweb data linked ChatGPT brand recommendations to a 2.5x higher chance of a site visit within seven days. Most of the associated traffic appeared as branded search rather than as a direct referral, limiting what standard referral reporting could show. Calls add another attribution problem because the report doesn’t explain what digital trail Invoca used to connect them to ChatGPT.

Why This Matters

Calls attributed to ChatGPT qualify as leads more often than calls from the other channels Invoca tracks, by about 10 points. Once someone picks up, they convert at about the rate businesses manage with everyone else. That complicates the read that’s been forming around AI referrals over the past year.

I wrote in May about Adobe’s finding that the conversion sign flipped on AI-referred traffic to U.S. retailers. In twelve months, it went from the worst-performing channel to converting 42% better than the others. The explanation on offer was that the research had already happened inside the assistant. Invoca’s data fits the first half of that. Someone who compares options with an assistant and then calls may be further along in the buying decision, which is how Invoca reads it, too.

The second half of the data doesn’t quite match up. While a higher lead rate is observed, it doesn’t translate into a higher on-call conversion rate when looking at Invoca’s averages. In this dataset, the difference appears at the qualifying stage but then vanishes afterward.

Looking Ahead

Invoca believes this is more of a signal to monitor rather than a channel to invest in, supported by the volume caveat. The key metric influencing this view is call count, which the report doesn’t specify. Another question is whether the 40% moves. If AI-referred callers continue to qualify at the top of the list while converting in the middle, the focus shifts from increasing call volume to understanding what happens during those calls.

The report also notes that 64% of businesses don’t ask callers to make a purchase or schedule an appointment, which is an issue on the business side.

https://www.searchenginejournal.com/chatgpt-calls-turn-into-leads-more-often-invoca-report/582400/




Google Says No SEO Penalty For Year-Long A/B Tests? via @sejournal, @martinibuster

Google’s John Mueller recently answered a question about A/B testing web pages for long durations, warning that an unintended consequence is that enabling variations to be indexed can result in uncertainty as to which will be visible in the search results.

A/B Testing Traffic From Live Search Results

A/B testing is when one or more versions of a web page is shown to users. The reason for doing this is generally for testing conversion rates and user responses.

The important takeaway from the guidelines is that A/B testing live web pages is the guidelines were created to minimize impact on search performance.

The guideline begins:

“This page covers how to ensure that testing variations in page content or page URLs has minimal impact on your Google Search performance.”

While Google does not explicitly forbid using A/B testing to test which page ranks better, the context of the guidelines itself is defined as protecting search performance; measuring search performance is not in the guidelines.

What Google’s document describes getting measured is consistently user behavior, not rankings.

On a side note, something that’s not in the guidelines is that there is no “right” button color and size for improving clicks on a call to action button. Longstanding SEO knowledge and experience about this is that large buttons and/or colors that contrast strongly against the web page backgrounds tend to get more clicks. This likely explains why Amazon’s Add To Cart button is a bright mustard color and Walmart’s version is bright blue contrasted against a solid white background.

Google’s Guidelines On A/B Testing

Google’s guidelines on A/B testing describe it as showing different versions of a website and collecting data on how users react to them. In terms of SEO performance it says not to expect any disruption but by allowing Google to index the slightly different pages once the testing is over the winning combination will be indexed much sooner.

There are two kinds of A/B testing:

  1. A/B Testing
    Testing two or more changes to a web page. Google uses the example of testing different fonts on buttons.
  2. Multivariate Testing
    This is a test of multiple changes all at once in order to identify which combination of factors work best together. Google uses the example of testing different combinations of different fonts on buttons and on the web page itself.

Four Considerations For A/B Testing

Google also recommends four best practices:

1. Use The rel=”canonical” Link Attribute
This is probably the most important factor to consider. Using the rel=canonical link attribute enables site owners to put all kinds of variations of a web page online and still include a strong hint about which version of a web page is best.

2. Use 302 redirects
If you’re randomly redirecting users to different versions of a web page you should be using a 302 redirect, not 301 redirects. 302 means that a resource (like a web page) has been temporarily moved. That’s different from a 301 redirect which means that a move or change in URL is permanent.

3. Don’t Cloak
Cloaking is the practice of showing one thing to Google and something else to users. If you’re testing different web pages to see how users react when they click through from search then Google insists that site owners show the same thing to Google, even if the page elements are constantly changing.

4. Don’t A/B Test For A Long Time

Google warns site owners to limit how long A/B testing goes on. They warn that excessive testing could get a site in trouble:

“If we discover a site running an experiment for an unnecessarily long time, we may interpret this as an attempt to deceive search engines and take action accordingly. This is especially true if you’re serving one content variant to a large percentage of your users.”

That last warning relates directly to the question asked on the Bluesky social network.

Google Answers Question About Long-term A/B Testing

The person asking the question specifically wanted to know about how Google handles A/B testing that lasts for as long as a year.

They asked:

“Hey @johnmu.com, As Google’s A/B testing guide suggests to avoid running same A/B test for long durations, I was wondering how does Google handle long term holdouts (eg. 10% for 6-12 months), especially for a large scale marketplace with 10s of millions of crawls to similar amount of pages.”

Google’s John Mueller answered:

“Depending on your setup, what might happen is that one or the other version is used for indexing. If they’re close enough, probably that doesn’t matter. If they’re significantly different, that could be visible in search results too.”

The person who asked the original question then followed up with an additional question that revealed more about how much the web pages are changing.

They asked:

“…what if it’s fully different like a redesigned page, and since Googlebot is getting alternative versions with each crawl (sometimes in a day). Can that rapid change in core HTML structure cause issues with indexing and lead to Google potentially dropping the pages from index?”

Mueller responded:

“We’d take the content into account the way that we crawl it for indexing. There’s no (as far as I know) “penalty” or “demotion” for having varying content (lots of sites have that), but it can make it harder for you to debug & monitor if the content constantly changes.”

The person asking the question wanted to know how Google handled long-term A/B testing. They did not ask how Google handles indexing, but that’s the question Mueller answered. That may explain why the person followed up with a second question that was more precise about the extent of their A/B testing and Mueller again focused on indexing.

No Penalty For Having Varying Content?

Mueller’s statement seems to contradict Google’s own guidance about long-term A/B experiments.

The relevant context of Google’s guidelines is:

  1. It confirms that A/B testing is legitimate.
  2. Normal experiments are reasonably assumed to be temporary.
  3. Once enough data is collected to reach conclusions the A/B test it’s normal that it ends.

That’s where we get to the warning part of the guidance:

“If we discover a site running an experiment for an unnecessarily long time, we may interpret this as an attempt to deceive search engines and take action accordingly. This is especially true if you’re serving one content variant to a large percentage of your users.”

So the point of where things get fishy is when the experiment goes on longer than what seems reasonable and where one variation of the content becomes the prime version for most users as part of an attempt to “deceive search engines.

Featured Image by Shutterstock/logofank

https://www.searchenginejournal.com/google-says-no-seo-penalty-for-year-long-a-b-tests/582349/




Google’s Mueller On First Link Priority & Link Obfuscation via @sejournal, @MattGSouthern

Google Search Advocate John Mueller responded to a plan to hide a homepage button from Google in hopes that a better-worded link further down the page would count instead. He suspects the person behind it is overthinking it.

The r/bigseo thread starts with a question about a homepage that links to the same services page twice. The first link is a ‘Services’ button near the top, while the second sits further down in an FAQ, worded the way the person wants Google to read it.

To get the second link to “win,” they plan to make the more prominent button stop being a link. It would still work when someone clicks it, but the page’s code wouldn’t call it a link anymore. That leaves the FAQ link as the only regular link on the page pointing to the services page.

They asked the thread whether it would make any visible difference.

What Mueller Said

Mueller replied in the thread:

“I suspect you’re overthinking it, Google has practice dealing with lots of websites so I wouldn’t expect you to see any visible change there.

That said, if you wanted to experiment with this, I’d suggest doing something more along the lines of using CSS / JS to position things on the page, regardless of where the link is placed in the HTML. That reduces the potential negative side-effects of “breaking” the HTML (turning links into buttons, or similar, ugh) while still letting you vary the position in your page’s HTML code.”

He didn’t say whether the first link wins. His answer is about the size of the effect and the cost of chasing it.

Why Anyone Would Try This

The idea behind the plan is called first link priority. It says that when one page links to another page twice, Google reads the words in the first link and ignores the second. If that were true, the button would win and the FAQ link would be wasted.

Google has never clearly defined “first link priority.” SEJ’s ranking factors chapter on first link priority traces the idea to a 2008 Rand Fishkin post and finds nothing to support treating it as a rule you can build on. Mueller has said before that Google hasn’t defined the behavior, and that whatever anyone figures out about how Google does it today isn’t necessarily how it will work tomorrow.

The idea keeps circulating anyway. SEJ’s Roger Montti covered a similar worry about anchor text dilution last April.

What Google Sees

Google can run JavaScript, but that doesn’t mean it treats everything clickable as a link. A link written the normal way puts the address inside a link tag, which tells Google where it goes. An address parked in some other element for a script to grab isn’t written as a link at all.

Google’s links best practices documentation says Google can generally only crawl a link when it’s an <a>element with an href attribute, and that it can’t reliably extract URLs from elements that behave like links through script events.

So the button doesn’t turn into a link with its words hidden; it stops being a link. The FAQ link is unaffected, and visitors clicking the button end up in the same place.

What Mueller Suggested Instead

His suggestion leaves the button alone. You move the FAQ link earlier in the page’s code so it comes first, then use CSS to put everything back where visitors expect it. The code order changes, the page looks the same, and both links stay links.

Google’s Martin Splitt made the same point in an SEO 101 session years ago, where his guidance was to use proper anchor markup and avoid buttons and click handlers as navigation.

Why This Matters

Internal anchor text has been an SEO lever for years. That’s why a plan like this sounds reasonable. It also means your homepage’s main button stops being a link, and Mueller wouldn’t expect you to see anything for it.

Looking Ahead

First link priority has gone unconfirmed since at least 2008, roughly as long as people have been running tests to pin it down, and one Reddit reply won’t end that. Anyone who keeps testing it now has Mueller’s version to work from, which changes the order in the code without taking a link away. He gave no indication that changing that order would produce a visible difference.

https://www.searchenginejournal.com/googles-mueller-on-first-link-priority-link-obfuscation/582316/




Gli assistenti AI di coding sono sicuri? Il caso xAI


Gli strumenti di AI per lo sviluppo software promettono di aumentare la produttività degli sviluppatori, ma una recente analisi indipendente riaccende il dibattito sulla sicurezza dei dati affidati agli assistenti di coding. Al centro della vicenda c’è Grok Build, il tool a riga di comando di xAI, accusato di aver trasmesso (in chiaro) ai server dell’azienda interi repository Git, cronologia compresa, insieme a file contenenti credenziali e altri dati sensibili. Secondo il ricercatore che ha condotto l’analisi, inoltre, il comportamento sarebbe avvenuto anche dopo aver attivato l’opzione di esclusione dall’addestramento del modello.

Un’analisi del traffico di rete fa emergere il problema

La vicenda nasce dall’analisi del traffico di rete effettuata dal ricercatore noto come cereblab, che ha instradato Grok Build attraverso mitmproxy per osservare nel dettaglio le comunicazioni tra il client e i server remoti. L’obiettivo era verificare quali dati venissero realmente inviati durante una normale sessione di sviluppo. I risultati non sono stati quelli sperati. Secondo il report, il software avrebbe aperto due canali distinti di comunicazione: uno destinato alle richieste del modello AI e un secondo utilizzato per il caricamento del codice (un comportamento decisamente non atteso e che ha allarmato il ricercatore).

Nel test effettuato su un repository Git di circa 12 GB, il traffico destinato al modello AI sarebbe stato limitato a circa 192 KB, mentre il canale di storage avrebbe trasferito 5,10 GiB di dati suddivisi in 73 blocchi da circa 75 MB ciascuno. Il rapporto tra i due flussi supera le 27.800 volte, un valore incompatibile con il semplice invio del contesto necessario alla conversazione con il modello e che di solito giustifica connessioni parallele. L’analisi sostiene inoltre che il contenuto inviato corrispondesse a un bundle Git completo, comprendente non solo i file correnti ma anche la cronologia del repository.

Anche i segreti sarebbero finiti nel trasferimento

Ancora più delicata è la parte relativa ai secret presenti nel progetto. Durante il test il ricercatore ha inserito volutamente un file .env contenente chiavi API e credenziali fittizie facilmente identificabili. Secondo quanto documentato, tali informazioni sarebbero state trasmesse integralmente durante la comunicazione con i server di xAI. Inoltre, ricostruendo il bundle Git catturato durante il trasferimento, il ricercatore afferma di aver recuperato anche un file che l’agente era stato esplicitamente istruito a non leggere, suggerendo che il caricamento del repository fosse indipendente dalle operazioni realmente effettuate dal modello.

Uno degli aspetti più controversi, secondo cerelab, riguarda l’impostazione “Improve the model”, utilizzata per escludere i propri dati dall’addestramento dell’intelligenza artificiale. Secondo la sua analisi, la disattivazione di questa opzione non avrebbe impedito il trasferimento del repository, ma soltanto il suo eventuale utilizzo per l’addestramento del modello. In altre parole, il codice continuerebbe comunque a lasciare la macchina dello sviluppatore per essere archiviato sui sistemi remoti. Si tratta di una distinzione importante, perché trasmissione, archiviazione e addestramento rappresentano tre aspetti differenti dal punto di vista della sicurezza e della conformità normativa.

xAI avrebbe già modificato il comportamento del servizio

La vicenda, tuttavia, sembra aver avuto un’evoluzione molto rapida. Nei giorni successivi alla pubblicazione del report, lo stesso ricercatore ha ripetuto i test osservando un comportamento differente. In sei prove consecutive non sarebbe più stato rilevato alcun caricamento del repository tramite l’endpoint dedicato allo storage. Al suo posto sarebbero comparsi nuovi flag server-side, tra cui disable_codebase_upload, che sembrerebbero disattivare la funzione senza richiedere un aggiornamento del client. Al momento, però, xAI non ha pubblicato alcun advisory di sicurezza, né un changelog che spieghi ufficialmente la modifica o chiarisca quale sia stato l’impatto del problema sugli utenti che hanno utilizzato Grok Build prima della mitigazione. Anche le note di rilascio più recenti del progetto non fanno riferimento alla questione.

Una lezione per tutti gli agenti di coding

Al di là del singolo caso, l’episodio evidenzia una criticità destinata a diventare sempre più rilevante con la diffusione degli AI coding agent. Molti sviluppatori tendono infatti a considerare questi strumenti come semplici assistenti locali, mentre nella maggior parte dei casi il lavoro viene svolto su infrastrutture cloud. Per le organizzazioni questo significa che repository, codice proprietario, segreti applicativi e informazioni sensibili potrebbero lasciare il perimetro aziendale se non vengono definite precise policy di utilizzo. E addirittura, questo potrebbe succedere anche se le opzioni di non condivisione sono attive, richiedendo una infrastruttura di controllo che vada oltre la semplice policy.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/07/14/gli-assistenti-ai-di-coding-sono-sicuri-il-caso-xai/?utm_source=rss&utm_medium=rss&utm_campaign=gli-assistenti-ai-di-coding-sono-sicuri-il-caso-xai




La guerra ucraina cambia la cybersecurity delle infrastrutture critiche


La guerra in Ucraina non si combatte solo sul terreno, nel mare o nello spazio aereo. Il cyberspazio è uno degli scenari più attivi, dove vengono perpetrati quotidianamente decine di attacchi mirati alle infrastrutture civili e militari. Il continuo bersagliamento di infrastrutture energetiche, reti di comunicazione e servizi pubblici ha praticamente trasformato l’intero Paese in un enorme laboratorio dove si sviluppa la cyber-resilienza. Ma una cosa è proteggere le infrastrutture critiche civili, un’altra quelle militari e, ovviamente, l’Ucraina non ha abbastanza risorse interne per far fronte all’enorme numero di problemi da affrontare. Per questo è stato creato il Tallinn Mechanism, un’iniziativa internazionale nata per sostenere la resilienza digitale delle infrastrutture civili del Paese e che, indirettamente, sta contribuendo ad accrescere anche le capacità difensive delle aziende europee. Ne abbiamo parlato con Alessio Aceti, CEO di HWG Sababa, azienda impegnata in prima fila.

Cos’è il Tallinn Mechanism

Nonostante il nome possa trarre in inganno, il Tallinn Mechanism non è un organismo con sede in Estonia. Il nome deriva semplicemente dalla città in cui si è svolto il primo incontro istituzionale. Si tratta di un programma internazionale di cooperazione civile che coinvolge diversi Paesi europei, insieme a Stati Uniti e Canada, con l’obiettivo di sostenere la digitalizzazione e la sicurezza delle infrastrutture civili ucraine, comprese quelle considerate critiche. Un elemento distintivo dell’iniziativa è la sua natura prettamente civile. Pur essendo presente come osservatore, la NATO non partecipa direttamente alle attività operative.

Il meccanismo funziona come una piattaforma di collaborazione tra settore pubblico e privato. Le istituzioni ucraine pubblicano le proprie esigenze attraverso un portale dedicato, mentre aziende e organizzazioni dei Paesi aderenti partecipano a bandi finanziati dai governi per fornire competenze, tecnologie e servizi. Dal 1° luglio al 31 dicembre, inoltre, l’Italia assume il coordinamento del programma, con il compito di facilitare la collaborazione tra istituzioni e industria.

La formazione OT per le infrastrutture ucraine e il ritorno per l’Italia

Come già accennato, tra le realtà coinvolte figura HWG Sababa che insieme al Competence Center Cyber 4.0 e a partner francesi si è aggiudicata un progetto dedicato alla formazione sulla sicurezza OT (Operational Technology). L’attività è rivolta ai tecnici che operano nelle infrastrutture critiche ucraine, in particolare nei settori della produzione e distribuzione dell’energia.

L’approccio adottato si discosta dalla formazione tradizionale. Le esercitazioni sono infatti costruite attorno a laboratori pratici nei quali gli operatori lavorano direttamente su PLC, sistemi SCADA e digital substation, simulando attacchi realistici e imparando tecniche di rilevamento, contenimento e risposta in uno scenario caratterizzato da minacce costanti. L’aspetto forse più interessante emerso dall’esperienza raccontata durante l’intervista riguarda il valore che queste attività generano anche per il sistema Paese. L’Ucraina rappresenta infatti uno degli ambienti in cui vengono sperimentate per prime nuove tecniche, tattiche e procedure (TTP) adottate dagli attaccanti. Molte delle infrastrutture utilizzate nel Paese impiegano gli stessi sistemi industriali presenti anche nelle aziende italiane, inclusi prodotti di vendor internazionali come Schneider Electric e ABB. Questo consente agli specialisti coinvolti di osservare direttamente modalità di attacco che potrebbero arrivare successivamente anche nell’Europa occidentale. L’esperienza maturata sul campo permette quindi di anticipare le difese, identificando vulnerabilità e sviluppando contromisure prima che determinate campagne diventino una minaccia concreta anche per le organizzazioni italiane.

La guerra cambia anche il cybercrime

Un altro elemento evidenziato durante l’intervista riguarda l’evoluzione delle minacce. Le tecniche sviluppate dai gruppi riconducibili agli Stati-nazione tendono infatti, con il passare del tempo, a essere riutilizzate anche dalla criminalità informatica tradizionale. Secondo gli esperti, questo fenomeno rischia di accelerare ulteriormente con la diffusione dell’Intelligenza Artificiale, che potrebbe abbassare le competenze necessarie per sviluppare campagne offensive sempre più sofisticate. Di conseguenza, strumenti e metodologie oggi osservati in scenari di guerra potrebbero trasformarsi domani nelle tecniche utilizzate dai gruppi ransomware contro aziende di ogni dimensione.

Cybersecurity e sovranità digitale viaggiano insieme

L’esperienza del Tallinn Mechanism alimenta anche una riflessione più ampia sul tema della sovranità digitale. Secondo quanto emerso nell’intervista, costruire competenze nazionali, sviluppare servizi ad alto valore aggiunto e rafforzare la collaborazione tra imprese italiane rappresenta un elemento fondamentale per ridurre la dipendenza tecnologica dall’estero. In quest’ottica, la federazione di competenze e servizi diventa un fattore strategico non soltanto per la cybersecurity, ma anche per la competitività industriale del Paese.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/07/10/la-guerra-ucraina-cambia-la-cybersecurity-delle-infrastrutture-critiche/?utm_source=rss&utm_medium=rss&utm_campaign=la-guerra-ucraina-cambia-la-cybersecurity-delle-infrastrutture-critiche




Google’s New Merchant Listing Structured Data Improves SEO via @sejournal, @martinibuster

Google made a major change to their Merchant Listing structured data requirements in addition to adding clarification on how to use structured data to indicate how long a sale prices will last. In total, there are three new additions but the biggest change by far is the addition of a new Category property. While it’s not a “required” structured data property it’s still a recommended one.

New Category Property

In Schema.org structured data, a Type is a classification of an entity, to say what something is. A structured data Property is an attribute of the Type, it can say what kind of type or add other descriptive details about the Type.

Google added a new category property to the Product structured data, which enables merchants to more granularly classify products directly in markup rather than relying solely on feed attributes. It also gives merchants a way to tie the web page structured data to Google’s own product taxonomy, closing a gap between what’s marked up on the page and what’s submitted through the Merchant Center feed.

Google’s new category property accepts either plain text or a CategoryCode object.

Plain Text

Plain text works like the existing product_type attribute in product feeds. It’s a custom category label that merchants define themselves.

CategoryCode

CategoryCode is a structured object that lets you declare a Google Product Category (GPC) directly in markup, using inCodeSet to point to Google’s taxonomy and codeValue to specify the category, either by numeric ID or full path. The CategoryCode object directly corresponds to the merchant feed specific Google Product Category (GPC). CategoryCode enables merchants to put that same GPC value directly into their on-page structured data instead of it only appearing in the merchant feed.

Here is example structured data showing how it works:

"category": [
{ "@type": "CategoryCode", "inCodeSet": "https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt", "codeValue": "2271"
},
{ "@type": "CategoryCode", "inCodeSet": "https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt", "codeValue": "Apparel & Accessories > Clothing > Dresses"
}, "Dresses", "Special Occasion > Wedding & Bridal Party Dresses"
]

Google’s new guidance explains:

“Text or CategoryCode

Specifies the product’s categories. This property can accept an array of values, mixing plain text strings and CategoryCode objects.

Custom product types: Plain Text values represent your custom product category, similar to the product_type attribute in product feeds. We recommend keeping custom product types under the 750-character limit.

Google Product Category (GPC): To specify a GPC, similar to the google_product_category attribute in product feeds, use the CategoryCode type.

Set @type to CategoryCode.

Set inCodeSet to a Google Product Taxonomy URL (for example, “https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt”).

Set codeValue to the GPC ID (for example, “2271”) or the full category path (for example, “Apparel & Accessories > Clothing > Dresses”).

When using the path format, use > as the separator between levels. Each segment in the path must contain at least one letter. Numeric IDs are also accepted.
You can provide multiple category values. For example, you can include several GPC codes or paths and several custom product type strings.”

Sale Duration Structured Data

Google also added a new section to the Merchant Listing structured data documentation that enables merchants to express how long a sale will last. It adds new documentation about three properties:

  • priceValidUntil
  • validFrom
  • validThrough

Here are the new explanations:

“priceValidUntil

Date

The date and time after which the price will no longer be available, in ISO 8601 format. Your listing may not display if the priceValidUntil property indicates a past date. For details and markup examples, see Sale duration.

validFrom
DateTime or Date

The start date and time when the price is valid, in ISO 8601 format. For details and markup examples, see Sale duration.

validThrough
DateTime or Date

The end date and time when the price is valid, in ISO 8601 format. For details and markup examples, see Sale duration.”

Sale Duration

Lastly there is an entirely new section about Sale Duration. Sale duration is just the date that corresponds to the three structured data properties, priceValidUntil, validFrom, and validThrough. It tells Google exactly when a sale price starts and ends. It’s meant to keep sale pricing accurate in search results, so a listing doesn’t keep showing a deal after it’s expired.

The new documentation explains:

“Sale duration
To specify the period when a sale price is active, use the following schema.org properties in ISO 8601 format (for example, 2025-12-31T23:59:59+01:00):

Start date and time: Use the validFrom property.
End date and time: Use either the validThrough property or the priceValidUntil property.

Best practices:
Provide both a start and an end date/time to clearly define the sale period.
Ensure the start date/time (from the validFrom property) is earlier than or equal to the end date/time (from the validThrough property or the priceValidUntil property).

We recommend including the time and timezone in the ISO 8601 format for accuracy in Google systems.

Where to place the properties:
On the Offer node: You can add the validFrom property and (the validThrough property or the priceValidUntil property) directly to the Offer node. These dates apply when the price property on the Offer node represents the current active sale price.

On a PriceSpecification node: If the sale price is defined within a PriceSpecification node (typically one without the priceType property when a StrikethroughPrice value is also present), add the validFrom property and the validThrough property to that specific PriceSpecification node. Note that the priceValidUntil property isn’t applicable to the PriceSpecification type.”

How It Benefits Merchants

Google’s new documentation for the Merchant Listing Structured Data enables merchants to express category and sale pricing details directly in structured data, which helps Google display accurate product information in the search results. The new structured data properties create unity between the Schema.org structured data and the Merchant Feed Google Product Category (GPC) data. Category now matches product_type and google_product_category from Merchant Center feeds, and Sale Duration matches sale_price_effective_date, so merchants have a page-level way to express them instead of relying solely on the feed.

Featured Image by Shutterstock/allegro

https://www.searchenginejournal.com/googles-new-merchant-listing-structured-data-improves-seo/581879/




YouTube Moves Ahead of Spotify As UK’s Top Podcast Service via @sejournal, @MattGSouthern

YouTube has become the top podcast platform in the UK, surpassing Spotify for the first time on record, according to Edison Research. Among weekly podcast listeners aged 15 and over, 29% now cite YouTube as their preferred service, compared to 28% for Spotify.

The one-point gap is quite small, and Edison describes the outcome as a first “on record” rather than a confirmed new trend. Edison Research at SSRS previewed YouTube’s rapid rise to become the top podcast service in the UK, ahead of a more detailed report expected later this month.

What the Data Shows

Edison’s trend data shows YouTube’s growth in the UK over four key periods. In 2023, YouTube held 19% of the primary platform share, increasing modestly to 20% in 2024, then rising to 25% in 2025, and reaching 29% in the first quarter of 2026. Meanwhile, Spotify’s share declined over the same timeframe, starting at 33% in 2023, slightly increasing to 34% in 2024, then dropping to 30% in 2025, and finally down to 28% currently.

BBC Sounds is the third most-used service, with 15% in the current reading, maintaining that share from 2024 and 2025, after 13% in 2023. Apple Podcasts holds 10%, a decrease from 12% in 2023. The remaining apps are grouped into an “Other” category, which makes up 18%.

Edison Podcast Metrics UK is based on interviews with 8,000 UK podcast listeners aged 15 and over each year. Edison did not disclose the sample size behind the Q1 2026 reading.

The US Crossover Came First

YouTube reached the top of the US podcast rankings about two years before the UK. In Edison’s US reading from October 2024, YouTube took 31% of primary-platform share among weekly podcast listeners aged 13 and over, against Spotify’s 27% and Apple Podcasts’ 15%. Edison tied much of the US move to younger listeners and video, reporting that 84% of Gen Z monthly podcast listeners ever listen to or watch podcasts with a video component.

SEJ has covered how YouTube reported more than one billion monthly active viewers of podcast content and became the platform Americans use most. The UK reading extends that same video-native pattern to a second major market.

Why Edison Says the UK Trailed the US

Edison points to the UK’s public-media presence as a possible reason YouTube climbed more slowly in the UK than in the US. BBC Sounds draws 15% of UK podcast consumers as their main service, a level Edison says has no equal among US public-media podcast offerings. A UK listener choosing among YouTube, Spotify, Apple Podcasts, and BBC Sounds weighs a different set of options than a US listener choosing among the first three, which Edison gives as part of why the two markets moved at different speeds.

Why This Matters

The UK now looks like the US did two years ago, and the direction of Edison’s trend line matters more than the one-point margin. For a show deciding where to make its main home, YouTube is now the platform the largest share of UK weekly listeners name.

BBC Sounds is the caveat when you compare the UK with the US. A UK plan built on American platform-share assumptions understates how much of the domestic audience sits with a public-service option the US market doesn’t have. The Edison data gives a UK-focused show a reason to invest in video, as long as that BBC Sounds share stays in the model.

Looking Ahead

Edison will host a webinar on July 16, 2026, at 2pm BST and 9am EDT to present the full UK Podcast Consumer 2026 report. The session will also explore UK audience opinions on AI in podcasting, which will be of interest once the data is publicly available.

The lead is one point, and Spotify has slipped from 34% in 2024 to 28% now while YouTube’s gains have held across the series. The next reading will show whether the order holds beyond this first crossover.


Featured Image: sitthiphong/Shutterstock

https://www.searchenginejournal.com/youtube-moves-ahead-of-spotify-as-uks-top-podcast-service/581832/




Google Search Hits All-Time Usage Record During World Cup via @sejournal, @MattGSouthern

Nick Fox, Google’s senior vice president of Knowledge & Information, said that Google Search reached its highest usage ever on July 7, coinciding with Argentina’s comeback victory over Egypt at the World Cup.

In the post, Fox wrote: “Google Search broke all prior usage records and saw its highest usage in history right after Argentina scored their winning goal in yesterday’s match!”

Robby Stein, vice president of product for Google Search, amplified the post, writing that Search “hit all time high in usage yesterday.”

Fox didn’t share any specific figures or methods for the record, and Google hasn’t released a blog post or data about it.

The statement is consistent with Google’s public messaging this year. During its Q1 2026 earnings call, Pichai mentioned that “Search queries are at an all-time high,” though specific numbers weren’t shared.

Google has pointed to a World Cup traffic record before. In the 2022 final, Pichai stated that Search reached its highest traffic in 25 years, again without providing exact figures.

Argentina defeated Egypt 3-2 in the Round of 16 on July 7, overturning a two-goal deficit with Enzo Fernández scoring a stoppage-time winning header. Their quarterfinal against Switzerland is next, which tracks with Fox’s line about looking ahead to “the semis and final.”

Why This Matters

There’s been a lot of talk recently about whether AI answers are changing the way we search. A record day, if it holds up, is a reminder that Google is still where people turn the moment something happens live.

Keep in mind that ‘record usage’ and ‘record queries’ refer to Google’s side, not clicks to publisher sites. It’s possible for search usage to increase even when outbound clicks to your pages remain low.

Fox also didn’t define how “usage” is counted, or say whether the figure excludes bots. Imperva, which sells bot-management tools, estimated that automated traffic made up more than 53% of web traffic in 2025, up from 51% in 2024. None of that shows Google’s record was driven by bots. Without a clear methodology, it’s hard for external readers to understand exactly how Google counts automated traffic.

Looking Ahead

Google put no figures behind the 2022 claim and none behind this one, so whether it backs the record with data is the thing to watch. Argentina’s quarterfinal is next, and another usage spike is possible if the run continues.

https://www.searchenginejournal.com/google-says-search-hit-all-time-usage-high-during-world-cup/581796/




Google Ads Expands Travel Campaigns To Things To Do And Events via @sejournal, @brookeosmundson

Google Ads is expanding its Search campaigns for Travel beta to two additional verticals: Things to Do and Events.

Google announced the update in a post on X and LinkedIn on July 8, 2026. Advertisers selling attractions, tours, and event tickets can now access the campaign type through an open beta, although availability remains limited.

The expansion gives eligible advertisers another campaign option to test alongside existing Search ands Performance Max campaigns.

What’s Changing With Search Campaigns For Travel

Search campaigns for Travel is a Google Ads campaign type designed for travel-related advertisers. It first appeared as Google expanded AI-powered campaign types across Travel and Shopping earlier this year.

With this update, the beta now extends beyond traditional travel categories to include Things to Do and Events. That means advertisers promoting attractions, guided tours, and event tickets may now be eligible to use the campaign type.

The announcement came as part of a five-post thread. At the time of writing, Google has not shared complete details around eligibility, supported features, or geographic availability.

Why This Matters

Attractions, tours, and event tickets share many of the same characteristics as hotel or airline bookings. Availability changes frequently, pricing can fluctuate, and purchase decisions are often tied to specific dates or locations. Those are all areas where Google’s newer campaign types have increasingly relied on automation to determine which searches are most likely to convert.

Until now, advertisers in these verticals have generally relied on standard Search campaigns or Performance Max. Expanding the Travel campaign type suggests Google sees these businesses as a natural fit for a more specialized campaign format.

The update also aligns with Google’s broader push toward AI-driven campaign management. Over the past year, the company has introduced AI Max across additional campaign types while continuing to consolidate older campaign formats.

While Google hasn’t explained why it selected these verticals, they fit naturally alongside other travel-related advertisers already using the campaign type.

What Advertisers Should Do

If you’re eligible for the beta, treat it as a controlled test rather than a replacement for your existing campaigns.

Review your current Search and Performance Max performance, set aside a limited testing budget, and compare booking or ticket sales against your existing campaign mix. Since Google has not released complete feature details, it’s also worth setting expectations internally that functionality may continue to evolve throughout the beta.

What’s Still Unknown

Google has not yet confirmed which bidding strategies, assets, reporting capabilities, or feed requirements will be available for the Things to Do and Events verticals. It also remains unclear how these campaigns will interact with existing AI Max for Travel functionality.

We’ll update this article as Google shares additional details about eligibility, features, and availability.

Featured image: Master1305 / Shutterstock

https://www.searchenginejournal.com/google-search-campaigns-travel-things-to-do-events-beta/581816/