Scott Kelby’s Bracket & Bounce Field Test

If you’ve ever looked at a portrait taken with your camera’s built-in flash or a speedlight mounted directly on the hot shoe and thought it looked harsh, flat, or just plain uninspiring, you’re not imagining it.

The biggest problem isn’t the flash itself. It’s where the light is coming from.

When your flash is mounted directly above the camera, the light travels in exactly the same direction as your lens. That removes shadows, flattens facial features, creates distracting reflections, and often leaves your subject looking as though they were photographed under a security light.

Professional photographers have known for years that moving the light away from the camera is one of the quickest ways to dramatically improve an image.

Why Off-Camera Flash Looks Better 

The human eye is used to seeing light come from the side, above, through windows, or from the sun. Directional light creates depth, texture, and dimension.

By moving your flash even a short distance away from the camera, you immediately begin creating:

  • More natural-looking shadows
  • Better separation from the background
  • Improved facial modeling
  • More interesting catchlights in the eyes
  • A softer, more three-dimensional look

It’s one of the simplest changes you can make that produces a professional-looking result.

The Challenge

Traditional off-camera flash isn’t always convenient. You often need a light stand, wireless triggers, extra bags, and more time to set everything up. That’s fine in a controlled studio, but much less practical when photographing events, weddings, travel, or environmental portraits.

Many photographers simply leave the flash on the camera because it’s quicker. Unfortunately, that usually means accepting lower-quality light.

Enter the Bracket & Bounce System

The Platypod Bracket & Bounce system was designed to bridge that gap.

Instead of carrying a full lighting kit, it allows photographers to move their flash off-axis while keeping everything attached to the camera. The result is dramatically improved lighting without dramatically increasing the size of your setup.

It’s compact, lightweight, and quick to deploy, making it ideal for photographers who need to work fast without sacrificing image quality.

Whether you’re photographing people indoors, creating environmental portraits, or shooting events, getting the flash away from the lens can completely transform the look of your images.

See the Difference for Yourself

On Camera Flash
With Bracket & Bounce

Scott Kelby has spent decades teaching photographers around the world and has seen just about every lighting setup imaginable.

In his video on PlatypodTV, he explains why he prefers the Bracket & Bounce system, demonstrates the difference between traditional on-camera flash and off-camera lighting, and shows just how much of an impact a small change in light position can make.

If you’ve ever wondered why your flash photos don’t quite have that professional look, this video does an excellent job of showing exactly why.

[embedded content]

https://layersmagazine.com/platypod-bracket-and-bounce-field-test.html




Google Search Console Adds Social & Video Platform Properties via @sejournal, @MattGSouthern

Google is introducing a new property type in Search Console called platform properties, which lets you monitor how social media and video posts perform in Google Search and Discover. This feature supports platforms such as Instagram, TikTok, X, and YouTube and is available even to creators who don’t have their own websites.

Moshe Samet, Product Manager Lead for Search Console, announced the feature in a Search Central blog post. Once an account is connected, a platform property shows which search terms lead people to your posts and how your audience interacts with that content.

The Reports You Get

Each platform property includes the reporting you would expect from a Search Console property, tailored to social and video content.

The Performance report displays total clicks, impressions, and other related metrics, allowing filtering and sorting to identify which posts and queries generate the most traffic. You can also export the data for further analysis in other tools.

The Insights report provides an overview of recent traffic patterns, your most successful posts, and the ways users find your account on Google.

Achievements monitor progress toward milestones, such as surpassing a new total click threshold from Search within a 28-day period.

How To Add a Platform Property

Setting one up involves following Search Console’s verification process: open Search Console, navigate to the verification page or property selector, select Add property, then choose Instagram, TikTok, X, or YouTube and follow the on-screen instructions to authorize the connection.

How This Differs From Search Profiles

Platform properties are distinct from Search profiles, which Google introduced in June as public profile pages for qualified creators and publishers. A Search profile is a shareable page that consolidates a creator’s content for followers. In contrast, a platform property focuses on analytics, showing how those posts perform in Search rather than directly exposing them to an audience. The current feature builds on a December 2025 experiment that initially integrated social-channel data into Search Console.

Why This Matters

You can now track performance across social media and video platforms, alongside your website’s Search performance. This feature allows creators who’ve never had a verified site to see how their posts gain visibility in Search.

Looking Ahead

Platform properties will be gradually available over the next few weeks, so the option might not be visible in your account immediately. Google is initially launching with four supported platforms and directs creators to its help documentation for setup guidance, along with providing a feedback link in Search Console and the Search Central Community.

https://www.searchenginejournal.com/google-search-console-adds-social-video-platform-properties/581634/




Google On Using Markdown For AI SEO via @sejournal, @martinibuster

Google’s John Mueller responded to a post on Bluesky that lamented all the effort being wasted on AI agent accessibility instead of focusing on the more productive activity of making sites accessible for humans.

Tactical SEO

One of the consistent aspects of the history of SEO is that practitioners tend to follow tactical trends if it’s apparent that everyone else is doing it. I guess it’s human nature.

Back in the early days there was a guy who built a directory and purchased enough high PageRank links to the home page to get it to about a PageRank of 7 (on a scale of 1-10). SEOs were practically pushing each other out of the way to hand this guy their money. He sold thousands of links from his directory, and nobody thought to check if any of the links actually made a ranking difference. It was easy to check, but nobody did.

The latest tactic is LLMs.txt and creating markdown pages for AI agent consumption. Cloudflare announced in February that their infrastructure can automatically create markdown files, largely as a way for developers to save LLM token consumption. Their announcement stated that OAI-SearchBot, OpenAI’s search crawler, was consuming markdown pages.

OpenAI’s official documentation explicitly positions its OAI-SearchBot as crawling websites and does not mention or recommend markdown files.

“OAI-SearchBot is for search. OAI-SearchBot is used to surface websites in search results in ChatGPT’s search features. Sites that are opted out of OAI-SearchBot will not be shown in ChatGPT search answers, though can still appear as navigational links. To help ensure your site appears in search results, we recommend allowing OAI-SearchBot in your site’s robots.txt file and allowing requests from our published IP ranges below.”

Yes, it can crawl markdown if it’s pointed to it but that’s not what it’s out there for.

Stephanie Walter posted:

“Sad truth: we are making the web accessible for AIs, not for people.
Some sites now offer a text version for LLMs, but still skip real accessibility needs like proper heading structure, landmarks that screen reader users need.”

Google’s John Mueller responded:

“A properly made website works well for AI agents … and search engines, and LLMs, and above all, for actual people.

If you’re trying to fix accessibility issues by making a separate “agent-friendly” version, you are just building technical debt. You’ll have to redo it multiple times. Just fix it.”

AI Agents Crawl HTML

It’s a relatively trivial thing to crawl HTML. Search engines have been doing it for over thirty years. Making sites accessible for everyone makes sense, especially since it’s user behavior signals that have always driven search engine rankings. From links to users searching with a brand name, Google has consistently used user signals for ranking purposes.

So, from the perspective of SEO, it makes a load of sense to make websites accessible for everyone.

Featured Image by Shutterstock/DETHAL

https://www.searchenginejournal.com/google-on-using-markdown-for-ai-seo/581606/




AI, il nuovo fronte della sicurezza: il red teaming diventa indispensabile


L’intelligenza artificiale sta entrando nelle aziende con una velocità che non ha precedenti, ma la sua diffusione sta facendo emergere una realtà che molti responsabili della sicurezza stanno iniziando a sperimentare direttamente: i tradizionali strumenti di difesa non sono stati progettati per proteggere sistemi che ragionano attraverso il linguaggio naturale. Firewall, Web Application Firewall e sistemi di protezione delle reti continuano a svolgere il loro ruolo, ma davanti a chatbot, agenti AI e Large Language Model si apre una superficie di attacco completamente nuova.

Secondo Gartner, entro quest’anno l’80% delle organizzazioni utilizzerà soluzioni basate sull’intelligenza artificiale, una crescita che supera in velocità perfino quella vissuta in passato da cloud computing, dispositivi mobili e Internet. Una diffusione tanto rapida quanto impegnativa dal punto di vista della cybersecurity.

Quando la conversazione diventa la superficie di attacco

L’evoluzione dell’AI segue percorsi differenti. Alcune aziende si limitano all’utilizzo di strumenti come ChatGPT, Copilot o Gemini per aumentare la produttività individuale, mentre altre stanno sviluppando chatbot interni, assistenti per il customer care oppure sistemi agentici capaci di eseguire attività autonome.

Ma in queste implementazioni più avanzate, la sicurezza cambia completamente natura. Il problema non riguarda più esclusivamente il codice o il traffico di rete, ma il modo in cui il modello interpreta, elabora e restituisce informazioni attraverso il linguaggio naturale. Una conversazione non può essere filtrata come un pacchetto IP. È questo il motivo per cui molti controlli tradizionali risultano inefficaci contro gli attacchi rivolti ai sistemi di AI.

Infatti, secondo i dati riportati da F5, il 75% dei CISO ha già registrato incidenti di sicurezza legati all’intelligenza artificiale, mentre il 91% dichiara di aver individuato tentativi di attacco contro la propria infrastruttura AI. Ancora più significativo è il fatto che il 94% considera ormai prioritario sottoporre le applicazioni AI a test di sicurezza specifici.

Dagli errori logici ai nuovi attacchi cognitivi

Le vulnerabilità che colpiscono le piattaforme di AI non sono necessariamente nuove dal punto di vista tecnico, ma assumono caratteristiche completamente differenti quando vengono inserite in sistemi basati su Large Language Model. Un errore nell’isolamento dei tenant, ad esempio, può trasformarsi nella restituzione di informazioni appartenenti ad altre organizzazioni direttamente all’interno di una conversazione naturale, rendendo molto difficile individuare il problema. Anche i classici attacchi di prompt injection possono avere conseguenze particolarmente gravi quando il modello dispone dell’autorizzazione a utilizzare strumenti esterni o ad interagire con sistemi aziendali. Se il controllo delle autorizzazioni viene affidato al modello anziché all’infrastruttura applicativa, il rischio aumenta sensibilmente.

Accanto a questi scenari stanno emergendo nuove categorie di minacce, che comprendono tecniche di jailbreak sempre più sofisticate, data poisoning durante l’addestramento e meccanismi di token compression, nei quali istruzioni malevole vengono nascoste in forme comprensibili al modello ma praticamente invisibili agli operatori umani.

Perché i test tradizionali non bastano più

Uno degli aspetti più complessi dell’AI riguarda il fatto che non ci si trova più davanti a software deterministico. Ogni conversazione può produrre risultati differenti in base al contesto, alla memoria dell’agente, ai documenti recuperati tramite retrieval oppure agli strumenti che il modello può utilizzare. Questo rende estremamente difficile applicare i normali processi di vulnerability assessment. Mentre in passato era sufficiente verificare il comportamento di un’applicazione seguendo scenari relativamente prevedibili, oggi le possibili combinazioni diventano praticamente infinite. Testarle manualmente è semplicemente irrealistico, soprattutto quando un’organizzazione gestisce decine o centinaia di chatbot o agenti AI.

Per questo diventa indispensabile strutturare un sistema di AI Red Teaming, ovvero la simulazione sistematica di attacchi contro sistemi basati sull’intelligenza artificiale per verificarne il comportamento in condizioni ostili. L’obiettivo non è soltanto individuare vulnerabilità tecniche, ma comprendere come il sistema reagisce a prompt malevoli, tentativi di manipolazione, richieste ambigue o scenari progettati per aggirare i controlli di sicurezza. Un approccio che deve produrre risultati riproducibili, permettendo agli sviluppatori di identificare esattamente quali conversazioni hanno generato il comportamento indesiderato e quali condizioni lo hanno reso possibile.

Normative e compliance spingono verso test continui

L’importanza del red teaming non nasce esclusivamente da esigenze tecnologichema anche dal quadro normativo che sta evolvendo rapidamente. L’AI Act europeo introduce esplicitamente attività di adversarial testing per determinate categorie di sistemi AI, mentre negli Stati Uniti organizzazioni come NIST e CISA stanno promuovendo procedure di verifica sempre più strutturate, soprattutto nei contesti considerati mission critical. La sicurezza dell’intelligenza artificiale diventa quindi non soltanto una misura di protezione, ma anche un requisito di conformità e governance.

Ma c’è un risvolto per alcuni versi “inatteso”. Storicamente, possiamo tutti ricordare l’avversione delle proprietà nei confronti della cybersecurity, troppo spesso vista come una spesa e addirittura un fastidio che tendeva a rallentare il business. Nel caso dell’intelligenza artificiale potrebbe invece verificarsi il contrario. Disporre di test automatizzati, evidenze documentate e verifiche continue consente infatti di portare più rapidamente in produzione nuovi casi d’uso, offrendo ai team di compliance e agli auditor elementi concreti per valutare il rischio.

L’AI red teaming si sta quindi trasformando da semplice attività specialistica a componente fondamentale della sicurezza delle applicazioni AI, permettendo alle aziende di adottare chatbot, agenti e workflow intelligenti con un livello di fiducia molto superiore rispetto agli approcci tradizionali. Purtroppo, non mancano le sfide. Molte delle competenze necessarie per fare AI Red Teaming sono ancora rare, ma si spera che verranno formate in tempi ragionevolmente brevi dal settore accademico e, soprattutto, dalle stesse aziende.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/07/06/ai-il-nuovo-fronte-della-sicurezza-il-red-teaming-diventa-indispensabile/?utm_source=rss&utm_medium=rss&utm_campaign=ai-il-nuovo-fronte-della-sicurezza-il-red-teaming-diventa-indispensabile




In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting

SecurityWeek’s cybersecurity news weekly roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.

Here are this week’s highlights:

Anonymous-linked hacker Aubrey Cottle jailed over Texas GOP cyberattack

Aubrey Cottle, a Canadian hacker associated with the hacktivist group Anonymous, has been sentenced to 18 months in prison for his involvement in a cyberattack on the Texas Republican Party’s website in September 2021. Cottle, 39, of Oshawa, Ontario, pleaded guilty to defacing the website, exfiltrating data from a Texas GOP server, and publishing the data online.

14 million impacted by KDDI data breach

Advertisement. Scroll to continue reading.

Japanese telecoms provider KDDI has disclosed (PDF) a data breach likely impacting the email addresses and passwords of 14,22 million people. The incident affected five ISP operators, including BIGLOBE, Chubu Telecommunications C., JCOM Co., NIFTY Corporation, and STNet. 

Push Security targeted in poisoned tenant attack

Three years after detailing the poisoned tenant attack, Push Security was targeted using the technique via OpenAI’s organization invitation feature. Multiple employees received an OpenAI invitation to join Push Security Inc. After they would join the tenant, the attacker could spy on their activities or target them with further social engineering. 

Rust-based PamStealer targeting macOS

Jamf has detailed PamStealer, an information stealer targeting macOS that validates the harvested credentials via Pluggable Authentication Modules (PAM) before using them. The malware is distributed as a compiled AppleScript file impersonating the open source clipboard manager Maccy.

Russian hackers behind the 2025 Jaguar Land Rover hack

The cyberattack that severely disrupted Jaguar Land Rover’s operations in September 2025 was mounted by Russian hackers, The New York Times says. Microsoft reportedly notified the car manufacturer about the hacking group, with Mandiant, Palo Alto Networks, and US and UK law enforcement agencies also involved in the investigation. 

Pegasus spyware targeted a European Parliament member investigating it

Former member of the European Parliament Stelios Kouloglou was hacked with NSO Group’s Pegasus spyware while he was investigating Pegasus abuse cases, as part of the PEGA committee, Citizen Lab discovered. The targeting has not been attributed to a specific government, and there is no evidence that the Greek Government was involved. 

Researcher drops dozens of zero-days in open source projects

A researcher known as Bikini has published proof-of-concept (PoC) code targeting dozens of zero-day vulnerabilities in multiple open source projects, including FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC. Nine of the security defects have been assigned a CVE identifier. The issues, the researcher says, were surfaced via LLM fuzzing. 

Pro-Russia influence operations are shifting

Four years into Russia’s invasion of Ukraine, pro-Russia influence operations are shifting from their single focus on Ukraine to pre-war objectives, Google says. Covert pro-Russia influence operations are targeting the US, European Union members, NATO, Russia’s neighbors, the Middle East and Africa, and internal entities. They focus on global events, elections, the war in Ukraine, and emerging geopolitical developments and events, and are increasingly relying on generative AI. 

Venezuelans sentenced in the US over ATM jackpotting

Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, have been sentenced to 78 months in prison in the US for their involvement in ATM jackpotting activities. As part of a sophisticated criminal group, they built and deployed a variant of the Ploutus malware on ATMs across the US and used it to withdraw money without authorization. They were also ordered to jointly pay $1.5 million in restitution. 96 other defendants have been charged over their roles in the operation. 

Cisco and Synology patches

Cisco has released fixes for seven ClamAV vulnerabilities impacting Secure Endpoint Connector for Windows, Linux, and macOS, and Secure Endpoint Private Cloud, and for one flaw in Catalyst Center. Synology resolved three security defects in MailPlus Server, including two critical bugs that could allow attackers to read or write arbitrary files and cause DoS conditions.

Join the AI Risk Summit | Ritz-Carlton, Half Moon Bay

https://www.securityweek.com/in-other-news-canadian-hacker-jailed-open-source-zero-days-two-sentenced-for-atm-jackpotting/




Google Says AI Visibility Hinges On Content People Actually Want To Read via @sejournal, @martinibuster

Google’s VP of Search, Liz Reid, sat down for an interview where she talked about the relationship between Google and publishers. When asked what the new rules are for showing up in AI search, she said that publishers need to publish content that people actually want to read.

Google Says Publisher Traffic Loss Is Not Just AI

One of the points that Reid stressed is that publisher traffic loss is not just about AI. She put part of the blame on people seeking out non-textual content. Her answer was in the context of what she would “say to publishers about the reality of this new time.”

Reid answered:

“I think to start with, there are, first of all, multiple things going on besides AI, right? One of the things that we see is that people are often going for new formats, right?
They want to see videos, not just text. They’re often going to social media for content.

There was a recent study from Reuters around this, really just talking about how people are shifting, and so one of the things I would generally tell publishers is make sure you’re innovating with what users want and how they want, right?”

Google Says Publishers Must Make Content People Want To Read

The next part of her answer to the question of what publishers need to know about the “reality of this new time” is that if publishers want to be seen on AI search, they need to not make the kind of slop content that is the “1,000th copy” of everything else. She put the burden on publishers to step up and make better content that people actually want to read.

She explained:

“I think the second thing that is really important is that people, to the extent that you produce really interesting expertise content, we still see that people are interested in that, right?

…And so the more that publishers produce content that is really where they shine, what they bring to the table, that it’s unique, it’s not the 1000th copy of the same story, but it’s something that has an interesting take on it. The more I think we’ll see that people will continue to click through and read that.”

What Publishers Can Do To Be More Visible In AI

The interview hosts circled back to what publishers can do to make content more visible in AI. They tried to elicit an answer that addressed the “new direction” that AI search is headed in, noting that publishers are concerned.

They asked:

“What can, what can publishers do or creators do to make their content more visible to AI? If this is something, if this is kind of the new direction that all of this is headed, which it clearly is, and publishers are concerned about getting the right eyeballs on their content.

How can they work with the system to ensure that they’re kind of playing by the new set of rules and getting their content maximized in front of the right places at the right time?”

Liz Reid answered that the way to be seen is to make content that people want to read.

She explained:

“Yeah, I mean, I think I would probably put it in two buckets. The first is make sure we can access your content. Like if you block the content, that will not work. If it makes it hard to discover, then that’s difficult.  We have various tools in webmaster console that give you controls so that publishers can choose. But making it easier for us to access is certainly the first step.

But we’ve also published an updated set of guidelines around for website owners and publishers to think about how they make great content in this day. At the heart of it is really this continuation of, if you want people to click through, then implicit in there is you want people to read your content.

That means you need to make content that people want to read, right? So the more you build the content that your audience will love, the more it will work. The more you build content that you think is just designed for the search engine, but not for the audience, then people will learn that over time.

So the more it brings in your expertise, that is sort of fresh and relevant content of what people are curious about, that it brings in that sort of experience, that detail and richness, that’s really great.”

Takeaways

Liz Reid’s comments show that Google is increasingly viewing publisher success in AI Search as dependent on two conditions:

  1. Let Google crawl everything.
  2. Create content that people actually want to read.

That kind of approach ignores the Google Zero fears that haunt even big-brand sites that are experiencing declines in search referrals. If the big-brand sites are having a freakout about declining search referrals, where does that leave small-brand publishers who write recipe blogs, product reviews, travel guides, advice, and news?

Watch the interview at about the 18 minute mark:

[embedded content]

Featured Image by Shutterstock/Roman Samborskyi

https://www.searchenginejournal.com/google-says-make-content-people-want-to-read/580642/




Bruce Clay, One of the Founding Figures of SEO, Has Died via @sejournal, @martinibuster

Bruce Clay, one of the first generation of search engine optimization experts, has passed away. Much of the terminology that he coined and many of the concepts that he pioneered continue to be used today.

Thirty Years Of SEO

Clay was among the cohort of SEOs who were learning and applying the art of optimization in the mid-nineteen nineties. While the SEO industry itself has a history of being divided by various practices and forums they belonged to, Bruce Clay always stood apart, not really belonging to one group or another but rather as his own person.

One of the approaches to SEO he is most remembered for is the concept of siloing content. If you’re one of the SEOs who organizes content in topic silos, you have Bruce to thank for that terminology.

Bruce Clay The Person

Bruce Clay was to many people someone whose articles taught them about SEO, a person to catch up with at search conferences, and to many a friend.

Photo Of Bruce Clay And Ash Nallwalla At A Conference

Image by Brendan O’Connell

Michael Bonfils (LinkedIn profile) shared his personal experience:

“There are three people who I learned SEO from back in the mid 90s, that was Danny Sullivan, Bruce Clay and Stephen Mahaney. Each offered me viewpoints that I’d consider valid or invalid. I wouldn’t have had a career without them. Although I personally know Danny, and indirectly corresponded with Stephen, Bruce was actually my friend.

So from a career perspective, I can’t say enough about his solid determination, the care he put into his work, the sheer amount of people who he taught and those who went off to teach others. This guy was the Yoda of search. He was who us OGs relied on.

From a personal perspective, he was my friend. I’m broken hearted. He wasn’t a stranger to me, it was: “Hey Hey Michael!” and a hug. Then a laugh about either something I said to him or something he said to me. So as a friend who just lost a friend. I’m sad. May he rest in peace, legend.”

Bill Hartzer (LinkedIn profile) published a tribute to Clay:

“I lost a friend. I’ve been sitting with this news, trying to figure out how to put into words what Bruce meant to me, to the people who worked with him, and to an entire industry that many people don’t realize he helped build from the ground up.”

He listed all the contributions to the search marketing community, among them having coined the phrase that is central to it:

“Bruce is credited with being the first person to use the term “search engine optimization.” Danny Sullivan himself confirmed that. Think about that for a moment. The very phrase that defines what thousands of professionals do every day — Bruce Clay coined it.”

Debra Mastaler (LinkedIn profile) shared her memories of Bruce:

“I first met Bruce in 2003 at an SES conference in California. When he learned it was my first time speaking at a conference, he went out of his way to introduce me to people and say hello between sessions. It was a kindness I long remembered.

To this day, when I hear the word “silos”, I think of Bruce. I bet Jill, Bill and Eric are in SEO heaven arguing with him over that one. RIP Bruce.”

For me, Bruce Clay’s innovation was to stand apart as an individual with original ideas, freely shared. I met him countless times at search conferences and our interactions were always warm and pleasant. Connecting people’s faces with names is not easy when one meets hundreds of people at search conferences, but he always seemed to remember mine over the course of twenty-plus years. He also had a knack for making people feel at the center of a conversation. There was no ego or overblown self-regard to him. He was just Bruce Clay, and if he was speaking to you, then you were the most important person in that room.

Books Authored By Clay

There are currently two physical books for sale that he has authored:

  • Search Engine Optimization All-in-One For Dummies
  • Content Marketing Strategies for Professionals: How to Use Content Marketing and SEO to Communicate with Impact, Generate Sales and Get Found by Search Engines

And he has published many digital books and guides as well:

  • Declaration of SEO: 6 Fundamental Truths To Live By
  • Google Analytics 4: What It Is and How To Get Started
  • Google’s Page Experience Update: A Complete Guide
  • SEO Siloing: How To Create a Relevant Website
  • The Guide to SEO for CMOs: Key Strategies for 2021
  • The New Link Building Manifesto: How To Earn Links That Count

Bruce Clay Will Be Missed

Many in the search marketing community are mourning his loss, but his spirit will live on in many of the approaches to SEO that remain relevant today.

https://www.searchenginejournal.com/bruce-clay-seo-pioneer-who-invented-content-siloing-has-died/580602/




Google Answers Question About SEO For AI Agents via @sejournal, @martinibuster

Google’s John Mueller responded to a question about whether Google’s search quality principles will change as AI agents increasingly browse websites on behalf of users. The answer may matter more to site owners than it first appears.

Question About Agentic Browsers And Search Quality Principles

An SEO asked Mueller on Bluesky whether Google’s guidance around satisfying user experiences, including principles around things like images and page design, would evolve as agentic AI tools gain the ability to navigate and retrieve information from websites autonomously.
The question reflects a concern that has been growing in the SEO community as tools like Google Gemini become capable of browsing websites, completing tasks, and returning answers to users without the user ever directly visiting a page.

They asked:

“Hi John – Given Computer use is now a built-in tool for Gemini 3.5 Flash, and as agentic becomes more of a “thing”, would you expect principles like “Images provide a satisfying experience” to evolve since the satisfying experience is an information agent? Curios on your thoughts.”

Websites Useful For Humans Will Generally Also Work For Agentic Browsers

Mueller explained that most of Google’s existing quality principles will remain in place. A website that is useful for human users will generally also be useful for agentic browsers.

He responded:

“I expect most principles will remain the same. A website that’s useful for users, will generally also be useful for agentic browsers.”

Mueller’s response means that it’s a good idea to keep making content useful for site visitors, which also means the site layout, navigation, and internal linking. AI agents do not change the fundamentals that Google’s algorithms are still picking up on external user signals for ranking purposes, especially signals that indicate site popularity with users.

Blindly Blocking Agentic Browsers Could Become An SEO Problem

Mueller’s answer also contained the observation that some details will evolve, and that site owners should avoid blindly blocking agentic browsers.

He said:

“Some details will undoubtedly evolve (and new basics – such as … not blindly blocking agentic browsers … will come into play), but in the end, it’s still users.”

Mueller’s response draws a line between content quality and technical accessibility. A site can meet Google’s quality standards and still create problems for itself if AI agents are blocked from accessing or interacting with its content.

In some ways this is similar to how nofollow links became an issue for some sites when it was introduced many years ago. Some site owners blocked off important sections of their websites in order to drive more PageRank to the pages they thought were important, giving zero priority to actually important parts of a website like the About Us pages.

The agentic browser situation may follow a similar pattern, where technical decisions made for one reason end up having unintended SEO consequences.

One way to think about it is that Google’s definition of a quality website is not being rewritten for the agentic era. The standards already in place were written for human users, and if AI agents are serving human users, then satisfying those agents is arguably the same job. What changes is the technical considerations of accommodating AI agents, not the underlying expectation of what a good website is.

Related Articles:

Google Gemini Can Now Control Your Computer. Hackers Are Already Targeting AI Agents

Google DeepMind: Traps For AI Agents Are Already Stealing Money

Featured Image by Shutterstock/Mijansk786

https://www.searchenginejournal.com/google-seo-for-ai-agents/580589/




Google Gemini Can Now Control Your Computer. Hackers Are Already Targeting AI Agents via @sejournal, @martinibuster

Google has moved “computer use” from a specialized model into Google Gemini 3.5 Flash, making agent-style control of browsers, apps, and desktop workflows a built-in capability instead of a separate product. That means Gemini can now see and interact with user interfaces, reason about what’s on a computer screen, and take direct actions. A Google DeepMind senior scientist recently warned that scaled AI agents create incentives “for malicious people to do malicious things.”

Developers can now build agents that do a lot more than call APIs. They can automate GUI-only workflows such as testing software, filling forms, navigating dashboards, or using legacy apps with no API access. This reduces bottlenecks for automation and expands what AI agents can realistically do in production.

If software has a graphical user interface (GUI) but no API, an AI agent can still use it. Agents can be told to log into a dashboard, export yesterday’s SEO reports to a spreadsheet, compare them with last week’s data, and email the user a summary. The workflow is handled with natural language instead of relying on custom scripts to connect the dashboard, spreadsheet, and email.

What It Means For SEO

SEO tools may become far more agentic in the near future. Instead of just surfacing data, AI could log into Google Search Console, audit sites, crawl a site with Screaming Frog, extract specific data points for comparison, and execute repetitive optimization workflows.

For site owners, it also carries the implication that another set of AI agents may act as “visitors,” which could affect how site owners interpret site interactions and engagement signals for site and sales optimization.

AI Agents Will Be Attacked

Google’s announcement is pretty upbeat but the “safety best practices” document it links to bears paying attention to because failure to get this part right may result in theft and other poor user experiences.

The document explains:

“Computer Use presents unique security and operational risks, as a model acting on a user’s behalf might encounter untrusted content on screens or make errors in executing actions.”

That “untrusted content on screens” may be reference to the “traps” set for AI agents that the senior scientist at Google DeepMind warned against.

Google recommends seven best practices when this new AI agent:

1. Human-in-the-Loop (HITL):
Enforce user confirmation: When the safety response indicates require_confirmation (or legacy safety decision requires it), prompt the user for approval.
Provide custom safety instructions: Implement a custom system instruction to define and enforce your own safety boundaries.

2. Secure execution environment:
Run your agent in a secure, sandboxed environment to limit its potential impact. This can be a sandboxed virtual machine (VM), a container (e.g., Docker), or a dedicated browser profile with limited permissions

3. Input sanitization:
Sanitize all user-generated text in prompts to mitigate the risk of unintended instructions or prompt injection. This is a helpful layer of security, but not a replacement for a secure execution environment.

4. Content guardrails:
Use guardrails and content safety APIs to evaluate user inputs, tool inputs and outputs, and the agent’s responses for appropriateness, prompt injection, and jailbreak detection.

5. Allowlists and blocklists:
Implement filtering mechanisms to control where the model can navigate and what it can do. A blocklist of prohibited websites is a good starting point, while a more restrictive allowlist is even more secure.

6. Observability and logging:
Maintain detailed logs for debugging, auditing, and incident response. Your client should log prompts, screenshots, model-suggested actions (function_call), safety responses, and all actions ultimately executed by the client.

7. Environment management:
Ensure the GUI environment is consistent. Unexpected pop-ups, notifications, or changes in layout can confuse the model. Start from a known, clean state for each new task if possible.

Beware Of Trap-Filled Websites

As attack surfaces grow, the greater the likelihood that hackers will seek to exploit them. What that means is that as the number of AI agents on the web proliferates, hackers will turn their attention to exploiting them. Websites become the battlefield from which attackers launch attacks on AI agents.

A senior scientist at Google DeepMind recently said that malicious actors are already setting traps to steal money from humans by targeting their AI agents.

That’s not an exaggeration. Just this month, a cybersecurity expert in California experienced illicit charges made to his credit card due to Anthropic Claude’s AI agent. According to the article, he appears to have downloaded a Skills.md file that may have contained an AI agent trap.

The article reports:

“…he found a problematic add-on connected to Claude, referred to as a “skill,” similar to a plug-in. ‘That basically told Claude to attempt to purchase different types of gift accounts on my stored information. So it was using the digital wallet that was on my computer for Claude to start to make these purchases…’”

Site owners may need stronger bot controls and the ability to identify when hackers have hidden prompt-injection instructions on their sites. But that’s not something website owners are looking for, which compounds the problem for users who are utilizing AI agents like the one that Google just released.

Read more: Google DeepMind: Traps For AI Agents Are Already Stealing Money

Featured Image by Shutterstock/blocberry

https://www.searchenginejournal.com/google-gemini-can-now-control-your-computer-hackers-are-already-targeting-ai-agents/580578/




Google Begins Rolling Out The June 2026 Spam Update via @sejournal, @MattGSouthern

  • Google began rolling out the June 2026 spam update, applying globally and to all languages.
  • It’s the second spam update of 2026, and Google announced no new spam policies with it.
  • Ranking or traffic changes over the next few days could trace to the rollout, so watch your Search Console data.

Google has begun rolling out the June 2026 spam update globally and across all languages. It’s the second spam update of the year.

https://www.searchenginejournal.com/google-begins-rolling-out-the-june-2026-spam-update/580424/