Skip to main content

What’s New in Google SecOps: 2026-07–20

  • July 20, 2026
  • 0 replies
  • 42 views

matthewnichols
Community Manager
Forum|alt.badge.img+20

This weeks update is brought to you by Chris Martin, Google Security Specialist. 

 

What’s New in Google SecOps for the interval July 13 through July 19 2026
 

 

What’s New in Google SecOps — July 19th 2026


Product Updates & New Features
 

Google SecOps

🚀 Release Notes from Google Cloud Docs

  • A new ‘Advanced Filtering in Dashboards’ feature is now available in Preview for security analysts, allowing dynamic values, regex, or boolean logic to be injected into YARA-L queries at runtime. [Read More]

I wrote a blog on using Advanced Filters in Native Dashboards recently.

  • A new feature allowing users to check the validation status of a SOAR migration to Google Cloud, with specific indicators for successful completion of Stage 1 and Stage 2 on the License Management page. [Read More]

 

Google Threat Intelligence

🚀 Release Notes from gtidocs.readme.io

  • New product updates for July 2026, including an enhanced URL Scanning 2.0, Role-Based Access Control for Service Accounts, and improved audit log capabilities. [Read More]

BindPlane

July 2026 at Bindplane: A new pipeline editor, friendlier pricing, and a Blueprints library from bindplane.com

  • Bindplane announced significant product updates for July 2026, including an Advanced Pipeline Editor, a Blueprints library, revised and friendlier pricing with an increased Free tier, and several new data sources and processors. [Read More]

This includes a new Windows Event logging updates, and the new Advanced Pipeline editor in the Bindplane UI. 

 

Google Cloud & AI

13 hands-on demos to build on Gemini Enterprise Agent Platform from Google Cloud Blog

  • Google is showcasing 13 hands-on demos for its recently introduced Gemini Enterprise Agent Platform, designed for building, scaling, governing, and optimizing AI agents. [Read More]

Guide to AI Tokenomics: Eleven Principles for Token Efficient Software Engineering from Google Cloud Blog

  • This guide presents eleven principles for optimizing token consumption in AI coding assistants, crucial for maintaining their speed and accuracy in software engineering. [Read More]

Cloud CISO Perspectives: How AI leverages deep context as the defender’s advantage from Google Cloud Blog

  • This article from Cloud CISO Perspectives explains how AI, utilizing deep context, provides a significant advantage for security defenders, as detailed by a Google Cloud executive. [Read More]

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management from Google Cloud Blog

  • The article outlines a blueprint for leveraging AI to enhance vulnerability management processes, referencing insights from the Mandiant M-Trends 2026 report. [Read More]

How to Analyze and Govern Gemini Enterprise App Usage at Scale with BigQuery from Google Cloud Blog

  • This article outlines how organizations can effectively analyze and govern the usage of the Gemini Enterprise app, an AI productivity tool, at scale using BigQuery. [Read More]

🔥 ✍ Google named a Leader in the 2026 IDC MarketScape for Worldwide Foundation Model Software from Google Cloud

 

Blog

  • Google has been recognized as a Leader in the 2026 IDC MarketScape for Worldwide Foundation Model Software, attributed to its long-standing focus on enterprise needs, robust infrastructure, security, and reliable data platforms. [Read More]

Claude at scale on Google Cloud: Frontier AI, built for enterprise production from Google Cloud Blog

  • The article announces the availability of Anthropic’s Claude frontier AI models on Google Cloud, optimized for demanding enterprise production environments with features like managed accelerators, low latency, and regulated data handling. [Read More]

Evolving Spec-Driven Development: Conductor Now Supports Antigravity from Google Cloud Blog

  • Conductor has evolved into a portable plugin for conversational Spec-Driven Development (SDD), now supporting platforms like Antigravity CLI and Claude. This allows developers to naturally interact with an AI assistant to manage markdown artifacts, improving workflow efficiency and maintaining a version-controlled repository. [Read More]
     

Community & Events

Bridging the Perimeter: Ingesting GCP Logs into SecOps SIEM Across Distinct Organizations from Google Cloud

 

Security Community

  • This article details methods for ingesting Google Cloud Platform (GCP) logs into a Google Security Operations (SecOps) SIEM when the source and destination are in distinct GCP organizations, addressing common multi-tenant challenges. [Read More]

Exciting News: Introducing “The Weekly Brief” — Your Ultimate Guide to Mastering Google Security! from Google Cloud Security Community

  • Google is launching “The Weekly Brief,” a new centralized resource within the Google Cloud Security Community to help security professionals stay updated and informed on Google Security. [Read More]

Note, this What’s New in Google SecOps weekly post is included in this official Google Cloud Security Community.

Multi-tenancy on a single Google SecOps — Part 3: Who Sees What, and Where the Alert Lands from Google Cloud Security Community

  • This article is Part 3 of a series detailing how to implement multi-tenancy on a single Google SecOps instance, specifically addressing data visibility for analysts and alert routing for different tenants. [Read More]

Vibe Coding Google SecOps Parsers with Gemini from Google Cloud Security Community

  • The article introduces “Vibe Coding” with Gemini AI, a method to rapidly prototype, build, and troubleshoot custom Google SecOps parsers, significantly reducing the manual effort and expertise typically required for onboarding log sources. [Read More]

Scaling Collective Defense: Introducing GitHub Support for Google SecOps Parsers from Google Cloud Security Community

  • Google Security Operations is introducing GitHub support for its parsers to overcome historical challenges of centralized, manual management, fostering greater community collaboration and scaling collective defense. [Read More]

 

3rd Party Blogs

“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either Future from Anton Chuvakin

  • The article provides security advice for artificial intelligence, designed to remain relevant whether AI becomes normal technology or rapidly advances to Artificial General Intelligence. [Read More]

 

Podcasts & YouTube

🎙️ Podcast: Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows from Google Cloud Security

Community

  • The article discusses the application of AI and human-machine teaming to enhance frontline threat intelligence workflows. [Read More]
     

Wiz

The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System from Wiz Blog

  • A security researcher discovered a critical business logic flaw in a B2B platform’s credit system, enabling a bypass of the paywall by altering a single client-side boolean value. [Read More]

M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions from Wiz Blog

  • The article details a supply chain compromise affecting AsyncAPI npm packages, facilitated through GitHub Actions, and advises on detecting and mitigating these malicious packages. [Read More]

Why IaC Coverage Belongs on Your Security Dashboard from Wiz Blog

  • The article advocates for integrating Infrastructure as Code (IaC) coverage into security dashboards to enhance the governance, traceability, and rapid remediation of an organization’s infrastructure [Read More]

 

Platform Issues

RESOLVED: Processing Delays for Google SecOps SIEM in Europe from Google Cloud Status

  • Google SecOps is experiencing processing delays in Europe, affecting customers, and an engineering team is actively investigating the incident. [Read More]