This weeks update is brought to you by Chris Martin, Google Security Specialist.
What’s New in Google SecOps for the interval July 20 through July 27th 2026.

Highlights
🔥 The preview of CodeMender to find and fix software vulnerabilities
🔥 Customizable schedules for YARA-L multi-event rules is now in Public Preview
🤔 Google Threat Intelligence has released a new Cyber Threat Actor Naming System
🔥 A Google SecOps update improving the integration with Wiz Defend
🔥 SecOps SIEMposium 2026 — A Google SecOps-Focused Conference, Oct 5–8 in San Diego
Early bird registration is now open for SecOps SIEMposium, happening October 5-8, 2026 in San Diego. Join the Google…www.siemposium.com
Product Updates & New Features
🔥🚀 Now in preview: Find and fix software vulnerabilities with CodeMender from Google Cloud Blog
-
Google Cloud is launching CodeMender in preview, a managed code security agent designed to help find and automatically remediate software vulnerabilities using machine-speed defenses, combating adversarial AI threats. [Read More]
-
Note, this appears a Private Preview, and access has to be explicitly granted to use it
Google SecOps
🔥🚀 Release Notes from Google Cloud Documentation
-
Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy [Read More]
📑 New Docs: Reference > Migrate From Legacy API To Chronicle API from Google Cloud Docs
-
This document announces the deprecation of Google SecOps’s legacy SIEM APIs (Backstory API and Ingestion API) and mandates migration to the modern Chronicle API.
-
Deprecation Timeline:
- The legacy APIs will be fully non-functional by July 20, 2027.
- Starting October 26, 2026, new instances will no longer be able to call legacy APIs.
- Migration is strongly recommended before July 20, 2027, to avoid service interruptions, security, and performance issues. -
Who is Affected:
- Organizations using custom integrations, automation scripts, or third-party tools that make programmatic calls to the legacy Backstory or Ingestion APIs. -
Who is NOT Affected:
- Organizations interacting only through the Google SecOps user interface (UI).
- Organizations whose integrations already use Chronicle API endpoints. -
Why Migrate (Benefits of Chronicle API):
- Enhanced Security & Performance: Aligns with Google Cloud API standards.
- Improved Integration: Stronger integration with Cloud Audit Logs, Cloud Monitoring, and Cloud Identity and Access Management (IAM).
- Self-Service Management: Simplifies credential and IAM management (vs. manual process).
- Modern Compliance: Built-in support for Data Residency, VPC Service Controls, Access Transparency, CMEK, and FedRAMP.
- Standardized Design: Resource-oriented, RESTful architecture with consistent naming (following AIPs), improving intuitiveness and data consistency.
- Broader Ecosystem: Integration with OneMCP, Terraform, client libraries, and SDKs. [Read More]
📑 New Docs:Reference > SIEM Endpoint Mapping Table from Google Cloud Docs
-
This document provides a mapping guide for migrating from legacy Google SIEM API endpoints (including Backstory API, Customer Management API, and Ingestion API) to their corresponding modern Google Chronicle API endpoints. [Read More]
Google Threat Intelligence
🚀 Release notes from GTI Docs
-
The article announces new product updates, including Agentic URL Scanning 2.0 integration, the introduction of target technology watchlists, and enhanced domain reputation capabilities. [Read More]
✍️ 🧐 Updated Cyber Threat Actor Naming System from Google Cloud Blog
-
Google Threat Intelligence Group is rolling out a unified naming system for cyber threat actors to standardize tracking across platforms and public reporting. [Read More]
🚀✍️ Public Preview: Target Technology Watchlists from Google Cloud Security Community
-
Google Threat Intelligence has launched Target Technology Watchlists in public preview, allowing customers to track vulnerability intelligence relevant to their specific technology stacks and receive customized alerts. [Read More]
Google Cloud
✍️ Generosity Under Conditions: Hardening Google Cloud Access Management from Google Cloud Blog
-
The article discusses the importance of Identity and Access Management (IAM) in Google Cloud and how to harden security by applying the principle of least privilege for better access control. [Read More]
AI
✍️ Open Knowledge format v0.2 tackles agentic trust from Google Cloud Blog
-
The article details the Open Knowledge Format (OKF) v0.2, which introduces new features to enhance agentic trust by adding trust signals and providing essential context for agents. [Read More]
Adoption Guides & Deep Dives
🔥 ✍️ Better Together: Integrating Wiz Defend and Google SecOps from Google Cloud Security Community
-
The article announces the integration of Wiz Defend and Google SecOps, creating a powerful cloud security synergy that offers centralized visibility, streamlined investigations, and AI-driven alert contextualization to enhance security operations. [Read More]
Community & Events
🔥 ✍️ SecOps SIEMposium 2026 — A Google SecOps-Focused Conference, Oct 5–8 in San Diego from Google Cloud Security Community
-
Google Cloud is launching SecOps SIEMposium 2026, a new technical conference and training week in San Diego this October, focused on Google SecOps, hands-on training, and best practices. [Read More]
I will be there!
✍️ Tuesday’s Tip of the Week: Vetting Compromised Service Accounts via UDM from Google Cloud Security Community
-
This article discusses the high-value nature of service accounts as targets for attackers and provides methods for vetting compromised service accounts using UDM search. [Read More]
✍️ Week 6: Hunting Compromised Service Accounts via UDM from Google Cloud Security Community
-
The article highlights service accounts as high-value targets for attackers due to their broad permissions and lack of MFA, and explains how to use UDM Search to detect signs of compromise. [Read More]
3rd Party Blogs
✍️ Beyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability Management from Anton Chuvakin
-
The article focuses on moving past an overwhelming state of security vulnerabilities by scaling foundational security practices and improving vulnerability management. [Read More]
Podcasts & YouTube
🎙️ EP27 The Challenges of Reversing Modern Languages: From C++ to Go and Rust with Jae Young Kim from YouTube
-
This episode explores the challenges and techniques involved in reverse engineering modern programming languages such as C++, Go, and Rust, featuring expert Jae Young Kim. [Read More]
Wiz
✍️ Opening the Black Box: Agentless Threat Detection for Virtual Appliances from Wiz Blog
-
The article presents a researcher’s guide to continuous agentless threat detection for virtual appliances like FortiGate, focusing on mapping event logs to real-world campaigns. [Read More]
✍️ Agentless Visibility: Uncovering Cloud Blind Spots from Wiz Blog
-
The article explains how agentless visibility and workload detection can expose hidden threats and critical blind spots within cloud networks and virtual appliances. [Read More]
✍️ 300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AI from Wiz Blog
-
Wiz’s integration network has reached 300 partners, establishing a strong, open security ecosystem designed to combat the accelerated threats and development driven by AI. [Read More]
✍️ Exploitation in the Wild of wp2shell from Wiz Blog
-
Wiz Research has identified active exploitation of “wp2shell,” a critical pre-authentication RCE vulnerability chain impacting WordPress Core, with attackers deploying persistent webshells. Organizations are urged to prioritize patching or applying WAF mitigations to counter this threat. [Read More]
Platform Issues
✅ RESOLVED: We are experiencing an issue impacting Google SecOps customers in Europe MultiRegion from Google Cloud Status
-
Google SecOps customers in Europe MultiRegion are experiencing an issue impacting Search/Dashboard query performance, which began on 2026–07–23 at 06:50 AM PDT. [Read More]
✅ RESOLVED: Some Google SecOps customers in the asia-southeast1 region may experience higher latency and failures when running dashboard queries from Google Cloud Status
-
Google Cloud is investigating an issue causing higher latency and failures for SecOps dashboard queries in the asia-southeast1 region, which began on 2026–07–20 23:01 PDT. [Read More]

