Skip to main content

What’s New in Google SecOps: 2026–07–27

  • July 27, 2026
  • 0 replies
  • 10 views

matthewnichols
Community Manager
Forum|alt.badge.img+20

This weeks update is brought to you by Chris Martin, Google Security Specialist. 

 

What’s New in Google SecOps for the interval July 20 through July 27th 2026.


Highlights

🔥 The preview of CodeMender to find and fix software vulnerabilities

🔥 Customizable schedules for YARA-L multi-event rules is now in Public Preview

🤔 Google Threat Intelligence has released a new Cyber Threat Actor Naming System

🔥 A Google SecOps update improving the integration with Wiz Defend

🔥 SecOps SIEMposium 2026 — A Google SecOps-Focused Conference, Oct 5–8 in San Diego

SecOps SIEMposium

Early bird registration is now open for SecOps SIEMposium, happening October 5-8, 2026 in San Diego. Join the Google…www.siemposium.com

 


Product Updates & New Features

🔥🚀 Now in preview: Find and fix software vulnerabilities with CodeMender from Google Cloud Blog

  • Google Cloud is launching CodeMender in preview, a managed code security agent designed to help find and automatically remediate software vulnerabilities using machine-speed defenses, combating adversarial AI threats. [Read More]

  • Note, this appears a Private Preview, and access has to be explicitly granted to use it

Google SecOps

🔥🚀 Release Notes from Google Cloud Documentation

  • Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy [Read More]

📑 New Docs: Reference > Migrate From Legacy API To Chronicle API from Google Cloud Docs

  • This document announces the deprecation of Google SecOps’s legacy SIEM APIs (Backstory API and Ingestion API) and mandates migration to the modern Chronicle API.

  • Deprecation Timeline:
    - The legacy APIs will be fully non-functional by July 20, 2027.
    - Starting October 26, 2026, new instances will no longer be able to call legacy APIs.
    - Migration is strongly recommended before July 20, 2027, to avoid service interruptions, security, and performance issues.

  • Who is Affected:
    - Organizations using custom integrations, automation scripts, or third-party tools that make programmatic calls to the legacy Backstory or Ingestion APIs.

  • Who is NOT Affected:
    - Organizations interacting only through the Google SecOps user interface (UI).
    - Organizations whose integrations already use Chronicle API endpoints.

  • Why Migrate (Benefits of Chronicle API):
    - Enhanced Security & Performance: Aligns with Google Cloud API standards.
    - Improved Integration: Stronger integration with Cloud Audit Logs, Cloud Monitoring, and Cloud Identity and Access Management (IAM).
    - Self-Service Management: Simplifies credential and IAM management (vs. manual process).
    - Modern Compliance: Built-in support for Data Residency, VPC Service Controls, Access Transparency, CMEK, and FedRAMP.
    - Standardized Design: Resource-oriented, RESTful architecture with consistent naming (following AIPs), improving intuitiveness and data consistency.
    - Broader Ecosystem: Integration with OneMCP, Terraform, client libraries, and SDKs. [Read More]

📑 New Docs:Reference > SIEM Endpoint Mapping Table from Google Cloud Docs

  • This document provides a mapping guide for migrating from legacy Google SIEM API endpoints (including Backstory API, Customer Management API, and Ingestion API) to their corresponding modern Google Chronicle API endpoints. [Read More]

Google Threat Intelligence

🚀 Release notes from GTI Docs

  • The article announces new product updates, including Agentic URL Scanning 2.0 integration, the introduction of target technology watchlists, and enhanced domain reputation capabilities. [Read More]

✍️ 🧐 Updated Cyber Threat Actor Naming System from Google Cloud Blog

  • Google Threat Intelligence Group is rolling out a unified naming system for cyber threat actors to standardize tracking across platforms and public reporting. [Read More]

🚀✍️ Public Preview: Target Technology Watchlists from Google Cloud Security Community

  • Google Threat Intelligence has launched Target Technology Watchlists in public preview, allowing customers to track vulnerability intelligence relevant to their specific technology stacks and receive customized alerts. [Read More]
     

Google Cloud

✍️ Generosity Under Conditions: Hardening Google Cloud Access Management from Google Cloud Blog

  • The article discusses the importance of Identity and Access Management (IAM) in Google Cloud and how to harden security by applying the principle of least privilege for better access control. [Read More]

AI

✍️ Open Knowledge format v0.2 tackles agentic trust from Google Cloud Blog

  • The article details the Open Knowledge Format (OKF) v0.2, which introduces new features to enhance agentic trust by adding trust signals and providing essential context for agents. [Read More]
     

Adoption Guides & Deep Dives

🔥 ✍️ Better Together: Integrating Wiz Defend and Google SecOps from Google Cloud Security Community

  • The article announces the integration of Wiz Defend and Google SecOps, creating a powerful cloud security synergy that offers centralized visibility, streamlined investigations, and AI-driven alert contextualization to enhance security operations. [Read More]


Community & Events

🔥 ✍️ SecOps SIEMposium 2026 — A Google SecOps-Focused Conference, Oct 5–8 in San Diego from Google Cloud Security Community

  • Google Cloud is launching SecOps SIEMposium 2026, a new technical conference and training week in San Diego this October, focused on Google SecOps, hands-on training, and best practices. [Read More]

I will be there!

✍️ Tuesday’s Tip of the Week: Vetting Compromised Service Accounts via UDM from Google Cloud Security Community

  • This article discusses the high-value nature of service accounts as targets for attackers and provides methods for vetting compromised service accounts using UDM search. [Read More]

✍️ Week 6: Hunting Compromised Service Accounts via UDM from Google Cloud Security Community

  • The article highlights service accounts as high-value targets for attackers due to their broad permissions and lack of MFA, and explains how to use UDM Search to detect signs of compromise. [Read More]


3rd Party Blogs

✍️ Beyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability Management from Anton Chuvakin

  • The article focuses on moving past an overwhelming state of security vulnerabilities by scaling foundational security practices and improving vulnerability management. [Read More]


Podcasts & YouTube

🎙️ EP27 The Challenges of Reversing Modern Languages: From C++ to Go and Rust with Jae Young Kim from YouTube

  • This episode explores the challenges and techniques involved in reverse engineering modern programming languages such as C++, Go, and Rust, featuring expert Jae Young Kim. [Read More]


Wiz

✍️ Opening the Black Box: Agentless Threat Detection for Virtual Appliances from Wiz Blog

  • The article presents a researcher’s guide to continuous agentless threat detection for virtual appliances like FortiGate, focusing on mapping event logs to real-world campaigns. [Read More]

✍️ Agentless Visibility: Uncovering Cloud Blind Spots from Wiz Blog

  • The article explains how agentless visibility and workload detection can expose hidden threats and critical blind spots within cloud networks and virtual appliances. [Read More]

✍️ 300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AI from Wiz Blog

  • Wiz’s integration network has reached 300 partners, establishing a strong, open security ecosystem designed to combat the accelerated threats and development driven by AI. [Read More]

✍️ Exploitation in the Wild of wp2shell from Wiz Blog

  • Wiz Research has identified active exploitation of “wp2shell,” a critical pre-authentication RCE vulnerability chain impacting WordPress Core, with attackers deploying persistent webshells. Organizations are urged to prioritize patching or applying WAF mitigations to counter this threat. [Read More]


Platform Issues

RESOLVED: We are experiencing an issue impacting Google SecOps customers in Europe MultiRegion from Google Cloud Status

  • Google SecOps customers in Europe MultiRegion are experiencing an issue impacting Search/Dashboard query performance, which began on 2026–07–23 at 06:50 AM PDT. [Read More]

RESOLVED: Some Google SecOps customers in the asia-southeast1 region may experience higher latency and failures when running dashboard queries from Google Cloud Status

  • Google Cloud is investigating an issue causing higher latency and failures for SecOps dashboard queries in the asia-southeast1 region, which began on 2026–07–20 23:01 PDT. [Read More]