What’s New in Google SecOps for the interval July 27th through 3rd August 2026.

Highlights
-
✍ John Stoner provides a new blog on using Advanced Filters in Native Dashboards
-
📢 ️ Check out upcoming Community Webinars and Workshops
-
🎉 ️ Read up on how Wiz’s first 6 months in Google Cloud have gone
-
🔥 ️ Learn more about Wiz’s autonomous AI Agent, Atlas, for vulnerability research, ranked #1 on CyberGym
-
✍ New docs for the SecOps SOAR Case 2 preview
Product Updates & New Features
Google SecOps
🚀 Release Notes from Google Cloud Docs
-
Google Chronicle now allows users to view prebuilt parser version content even when custom parsers are active for the same log type [Read More]
-
Google SecOps has launched a public preview of Data RBAC for 1P cases and alerts, enhancing data access control by applying SIEM data scopes to ensure analysts only view authorized information. [Read More]
-
Google SecOps has introduced a public preview of a revamped Investigation and Case Management experience for single-SIEM deployments, designed to handle higher investigation volumes and support diverse workflows like retrohunting and threat hunting alongside standard alert tracking. The updated feature enhances queue navigation with customizable table views, side-drawer previews, and integrated UDM Search. [Read More]
Note, the Case 2 preview was technically in last week’s release note interval, but the date was backdated.
SecOps SIEM
📑 New Docs: Investigation > UDM Search Vs Rules Results from Google Cloud Docs
-
This document explains why event counts from Google SecOps UDM search queries can differ from those generated by live YARA-L 2.0 detection rules, despite both using UDM and YARA-L 2.0 syntax. The discrepancies arise due to fundamental differences in their execution engines, data evaluation time windows, handling of repeated fields, and deduplication behavior. [Read More]

Investigation > UDM Search Vs Rules Results
📝 Updated Docs: Administration > Migrate From Legacy API To Chronicle API from Google Cloud Docs
-
The document now features a clearer, numbered “Migrate to the Chronicle API” section outlining five distinct steps: “Audit API usage”, “Set up authentication and authorization”, “Map endpoints and update URLs”, “Update API logic”, and “Test your integration”. [Read More]
📝 Updated Docs: Investigation > Statistics Aggregations In Udm Search from Google Cloud Docs
-
In summary, the document has been significantly updated to provide more detailed explanations and practical guidance on how YARA-L 2.0 handles data types, especially uninitialized values in UDM, and to improve the clarity and structure of its function documentation and time-based grouping features. [Read More]
SecOps SOAR
📑 New Docs: Integrations Setup > Managing Integration Dependencies from Google Cloud Docs
-
This Google SecOps SOAR document outlines the process for updating custom integration script dependencies to support newer Python runtimes, such as migrating from Python 3.7 to 3.11. [Read More]
📑 New Docs: Investigation Management > Overview from Google Cloud Docs
-
This document provides an overview of the new, enhanced Cases experience within Google Security Operations (Google SecOps), primarily for security analysts and SOC managers. [Read More]

New Docs: Investigation Management > Overview
📑 New Docs: Investigation Management > Create Case From Search from Google Cloud Docs
-
This document describes a new Pre-GA feature in Google SecOps that allows users to directly attach SIEM search results to cases. This enhancement is designed for Google SecOps unified customers using the enhanced Cases experience and aims to connect threat hunting and search workflows directly to case management [Read More]
Note, this is rolling out this week.
BindPlane
⚙️ v1.105.1 from GitHub
-
This is a patch release for the `bindplane-otel-collector` (v1.105.1) addressing a bug where a blank `manager.yaml` was not correctly recreated from environment variables. [Read More]
Google Cloud
✍️ Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline from Google Cloud Blog
-
This Cloud CISO Perspectives article from Google Cloud explains why boards of directors must understand AI security and how to prepare their organizations for effective governance and business agility in the AI era. [Read More]
✍️ Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise from Google Cloud Blog
-
The article provides essential mitigation guidance to help secure software packages and protect against supply chain compromises, offering proactive advice for users. [Read More]
✍️ Cyber Snapshot Report: Go beyond the toolchain and build enterprise resilience from Google Cloud Blog
-
The Cyber Snapshot Report by Mandiant highlights that despite advanced threats, most successful cyber intrusions result from fundamental human and systemic failures, emphasizing the need for enterprise resilience beyond just security tools. [Read More]
AI
✍️ What’s new in AI infrastructure and orchestration this month from Google Cloud Blog
-
This article details the latest updates and new developments in Google’s AI infrastructure, orchestration, models like Gemini, and AI integration into various tools and software frameworks. [Read More]
✍️ Do more with less: How GKE can reduce your cost per agent by 75% from Google Cloud Blog
-
The article explains how Google Kubernetes Engine (GKE) can help platform engineering teams reduce the cost per agent for modern cloud applications by up to 75%. It highlights GKE’s role in optimizing expenses for autonomous digital workers. [Read More]
✍️ What’s new in Gemini Enterprise Agent Platform from Google Cloud Blog
-
The article provides an update on the Gemini Enterprise Agent Platform, highlighting the inspiring progress observed since its launch [Read More]
✍️ Automate your agent development lifecycle using any coding agent from Google Cloud Blog
-
This article is a deep dive into Google’s Gemini Enterprise Agent Platform, providing a practical guide on how to build and automate the development lifecycle of production-ready AI agents. [Read More]
✍️ Agent and Model Evaluations in Gemini Enterprise Agent Platform are now GA from Google Cloud Blog
-
Google’s Agent Platform has made its evaluation service generally available, offering developers a unified engine to consistently measure agent quality using pre-built, DeepMind-backed, or custom LLM-as-a-judge metrics, integrated directly into existing workflows. [Read More]
Adoption Guides & Deep Dives
🔥 ✍️ New to Google SecOps: Additional Methods to Filter in Dashboards from Google Cloud Security Community
-
John Stoner blogs on new methods to filter data within its dashboards, expanding beyond basic time and string matching filters for more advanced data constraining. [Read More]
Community & Events
⚠️ ✍️ Important Update: Generative AI Use in Our Community from Google Cloud Security Community
-
The article discusses the role of generative AI content within a community, emphasizing the continued importance of human connection and interaction despite AI’s increasing utility in daily workflows. [Read More]
I review a lot of Google Cloud Security Community posts and have noticed a steady uptick in what clearly looks like copy-and-pasted AI output (especially from Claude).
To be clear, I use Anthropic, OpenAI, and Google models daily myself — in fact, this weekly blog post is created using a series of agents. But when I use AI for forum posts or articles I try:
-
Disclose it clearly: Explicitly state it’s AI-generated (and format/italicize it accordingly).
-
Keep human thoughts first: Write out my own ideas first, then use AI solely to edit, structure, or improve clarity.
When you copy and paste raw AI output wholesale, readers can’t tell if the underlying ideas are actually yours. Beyond potentially introducing generic or unverified technical advice, it ultimately devalues the genuine human connection and insight you’re trying to share.
This isn’t unique to the Google Cloud Security Community — you see the exact same pattern on platforms like LinkedIn and Reddit — but as a technical SecOps focused community, the ideal focus should stay on real human experience and clear intent.
How to Stop Claude Writing Like an AI - Guide & Prompt
🔥 📢 ✍️ Community Learning! 4 Webinars and 3 Workshops. Register Now from Google Cloud Security Community
-
The Google Security Operations community is announcing a lineup of four webinars and three workshops, inviting community members to register for these enablement sessions. [Read More]
Tue, Aug 11, 9:00 PM — 10:00 PM (PDT): Meet SecOps — Your Agentic SOC
- Explores Google Cloud SecOps, demonstrating how unified data ingestion and AI-driven analytics transform raw security logs into actionable intelligence.
Wed, Aug 12, 7:00 AM — 8:00 AM (PDT): From Blocks to Bots — Scaling SecOps with Modular Playbooks and Agentic Automation
- Teaches SOC teams how to build modular Google SecOps playbooks and safely integrate AI-driven agentic automation to reduce engineering toil.
Wed, Aug 19, 7:00 AM — 8:00 AM (PDT): Exposing Relevant Threat Intelligence — Supercharge Your Brand Protection and Livehunting with Agentic AI
- Leverage Gemini-powered Google Threat Intelligence and agentic AI to neutralize phishing threats, secure brand reputation, and automate YARA-X threat hunting.
Tue, Sep 15, 9:00 PM — 10:00 PM (PDT): A Day in the Life of A SecOps Analyst & Engineer
- Follow a modern security analyst’s daily journey from alert to resolution, learning to shift from reactive triage to proactive threat hunting using Google Security Operations.
✍️ Tuesday’s Tip of the Week: Your first YARA-L Rule from Google Cloud Security Community
-
This article from David Nehoda provides a tutorial detailing the structure and creation of a YARA-L rule, specifically demonstrating how to build one for detecting brute force login attempts. [Read More]
Podcasts & YouTube
🎙️ Shadow LLMs, Agentic Identities, and Securely Integrating AI from YouTube
-
This content explores the security challenges and best practices for integrating AI, specifically addressing risks from unsanctioned ‘shadow’ LLMs and managing AI agent identities. [Read More]
Wiz
✍️ Rethinking scanning for the AI era: Wiz’s Agentic Code Security System from Wiz Blog
-
Wiz has introduced its Agentic Code Security System, designed to address the unique challenges of enterprise AI AppSec by balancing speed, depth, and cost across the software lifecycle. [Read More]
🔥 🎉 ✍️ Wiz’s First 6 Months as Part of Google from Wiz Blog
-
Wiz has completed its first six months as part of Google, accelerating efforts to redefine security for the AI era and strengthen its multicloud commitment. [Read More]
🚀 ✍️ The Wiz Red Agent is Now Generally Available from Wiz Blog
-
The Wiz Red Agent, a tool designed to continuously uncover complex, exploitable risks in the AI Threat Era, is now generally available. [Read More]
✍️ The risk hiding behind exposed MCP servers from Wiz Blog
-
The article highlights the severe security risks posed by exposed and unauthenticated Model Context Protocol (MCP) servers, which can lead to sensitive cloud data access, IAM compromise, and command execution. [Read More]
🔥 ✍️ Atlas: Wiz’s autonomous AI Agent for vulnerability research, ranked #1 on CyberGym from Wiz Blog
-
Wiz has developed Atlas, an autonomous AI agent for vulnerability research that validates findings with real exploits and has achieved the #1 ranking on CyberGym. [Read More]
Introducing Atlas: Wiz's AI vulnerability researcher | Wiz Blog
Platform Issues
✅ RESOLVED: Mandiant Threat Defense customers’ investigation reports may experience delays in publication from Google Cloud Status
-
Mandiant Threat Defense customers are experiencing delays in the publication of investigation reports due to an ongoing issue with the Managed Defense service. [Read More]
✅ RESOLVED: We are investigating a potential issue with Google SecOps from Google Cloud Status
-
Google is currently investigating a potential issue with Google SecOps, which began at 2026–07–31 10:11 US/Pacific, and has no workaround available at this time. [Read More]
⚠️ ONGOING: We are investigating a potential issue with Google SecOps from Google Cloud Status
-
Google is investigating a potential issue with its SecOps service, which began on July 23, 2026. [Read More]
✅ RESOLVED: Google SecOps customers are currently unable to load the MITRE Attack UI Tab from Google Cloud Status
-
Google SecOps customers are currently unable to load the MITRE Attack UI Tab due to an ongoing incident, though the engineering team has identified the root cause and is working on a mitigation. [Read More]
