Skip to main content

What’s New in Google SecOps: 2026–08–10

  • August 10, 2026
  • 0 replies
  • 18 views

Forum|alt.badge.img+15

What’s New in Google SecOps for the interval August 03 through August 10 2026.

 

What’s New in Google SecOps — August 10th 2026

 

Highlights

Product Updates & New Features

 

Google SecOps

🚀 SecOps Release Notes from Google Cloud Documentation

  • Self-service Bindplane Enterprise license download. Google SecOps Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents. [Read More]

  • Google SecOps SIEM (Chronicle) introduces a new public preview feature allowing users to analyze feed activity with Cloud Logging to monitor, debug, and troubleshoot ingestion pipelines and diagnose log delivery issues. [Read More]

  • Google Cloud Chronicle has deprecated the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds, recommending migration to the GTI_IOC feed before their removal on March 18, 2027. [Read More]

  • Updated rich-text editor. Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.

  • The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026. For more information, refer to the SOAR migration guide.

  • 🔥 Google SecOps has launched the Threat Hunt Agent in Public Preview for Enterprise Plus customers, an AI-powered tool (Gemini) that autonomously automates proactive threat hunting using Google Threat Intelligence and Mandiant expertise. [Read More]

The Threat Hunting Agent is available for E+ customers in preview and is accessed via Emerging Threats.
 

Launch the Agentic Threat Hunt from Emerging Threats

 

A Threat Hunt can be launched for several pre-defined objects from Google TI, such as Actor, Threat Campaign, Malware, Software Toolkit or TTP.
 

View Agentic Threat Hunt results from Case 2

 

The process can take 1 to 2 hours depending on the complexity and amount of data that is queried (with a limit of up to 30 steps at present), and will create a Case (in Case 2) with its results.

📑 New Doc: Detection > Threat Hunt Agent from Google Cloud Docs

  • Core Function: Automates the planning, querying (using YARA-L 2.0), and analysis of forensic evidence to detect hidden adversaries and validate security hypotheses.

  • AI Power: Powered by Gemini, Google Threat Intelligence, Mandiant frontline expertise, and the MITRE ATT&CK® framework.

  • Benefits: Reduces investigation time, accelerates response to emerging threats, and frees up senior analysts by automating research, query construction, and noise filtering.

  • Pre-GA Status: Currently a Pre-GA offering with limited support; changes may not be compatible with other pre-GA versions.

  • Prerequisites:
    - Enterprise Plus license (during public preview).
    - New Case Management experience enabled.
    - Appropriate Google SecOps permissions.

  • Initiating a Hunt:
    - Can be started from the Emerging Threats section, Google Threat Intelligence pop-outs, threat association details, or the MITRE ATT&CK matrix.
    - Users select a threat category (Actor, Campaign, Malware, Software Toolkit, TTP) and a specific threat, then define a historical telemetry timeframe (up to 30 days).

  • Process & Outputs:

  • Runs autonomously in the background, creating a new case in Case Management (prefixed “Threat Hunt for [Subject Name]” and tagged “Threat Hunt”).

  • Limitations (during Preview):
    - Typical execution time: 60–90 minutes.
    - Quota: Limited to two concurrent hunts and up to five hunts per day.

  • Feedback: Users can provide feedback on hunt results to help improve AI accuracy.

SecOps SIEM

📑 Updated Docs: Agentic SOC Trial from Google Cloud Docs

  • The key change in this document is the extension of the trial period for the Triage and Investigation Agent (TIN).Previously: The trial was set to end on June 30, 2026.Now: The trial has been extended and will automatically end on August 31, 2026. [Read More]

📑 Updated Docs: Detection > Composite Detections from Google Cloud Docs

  • New Basic Rule Correlation Template Example: A new example rule, Basic_Rule_Correlation_Template, has been introduced. This rule provides a basic template for correlating two different sub-rule detections by the same user within a specified time window (e.g., 14 days).

  • Recontextualized Existing Example: The existing CheckCuratedDetection_with_EDR_and_EG example is now explicitly described as a more advanced example that uses YARA-L functions and variable definitions.

  • New Limitation on Exclusions: A new limitation regarding “Exclusions” has been added. It clarifies that UDM-field exclusions cannot be applied directly to composite rules but must instead be applied to the foundational, underlying rules. [Read More]

📑 Updated Docs: Ingestion > Data Processing Pipeline from Google Cloud SecOps

The key change in this document is the addition of the “Unroll” processor to the list of available processors and detailed guidance on its usage.

  • Introduction of the Unroll processor, which provides “Event breaking” capability to split a slice of logs into multiple individual log events.

  • Requirements and usage instructions for the Unroll processor, emphasizing that it requires a structured internal object (like parsed JSON, XML, or CSV) and cannot operate on raw strings. Users are advised to place a Transform processor before the Unroll processor to parse raw log payloads.

  • A note that the Unroll processor is based on the OpenTelemetry Collector unrollprocessor. [Read More]

📑 Updated Docs: Secops: Use Google SecOps MCP from Google Cloud SecOps

  • New Antigravity Integration Guide:
    - A comprehensive new section titled “Configure Antigravity to use the Google SecOps MCP server” has been added.
    - This section details how to configure both the Antigravity desktop IDE and CLI to connect to the Google SecOps MCP server.

  • New Gemini Enterprise Integration Guide:
    - A substantial new section titled “Configure Gemini Enterprise to use the Google SecOps MCP server” has been added.
    - This guide provides detailed steps for integrating Google SecOps with Gemini Enterprise using a Custom MCP datastore.

SecOps SOAR

📑🎉🔥 New Docs: Investigation Management > Create Case From Search from Google Cloud Docs

Technically this was something that I mentioned last week, but it has rolled out to production now. If you’ve not seen it, you can now:

  • Create a Case from UDM Events or Detection results

  • Add UDM Events or Detections to an existing case

 

 

Creating or adding Events or Detections to Case 2

Note, this is only available in the Case 2 preview.

 

Google Threat Intelligence

✍️ UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments from Google Cloud Blog

  • The threat actor UNC6671 has rebranded and is actively using multi-brand vishing extortion campaigns to target financial services and enterprise cloud environments. [Read More]

 

Google Cloud

✍️ How Google Cloud detects, contains, and protects against emerging threats from Google Cloud Blog

  • The article highlights Google Cloud’s foundational commitment to securing customer data and business systems by empowering them with tools and infrastructure to detect, contain, and protect against emerging threats. [Read More]

AI

🔥✍️ Your agentic summer: No-cost lessons from Google experts to build and scale agents from Google Cloud Blog

  • Google is offering free, expert-led training sessions this summer to help developers and IT leaders build and scale AI agents into production environments. [Read More]

✍️ Behind the scenes: How we build, test, and scale Google Agent Skills from Google Cloud Blog

  • The article provides an inside look at how Google develops, tests, and scales its open-source Google Agent Skills, focusing on encoding Google Cloud domain knowledge into structured instructions for AI agents [Read More]

✍️ Agent Plugins package your skills, tools, and more from Google Developers Blog

  • Agent Plugins 1.0.0 is a new, vendor-neutral specification backed by major tech companies, standardizing the packaging of AI agent skills and servers to simplify development across various AI platforms and IDEs. [Read More]

✍️ 🔥 Scaling AI Agent Infrastructure with the MCP Stateless updates from Google Developers Blog

  • The article introduces the 2026–07–28 Model Context Protocol (MCP) specification, which replaces stateful constraints with a stateless core to enable cloud-native horizontal scaling, serverless deployments, and efficient handling of AI agent infrastructure. [Read More]

This is an exciting update, and one that may reboot MCP by solving several of the problems that have held it back.

While the new version 2026–07–28 is released as GA, Google is marking it as a release candidate, and from my own testing no hosted Google MCP servers or Google Agentic harnesses, e.g., AntiGravity appear to support it yet.
 

MCP 2026–07–28 (aka MCP 2) and what it fixes

 

✍️ A unified API for AI model routing from Google Developers Blog

  • Google Cloud API Gateway is now in Public Preview, introducing a model routing feature that enables developers to dynamically route traffic to various AI models like Gemini, Claude, or OpenAI OSS-GPT, simplifying endpoint management. [Read More]

✍️ Scaling real-time AI agents with session-aware load balancing from Google Developers Blog

  • The article discusses a new approach to scaling real-time AI agents by implementing session-aware load balancing, which addresses the challenges of traditional request-response paradigms with long-lived, stateful streams by using application-level session tracking. [Read More]

Community & Events

✍️ Multi-tenancy on a single Google SecOps — Part 4: Content That Respects the Boundary from Google Cloud Security Community

  • This article, the final part of a four-part series, focuses on ensuring content respects tenant boundaries within a single Google SecOps instance, building on previous discussions of mental models, telemetry ingestion, and analyst visibility. [Read More]

✍️ Vendor-Agnostic AI Investigations: Using Google SecOps SOAR Playbooks from Google Cloud Security Community

  • Google SecOps SOAR playbooks leverage native AI to automate repetitive steps in vendor-agnostic security investigations. This aims to alleviate challenges like talent shortages and overwhelming alert volumes faced by security teams. [Read More]

✍️ Tuesday’s Tip of the Week — Match Windows and Outcomes: Controlling When and What Your Rules Report from Google Cloud Security Community

  • This article explains how the ‘match’ section in YARA-L rules controls event grouping variables (like source IP or user) and time windows, which fundamentally changes what a security rule detects. [Read More]

✍️ Governing the Autonomous SOC: Securing AI Agents End-to-End on Google’s Agent Platform from Google Cloud Security Community

  • This webinar focuses on securing and governing an autonomous Security Operations Center (SOC) staffed by AI agents on Google’s Agent Platform, building on a previous session that demonstrated AI agent vulnerabilities. [Read More]

3rd Party Blogs

🔥✍️ Implementing Data RBAC in Google SecOps via Google Workspace OUs from Chris Martin (@thatsiemguy)

  • The article details the process of implementing data Role-Based Access Control (RBAC) in Google SecOps, leveraging Google Workspace Organizational Units (OUs) for effective management. [Read More]

This was a blog post I wrote from a common customer request — how to apply data RBAC to different groups for a single log source. Even if you don’t have this exact requirement I recommend giving it a read as it covers the new feature of using JavaScript for writing Parsers and Parser Extensions, and using the SecOps Data Pipeline for adding custom Ingestion Labels.

 

Podcasts & YouTube

️🎙️ EP289 Software Engineering vs Software Craft: How Google Scalably Eliminates Classes of Vulnerabilities from Cloud Security Podcast (via Spotify)

  • How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? In this episode, hosts Timothy Peacock and Anton Chuvakin sit down with Christoph Kern, Principal Security Engineer at Google, to look under the hood of “secure-by-design.” They trace Google’s 15-year engineering journey to fundamentally eliminate entire classes of vulnerabilities rather than just playing whack-a-mole with bugs after they are written.

Note, the official Cloud Security Podcast website is no longer updating, so the Weekly report hasn’t been including episodes. I’ve switched to get the updates from Spotify for now.

 

Wiz

✍️ Cloud Threat Highlights: H1 2026 from Wiz Blog

  • The article summarizes cloud and AI threat activity tracked by Wiz Research and CIRT during the first half of 2026. [Read More]

✍️ Wiz at Black Hat 2026: Driving AI Threat Readiness from Wiz Blog

  • Wiz is announcing new capabilities at Black Hat 2026 to help organizations prepare for the AI era by enhancing security visibility and accelerating response. [Read More]

✍️ Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era from Wiz Blog

  • Wiz is introducing a new sensor for developer workstations to protect endpoints, recognizing them as a critical security perimeter in the AI era due to their access to sensitive credentials and cloud environments. [Read More]

Platform Issues

RESOLVED: Customers in the asia-south1 region may experience an issue where their SecOps dashboards (Looker based) fail to load and display data from Google Cloud Status

  • Google Cloud customers in the asia-south1 region are experiencing an issue where their SecOps dashboards (Looker based) are failing to load and display data, with the incident beginning on 2026–08–04 11:01 PDT [Read More]