What’s New in Google SecOps for the interval September 13th through September 20th, 2026.

What’s New in the World of Google SecOps, September 20th 2026
Highlights
-
🔥 🥳 The major SecOps update this week is the release of GoogleSQL support in UDM Search. I wrote a detailed post the topic this week too.
|> SQL in Google SecOps
Google SecOps has launched into public preview SQL support for Search 🥳medium.com -
🔥🤖 Google Cloud’s hosted MCP servers now support the new Stateless MCP Protocol (Version 2026–07–28)
-
⚠️💀 The following global context sources MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC are replaced by the single source GTI_IOC. If you use any of these for custom rules, read about the changes and start planning accordingly.
-
✍️ 🔥 Several of the sessions from the recent Mandiant Cyber Defense Summit are available on YouTube, e.g., Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses
Product Updates & New Features
Google SecOps
🚀 SecOps Release Notes from docs.cloud.google.com
-
🔥 GoogleSQL query support in Search: This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data — using either standard declarative SQL or the linear, sequential Piped SQL syntax. Read More
-
Google SecOps parser syntax now supports the match_all option in Grok filters, enabling the extraction of all non-overlapping pattern occurrences in a field. Read More
-
💀 Google Chronicle is deprecating and removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds, in favor of the GTI_IOC feed, with removal planned for March 18, 2027.Read More
-
Resizable side panels in the Investigation Management experience: You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management experience in Google SecOps. You can adjust the panel width using your mouse or keyboard shortcuts to view detailed telemetry, parsed UDM records, and raw logs without navigating away from your main case queue. Read More
🔥 📝 Updated Docs: Secops: Use Google Secops Mcp from docs.cloud.google.com
New Stateless MCP Protocol (Version 2026–07–28)
This update introduces a significant change to the MCP protocol, transitioning it from a stateful, bidirectional protocol to a stateless one, effective with MCP version 2026–07–28. Key implications include:
-
Self-describing requests: Each request is now self-contained, eliminating the need for an initialize/initialized handshake or Mcp-Session-Id.
-
Header-based routing: Requests are routed using HTTP headers.
-
Multi-round-trip requests (MRTR): MCP servers can now use MRTR to gather additional information.
-
Required headers: Specific headers from the MCP specification and custom headers (mirrored from the tool’s input schema using x-mcp-header) are now mandatory for routing and processing.
-
Transport update: The recommended transport for remote MCP servers is now Streamable HTTP Read More

MCP 2026–07–28 updates in Google Cloud’s hosted MCP
📃 New Docs: Event Processing: Reparse Historical Data from docs.cloud.google.com
-
This new document introduces Log Replay in Google Security Operations SIEM, a feature enabling security and detection engineers to re-process up to 180 days of historical raw log data. It outlines how to apply updated prebuilt, custom, or extended parsers to backfill Unified Data Model (UDM) field mappings. This capability improves historical threat hunting, detection rule coverage, and data consistency without requiring manual log re-ingestion. The guide details prerequisites (permissions), limitations (e.g., 180-day window, active parser only), and the process of submitting a Log Replay request via Google Cloud Support, including required information and a request template. Read More.
Note, this is not an automated process as I understand it, rather this is making formal the existing process via Google Support.
📃 New Docs: Reports: Manage Native Dashboard Charts Sankey from docs.cloud.google.com
-
This document introduces support for Sankey charts in Google SecOps SIEM dashboards, enabling security engineers and analysts to visualize multi-hop pathways, relationships, and directional flows. Read More.
-

Using Sankey diagrams in Google SecOps
📃 New Docs: API Parity Guides from docs.cloud.google.com
-
A range of API party guides have been added covering many legacy API methods, and their replacement, e.g., Create Parser, Deactivate Parser, Get Parser, etc… Read More.
📃 New Docs: GoogleSQL Functions from docs.cloud.google.com
-
To support the new GoogleSQL feature, a large range of documents covering all the available SQL functions is now available. Read More.
📃 New Docs: Secops: Data Encryption from docs.cloud.google.com
-
The document provides comprehensive guidance on data encryption within Google Security Operations, detailing both default encryption at rest (AES-256) and in transit (TLS). It introduces and thoroughly explains the implementation of Customer-Managed Encryption Keys (CMEK) using Cloud KMS for enhanced data control and compliance. Read More.
📝 Updated Docs: Detection: Gti Byol from docs.cloud.google.com
-
The documentation now highlights the ability to use ingested Google Threat Intelligence data with prebuilt curated detection rules in Google SecOps for Standard and Enterprise customers.
-
Detailed instructions are provided on how to enable these curated rules within Google SecOps, including navigating to “Curated Detections” and activating the “Google Threat Intelligence (BYOL)” rule set. Read More.
Google Threat Intelligence
✍️ Google named a Leader in the External Threat Intelligence Service Forrester Wave from cloud.google.com
-
Google has been recognized as a leader in the Forrester Wave™ for External Threat Intelligence Service, affirming its capabilities in providing high-fidelity intelligence against evolving cyber threats. Read More
BindPlane
✍️ Bindplane Agent Is Here: Build, Edit, and Understand Pipelines in Plain Language from bindplane.com
-
Bindplane Agent has been released, providing an AI assistant within Bindplane to help users build, edit, and understand telemetry pipelines using natural language. Read More

The new Bindplane Agent
⚙️ OTEL v1.108.1 from github.com
-
This content announces the release of software version v1.108.1, indicating a preparatory or maintenance update. Read More
Google Cloud
✍️ 🔥 Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses from cloud.google.com
-
This article discusses Google’s strategies for monitoring AI threats and leveraging AI to enhance its defenses against attackers, as shared by Sandra Joyce. Read More
Security in the AI Era
✍️ Introducing new session management tools with native, granular controls from cloud.google.com
-
Google Cloud is launching new session management tools, offering flexible, native, and granular controls to align with organizational security policies. Read More

Improved session management controls for Google Cloud session management
✍️ Best practices for handling cloud reliability incidents from cloud.google.com
-
This article outlines best practices and a structured workflow (Verify > Investigate > Report > Resolve > Review) for effectively handling cloud reliability incidents and outages on Google Cloud Platform. Read More
Relevant guidance for SecOps customers here on using services like Personalized Service Health and Cloud Service Health dashboard for keeping up to date on issues impacting Google Cloud and SecOps.
✍️ Google is a leader in The Forrester Wave: Public Cloud Platforms, Q3 2026 from cloud.google.com
-
Google Cloud has been named a Leader and achieved the highest score in the ‘current offering’ category in The Forrester Wave™: Public Cloud Platforms, Q3 2026 report. Read More
Google also received the highest possible score in 23 out of 30 evaluation criteria, including, but not limited to vision, innovation, AI development services, database services, analytics services, containers and kubernetes services, modernization services, and security services.
Impressive going to see that Google Cloud is being received by analysts has having the strongest Cloud Platform offering in 2026.
✍️ 🤖 Agent Anomaly Detection, now in Private Preview on the Gemini Enterprise Agent Platform from developers.googleblog.com
-
Agent Anomaly Detection is now available in private preview on the Gemini Enterprise Agent Platform, providing an out-of-band oversight layer to detect behavioral risks, logical anomalies, and policy violations in OpenTelemetry traces and tool calls using a multi-tiered statistical and LLM-based pipeline. Read More
If you’re building Agents on Gemini Enterprise this may be an interesting Private Preview to be aware of.
✍️ 🤖 Build zero-trust AI agents that judge intent, not just syntax from developers.googleblog.com
-
The article details how to build zero-trust AI agents that judge intent, not just syntax, using the Gemini Enterprise Agent Platform’s dynamic runtime governance. It outlines managed defenses such as Model Armor, Semantic Governance Policies, and Agent Anomaly Detection to enhance AI security. Read More
Adoption Guides & Deep Dives
✍️ Building Custom Anomaly Detection Models with Google SecOps and BigQuery ML: Abnormal DLL Path (Part 2) from security.googlecloudcommunity.com
-
This article, part two of a series, details building custom anomaly detection models for abnormal DLL paths using Google SecOps and BigQuery ML, following up on time-series forecasting methods discussed in part one. Read More
🔥 New to Google SecOps: Building Your First Search with SQL Pipes from security.googlecloudcommunity.com
-
Google SecOps is introducing the capability to leverage SQL for building searches, adding a new tool alongside its existing YARA-L constructs. Read More
Community & Events
✍️ Tuesday’s Tip of the Week — Three Playbook Patterns That Cover 80% of Use Cases from security.googlecloudcommunity.com
-
This tip of the week introduces three playbook patterns, focusing on enrichment actions that use external sources like VirusTotal to help security analysts make faster, better decisions through automated read-only operations such as hash, URL, and domain lookups. Read More
✍️ Adoption Guide: Scaling Incident Response with the Google SecOps Triage and Investigation Agent from security.googlecloudcommunity.com
-
The adoption guide introduces Google SecOps’ Triage and Investigation (TIN) Agent, powered by Google Gemini, as a solution to scale incident response by moving from rigid automation to dynamic, AI-assisted reasoning in cybersecurity. Read More
3rd Party Blogs
✍ 🔥️ |> SQL in Google SecOps from Chris Martin (@thatsiemguy)
-
The article discusses the application and utility of SQL within Google’s SecOps platform, likely detailing how it can be used for security operations. Read More
I feel like the Gemini AI summary phoned it in there on my blog. So to expand on it a little, the GoogleSQL in SecOps private preview has been running for several months now. I’ve had this blog post parked for all that time waiting for it to go Public so I could release. I’ll likely be writing more on this topic, but GoogleSQL opens up a broad range of new functionality, and for those building Agents opens the possibility of vastly more powerful agentic capabilities too.
Podcasts & YouTube
Several presentations from the recent Mandiant Cyber Defense Summit are available on YouTube.
Cyber Defense Summit by Google Cloud Security
▶️ National Security, Frontline Defense: A Fireside Chat with CISA’s Nick Andersen from youtube.com
-
In this mainstage fireside chat, Sandra Joyce (Vice President, Google Threat Intelligence) sits down with Nick Andersen (Acting Director, CISA) to discuss the critical challenges facing security leaders across both the public and private sectors — from defending at machine speed and securing frontier AI to safeguarding critical OT infrastructure and driving collective action on systemic risk. Read More
▶️ AI is here. What’s our next move? from youtube.com
-
In the agentic era, the traditional tension between development velocity and security control is evolving. As automated agents transform business operations, relying on manual security verification is no longer viable against the machine-speed of modern cyber threats. Google advocates for building durable trust through automated defenses, integrating hardware-based controls, safe coding principles, and intent-based authorization to secure intelligent applications against the rapid, AI-driven risks of the modern cybersecurity landscape. Read More
▶️ Security in the AI Era from youtube.com
-
The era of manual cyberattacks is giving way to the rise of autonomous adversary agents that operate at speeds manual security processes simply cannot match. In this presentation, Sandra Joyce, VP of Google Threat Intelligence breaks down how threat actors are leveraging AI to scale their operations and heighten attack sophistication. Beyond AI-enabled exploits, the rapid integration of AI across organizations has fundamentally altered the threat landscape, introducing critical points of failure and expanding supply chain surfaces. Read More
▶️ From Breach to Lessons Learned from youtube.com
-
Listen to incident responders for a deep dive into recent data breaches, both internal and within the supply chain. They explore how these incidents unfolded, and communication strategies used with leadership, employees, media, and the board. Learn actionable takeaways to bring back to your own security discussions. Read More
▶️ The AI Advantage: Flipping the Script on Next-Generation Adversaries from youtube.com
-
In these opening comments, Jurgen Kutscher explores how Mandiant consultants are leveraging AI to change the game for defenders and incident responders. He covers how Mandiant and Google Cloud are turning the tide by integrating hyper-scale AI directly into our tools and methodologies to stay ahead of the Threat Actors and empower our clients with machine speed defense, giving defenders the ultimate high ground. Read More
Wiz
✍️ Exploring the new AWS Sign Up experience from wiz.io
-
The article explores AWS’s new sign-up and account access features, emphasizing the continuous need for a strong security posture beyond the initial sandbox environment. Read More
✍️ Building an AI Detection Engine That Understands Agent Intent from wiz.io
-
This article discusses the development of an AI detection engine designed to understand agent intent and uncover malicious AI behavior by analyzing model input and output logs. Read More
🔥 ✍️ Investing Together: Wiz Defend and Google Security Operations from wiz.io
-
Wiz Defend and Google Security Operations are deepening their integration to help security teams work faster and more efficiently in their investigations. Read More
Note, this is in effect the Wiz version of this blog post in the Google Cloud Security Community a month ago, detailing the updated SOAR Integration between Wiz and SecOps.
Better Together: Integrating Wiz Defend and Google SecOps | Community
Platform Issues
❗ ONGOING: Google SecOps customers are experiencing failures in querying Entity Context Graph for rules, search, and dashboard queries from status.cloud.google.com
-
Google SecOps customers are experiencing failures in querying Entity Context Graph data sets, with engineering teams actively investigating the issue. Read More
✅ RESOLVED: Google SecOps customers are experiencing intermittent issues with Google managed BigQuery and BYOBQ Exports in multiregion US from status.cloud.google.com
-
Google SecOps customers are experiencing intermittent issues with Google managed BigQuery and BYOBQ Exports in multiregion US, with the incident beginning on September 15, 2026. Read More
✅ RESOLVED: Google SecOps customers are experiencing issues with RAW log search UI in multiple regions from status.cloud.google.com
-
Google SecOps customers are experiencing issues with RAW log search UI in multiple regions, with an incident beginning on Monday, 2026–09–14 02:03 PDT, and the engineering team is investigating. Read More
✅ RESOLVED: Some Google SecOps customers in the US multi-region may experience delays with data normalization and detections from status.cloud.google.com
-
Google SecOps is experiencing an incident in the US multi-region, causing delays in data normalization and detections for some customers, though log ingestion continues and data is queued. Read More
