Skip to main content

What’s New in Google SecOps: 2026–09–28

  • September 28, 2026
  • 1 reply
  • 18 views

Forum|alt.badge.img+15

What’s New in Google SecOps for the interval September 20th through September 27th, 2026

 

 

Highlights
 

Simone Bruzzechesse wrote up a great solution article on using asynchronous UDM Search to automatically populate Data Tables
 

And some new official documentation:

 

Product Updates & New Features

 

Google SecOps

 

🚀 Release Notes from Google Cloud Docs

  • Google SecOps now automatically enriches logs ingested via direct ingestion with the Google Cloud organization ID, improving log visibility and addressing a previous limitation. Read More

This is a popular public Feature Request (462528711) tracker issue, and so a welcome change it’s been implemented.

 

Google SecOps > New Documentation

 

🔥 📃 Detection: Integrate Threat Intel Feeds from Google Cloud Docs

This document introduces a comprehensive guide for integrating custom Indicators of Compromise (IoCs) and third-party threat intelligence feeds into Google Security Operations. Key additions include:

  • Detailed Workflow: Explains the end-to-end process from ingesting threat feeds, normalizing indicators into the Unified Data Model (UDM) Entity Context Graph (ECG), to correlating indicator entities with streaming event telemetry.
  • Diverse Ingestion Mechanisms: Lists and explains various methods for ingesting threat feeds, including prebuilt parsers, Feed Management API, Ingestion API, Bindplane agent, Cloud Run functions, and Content Hub connectors.
  • IoC Recognition Requirements: Specifies the five mandatory UDM field groups (metadata.entity_type, metadata.source_type set to ENTITY_CONTEXT, artifact identifier (entity.*), metadata.threat, metadata.interval) that an entity record must contain to be recognized as an actionable IoC.
  • Automated IoC Matching: Describes the system-generated findings for incoming security events matching active indicators, including latency expectations for streaming and historical events.
  • YARA-L 2.0 Integration: Provides guidance and code examples for authoring YARA-L 2.0 correlation rules to join event telemetry with ECG entities, including the use of retrohunting for historical analysis.
  • Troubleshooting and Validation: Includes dedicated sections for troubleshooting common issues (e.g., unparsed logs, missing search results, rule failures, false positives) and best practices for validating rules using the ‘Test rule’ feature.

 

🔥 📃 Secops: MSSP Multi Tenant Federated Search from Google Cloud Docs

This document introduces MSSP multi-tenant operations and Federated Search in Google Secops. This new feature enables security analysts and MSSPs to perform simultaneous Unified Data Model (UDM) searches and statistical queries across multiple Google Security Operations instances from a single designated managing instance. Read More

 

🔥 📃 Onboard: Provision Additional Instance from Google Cloud Docs

This document introduces a new self-service workflow for platform administrators and security engineers to deploy additional Google SecOps instances within an existing unified subscription. This new capability enables scaling multi-tenant security operations across business units, subsidiaries, or for managed customers without manual support assistance. Read More

 

 

Google SecOps > Updated Documentation

 

📝 Reference: Chronicle API Feeds from Google Cloud Docs

The document significantly expands and clarifies IP allowlisting requirements for data ingestion:

  • New ‘Set up IP allowlisting’ section: Introduces a dedicated section detailing when Google SecOps connects outbound and specifies required IP range files for different feed types:
  • V2 feeds (S3_V2, SQS_V2, Azure_Blobstore_V2): Require ipranges.json for Google Cloud Storage Transfer Service (STS).
  • Third-party APIs: Require goog.json.
  • Legacy feeds (S3, Azure_Blobstore): Require dedicated IP ranges (contact support).
  • Azure Event Hub: Requires region-specific IP ranges.
  • Dynamic IP ranges: Adds a note advising periodic fetching and parsing of ipranges.json, goog.json, and cloud.json due to dynamic changes.
  • Mandatory requirement: Phrases like ‘may need to add’ have been changed to ‘must add’ in sections for Amazon S3_V2, Amazon SQS_V2, and Azure_Blobstore_V2, emphasizing the necessity of allowlisting.
  • Clarified scope: For Amazon SQS_V2 and Azure_Blobstore_V2, the allowlisting now explicitly enables access for “STS and Google SecOps”.
  • Specific IP files: Updates mentions of general “IP ranges” to specific files (goog.json, cloud.json) for third-party APIs and CMDB data sources, linking to the new allowlisting section. Read More

 

📝 Reference: Standard Sql: Operators from Google Cloud Docs

This update introduces General quantified comparisons as a new operator type:

  • Operator Precedence: Added General quantified comparisons to the operator precedence table under level 5.
  • New Feature Definition: A new section detailing General quantified comparisons has been added.
  • Syntax and Semantics: Describes the syntax expression comparison_operator quantifier value_set and defines the quantifier (ANY, SOME, ALL) and value_set options (expression list, subquery, UNNEST).
  • Three-Valued Logic: Explains the semantic rules for ANY/SOME and ALL comparisons, including how they handle TRUE, FALSE, and NULL values, and the behavior with empty value_set.
  • Examples: Provides comprehensive examples demonstrating the use of ANY and ALL with various value_set forms, including scenarios illustrating the three-valued logic and empty sets. Read More

 

📝 Soar: Respond: Working With Playbooks: Case Playbooks from Google Cloud Docs

  • Added a new requirement for playbook actions executing on Remote Agents: agents must be version 2.6.6 or higher. Actions dispatched to older agent versions will fail, and instructions for upgrading Remote Agents are provided. Read More

 

SecOps SOAR

 

⚠️ Security Bulletins from Google Cloud Docs

Added a new critical security bulletin, GCP-2026–063, detailing an Improper Privilege Management vulnerability (CVE-2026–15587) in Google Security Operations SOAR. This vulnerability allowed authenticated attackers to escalate privileges to system-level administrative access. The issue was patched in version 6.3.85, and all customers have been automatically upgraded, requiring no customer action. Read More

 

Google Threat Intelligence

 

✍️ ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft from Google Cloud Blog

  • The threat actor ShinyHunters has initiated a renewed mass exploitation campaign specifically targeting Oracle PeopleSoft, following previous attacks that impacted the education sector. Read More

 

Google Cloud

 

✍️ 🤖 Introducing Support for Local AI Models in the Antigravity SDK from Google Developer Blog

  • The Google Antigravity SDK now supports local AI models, facilitating offline agentic workflows, secure on-device processing, and powerful hybrid orchestration architectures, with compatibility for OpenAI-compatible inference servers. Read More

✍ 🤖️ Power your agents: Gemini 3.8 Live with Live Avatar is now generally available from Google Cloud Blog

  • Gemini 3.8 Live with Live Avatar is now generally available, following its announcement last week. Read More

I added this new feature to my demo Agentic Detection & Response application, and here’s what it looks like in action. 

Gemini 3.8 Live Avatars

 

Community & Events

 

✍️ [Fixed] Left Outer Join — Rules and Datatables from Google Cloud Security Community

  • Google Security Operations has fixed a bug concerning left outer joins in rules and datatables, providing reference examples for detection use-cases. Read More

✍️ Announcing Private Preview: Mandiant Recommended Rules in Google Security Operations from Google Cloud Security Community

  • Google is announcing a private preview for Google Security Operations Enterprise Plus customers to enroll in Mandiant Recommended rules, aiming to help Security Operations Centers establish high-fidelity threat detection and reduce false positives. Read More

🔥 ✍️ Scheduling UDM Searches to Data Tables with the Google SecOps Asynchronous Search API from Google Cloud Security Community

  • The article from Simone Bruzzechesse details how to schedule UDM searches to Data Tables in Google SecOps using its Asynchronous Search API, enhancing contextual data for high-fidelity threat detection and rapid incident response. Read More

✍️ How to Automate a Threat Intelligence Feedback Loop: Google SecOps to Google Threat Intelligence (GTI) from Google Cloud Security Community

  • The article from ragaom details how to automate a threat intelligence feedback loop from Google SecOps to Google Threat Intelligence (GTI), allowing analysts to contribute novel indicators back to improve future threat detection and break the one-way intelligence flow. Read More

✍️ Accelerating Enterprise Defense with Google Threat Intelligence Single Target Operations from Google Cloud Security Community

  • Google Threat Intelligence introduces Single Target Operations, an innovative capability powered by Mandiant, which accelerates enterprise-wide protection from active breach investigations in under 24 hours, moving beyond traditional multi-victim analysis. Read More

✍️ Streamlining Vulnerability Management with Target Technology Watchlists from Google Cloud Security Community

  • Google Threat Intelligence introduces Target Technology Watchlists to streamline vulnerability management, helping security teams prioritize critical threats amidst an overwhelming volume of vulnerability disclosures. Read More

 

Wiz

 

✍️ Wiz Named a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026 from Wiz Blog

  • Wiz was recognized as a leader in Forrester’s Q3 2026 Proactive Security Platforms evaluation, earning top scores for its commitment to securing the AI era. Read More

✍️ Scan for Good: Using AI to discover and fix high-priority exposures across public services and critical infrastructure from Wiz Blog

  • The ‘Scan for Good’ initiative leverages AI to discover and remediate high-priority security exposures across public services and critical infrastructure, specifically partnering with under-resourced organizations. Read More

✍️ Growing the WIN AI Ecosystem with Agent Integrations from Wiz Blog

  • The article describes how Wiz’s MCP for WIN is expanding the WIN AI ecosystem through agent integrations and partnerships, aiming to accelerate a more connected environment. Read More


Platform Issues

 

✅ RESOLVED: Google SecOps SIEM customers are experiencing delays with Cloud based Ingestion Feeds in V1 (AMAZON_S3, AMAZON_SQS, GOOGLE_CLOUD_STORAGE, AZURE_BLOBSTORE) from Google Cloud Status

  • Google SecOps SIEM customers are experiencing delays with cloud-based ingestion feeds from various platforms including Amazon S3/SQS, Google Cloud Storage, and Azure Blobstore, beginning on Friday, 2026–09–25 17:02 PDT. Read More

✅ RESOLVED: Google SecOps customers are experiencing delays for event ingestion for europe-west3 from Google Cloud Status

  • Google SecOps customers in the europe-west3 region are experiencing delays in event ingestion, an issue currently under investigation by the engineering team. Read More

✅ RESOLVED: Google Security Operations customers are experiencing an issue where cases are not getting synced from Google Cloud Status

  • Google Security Operations customers are experiencing an incident where security cases are not syncing, and the engineering team is currently investigating the issue. Read More

✅ RESOLVED: Some Google SecOps customers in the europe-west3 region may experience delays with data normalization and detections from Google Cloud Status

  • Google SecOps customers in the europe-west3 region are experiencing delays with data normalization and detections due to an ongoing incident that began on 2026–09–24 04:40 PDT. Read More

✅ RESOLVED: Google SecOps customers are experiencing ingestion failure with the 3P Proofpoint API in US Multi-region from Google Cloud Status

  • Google SecOps customers are experiencing ingestion failure with the 3P Proofpoint API in the US Multi-region, beginning on 2026–09–20 03:53 PDT. Read More

✅ RESOLVED: Google SecOps customers may be experiencing higher detection latency in me-central1 region from Google Cloud Status

  • Google SecOps customers in the me-central1 region may be experiencing higher detection latency due to an ongoing issue identified by the engineering team. Read More

1 reply

maxjunker
Forum|alt.badge.img+4
  • Bronze 5
  • September 28, 2026

has anyone already configured the Federated Search yet? We set the required permissions. Do we need to shuffle GCP projects somehow?