Skip to main content

What’s New in Google SecOps: 2026–10–05

  • October 5, 2026
  • 0 replies
  • 3 views

Forum|alt.badge.img+16

What’s New in Google SecOps for the interval Sep 28th through 4th Oct, 2026.

 

 

Product Updates & New Features

 

Google SecOps

 

🚀 Release Notes from Google Cloud Docs

Google SecOps has updated the Chronicle API Restricted Data Access Viewer IAM role, expanding its read-only permissions to include those of the Chronicle API Viewer role, excluding global data access. Read More

📑 New Docs: Investigation > Search Syntax Reference from Google Cloud Docs

This document outlines the comprehensive search syntax for Google SecOps SIEM, guiding security analysts on configuring search expressions in the query editor. Read More

📝 Updated Docs: Use Google Secops MCP from Google Cloud Docs

This update introduces a comprehensive guide for integrating Google SecOps with Gemini Enterprise. The new section details the process, including:

  • Setting up an OAuth 2.0 Web Application in Google Cloud Console, specifying redirect URIs, and outlining required IAM roles.

  • Configuring a Custom MCP datastore within Gemini Enterprise, providing steps for entering MCP server URL, OAuth details (Authorization URL, Token URL, Client ID/Secret), and OAuth Scopes.

  • User authentication for the connector within the chat interface.

  • Setting up Gemini Memory to provide necessary tenant context for queries.

  • Examples for querying Google SecOps using natural language within Gemini Enterprise.

Additionally, the documentation significantly updates the example for listing MCP tools (tools/list method), replacing the basic HTTP POST with a detailed curl command that includes specific headers (MCP-Protocol-Version, Mcp-Method) and an expanded JSON request body with _meta parameters for protocol version and client capabilities. New placeholders for TOOLSET_ENDPOINT and MCP_PROTOCOL_VERSION are also introduced. Read More

 

Google Threat Intelligence

 

✍️ Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances from Google Cloud Blog

Mandiant Consulting and Google Threat Intelligence Group identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026–88772) affecting Citrix NetScaler ADC and Gateway appliances, impacting various sectors globally. The article discusses defending against this critical exploitation. Read More

 

Google Cloud

 

✍️ Google Cloud partners deliver new security agents and AI defenses with Gemini Enterprise from Google Cloud Blog

Google Cloud partners are integrating new security agents and AI defenses, powered by Gemini Enterprise, to help businesses combat AI-accelerated cyberattacks across all enterprise layers. Read More

 

Adoption Guides & Deep Dives

 

🔥 ✍️ Agentic Threat Intelligence, now in your own pipelines: a practical guide to the API from Google Cloud Security Community

The article introduces the Agentic Threat Intelligence API, allowing security analysts to integrate Google Threat Intelligence’s autonomous reasoning and tools directly into their existing security pipelines and automated workflows. This new API aims to move threat intelligence beyond browser-based investigations into core operational tools. Read More

 

Community & Events

 

✍️ Tuesday’s Tips of the Week — Curated Detections from Google Cloud Security Community

Google and Mandiant offer “Curated Detections,” which are YARA-L 2.0 rule sets providing vendor-maintained coverage against known threat techniques for UDM-normalized telemetry. Read More

✍️ Leveraging IOC Feeds in SecOps from Google Cloud Security Community

Google Cloud Security has released a new “Adoption Guide: Leveraging IOC Feeds in SecOps” to help security teams use threat intelligence feeds for proactive detections effectively, reducing unmanageable noise. Read More

https://security.googlecloudcommunity.com/google-security-operations-66/adoption-guide-leveraging-ioc-feeds-in-secops-8241

 

Wiz

 

✍️ The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub from Wiz Blog

The article details a ‘Blue Agent’ investigation into a multi-platform data exfiltration attack spanning AWS and GitHub, uncovering compromised credentials, stolen source code, and custom exfiltration tools. Read More

✍️ Introducing the Wiz Partner Alliance Managed Service Provider Program from Wiz Blog

Wiz is launching a new Managed Service Provider (MSP) program within its Partner Alliance to empower partners in delivering world-class cloud and AI security solutions at scale. Read More

 

Platform Issues

 

✅ RESOLVED: We are experiencing elevated error rates and latency affecting Chronicle Search & Investigations in the US Multiregion from Google Cloud Status

Google Cloud is experiencing elevated error rates and latency affecting Chronicle Search & Investigations and Chronicle Search & Rules in the US Multiregion. Read More

✅ RESOLVED: Some Google SecOps customers may experience increased search latencies and intermittent error rates in the US region from Google Cloud Status

Google SecOps customers in the US region are experiencing increased search latencies and intermittent error rates due to an ongoing issue. Read More

✅ RESOLVED: Some Google SecOps customers in EU may experience delays with data normalization and detections from Google Cloud Status

Google SecOps customers in the EU are experiencing an ongoing incident causing delays with data normalization and detections, which began on 2026–09–29 05:26 PDT. Read More

✅ RESOLVED: Google SecOps is experiencing intermittent login failures and HTTP 500 errors in multiple regions, including us-east1, us-central1, and europe-west1 from Google Cloud Status

Google SecOps is experiencing intermittent login failures and HTTP 500 errors in multiple regions, including us-east1, us-central1, and europe-west1, impacting customer access to the platform. Read More