← Back to list

What’s New in Google SecOps: 2026–05–17

What’s New in Google SecOps for the interval May 11th through May 17th 2026

Chris Martin (@thatsiemguy) · 2026-05-17 09:47 · 1 claps · 6.5 min read
#google-cloud-security #chronicle-siem #chronicle-soar #google-threat-intel #google-secops
Open on Medium ↗

What’s New in Google SecOps: 2026–05–17

What’s New in Google SecOps for the interval May 11th through May 17th 2026

What’s New in Google SecOps, May 17th 2026

What’s New in Google SecOps, May 17th 2026

Highlights

Product Updates & New Features

✍️ **Cloud CISO Perspectives: How Google + Wiz changes multicloud strategy for CISOs from Google Cloud Blog**

  • This Cloud CISO Perspectives article discusses the multicloud strategy for CISOs, highlighting insights from a fireside chat between Google and Wiz at the RSA Conference. [Read More]

SecOps SIEM

📝 **Updated Docs: Deprecations > Reference Lists from Google Cloud Docs**

  • *The key change in this document is the update to the deprecation and shutdown dates for the “Reference lists” functionality:
  • The deprecation date has been moved from June 2026 to May 2027.
  • The shutdown date has been extended from September 2026 to July 2027.*

SecOps SOAR

🔥📑 **New Docs: SOAR > Admin > Map SOAR Permissions To IAM from Google Cloud Docs**

  • This document serves as a mapping guide, translating legacy Google Security Operations (SOAR) permissions into Google Cloud IAM permissions. Its primary purpose is to assist users in managing access and capabilities within Google SecOps SOAR when migrating from older permission models to the newer IAM framework. [Read More]

📑 **New Docs: SOAR > Use reaction triggers in Playbooks from Google Cloud Docs**

  • This document introduces Reaction Triggers in Google SecOps SOAR, a new (currently Pre-GA) feature designed to automate playbooks based on real-time modifications and specific events during an active investigation [Read More]

Google SecOps SOAR Reaction Triggers

Google SecOps SOAR Reaction Triggers

📝 **Updated Docs > SOAR: Collect Secops SOAR Logs from Google Cloud Docs**

  1. Automatic Routing of SOAR Logs: It is now explicitly stated that Google SecOps SOAR logs for all customer types (both managed and standalone) are automatically routed to the _Default cloud logging bucket.
  2. *Cost Implication & Recommendations: The document highlights that this automatic routing incurs costs. To mitigate these costs, Google now recommends:
  • Setting up exclusion filters to drop low-value logs.
  • Adjusting retention periods for logs.*

📝 **Updated Docs > SOAR: Pre-migration validation guide from Google Cloud Docs**

  • Expanded Authentication Support: The document now explicitly includes OIDC (OpenID Connect) as a supported standard for user authentication and authorization, alongside SAML.
  • *New OIDC Troubleshooting Section: A comprehensive “OIDC flow and troubleshooting” section has been added, which includes:
  • A detailed, step-by-step OIDC troubleshooting procedure, structured into phases for validating authorization requests, callback and token exchange, Google SecOps authentication, and SOAR permissions access.*

Google Threat Intelligence

✍️ **Welcome to BlackFile: Inside a Vishing Extortion Operation from Google Cloud Blog**

  • Google Threat Intelligence Group is tracking an expansive vishing extortion campaign operated by threat actor UNC6671 under the “BlackFile” brand. [Read More]

✍️ **GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access from Google Cloud Blog**

  • Google’s Threat Intelligence Group (GTIG) reports that adversaries are increasingly leveraging AI for vulnerability exploitation, augmented operations, and gaining initial access to systems. [Read More]

GTIG AI Threat Tracker

GTIG AI Threat Tracker

Bindplane

✍️ **May 2026 at Bindplane: Global Pipeline Intelligence and the CLI AI Skill from Bindplane Blog**

  • The article recaps Google Cloud Next 2026 and details Bindplane’s May 2026 product updates, including the launch of its AI Skill for CLI workflows, the general availability of Pipeline Intelligence, SSO for the Growth plan, and a new Azure Event Hub source. [Read More]

AI

✍️ **Google Named a Leader in the Gartner® Magic Quadrant™ for AI Application Development Platforms: Mid-cycle update from Google Cloud Blog**

  • Google has been named a leader in the Gartner® Magic Quadrant™ for AI Application Development Platforms, a recognition highlighted in a mid-cycle update to reflect the platform’s evolution. [Read More]

✍️ **Beyond source code: The files AI coding agents trust — and attackers exploit from Google Cloud Blog**

  • The article highlights how AI coding agents’ deep integration into developer workflows and access to local files create new attack surfaces, necessitating a redefinition of malicious files and updated security defenses. [Read More]

Beyond source code: The files AI coding agents trust — and attackers exploit

Beyond source code: The files AI coding agents trust — and attackers exploit

🔥 ✍️ **Build Long-running AI agents that pause, resume, and never lose context with ADK from Google Developers Blog**

  • The article introduces Google’s Agent Development Kit (ADK) for building long-running, production-grade AI agents that maintain context through durable state machines and persistent storage, enabling complex enterprise workflows. [Read More]

Building Long-running agents with Google ADK

Building Long-running agents with Google ADK

Adoption Guides & Deep Dives

🔥 **New to Google SecOps: In Between Days — Spotting the Outlier from Google Cloud Security Community**

  • John Stoner introduces a method within Google SecOps using multi-stage searches to identify excessive user logins based on their 7-day average, building on previous discussions about outlier analysis techniques like Z-scores. [Read More]

New to Google SecOps: In Between Days — Spotting the Outlier

New to Google SecOps: In Between Days — Spotting the Outlier

Community & Events

🔥 🌐 **Unlock Advanced SOC Metrics: Joining case and case_history in Native Dashboards from Google Cloud Security Community**

  • The article provides a guide on how to join ‘case’ and ‘case_history’ data sources in Google Security Operations native dashboards to track advanced SOC performance metrics like MTTR, analyst workloads, and SLA compliance. [Read More]

🌐 **Webinar: Foundation security for AI and cloud workloads from Google Cloud Security Community**

  • This webinar will explore practical approaches to foundational security for AI and cloud-native workloads, focusing on adapting security posture without hindering innovation and discussing the enhanced SCC Standard Tier. [Read More]

🌐 **Revamped Dashboard Docs & 1,000+ YARA-L 2.0 Reference Queries Now Available from Google Cloud Security Community**

  • Google SecOps has released revamped documentation for custom dashboards and over 1,000 new YARA-L 2.0 reference queries to enhance SOC visibility and accelerate data utilization. [Read More]

3rd Party Blogs

🔥✍️ **Automating SecOps Ingestion Health: Monitoring Bindplane Agents with Google SecOps SOAR** from Simone Bruzzechesse

  • The article focuses on automating the monitoring of Bindplane agents to ensure healthy data ingestion within SecOps, leveraging Google SecOps SOAR. [Read More]

Monitoring Bindplane Agents with Google SecOps SOAR

Monitoring Bindplane Agents with Google SecOps SOAR

🔥✍️ **Next-Gen MDR Has To Become An AI-Native SecOps Control Plane from Raffy.ch**

  • The article asserts that the traditional service-first MDR model is outdated, advocating for a future where MDR becomes a product-first, AI-native, and action-oriented SecOps control plane. [Read More]

✍️ **The Natural MDR Extensions from Raffy.ch**

  • The article discusses the necessary evolution of Managed Detection and Response (MDR) services, advocating for them to expand beyond alert triage and become a comprehensive control plane for cybersecurity operations and risk reduction. [Read More]

Podcasts & YouTube

🎙️ **EP276 AI Governance vs. The Hyper-Velocity Agentic Future: A Lawyer’s Take from the Cloud Security Podcast**

  • This podcast episode features a lawyer’s perspective on the challenges of AI governance in the face of rapidly evolving agentic AI, questioning if AI is a fundamental shift requiring new regulatory approaches. [Read More]

[embed]EP276 Cloud Security Podcast

🎙️ ️**EP25 The Future of Debugging: A Paradigm Shift with Xusheng Li from Behind the Binary**

  • This episode, featuring Xusheng Li, discusses the future of debugging and an upcoming paradigm shift in the field. [Read More]

[embed]EP25 Behind the Binary Podcast

Wiz

**Introducing Wiz Audit History: Track Every Change Across your Environment from Wiz Blog**

  • Wiz has introduced Audit History, a new generally available feature that provides a continuous, cross-cloud timeline of changes to resource configurations and findings, designed to accelerate incident response and simplify compliance. [Read More]

**Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised from Wiz Blog**

  • A new ‘Mini Shai-Hulud’ supply chain attack has compromised multiple npm packages, including TanStack, targeting high-value developer tooling. [Read More]

**Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP from Wiz Blog**

  • A new page-cache corruption vulnerability, dubbed Fragnesia, in the Linux kernel’s ESP-in-TCP allows unprivileged local attackers to achieve root-level privilege escalation. [Read More]

**Wiz at Wiz: Reducing Risk through Service Ownership from Wiz Blog**

  • The article explains how Wiz’s internal security team leverages a Service Catalog to implement service ownership, effectively reducing cloud risk. [Read More]

Platform Issues

Nothing to report


메타데이터
post_id
07f8d9ffc57a
slug
whats-new-in-google-secops-2026-05-17-07f8d9ffc57a
url
https://medium.com/@thatsiemguy/whats-new-in-google-secops-2026-05-17-07f8d9ffc57a
canonical_url
https://medium.com/@thatsiemguy/whats-new-in-google-secops-2026-05-17-07f8d9ffc57a
author_url
https://medium.com/@thatsiemguy
status
ok
fetched_at
2026-07-11 17:44:30