GCP Releases

Google Cloud releases and Terraform Google provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.

Tracking 829 GCP releases · Updated

  • Google Cloud release notes securitygcpengineer ·

    Google SecOps SOAR Release 6.3.94

    Google SecOps SOAR has released version 6.3.94, currently rolling out to initial regions. This update focuses on internal and customer bug fixes. Affected users should check the provided region list for availability.

    announcement
  • Google Cloud release notes securitygcpengineer ·

    Google SecOps SOAR 6.3.93 Release

    Google SecOps SOAR has released version 6.3.93, which is now available in all regions. This update brings improvements and fixes to the security orchestration, automation, and response platform. All users of Google SecOps SOAR can access this new version.

    announcement
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Container Optimized OS Updates Address Security and Memory Errors

    This update to Container Optimized OS includes several security fixes for CVEs in systemd and the Linux kernel, alongside a feature that enhances memory error handling for CUDA workloads on ARM64. It also contains patches for Docker and GPU drivers. Users running CUDA on ARM64 may see improved stability, and all users benefit from the security remediations.

    security feature patch
  • Google Cloud release notes securitygcpgaarchitect ·

    Cloud KMS adds post-quantum cryptography signing algorithms

    Google Cloud Key Management Service (KMS) has added support for several post-quantum cryptography (PQC) signing algorithms, making them generally available. This enhancement aims to bolster security against future quantum computing threats, impacting users concerned with long-term cryptographic resilience. The new algorithms include various PQ_SIGN_HASH_SLH_DSA_SHA2_128S_SHA256 and ML_DSA variants, detailed in the provided documentation.

    feature
  • Google Cloud release notes securitygcppreview ·

    Secret Manager adds Feature Parameter templates in Preview

    Google Cloud Secret Manager now offers Feature Parameter templates in Preview. This capability allows users to create standardized configuration blueprints and securely inject environment-specific variables during deployment. The feature is currently available in preview, with more details in the parameter templates overview.

    feature
  • Google Cloud Blog blogaisecuritygcpengineergovernmentgcp-gke ·

    Google Cloud AI Threat Defense Combats AI-Driven Cyberattacks

    Google Cloud introduces AI Threat Defense, a unified platform leveraging Gemini, Wiz, CodeMender, and Mandiant to counter AI-powered cyberattacks. This new framework aims to provide defenders with a speed and context advantage over attackers who are increasingly using AI for zero-day exploits and rapid multi-agent attacks. The platform assists organizations in preparing, scanning, prioritizing, remediating, and monitoring threats across their software development lifecycle. It's designed for security engineers and architects managing cloud environments.

    feature announcement
  • Google Cloud Blog blogaisecuritygovernanceeolengineergovernmentenergy ·

    Safely Integrate AI for Vulnerability Management

    This blog post offers practical guidance from Mandiant Consulting on establishing operational guardrails for AI-assisted vulnerability management. It addresses the risks of deploying AI agents without mature integration processes, suggesting a hybrid approach combining AI with deterministic controls and human oversight. The recommendations are aimed at security teams looking to accelerate vulnerability discovery and remediation workflows while maintaining environmental integrity.

    announcement
  • Google Cloud release notes securityawsgcpengineer ·

    Google SecOps Marketplace: OIDC Support, Performance Optimizations, and More

    The Google SecOps Marketplace has released updates across several integrations, notably adding Google Cloud Web Identity (OIDC) Federation authentication to the AWS GuardDuty connector. These updates include performance refactoring for SCC Enterprise, enhanced routing for Google Threat Intelligence, expanded normalization for Chronicle Alerts, and stability improvements for Microsoft Defender ATP actions. The release also features bug fixes for ServiceNow and CrowdStrike Falcon connectors, impacting engineers and architects managing cloud security operations.

    patch
  • Google Cloud release notes securitygcppreviewengineer ·

    Google SecOps SIEM adds advanced dashboard filtering (public preview)

    Google SecOps SIEM is rolling out advanced filtering capabilities for dashboards. This feature allows security analysts to dynamically inject values, regular expressions, or boolean logic into YARA-L queries using query variables, enhancing dashboard flexibility. The capability is currently in public preview and requires understanding of YARA-L query syntax.

    feature
  • Google Cloud release notes securitygcppreviewengineer ·

    Google SecOps adds advanced dashboard filtering in preview

    Google SecOps is introducing advanced filtering capabilities for dashboards, currently in preview. This feature allows security analysts to dynamically inject values and complex logic into YARA-L queries using tokens, improving query flexibility and runtime analysis. It enables multi-select options and customizable wrappers, providing enhanced control over dashboard data exploration for security teams.

    feature
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Apigee X 1-18-0-apigee-1 Release

    This release of Apigee X includes several security fixes and bug resolutions, enhancing reliability and patching vulnerabilities. It affects users of Apigee X, particularly those using cache policies, API proxy deployments, and SAML assertions. The rollout began today and may take several business days to complete across all Google Cloud zones.

    security patch announcement
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Cloud Service Mesh updates address multiple critical CVEs

    New versions of Cloud Service Mesh (1.29.5-asm.12, 1.28.10-asm.4, and 1.27.9-asm.15) are available, bringing fixes for numerous platform CVEs, including several rated Critical. These updates are crucial for maintaining the security posture of your service mesh deployments. Users are advised to consult the provided upgrade documentation to apply these security patches.

    patch announcement
  • Google Cloud Blog blogsecuritygcpengineerfinanceretailmediagovernmentgcp-cloud-rungcp-cloud-storagegcp-compute-enginegcp-cloud-functions ·

    Securing Serverless Applications Against Common Attacks on GCP

    Mandiant highlights risks of publicly exposed serverless applications on Google Cloud, such as Cloud Run, lacking authentication. Exploiting vulnerabilities like LFI and command injection can lead to full cloud environment compromise, a growing concern with increased AI usage. This post details attack scenarios and provides hardening guidance, applicable to any public serverless deployment, emphasizing secure secrets management and least privilege principles for service accounts.

    announcement security
  • Google Cloud release notes securitygcpengineer ·

    Apigee Hybrid v1.15.6 Release Includes Security Fixes

    Apigee hybrid has been updated to version v1.15.6, released on July 15, 2026. This release incorporates various security and CVE fixes, enhancing the overall security posture of the hybrid runtime. The update is delivered via Helm charts, automatically updating container images, and is recommended for all users.

    security announcement
  • Google Cloud release notes securitygcpengineer ·

    Google SecOps SOAR: Migration Validation Status

    Google SecOps SOAR has introduced a validation status for its migration to Google Cloud. Users can now verify the migration's success by checking the SOAR Settings > License Management page, which will display "Google.com" or "Google.com and CloudIAM Enabled" after the system version number upon completion of respective stages. This feature provides clarity to users undergoing or having completed the SOAR migration process.

    feature
  • Google Cloud release notes securitygcpengineer ·

    Google SecOps SOAR Migration Validation Updated

    Google SecOps now allows users to validate the success of their SOAR migration through the License Management page. This feature provides clear indicators in the system version number to confirm Stage 1 and Stage 2 completion. This enhancement is relevant for all users who have migrated or are planning to migrate their SOAR environment.

    feature
  • Google Cloud release notes securityinfragcpgapreviewdeprecationsecurity-advisoryengineergcp-bigquerygcp-cloud-rungcp-gkegcp-cloud-sqlgcp-cloud-storagegcp-dataprocgcp-compute-enginegcp-looker ·

    Cloud SDK 576.0.0: BigLake, GKE, Compute Engine updates

    Cloud SDK version 576.0.0 introduces several feature promotions to GA, including BigLake Delta sharing commands and GKE rollbackable upgrades, alongside numerous enhancements across Compute Engine, Cloud SQL, and other services. A breaking change updates gcloud storage rsync to decompress gzip files by default, impacting users who previously relied on the default behavior. Linux bundled Python was updated to address a security vulnerability, and a performance regression in Artifact Registry was fixed. Most changes are applicable to engineers and architects managing Google Cloud resources.

    breaking
  • Google Cloud Blog blogsecuritygcpengineer ·

    ADFS signing key recovery via Machine DPAPI, bypassing MFA

    Mandiant discovered a vulnerability where manually rotated Active Directory Federation Services (ADFS) signing keys can be exposed in Machine DPAPI, allowing attackers to forge SAML tokens. This 'ghost certificate' issue arises when AutoCertificateRollover is disabled and the WID database isn't updated after manual certificate rotation. The technique bypasses traditional defenses like LSASS monitoring and MFA, granting unauthorized access to federated applications.

    security announcement
  • Google Cloud Blog blogaisecurityawsazurepreviewengineermediagovernment ·

    Google's Gemini Startup Forum Selects 33 Cybersecurity Startups

    Google has launched its Gemini Startup Forum, selecting 33 cybersecurity startups focused on AI integration. This program aims to foster innovation by providing these companies with access to Google's AI and cybersecurity experts. The selected startups will work on solutions across six specialized areas, including AI agent security, application security, cloud security, endpoint security, and SOC automation. The initiative highlights Google's commitment to advancing AI-native cybersecurity solutions.

    announcement feature
  • Google Cloud Blog blogsecuritygcpengineergovernment ·

    Google Cloud integrates Threat Intelligence with Wiz ASM for proactive security

    Google Cloud is integrating Google Threat Intelligence with Wiz Attack Surface Management (ASM) to help organizations proactively prioritize security defenses. This integration correlates real-world exposures with real-time adversary activity, enabling faster detection and prioritization of exploitable issues and logic-driven vulnerabilities. The combined approach aims to shift security strategies from reactive maintenance to proactive risk management by highlighting actively targeted exposures. Contact your Google sales representative to get started.

    feature announcement

About GCP release tracking on ReleaseBytes

Google Cloud publishes release notes per product — BigQuery, GKE, Cloud Run, Cloud SQL, Vertex AI and dozens more — which makes platform-wide awareness hard. ReleaseBytes aggregates the official GCP release notes and the Terraform Google provider changelog into a single feed, with a plain-English summary of each update and tags for breaking changes, deprecations and security fixes.

Frequently asked questions

How often are GCP release notes updated on ReleaseBytes?

Continuously. ReleaseBytes monitors the official GCP release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.

What kinds of GCP changes does ReleaseBytes track?

New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.

How can I get alerts for new GCP releases?

Set up a free email or Slack alert filtered to GCP, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.

Where does the GCP release data come from?

From the official sources: Google Cloud releases and Terraform Google provider. Every item links back to the original vendor announcement.