The week in one paragraph
162 notes, the lightest week this series has covered, and the most thematically consistent. VPC Service Controls is the thread: the Cloud Trace Observability API now supports it at GA, Agent Gateway enforces its perimeters, and Gemini Notebook Enterprise announced — as a breaking change — that projects with VPC Service Controls enabled cannot add website URLs as notebook sources. Three services gaining a control and one losing a feature to it, in the same week. On security, GCP-2026-062 escalates last week's single Slurm CVE into eight, still through Cluster Toolkit, and GCP-2026-061 is a containerd privilege escalation that Google is careful to say does not affect default GKE clusters because the node images do not ship the tool it needs. Privileged Access Manager reached GA. And the most consequential small item: the chronicle.readonly OAuth scope loses its write permissions on 25 January 2027, which is an admission that a scope named readonly has not been.
The VPC Service Controls week
Post #30, published yesterday, listed "mitigate data exfiltration through Google APIs" as one of seven security controls a landing zone has to decide. This week is what that decision costs and buys, arriving in four notes.
Gaining coverage. The Cloud Trace Observability API supports VPC Service Controls, generally available. Agent Gateway now enforces VPC Service Controls perimeters. Each is a service that could previously sit outside a perimeter and now cannot — which is straightforwardly good, and is the slow work that makes a perimeter meaningful rather than decorative.
Losing a feature to it. Gemini Notebook Enterprise: projects with VPC Service Controls enabled can't add website URLs as notebook sources. Filed by Google under Breaking, which is the correct classification and a rare one — this series has seen three Breaking notes in five weeks, and three of them were this week.
The pairing is the lesson. A perimeter works by refusing egress, and a feature that fetches a URL from the public internet is egress. Google gives the reason outright: direct website ingestion performs a live web crawl, generating outbound traffic beyond Google networks, which would violate VPC Service Controls perimeter policies. Other source types, such as Google Docs and YouTube URLs, remain supported. There is no configuration that reconciles a live crawl with a perimeter; one of them has to lose. What is worth noticing is that the answer arrived as a release note rather than as a design document, which is how most perimeter incompatibilities are discovered — after somebody enables the control and a feature stops working.
Two bulletins, and how to read a Medium
| Bulletin | Severity | Subject | What it asks of you |
|---|---|---|---|
| GCP-2026-062 | High | Slurm, via Cluster Toolkit | Follow the Cluster Toolkit bulletin. Eight CVEs. |
| GCP-2026-061 | Medium | containerd CRI checkpoint restore | Nothing, for default clusters. |
GCP-2026-062 — last week's bulletin, grown
Multiple security vulnerabilities were discovered in Slurm that affect Cluster Toolkit blueprints referencing specific image versions, touching the slurmstepd daemon, RPC request handling and the accounting database. Eight CVEs, from CVE-2026-65107 through CVE-2026-65168.
Roundup #4 covered GCP-2026-060 nine days ago: one Slurm flaw, CVE-2026-65107, reaching Google Cloud through Cluster Director. That same CVE heads this week's list of eight. So this is not a new problem but a fuller accounting of the same one, which is a useful reminder that a bulletin is a snapshot of what was known rather than a bounded incident. If you patched on the strength of #4, the patch was right and the scope was smaller than the truth.
GCP-2026-061 — a Medium worth reading precisely
A vulnerability in containerd's CRI implementation, GHSA-p7v4-vr35-mj6f with a CVE still pending, allows a container restored from an untrusted checkpoint through the CreateContainer API to bypass the destination security context and execute with elevated privileges. That is a serious mechanism described in one sentence.
The scoping is what makes it a Medium, and Google states it plainly: GKE clusters are not vulnerable by default, because GKE node images do not include the criu tool that checkpoint restore requires. No immediate action for default clusters; action only if you install custom runtime software or node tools that bring criu with them.
Worth keeping as a template for reading severity. The vulnerability is not Medium because the escalation is mild — it is Medium because the precondition is absent on the default install. Which means the rating is only true of you if you have not customised your nodes, and the one group for whom it is a higher severity is precisely the group most likely to skim a Medium.
Three dated deadlines, one of them moved
- 25 January 2027 —
chronicle.readonlyloses write permissions. Effective 25 January 2027, write permissions will be removed from thechronicle.readonlyOAuth scope, restricting it strictly to read operations — workflows performing writes must move to thechroniclescope. Read that twice: anything currently writing through that scope is relying on a permission the scope's name denies, and it has fourteen months to stop. - 31 January 2027 — Looker Mobile (Legacy), postponed. Roundup #4 reported this application as already gone from both app stores with support discontinued. The deprecation has now been postponed to 31 January 2027, which is a genuine change to what that roundup said rather than a repeat of it.
- Cloud SQL sqlcommenter, temporarily disabled. Appending sqlcommenter tags via the
sql_commenter_enabledparameter on a Cloud SQL remote MCP server is temporarily disabled, announced across MySQL and PostgreSQL as Breaking. No date attached, which is its own kind of information.
The chronicle.readonly item is the one to act on rather than note. A scope that grants more than its name implies is a finding in any access review, and the fix window is long enough that nobody will remember it in December 2026 unless it goes in a calendar now.
Access, data and the rest
- Privileged Access Manager reached general availability, announced under both Access Approval and Access Transparency. Just-in-time privileged access is the control that makes post #30's "managing cloud service provider access" something other than a standing grant, and GA is the point at which it belongs in a landing zone rather than a proof of concept.
- Regional endpoints reached GA for the Cloud SQL Admin API across MySQL, PostgreSQL and SQL Server. A regional endpoint keeps API traffic in-region, which is a data-residency control that looks like a networking convenience.
- Compute Engine reservations became convertible, single-project to shared and back, at GA — a genuine reduction in the cost of getting a capacity decision wrong.
- Storage Intelligence advisor reached GA.
- BigQuery continued its run with
ML.CORRELATION,ML.METRICSandAI.CAUSAL_EFFECT, plus newer Gemini models behind the generative AI functions.
What I would act on
- Put 25 January 2027 in a calendar for
chronicle.readonly. Then find out today whether anything you run writes through that scope. If it does, you have a fourteen-month runway and an access-review finding to explain in the meantime. - Check whether your GKE nodes ship
criu. GCP-2026-061 is a Medium for default clusters and something else entirely for anyone running custom node tooling. That is a five-minute answer and it decides whether the bulletin applies. - Re-read GCP-2026-062 against the patch you took after roundup #4. Same root component, eight CVEs instead of one. The earlier fix was correct and incomplete.
- If you are enabling VPC Service Controls, inventory what breaks first. The Gemini Notebook item is one instance of a general pattern, and the pattern is that you find out from a release note after the perimeter is on.
Complete inventory — all 162 notes
Everything Google Cloud published between 7 and 11 September 2026, from four feeds. Nothing is omitted; where a run of notes repeats the same text once per release, it is rolled up with its count intact and its identifiers listed, never deduplicated.
How this inventory reconciles
Google Cloud published 162 notes across 42 products and 5 days in this window, read from 4 feeds. Every one of them is accounted for below, in exactly one place:
| Bucket | Notes | Why |
|---|---|---|
| Listed individually | 118 | Every note that is its own distinct fact. |
| Published under several products | 6 | 3 texts issued once per runtime or service; shown once, with the products named. |
| Repeating runs, rolled up | 38 | 1 product/type run where the same text recurs once per release. Summarised with the full identifier list, not deduplicated. |
| Total | 162 |
Repeating runs, rolled up
- Container Optimized OS (38 notes) — Fixed38 notes, across 4 releases (cos-117-18613-731-6, cos-121-18867-584-7, cos-125-19216-655-12, cos-dev-138-20098-0-0). They fix 2 distinct CVEs. A CVE is patched once per release, so the note count is higher than the CVE count — these are separate notes, not duplicates, and are counted as such: CVE-2026-33186, CVE-2026-6238.
One change, published under several products
- DeprecatedDeprecation of write permissions from the chronicle.readonly OAuth scope Effective January 25, 2027, write permissions will be removed from the chronicle.readon…Published under 2 products: Google SecOps, Google SecOps SIEM.
- BreakingAppending sqlcommenter tags using the sql_commenter_enabled parameter when executing SQL queries on a Cloud SQL remote MCP server is temporarily disabled. For m…Published under 2 products: Cloud SQL for MySQL, Cloud SQL for PostgreSQL.
- FeaturePrivileged Access Manager is generally available (GA) .Published under 2 products: Access Approval, Access Transparency.
Everything else, by product
AI Hypercomputer — 1
- SecurityGoogle addressed a security vulnerability (CVE-2026-65107) that affects Slurm clusters. Based on the Google Cloud product that you used to create your Slurm clu…Mon 07 Sep
API Gateway — 1
- FeatureEnable Model Context Protocol (MCP) You can now configure API Gateway to act as a remote Model Context Protocol (MCP) server. This Public Preview feature allows…Fri 11 Sep
Agent Platform Workbench — 1
- FixedScheduled upgrade metadata is validated The value of the notebook-upgrade-schedule metadata key is now validated when you create or update an Agent Platform Wor…Tue 08 Sep
AlloyDB for PostgreSQL — 1
- FeatureYou can now monitor the status, throughput, and backlog of the audit logging pipeline for your AlloyDB for PostgreSQL instances and nodes using Cloud Monitoring…Fri 11 Sep
Apigee X — 2
- FeatureSemanticCacheLookup policy supports non-default Vector Search distance measures Available in Apigee 1-18-0-apigee-4 and later. A new optional <DistanceMeasureTy…Wed 09 Sep
- FixedAddendum to Apigee release notes dated August 27, 2026 (1-18-0-apigee-4). Bug ID Description 502540992 Fixed an issue where the SemanticCacheLookup policy was i…Thu 10 Sep
Assured Workloads — 1
- FeatureThe EU Data Boundary with Access Justifications supports the following products: AlloyDB for PostgreSQL Apigee EventarcTue 08 Sep
BigQuery — 5
- FeatureConversational analytics now supports predictive modeling questions using the AI.PREDICT function . This feature is in Preview .Tue 08 Sep
- FeatureBigQuery generative AI functions now support the following Gemini models: gemini-3.5-flash-lite gemini-3.6-flash gemini-3.7-flashWed 09 Sep
- FeatureConversational analytics in BigQuery now supports the ML.CORRELATION function to calculate statistical correlations between a target column and one or more metr…Thu 10 Sep
- FeatureYou can now use the ML.METRICS function to compute evaluation metrics for machine learning classification or regression tasks on any table or query that contain…Thu 10 Sep
- FeatureYou can use the AI.CAUSAL_EFFECT function to quantify the impact of specific interventions on time series data. This feature is in Preview .Thu 10 Sep
Blog — 13
- PostPower agent hubs or custom harnesses with the Antigravity SDK in one toolkitTue 08 Sep
- PostAgentic analytics with the Data Agent KitTue 08 Sep
- PostHow KDDI built Buffmee, a faster, reliable consumer RAG appTue 08 Sep
- PostGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AITue 08 Sep
- PostEnterprise-grade PostgreSQL with AlloyDB Omni RPM Orchestrator is generally availableWed 09 Sep
- PostGoogle is a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise AI AssistantsWed 09 Sep
- PostBeyond DMS: Accelerating Migrations SQL Server Logins and Users to Cloud SQLWed 09 Sep
- PostSpanner: Removing cumulative mutation limits for DML transactionsWed 09 Sep
- PostHow Airtel delivered its flawless Indian Premiere League 2026 cricket broadcastsWed 09 Sep
- PostIntroducing the Google Cloud Developer Plugin for AI Coding AgentsThu 10 Sep
- PostWhat’s new with Google CloudThu 10 Sep
- PostWhat’s new with Google Data CloudThu 10 Sep
- Post3 Highlights from Thomas Kurian’s Keynote at the Goldman Sachs Communicopia & Technology ConferenceFri 11 Sep
Cloud Monitoring — 1
- FeatureA chart on a dashboard can override the dashboard's time-range setting. This feature lets you view trends over a long period or metric data with low sampling ra…Wed 09 Sep
Cloud Run — 1
- FeatureTo take advantage of reduced pricing for Cloud Run jobs, you can delay job execution to defer non-urgent tasks for up to 12 hours ( Preview ).Tue 08 Sep
Cloud SQL for MySQL — 1
- FeatureRegional endpoints (REP) are now generally available ( GA ) for the Cloud SQL for MySQL Admin API. Regional endpoints let you interact with Cloud SQL for MySQL…Tue 08 Sep
Cloud SQL for PostgreSQL — 1
- FeatureRegional endpoints (REP) are now generally available ( GA ) for the Cloud SQL for PostgreSQL Admin API. Regional endpoints let you interact with Cloud SQL for P…Tue 08 Sep
Cloud SQL for SQL Server — 1
- FeatureRegional endpoints (REP) are now generally available ( GA ) for the Cloud SQL for SQL Server Admin API. Regional endpoints let you interact with Cloud SQL for S…Tue 08 Sep
Cloud Storage — 1
- FeatureStorage Intelligence advisor is now generally available . Storage Intelligence advisor lets you monitor and manage your Cloud Storage environment at scale acros…Thu 10 Sep
Cloud Trace — 1
- FeatureThe Observability API supports VPC Service Controls. This integration is generally available . For more information, see the following: Use VPC Service Controls…Tue 08 Sep
Cluster Toolkit — 3
- FeatureCluster Toolkit version v1.103.0 is available. This release simplifies the gcluster job configuration workflow, adds dynamic catalog fallback for system node po…Mon 07 Sep
- SecurityGoogle addressed a security vulnerability (CVE-2026-65107) in the Slurm sbcast tool that affects Cluster Toolkit. For more information, see the security bulleti…Mon 07 Sep
- SecurityGoogle addressed multiple security vulnerabilities in Slurm that affect Cluster Toolkit. For more information, see the security bulletin .Fri 11 Sep
Compute Engine — 1
- FeatureGenerally available : You can convert a single-project reservation into a shared reservation, or a shared reservation into a single-project reservation. Modify…Tue 08 Sep
Config Connector — 5
- AnnouncementConfig Connector version 1.156.0 is now available.Tue 08 Sep
- ChangeReconciliation Improvements: We have added support for direct reconciliation to more resources, with opt-in behavior. The API is unchanged. To use the direct re…Tue 08 Sep
- FeatureNew Alpha Resources (Direct Reconciler): CCInsightsQAScorecard Manage Contact Center Insights QA scorecards to manage and evaluate agent performance. ContentWar…Tue 08 Sep
- FeatureNew Fields: BigtableTable Added spec.automatedBackupPolicy.locations field. ContainerCluster Added spec.nodeConfig.swapConfig field. ContainerNodePool Added spe…Tue 08 Sep
- FeatureNew Features: Optional NAT IP Allocate Option : Made natIpAllocateOption an optional field in ComputeRouterNat to support dynamic allocation. Preview Summary CL…Tue 08 Sep
Container Optimized OS — 19
- Changecos-beta-133-19999-44-28 Kernel Docker Containerd GPU Drivers COS-6.18.48 v29.4.3 v2.3.4 See ListTue 08 Sep · cos-beta-133-19999-44-28
- Changecos-129-19506-448-20 Kernel Docker Containerd GPU Drivers COS-6.12.105 v27.5.1 v2.2.7 See ListTue 08 Sep · cos-129-19506-448-20
- Changecos-dev-138-20098-0-0 Kernel Docker Containerd GPU Drivers COS-6.18.49 v29.4.3 v2.3.2 See ListTue 08 Sep · cos-dev-138-20098-0-0
- ChangeUpdated containerd and containerd-test to v2.3.4.Tue 08 Sep · cos-dev-138-20098-0-0
- ChangeUpdated the Linux kernel to v6.18.48.Tue 08 Sep · cos-dev-138-20098-0-0
- ChangeUpdated the Linux kernel to v6.18.49.Tue 08 Sep · cos-dev-138-20098-0-0
- ChangeRuntime sysctl changes: Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068Tue 08 Sep · cos-dev-138-20098-0-0
- Changecos-117-18613-731-6 Kernel Docker Containerd GPU Drivers COS-6.6.153 v24.0.9 v1.7.34 See ListTue 08 Sep · cos-117-18613-731-6
- Changecos-121-18867-584-7 Kernel Docker Containerd GPU Drivers COS-6.6.153 v27.5.1 v2.0.10 See ListTue 08 Sep · cos-121-18867-584-7
- Changecos-125-19216-655-12 Kernel Docker Containerd GPU Drivers COS-6.12.105 v27.5.1 v2.2.7 See ListTue 08 Sep · cos-125-19216-655-12
- ChangeRuntime sysctl changes: Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068Tue 08 Sep · cos-125-19216-655-12
- SecurityUpdate dev-go/net to v0.55.0 to fix CVE-2026-25680.Tue 08 Sep · cos-dev-138-20098-0-0
- SecurityUpdated dev-go/net to v0.55.0 to fix CVE-2026-25680.Tue 08 Sep · cos-dev-138-20098-0-0
- SecurityFixed CVE-2026-6238 in sys-libs/glibc.Tue 08 Sep · cos-117-18613-731-6
- SecurityUpdated dev-go/net to v0.55.0 to fix CVE-2026-25680.Tue 08 Sep · cos-117-18613-731-6
- SecurityFixed CVE-2026-6238 in sys-libs/glibc.Tue 08 Sep · cos-121-18867-584-7
- SecurityUpdated dev-go/net to v0.55.0 to fix CVE-2026-25680.Tue 08 Sep · cos-121-18867-584-7
- SecurityFixed CVE-2026-6238 in sys-libs/glibc.Tue 08 Sep · cos-125-19216-655-12
- SecurityUpdated dev-go/net to v0.55.0 to fix CVE-2026-25680.Tue 08 Sep · cos-125-19216-655-12
GKE security bulletin — 1
- GCP-2026-061Published: 2026-09-09 Reference: GHSA-p7v4-vr35-mj6f Description Severity A security vulnerability GHSA-p7v4-vr35-mj6f (CVE assignment pending) in containerd's…Wed 09 Sep
Gemini Enterprise — 4
- FeatureGemini Enterprise: Semantic search support in Google Cloud Marketplace (Preview) The agent search in Google Cloud Marketplace now supports semantic search, allo…Tue 08 Sep
- BreakingGemini Notebook Enterprise: Website URL ingestion blocked by VPC Service Controls Projects with VPC Service Controls enabled can't add website URLs as notebook…Wed 09 Sep
- FeatureGemini Enterprise: Pay-as-you-go edition and AI developer tools available for all invoiced Cloud Billing accounts Subscribing to the Gemini Enterprise Pay-as-yo…Thu 10 Sep
- FeatureGemini Enterprise: Support for channel mentions and multi-turn conversations in the Gemini Enterprise app for Slack The Gemini Enterprise app for Slack has the…Thu 10 Sep
Gemini Enterprise Agent Platform — 5
- FeatureAgent connectivity templates for VPC connectivity in Agent Gateway Agent Gateway now uses agent connectivity templates ( agentConnectivityTemplate ) to configur…Tue 08 Sep
- FeatureComputer Use and Shell sandboxes are generally available Computer Use and Shell sandboxes in Gemini Enterprise Agent Platform are now generally available (GA).…Wed 09 Sep
- FeaturePriority PayGo now supports the US and EU multi-region endpoints You can send Priority PayGo requests to the us and eu multi-region endpoints, in addition to th…Wed 09 Sep
- FeatureAgent Gateway supports multiple Agent Registry instances Agent Gateway now lets you associate up to two Agent Registry instances (one global registry and one re…Wed 09 Sep
- FeatureAgent Gateway supports VPC Service Controls Agent Gateway now enforces VPC Service Controls perimeter rules for agent communications. When you configure Agent G…Wed 09 Sep
Google Cloud Contact Center as a Service — 12
- AnnouncementAdvanced reporting dashboards prerelease notes 6.4 Here are the pre-release notes for updates to the advanced reporting dashboards and other reporting in CCAI P…Tue 08 Sep
- FeatureReal-time Agent Monitoring dashboard: new Active call ID(s) column The Real-time Agent Monitoring dashboard now has an Active Call ID(s) column in the Live Agen…Tue 08 Sep
- FeatureImproved filtering by team We made the following changes to team-based filtering: Renamed the Teams filter to Agent Teams to clarify that it filters by the agen…Tue 08 Sep
- FeatureImproved the Real-time Calls and Real-time Chats dashboards We made the following dashboard improvements: Real-time Calls - Calls Connected dashboard . Added th…Tue 08 Sep
- FeatureReal-time Calls - Calls Queued dashboard: new Projecting column The Real-time Calls - Calls Queued dashboard has a new Projecting column in the Call Queued tabl…Tue 08 Sep
- FixedThis release addresses the following issues: Fixed an issue where the formatting of numeric values was inconsistent across tiles. Fixed an issue where column he…Tue 08 Sep
- AnnouncementGoogle Cloud CCaaS 6.12 We've released version 6.12 of Google Cloud CCaaS. The timing of the update to your instance depends on the deployment schedule that you…Fri 11 Sep
- FeatureCold transfers auto-resume When an agent performs a cold transfer, the call now resumes at the moment the receiving agent answers the call. The receiving agent…Fri 11 Sep
- FeatureHubspot: Configure Do Not Call by phone number In HubSpot integrations, you can now configure Do Not Call for specific phone numbers instead of for an entire co…Fri 11 Sep
- FeatureAgent desktop: New network diagnostics tool The agent desktop has a new network diagnostics tool in the navigation menu that displays network strength and diagn…Fri 11 Sep
- FeatureAgent desktop: Open from the CCaaS portal You can now access the Agent Desktop using the new Apps menu. In the CCaaS portal, click Apps > Agent Desktop to open…Fri 11 Sep
- FixedThis release addresses the following issues: Fixed an issue where SmartAction statuses were incorrectly marked as "failed" when a call ended before a photo or v…Fri 11 Sep
Google Cloud Managed Service for Apache Kafka — 1
- FeatureYou can configure a Managed Service for Apache Kafka cluster as a public cluster to let client applications connect over the public internet. For more informati…Thu 10 Sep
Google Kubernetes Engine — 13
- Change(2026-R38) Version updates GKE cluster versions have been updated. New versions available for upgrades and new clusters. The following versions are now availabl…Tue 08 Sep
- Change(2026-R38) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Tue 08 Sep
- Change(2026-R38) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Tue 08 Sep
- Change(2026-R38) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Tue 08 Sep
- Change(2026-R38) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Tue 08 Sep
- Change(2026-R38) Version updates Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and…Tue 08 Sep
- Extended channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Tue 08 Sep
- No channel (deprecated)Note : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Tue 08 Sep
- Rapid channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Tue 08 Sep
- Regular channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Tue 08 Sep
- Security(2026-R38) Security updates This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorpor…Tue 08 Sep
- Stable channelNote : Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to…Tue 08 Sep
- FeatureAgent Substrate on GKE is now available for evaluation and non-production use. Production support is offered on an allowlist basis under a limited GA program. A…Fri 11 Sep
Google SecOps Marketplace — 4
- ChangeMicrosoft 365 Defender : Version 31.0 Updated alert tracking logic, extracted alert object metadata, and improved the pagination and timeout handling mechanism…Wed 09 Sep
- ChangeGoogle Chronicle : Version 95.0 Integration : Improved OAuth 2.0/JWT authentication logging, validation diagnostics, and error messaging.Wed 09 Sep
- ChangeTrend Vision One : Version 12.0 Made the Description parameter mandatory in the following actions: Isolate Endpoint Unisolate EndpointWed 09 Sep
- FeatureGoogle Chronicle : Version 95.0 The following new action has been added: Is Value In Data Table AsyncWed 09 Sep
Identity and Access Management — 2
- FeatureYou can get IAM role suggestions from Gemini programmatically by using the Policy Assist API ( Preview ). For more information, see the following documentation:…Wed 09 Sep
- FeatureThe Identity and Access Management (IAM) Model Context Protocol (MCP) server is generally available . You can connect to the IAM remote MCP server from AI appli…Thu 10 Sep
Knowledge Catalog — 1
- FeatureData domains in Knowledge Catalog allow you to logically organize the resources within the enterprise to discover and curate your data at scale. This feature is…Mon 07 Sep
Looker — 2
- DeprecatedThe deprecation of the Looker Mobile (Legacy) application has been postponed to January 31, 2027. Starting on January 31, 2027, support for the Looker Mobile (L…Wed 09 Sep
- FeatureThe Looker extension for VS Code is now generally available, enabling local LookML development and AI-assisted "vibe coding" using the Model Context Protocol (M…Thu 10 Sep
NetApp Volumes — 1
- AnnouncementGoogle Cloud NetApp Volumes now supports the Flex Unified service level in the following regions: asia-east1 (Taiwan) australia-southeast2 (Melbourne) europe-so…Wed 09 Sep
Network Connectivity Center — 1
- FeatureSupport for global Google APIs for endpoint propagation through Network Connectivity Center is available in Preview . For information about the new quota for pr…Thu 10 Sep
Network Intelligence Center — 1
- FeatureYou can deploy Monitoring Points optimized for Amazon Web Services (AWS) or Microsoft Azure cloud infrastructure from Cloud Network Insights .Wed 09 Sep
Policy Intelligence — 2
- FeatureThe Policy Assist remote MCP server is available in Preview . To learn about using the Policy Assist remote MCP server to let external AI agents and application…Wed 09 Sep
- FeatureThe Policy Assist REST API is available in Preview . Policy Assist lets you get IAM role suggestions for individual principals with AI assistance. To learn abou…Wed 09 Sep
Secret Manager — 1
- FeatureParameter Manager supports using tags to group and organize parameters and conditionally manage access control using Identity and Access Management (IAM) polici…Tue 08 Sep
Security bulletin — 2
- GCP-2026-061Published: 2026-09-09 Description Description Severity Notes A security vulnerability ( GHSA-p7v4-vr35-mj6f , CVE assignment pending) in containerd's CRI implem…Wed 09 Sep
- GCP-2026-062Published: 2026-09-11 Description Description Severity Notes Multiple security vulnerabilities were discovered in Slurm that affect Cluster Toolkit blueprints t…Fri 11 Sep
Sovereign Controls by Partners — 3
- FeatureThe France Data Boundary by S3NS supports the following products: AlloyDB for PostgreSQL Apigee EventarcTue 08 Sep
- FeatureThe Italy Data Boundary by PSN supports the following products: AlloyDB for PostgreSQL Apigee EventarcTue 08 Sep
- FeatureThe Germany Data Boundary by T-Systems supports the following products: AlloyDB for PostgreSQL Apigee EventarcTue 08 Sep
VPC Service Controls — 1
- FeatureGeneral availability support for the following integration: Observability APITue 08 Sep
Virtual Private Cloud — 1
- FeaturePreview : Propagated connections support Private Service Connect endpoints that access global Google APIs . With propagated connections, endpoints that access g…Thu 10 Sep
Comments