🔐 Zero-Trust Security, Identity & Threat Defence
Security frameworks are transitioning towards proactive software supply chain defences, identity propagation resilience, real-time DNS armouring, and autonomous agent threat modelling.
- Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure: Mandiant and Google Cloud Threat Intelligence establish a comprehensive security blueprint for the Software Development Lifecycle (SDLC), addressing continuous integration vulnerabilities, pipeline privilege abuse, and build provenance attestation across modern code repositories.
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft: Mandiant tracks threat group UNC6240 (ShinyHunters) mass-exploiting Oracle PeopleSoft via CVE-2026-35273, detailing how adversaries bypass Web Application Firewall (WAF) rules with a single URL-encoded character and outlining tactical post-exploitation mitigations.
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances: Google Threat Intelligence Group (GTIG) outlines forensic detection strategies and indicators of compromise (IOCs) to protect enterprise perimeters against active zero-day exploitation chains targeting Citrix NetScaler ADC and Gateway appliances.
- Vulnerability Discovery and Exploitation Trends in the AI Era: A research study by GTIG analysing multi-year disclosure statistics, revealing how generative and agentic AI tools are compressing the discovery-to-exploitation window for common vulnerabilities while shifting the landscape of discovered flaw categories.
- Google Cloud partners deliver new security agents and AI defenses with Gemini Enterprise: Google Cloud broadens its ecosystem of partner-built security agents on Gemini Enterprise, integrating SIEM contexts, threat intelligence feeds, and automated remediation playbooks directly into enterprise SecOps workflows.
- Strengthen your CI/CD pipeline with new Secure Source Manager capabilities: Secure Source Manager introduces unified authentication and fine-grained authorisation mechanisms across internal source repositories and CI/CD engines to protect software supply chains against insider threats and token compromise.
- GCP IAM propagation lag and Terraform CI/CD: Investigating intermittent 403 and 404 errors during automated Terraform CI/CD runs caused by Google Cloud IAM eventual consistency, with architectural patterns for retry loops, policy polling, and deterministic resource staging.
- The Cloud Guardrails : Mastering GCP Organization Policy: Moving from reactive post-deployment security alerts to preventive enforcement using hierarchical GCP Organisation Policies, blocking non-compliant API calls and misconfigurations at the resource manager layer before resources are provisioned.
- Your GCP Project Shipped Insecure by Default. Here’s How to Fix It Fast.: A pragmatic hardening guide targeting out-of-the-box GCP project defaults, explaining how default service accounts, broad API access scopes, and open ingress rules create unnecessary attack surfaces.
- Detecting and Blocking Malicious DNS Queries on GCP: Building an automated, event-driven threat response system using Cloud DNS Armor, Pub/Sub, and Cloud Functions to dynamically add detected command-and-control domains to a DNS Response Policy Zone (RPZ).
- New to Google SecOps: |> WHERE Did Our Logs Go?: A practitioner tutorial on mastering the GoogleSQL
WHEREpipe operator for high-performance log analysis in Google Security Operations, covering regex filters, case handling, and nested array queries. - The future of browser-based security: Leveraging browser data for proactive defense: Chrome Enterprise Premium transforms enterprise browsers into telemetry engines, capturing fine-grained user activity to intercept Shadow AI tool usage, credential exfiltration, and unauthorised data pasting in real time.
- Separating metadata and prompt access for Antigravity logs: Implementing role-based access control (RBAC) in Gemini Enterprise to decouple sensitive prompt contents from operational metadata, allowing platform engineers to troubleshoot execution errors without viewing confidential user queries.
- Secure, intelligent experiences across every endpoint: Discover how Google Intelligent Endpoints combine agentic AI, Chrome Enterprise Premium, and next-generation device management to balance workforce productivity with zero-trust endpoint protections.
- Cloud CISO Perspectives: How cybersecurity startups can win CISOs: Google Cloud Office of the CISO provides strategic guidance for enterprise security vendors, focusing on frictionless identity integration, verifiable compliance artefacts, and agentic interoperability.
- Defending at machine speed: Securing the public sector in the agentic era: Case studies illustrating how public sector organisations deploy autonomous AI security agents to correlate national-scale threat feeds and orchestrate perimeter incident responses in seconds.
- New regions and networks: Firebase Phone Number Verification adds more networks: Firebase Phone Number Verification expands to 10 additional carrier networks across Europe and Asia, replacing vulnerable SMS OTP authentication with cryptographic, tap-to-consent SIM-based verification.
📊 High-Performance Databases, Lakehouse & Big Data Analytics
Data platforms are unifying transactional messaging with operational databases, scaling hybrid vector caching, and operationalising agentic SQL tooling across enterprise lakehouses.
- Announcing Spanner queues: Transactional messaging for agentic workloads and beyond: Spanner queues embed transactional message queuing natively into Cloud Spanner, allowing developers to enqueue messages as standard transaction writes with strict ACID consistency, automatic deduplication, and zero external broker management.
- Spanner Omni, now GA: A distributed, multi-model database that you can deploy anywhere: Google Cloud makes Spanner Omni Generally Available, allowing enterprises to run Spanner's distributed SQL engine across on-premises data centres and rival cloud platforms while maintaining relational schema integrity and multi-region replication.
- AlloyDB delivers PostgreSQL for agents: Real-time data at agent scale, with full workload isolation: AlloyDB introduces a specialised PostgreSQL architecture for agentic workloads, decoupling analytical AI queries from operational transactions to support millions of concurrent vector and text lookups with guaranteed workload isolation.
- A new, no-compromises database architecture for the agentic era: A deep dive into AlloyDB's decoupled storage-compute architecture, demonstrating how zero shared fate by design and sub-millisecond NVMe caching enable elastic scaling from zero to thousands of read instances for high-burst AI agent requests.
- Unlock 3x QPS and microsecond latency with Memorystore for Valkey 9.1: Memorystore for Valkey 9.1 enters General Availability, delivering up to three times higher query throughput at sub-millisecond latencies for high-concurrency caching and session storage backends.
- How to implement long-term AI agent memory in AlloyDB and Memorystore for Valkey: Designing a tiered agent memory architecture that pairs microsecond-latency working memory in Memorystore for Valkey with persistent, vector-indexed semantic recall in AlloyDB AI.
- Data Agent Kit is now GA: Bring Google Data Cloud to any coding agent: Google Cloud announces the General Availability of Data Agent Kit, an open-source suite of Model Context Protocol (MCP) tools and Agent Skills that connects coding agents directly to BigQuery, Spanner, Bigtable, and Cloud Storage.
- Maximizing Apache Spark availability: Mitigating compute stockouts with flexible VMs and other best practices: Guidance on leveraging flexible VM configurations within Managed Service for Apache Spark to mitigate regional compute shortages, stabilise large-scale data processing batches, and protect critical pipeline SLAs.
- Accelerating analytics: PayPal’s journey with Managed Service for Apache Spark: PayPal shares technical learnings from migrating petabyte-scale data pipelines to Google Cloud Managed Service for Apache Spark, significantly reducing infrastructure management overhead and improving query execution predictability.
- Why I Reworked a BigQuery Sink from Pending Streams to Buffered Streams: Apache SeaTunnel engineers document why switching BigQuery write sinks from pending commit streams to buffered streaming APIs improved disaster recovery, fault tolerance, and ingestion throughput under intermittent worker failures.
- Eliminate First: How We Architected a 60% + BigQuery Cost Reduction: A case study in re-architecting an enterprise analytics warehouse, demonstrating how eliminating redundant table scans, optimising clustering keys, and trimming unused scheduled queries achieved more than 60% in BigQuery compute savings.
- Bring Jev to BigQuery with Cloud Run: Converting unstructured text into typed, validated SQL records by deploying TypeSafe's Jev model as a serverless Cloud Run remote function invoked directly from BigQuery queries.
- Jev and BigQuery AI functions, from one row to ten million: Benchmarking latency, inference cost, and extraction fidelity across Jev and BigQuery native AI functions, highlighting how cascading lightweight routing models before heavyweight LLMs optimises large-scale data extraction.
- Lessons From Streaming Pipelines on GCP: Hard-won operational lessons on Apache Beam and Cloud Dataflow streaming pipelines, covering watermark management, state storage sizing, drain caveats, and handling catastrophic upstream schema drift.
- Pub/Sub AI Bytes: Part 3 - Generate and edit SMTs with Gemini in seconds: Using Gemini inside Google Cloud Pub/Sub to generate, test, and refine User-Defined Function (UDF) Single Message Transforms (SMTs) in JavaScript using natural language prompts.
- Pub/Sub AI Bytes: Part 4 - High-throughput ingestion for large-scale model training: Architecting serverless Pub/Sub ingestion pipelines capable of sustaining millions of events per second to feed distributed training clusters across GPUs and TPUs without operational bottlenecks.
- Introducing Ask, a new Google Earth Engine feature to accelerate geospatial coding: Google Earth Engine introduces Ask in the Code Editor, embedding Gemini to help geospatial developers write, troubleshoot, and optimise complex raster queries and satellite imagery analyses.
- Scribd, Inc. classifies more than 400 million documents with Gemini batch inference on Gemini Enterprise: Scribd details running trust and safety classification across 400 million user documents (spanning 12 billion pages) in months using Gemini native PDF parsing and Gemini Enterprise batch prediction.
⚡ Cloud-Native Infrastructure, GKE & Serverless Workloads
Kubernetes and serverless architectures are unlocking instant elasticity with native scale-to-zero runtimes, memory-preserving Pod snapshots, and intelligent GPU accelerator scheduling.
- GKE becomes more elastic: Scale to zero, save costs, and keep workloads responsive: Google Kubernetes Engine introduces native scale-to-zero capabilities, enabling inactive workloads to release all node compute and accelerator resources while automatically re-provisioning on incoming traffic.
- Scale your AI workloads faster and more efficiently with GKE Pod snapshots: GKE Pod snapshots capture the complete in-memory execution state of running containers (including CPU and GPU VRAM), slashing AI model cold starts from minutes to seconds by resuming directly from persistent storage.
- Global AI routing with <1% overhead on multi-cluster GKE Inference Gateway: Benchmarking GKE Inference Gateway across multi-cluster GPU and TPU fleets in the US and Europe, showcasing global intelligent request routing that maximizes accelerator utilisation with under 1% proxy overhead.
- An AI-assisted plugin for EKS-to-GKE migrations with built-in governance: Announcing the GKE agentic migration plugin, an AI-assisted CLI tool that converts AWS EKS manifests and Helm charts into idiomatic GKE configurations while enforcing strict enterprise security guardrails.
- Scale your own way, using HPA with built-in support for PromQL metrics queries in GKE: Google Kubernetes Engine integrates native Prometheus PromQL support into Horizontal Pod Autoscaler (HPA), allowing operators to define sophisticated custom autoscaling triggers without deploying external metric adapters.
- GKE CPU startup boost: Accelerate app starts without over-provisioning: GKE CPU startup boost leverages in-place pod resizing to temporarily grant additional CPU cores during container initialisation, halving JVM and framework boot times without inflating steady-state resource allocations.
- Re-Architecting GKE: From Rigid Node Pools to Workload-Driven ComputeClasses: Moving from sprawling, statically sized Kubernetes node pools to namespace-scoped ComputeClasses, enabling workloads to declare hardware requirements declaratively and empowering cluster autoscalers to provision just-in-time infrastructure.
- Kueue v0.20: What’s new?: Exploring Kueue v0.20 on GKE, highlighting multi-tenant AI cluster orchestration features including configurable workload preemptions, dynamic hierarchical quota sharing, and topology-aware accelerator placement.
- One StorageClass, Two VM Generations: Platform engineering patterns to resolve volume attachment failures across mixed-generation GKE node fleets (such as N2 and N4 VMs) through automated disk type selection and custom ComputeClasses.
- How Google Cloud Networking Supports Your Fluid Compute Choices for AI Workloads: An architectural overview of Google Cloud's high-speed networking fabric, comparing Standard VPC, GPUDirect-TCPX/TCPXO, RoCEv2 RDMA, Cloud TPU meshes, and Cloud Run for distributed AI training and inference.
- Cloud Run CPU Throttling: Unraveling Serverless Performance Mysteries: An analysis of Cloud Run's default CPU allocation model, explaining how CPU throttling freezes background tasks immediately after HTTP responses complete and how to configure background CPU or Cloud Tasks for reliable execution.
- Private GCS via Internal Load Balancers: No Client Auth Required: A clever networking pattern using Cloud Run traffic extensions on regional Internal Application Load Balancers to inject IAM credentials and serve private Cloud Storage objects to internal clients without client-side authentication.
- Storage-optimized Z4D machine family, now GA, is designed for IO-intensive workloads: Compute Engine makes Z4D VM and bare metal instances Generally Available, offering up to 3 TB memory and 42 TB of high-performance local NVMe storage for extreme I/O databases, cache nodes, and data warehouses.
- Democratizing Managed Lustre with lower cost and frictionless development: Google Cloud Managed Lustre introduces the Dynamic Tier, lowering entry costs for high-throughput parallel file storage while allowing engineering teams to run interactive notebooks and petabyte AI training on shared storage.
- Storage Intelligence advisor: Know what changed in your storage estate and act on it: Enhancements to Storage Intelligence advisor and batch operations allow cloud storage administrators to surface cost-saving opportunities, identify orphaned datasets, and execute automated lifecycle transitions across large bucket estates.
- Enabling Cloud Storage end-to-end checksums for improved data integrity and durability: Cloud Storage client SDKs now enable automated end-to-end checksumming by default, establishing an unbroken cryptographic chain of custody from client memory to physical storage media.
- Mastering GCP Multi-Org Hybrid Cloud DNS: Navigating Inbound Forwarding Patterns (Part 1): Architecting multi-organisation DNS inbound forwarding topologies on Google Cloud, resolving domain resolution overlaps and cross-VPC routing constraints in complex hybrid enterprise environments.
- Mastering GCP Multi-Org Hybrid Cloud DNS: Solving Outbound DNS and Asymmetric Routing Concerns (Part 2): Part two investigates outbound hybrid DNS queries across shared interconnects, detailing routing policies to eliminate asymmetric routing loops and dropped responses across shared egress IP pools.
- Certificate Manager: Zero downtime SSL certificate migration with LB authorization: Combining Google Cloud Certificate Manager and Google Public CA to execute zero-downtime SSL/TLS migrations without requiring direct DNS registrar access or risking handshake disruptions.
- Managed SFTP on Google Cloud: A hands-on deployment guide for Google Cloud's managed SFTP service, enabling legacy on-premises systems to securely deposit files into Cloud Storage using IAM authentication without self-hosted bastion VMs.
- Google is a Leader in the 2026 Gartner Magic Quadrant for Container Management: Gartner recognises Google as a Leader in the 2026 Magic Quadrant for Container Management, ranking GKE and Cloud Run highest in Ability to Execute.
🛠️ AI Agents, Runtimes & Platform Modernisation
The agentic developer stack is standardising on remote Model Context Protocol servers, graph-orchestrated workflows, local on-device model runtimes, and memory-backed agent architectures.
- Introducing Support for Local AI Models in the Antigravity SDK: Google Antigravity SDK adds native support for local, offline agent workflows using Gemma 4 26B-A4B via LiteRT and OpenAI-compatible endpoints (Ollama, vLLM), establishing hybrid cloud-local agent architectures.
- Empower your agents with the Google Cloud CLI remote MCP server: Introducing the Google Cloud CLI remote Model Context Protocol server in Preview, providing AI coding assistants with secure, managed tools to discover and manage Google Cloud resources directly from IDEs.
- Turn your REST APIs into MCP tools with Google Cloud API Gateway: Google Cloud API Gateway can now function as a remote MCP server, allowing engineering teams to annotate existing OpenAPI 3.x specifications to expose standard REST backends to autonomous agents without writing custom middleware.
- Accelerating agentic RL and evaluation research velocity with 45x faster GKE Agent Sandbox: GKE Agent Sandbox delivers 45x faster container environment spinning for agentic reinforcement learning (RL) and trajectory evaluation, supported by an orchestration SDK and native integration with major RL gym harnesses.
- Graph Workflows in ADK: Everything You Need to Know: A comprehensive exploration of graph workflows within Google Cloud Agent Development Kit (ADK), explaining how stateful acyclic graphs and conditional routing provide deterministic guarantees for multi-agent business automations.
- Create an Agent that Remembers with Agent Platform Memory Bank: Integrating Agent Platform Memory Bank with Google ADK to equip autonomous agents with long-term semantic memory, conversational state recall, and cross-session user context.
- The Firebase plugin is now available in Codex: Google launches the official Firebase plugin for Codex, bundling agent skills, CLI tooling, and MCP servers so coding assistants can provision Firestore databases, set up auth providers, and draft security rules automatically.
- Agent Factory recap: Agent harnesses, shifting left, and autonomous coding: Key architectural takeaways from Google's Agent Factory, exploring the three-layer stack of foundation models, test harnesses, and curated knowledge stores required to operationalise autonomous coding agents.
- Introducing the Server Side Cloud Swift SDK: Google introduces the official Server Side Cloud Swift SDK, empowering Swift 6.2+ developers to build memory-safe, non-blocking cloud backends and automation tooling across more than 100 Google Cloud services.
- Power your agents: Gemini 3.8 Live with Live Avatar is now generally available: Gemini 3.8 Live with Live Avatar reaches General Availability across US and EU endpoints, delivering low-latency bidirectional voice and interactive avatar streaming with enterprise compliance controls.
- Colab is now part of your Google AI plan: Google unifies Colab compute subscriptions into the Google AI plan, granting researchers and data scientists priority access to high-end GPUs, increased RAM, and background execution for persistent model training.
- Google's QAT Gemma 4 26B-A4B on One TPU v6e: 15.6x the KV Cache and 1.9x the Throughput of FP8: A technical walkthrough demonstrating how Quantisation-Aware Training (QAT) enables Gemma 4 26B-A4B to run on a single Cloud TPU v6e with vLLM, expanding effective KV cache by 15.6x and doubling inference throughput.
- Gemma 4 QAT on One TPU v5e: What Runs and What Doesn't: Testing memory footprint and token throughput when repacking and serving QAT Gemma 4 models on budget-friendly single TPU v5e chips, detailing precision trade-offs across 12B and 26B variants.
- Reproducing OLMo 3 7B Pre-training in MaxText: case study of large scale training on TPUs: The MaxText team reproduces AI2's OLMo 3 7B model from scratch using JAX/XLA on Google Cloud TPUs, matching original PyTorch benchmarks while achieving 57.4% Model Flops Utilisation (MFU) across cluster resizes.
- Accelerating Spatio-Temporal Attention for Video Diffusion on TPUs: Overcoming attention latency bottlenecks in high-definition video diffusion models by implementing Sparse VideoGen (SVG) and optimised Splash Attention kernels on Cloud TPUs.
- AI21 achieves an 83% reduction in time-to-start for AI workloads with AI Hypercomputer: AI21 slashes startup latency by 83% for massive foundation model training workloads by combining GKE, AI Hypercomputer orchestration, and A3 Ultra instances powered by NVIDIA H200 GPUs.
- A guide to speeding up your video processing with AlphaEvolve: Using AlphaEvolve algorithms to optimise parallel video transcoding pipelines, resolve pipeline concurrency bottlenecks, and accelerate multimodal preprocessing pipelines.
- Best practices guide for customizing Gemini models via Reinforcement Learning (RL): A field guide detailing reward function engineering, trajectory dataset curation, and iterative training loops when using Google Cloud's managed Reinforcement Learning fine-tuning service for Gemini.
- How to build a Jev-style classifier with DiffusionGemma and vLLM: Building fast, calibrated intent routing classifiers on Cloud Run GPUs using DiffusionGemma and vLLM without expensive full-model parameter fine-tuning.
- How to Run Open Models in the Cloud Without Going Broke: Strategies for deploying open-weight foundation models on Vertex AI Model Garden cost-effectively, leveraging spot instances, scale-to-zero autoscaling, and quantised container runtimes.
- Per-User LLM Spend Capping on Apigee X: Implementing granular token budgeting and per-user financial spend quotas on Apigee X API proxies in front of LLM endpoints using rate-limiting policies and quota counters.
- Governing LLM Spend on Google Cloud: The Three Levers: A strategic FinOps analysis of LLM expense management on GCP, exploring platform quotas, automated billing alerts, hard request rejection, and custom application middleware.
- Enforcing Per-User AI Spend Limits on Google Cloud Vertex AI: Bridging the gap beyond project-level quotas by implementing custom per-user cost tracking and real-time invocation throttles for Vertex AI endpoints.
- What Nobody Is Using in Your Google Cloud Projects, and What It Costs: Building a lightweight, read-only Python waste scanner that queries Cloud Asset Inventory and the Cloud Billing Catalog API to identify forgotten disks, unattached IPs, and idle NAT gateways.
- Certification - How to Prepare for Google Cloud Professional Agentic Architect: A study roadmap and syllabus review for the Google Cloud Professional Agentic Architect certification, covering multi-agent choreography, tool interfaces, evaluation harnesses, and security boundaries.
- Why your startup needs open models alongside frontier APIs: Exploring hybrid AI architecture for startups, demonstrating why pairing specialised open-source models like Gemma 4 with frontier APIs like Gemini 3.8 balances latency, unit economics, and data privacy.
- Google Analytics for Firebase iOS SDK outage on September 28, 2026: An SRE post-mortem analysing how a routine configuration cleanup in the Google Analytics for Firebase SDK inadvertently caused widespread iOS application crashes, and the rollout safeguards instituted since.
- GCP Bytes Podcast Episode #50: Celebrating episode 50 by discussing Claude Control, 128 GB RAM workstations, AWS regional dynamics, GCVE self-management, agentic safety vulnerabilities, Grok 4.7, and the Jev classification model.
📋 Essential Release Notes
A curated review of runtime additions, enterprise security controls, and managed infrastructure milestones rolling out across Google Cloud.
- API Gateway: API Gateway introduces Public Preview support for streaming LLM responses and real-time data over HTTP/2, SSE, and gRPC, alongside API key authentication for Model Context Protocol (MCP) tool discovery.
- Agent Assist: Companion agent enters General Availability (GA), unifying proactive live-conversation guidance with streaming on-demand assistant panels and grounded tool execution across enterprise contact centres.
- Apigee API Hub: Reaches GA for the Service Type system attribute (classifying APIs as Code, Model, Agent, or Skill) and introduces dedicated AI and Tool performance dashboards in API insights to monitor token volumes, model latency, and MCP tool usage.
- BigQuery: BigQuery Data Transfer Service MCP server reaches GA. Continuous queries can now write directly into Apache Iceberg managed tables,
AI.KEY_DRIVERSenters GA for automated statistical anomaly detection, andOBJ.LISTprovides spontaneous unstructured object queries without table definitions. - Bigtable: Bigtable integrates with Google Cloud Data Agent Kit for coding agents in GA, and adds console support for authoring and managing protobuf schemas (schema bundles) in Bigtable Studio.
- Cloud Run: Preview launch of free custom URLs (
*.cloud.run) without requiring load balancers or DNS provisioning, alongside General Availability of fine-grained target CPU and concurrency scaling controls. - Google Kubernetes Engine (GKE): Storage-optimised Z4D node support reaches GKE, automated TPU node pool protection tier labelling is introduced, and Vertical Pod Autoscaler (VPA) CPU rightsizing is enabled alongside Horizontal Pod Autoscaler (HPA) in Public Preview.
- Load Balancing: Application Load Balancers adopt a complexity-based quota system in GA that increases individual URL map configuration limits from 64 KB / 128 KB up to 1 MB, alongside Preview support for IPv6-only zonal NEGs.
- Cloud Storage: Client libraries provide automated end-to-end checksum validation by default for object read and write operations, guaranteeing data integrity across transfers.
- Compute Engine: Introduces a 120-second preemption notice duration for Spot VMs in GA, allows CMEK-encrypted disk snapshots independent of source disk keys, and deprecates NVIDIA T4 and P4 GPUs with full end-of-support scheduled for August 1, 2027.
- Cloud SQL: Cloud SQL removes export permissions from default Viewer and Reader roles to harden database security, rolls out the C4 machine series for PostgreSQL Enterprise Plus, and integrates the
pgAuditextension to suppress sensitive credentials in query logs. - Dataform: The Dataform remote MCP server reaches GA, enabling AI coding agents to manage git workspaces and compile pipelines. Extended access controls, user credentials scheduling, and automated Knowledge Catalog metadata scorecards are also Generally Available.
- Security Command Center: SCC Risk Engine introduces toxic combination detection for AI reasoning engines capable of altering IAM policies, while Event Threat Detection integrates with Sensitive Data Protection for sensitive resource enrichment.
- Service Mesh: Cloud Service Mesh officially deprecates both managed and in-cluster ISTIOD control planes on GKE as of September 28, 2026, establishing a mandatory migration deadline to the
TRAFFIC_DIRECTORcontrol plane by March 1, 2028. - VPC Service Controls: General Availability of Google Cloud folder and organisation references in ingress and egress perimeter rules, alongside native folder membership for service perimeters to automatically protect nested project hierarchies.
- Cloud NGFW: Cloud NGFW Enterprise advanced threat prevention enters Preview for cross-region internal Application Load Balancers, enabling intrusion detection (IDS/IPS) and WildFire malware inspection on load balancer forwarding rules.
- Cloud Interconnect: Network Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect with Amazon Web Services (AWS) reaches General Availability.
- Workstation: Regional endpoints reach General Availability for Cloud Workstations across Europe, the US, and APAC, enforcing strict data residency for remote developer environments under HIPAA compliance.