BigQuery
Feature
For additional layers of security and control, you can now use query templates to predefine and limit the queries that can be run in data clean rooms. For more information, see Use query templates. This feature is in preview.
Bigtable
Announcement
Bigtable tools are available in Agent Development Kit (ADK). With these tools, you can build AI agents that can interact with Bigtable data and metadata in the following ways:
- Obtain metadata about Bigtable tables and instances.
- Execute LLM-powered SQL queries.
Compute Engine
Feature
Generally available: M4 memory-optimized hypermem VMs are now generally available. These smaller machine types expand the memory-optimized family to allow for greater flexibility in matching your specific application needs. Hypermem VMs have a GB/vCPU ratio of 15.5:1 and are offered in the following sizes:
- m4-hypermem-16
- m4-hypermem-32
- m4-hypermem-64
See the Regions and zones page to learn where you can create M4 VMs.
Google Cloud VMware Engine
Announcement
VMware Engine ve2
nodes are now available in the London, England, Europe region (europe-west2-a
).
Google Distributed Cloud (software only) for bare metal
Announcement
Google Distributed Cloud for bare metal 1.32.400-gke.68 is now available for
download.
To upgrade, see Upgrade
clusters.
Google Distributed Cloud for bare metal 1.32.400-gke.68 runs on Kubernetes
v1.32.7-gke.200.
After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API
clients:
the Google Cloud console, the gcloud CLI, and Terraform.
If you use a third-party storage vendor, check the Ready storage
partners
document to make sure the storage vendor has already passed the qualification
for this release of Google Distributed Cloud for bare metal.
Fixed
The following issues were fixed in 1.32.400-gke.68:
-
Fixed an issue that caused the Ansible playbook for handling
Customer-Acquired Licenses (CAL) to fail and not complete. -
Fixed vulnerabilities listed in Vulnerability
fixes.
Issue
For information about the latest known issues, see Google Distributed Cloud for
bare metal known
issues
in the Troubleshooting section.
Google Kubernetes Engine
Security
GKE version 1.33.0-gke.1276000 and later remediate a low severity
vulnerability, in which an attacker with the ability to patch Node resources by
using the Kubernetes API could change specific node labels in clusters that use
Workload Identity Federation for GKE. This could result in the attacker gaining
access to node metadata, such as the IAM service account.
To remediate this
vulnerability, a validation policy is enforced that prevents unauthorized
modifications to the node labels that control metadata protection.
Feature
You can now run GPU workloads on Confidential GKE Nodes with the A3 High
machine type and NVIDIA H100 GPUs. This feature is available in
GKE version 1.32.2-gke.1297000 and later for manual GPU driver
installation, and in version 1.33.3-gke.1392000 and later for automatic driver
installation. This enables stronger data protection and integrity for
GPU-accelerated computations running within GKE clusters and
nodes. This feature is in General Availability.
For more information, see Encrypt GPU workload data in use with Confidential GKE Nodes.
Feature
You can now run GPU workloads on Confidential GKE Nodes with the A3 High
machine type and NVIDIA H100 GPUs. This feature is available in
GKE version 1.32.2-gke.1297000 and later for manual GPU driver
installation, and in version 1.33.3-gke.1392000 and later for automatic driver
installation. This enables stronger data protection and integrity for
GPU-accelerated computations running within GKE clusters and
nodes. This feature is in General Availability.
For more information, see Encrypt GPU workload data in use with Confidential GKE Nodes.
Google SecOps
Changed
Composite detections for MITRE ATT&CK
The Curated Detections feature has been enhanced with new composite rules that define chains of MITRE ATT&CK tactics and techniques.
These powerful new rule packs are now in public preview for customers with a Google SecOps Enterprise or Enterprise Plus license.
To learn more, a companion blog post will be published on the Google Security Cloud Community on September 9, 2025.
Google SecOps SIEM
Changed
Composite detections for MITRE ATT&CK
The Curated Detections feature has been enhanced with new composite rules that define chains of MITRE ATT&CK tactics and techniques.
These powerful new rule packs are now in public preview for customers with a Google SecOps Enterprise or Enterprise Plus license.
To learn more, a companion blog post will be published on the Google Security Cloud Community on September 9, 2025.
Source: Google Cloud Platform