Google Security Products Status Dashboard

This page provides status information on the services that are part of Google Security Products. Check back here to view the current status of the services listed below. If you are experiencing an issue not listed here, please contact Support. For additional information on these services, please visit https://cloud.google.com/security.

Incident affecting Google SecOps

Some Google SecOps customers are experiencing delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Incident began at 2025-10-30 10:00 and ended at 2025-11-07 15:00 (all times are US/Pacific).

Previously affected location(s)

Johannesburg (africa-south1)Tokyo (asia-northeast1)Mumbai (asia-south1)Singapore (asia-southeast1)Jakarta (asia-southeast2)Sydney (australia-southeast1)Multi-region: europeTurin (europe-west12)London (europe-west2)Frankfurt (europe-west3)Zurich (europe-west6)Paris (europe-west9)Doha (me-central1)Dammam (me-central2)Tel Aviv (me-west1)Toronto (northamerica-northeast2)São Paulo (southamerica-east1)Multi-region: us

Date Time Description
7 Nov 2025 17:06 PST

Summary

Some Google SecOps customers may have experienced delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Description

Applied Threat Intelligence - Curated Prioritization rule sets were inadvertently disabled due to defective code. The defective code has been remediated.

We restored the prior ‘enabled status’ and ‘alerting status’ of these rules. Reprocessing of these rules has now completed successfully.

We thank you for your patience while we worked on resolving the issue.

31 Oct 2025 18:10 PDT

Summary

Some Google SecOps customers experienced delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Description

Applied Threat Intelligence - Curated Prioritization rule sets were inadvertently disabled due to defective code. The defective code has been remediated.

We have restored the prior ‘enabled status’ and ‘alerting status’ of these rules. Reprocessing of these rules has also commenced and we expect this to take up to a week.

If you have updated your rule configuration in the interim, reprocessed events will adhere to your new configuration.

We will provide more information on the status of the reprocessing by Friday, 2025-11-07 17:00 PST with current details.

Customer Symptoms

N/A

Workaround

N/A

31 Oct 2025 17:14 PDT

Summary

Some Google SecOps customers are experiencing delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Description

Applied Threat Intelligence - Curated Prioritization rule sets were inadvertently disabled due to defective code. The defective code has been remediated.

We are working to restore the prior ‘enabled status’ and ‘alerting status’ of these rules and anticipate that restoration to be completed sometime Friday, 2025-10-31.

In the meantime as a work around, customers can re-enable the rules manually to restore the operation of Applied Threat Intelligence rules.

We will provide more information by Friday, 2025-10-31 18:00 PDT with current details.

Customer Symptoms

  • Affected customers will see that ATI rule packs are set to disabled.
  • Detections from these rules will be delayed (only visible once the issue is resolved).

Workaround

Customers may view and update configurations for the ATI packs in their SecOps tenant.

  1. In your tenant, go to Detections > Curated Detections > Rule Sets
  2. Find the Applied Threat Intelligence - Curated Prioritization Pack
  3. Recommended configuration:
    1. Active Breach, High Priority & Inbound Rules (5 rules):

      1. Precise: On, Alerting > On
      2. Broad: On, Alerting > Off
    2. Medium Priority (2 Rules):

      1. Precise: Status > On, Alerting > Off
      2. Broad: Status > On, Alerting > Off

Reference public documentation:

https://cloud.google.com/chronicle/docs/detection/ati-prioritization

https://docs.cloud.google.com/chronicle/docs/detection/curated-detections#enable-configure

https://docs.cloud.google.com/chronicle/docs/detection/ati-curated-detections

30 Oct 2025 21:05 PDT

Summary

Some Google SecOps customers are experiencing delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Description

Applied Threat Intelligence - Curated Prioritization rule sets were inadvertently disabled due to defective code. The defective code has been remediated.

We are working to restore the prior ‘enabled status’ and ‘alerting status’ of these rules and anticipate that restoration to be completed sometime Friday, 2025-10-31.

In the meantime as a work around, customers can re-enable the rules manually to restore the operation of Applied Threat Intelligence rules.

We will provide more information by Friday, 2025-10-31 17:00 PDT with current details.

Customer Symptoms

  • Affected customers will see that ATI rule packs are set to disabled.
  • Detections from these rules will be delayed (only visible once the issue is resolved).

Workaround

Customers may view and update configurations for the ATI packs in their SecOps tenant.

  1. In your tenant, go to Detections > Curated Detections > Rule Sets
  2. Find the Applied Threat Intelligence - Curated Prioritization Pack
  3. Recommended configuration:
    1. Active Breach, High Priority & Inbound Rules (5 rules):

      1. Precise: On, Alerting > On
      2. Broad: On, Alerting > Off
    2. Medium Priority (2 Rules):

      1. Precise: Status > On, Alerting > Off
      2. Broad: Status > On, Alerting > Off

Reference public documentation:

https://cloud.google.com/chronicle/docs/detection/ati-prioritization

https://docs.cloud.google.com/chronicle/docs/detection/curated-detections#enable-configure

https://docs.cloud.google.com/chronicle/docs/detection/ati-curated-detections

30 Oct 2025 18:16 PDT

Summary

Some Google SecOps customers are experiencing delay in detections for Applied Threat Intelligence - Curated Prioritization rule sets.

Description

Applied Threat Intelligence - Curated Prioritization rule sets were inadvertently disabled due to defective code.

Mitigation work is currently underway by our engineering team to restore the code and is expected to be complete by Thursday, 2025-10-30 21:00 PDT.

We will provide more information by Thursday, 2025-10-30 21:30 PDT with current details.

Diagnosis / Customer Symptoms

  • Affected customers will see that ATI rule packs are forcibly set to disabled.

  • Detections from these rules will be delayed (only visible once the issue is resolved).

Workaround

None at this time.

30 Oct 2025 16:51 PDT

Summary

Some Google SecOps customers are experiencing delay in detections for ATI content.

Description

We are experiencing an issue with Google SecOps beginning at Monday, 2025-10-27 10:00 PDT

Our engineering team continues to investigate the issue.

We will provide more information by Thursday, 2025-10-30 18:00 PDT with current details.

We apologize to all who are affected by the disruption.

Diagnosis / Customer Symptoms

  • Customers will see ATI rule packs are set to disabled.
  • Detections from these rules will be delayed (only visible once they are created)

Workaround

None at this time.