Questions about Security Command Center? You've come to the right place. Connect with other SCC users, discuss best practices, overcome challenges.
Recently active
Hello Everyone,As we realized, the impact of the React Vulnerability is very critical among your workloads. The React vulnerability, CVE-2025-55182, has a CVSS score of 10 and is being actively exploited. Customers need to be aware if their organization is impacted with this CVE. Google has created a pre-defined security graph rule for SCC Enterprise and Premium customers that will generate an "Issue" if your GKE workloads or Compute instances are externally exposed and vulnerable. You can view these alerts in the "Issues" queue within your environment.A sample representation of how this Issue appears in your SCC console is shown below, with the associated Findings for the vulnerability displayed within the Issue.If you are an SCC Premium or Enterprise customer, you can use Graph Search to check if your organization is impacted with this vulnerability. You can also use reachability context in Graph Search to prioritize remediation among impacted workloads with the CVE and focus on tho
Hi Team,I am not getting what exactly withing the file is matching the signatures of these SCC yara rules can anyone help here please this is first time i am getting this not sure if this is some SCC premium service this triggered this but not able to get if its true or false positive.
Hi Team anyone has any idea on what this low sev SCC findings are actually i am very much confused as most of them are having source IPs as AWS and Google and generating lot of noise also the url contains nessus so not sure why a google / AWS source IP would trigger this :E.g : Source IP100.27.42.240 "refererUrl": "${jndi:ldap://log4shell-generic-lQr0LA9voF9PHEyop2C6${lower:ten}.w.nessus.org/nessus}"and these are generated daily via multiple different AWS and Google IPs as source
I speak with customers daily. A challenge many security teams face isn't just finding vulnerabilities—it is mapping those vulnerabilities to compliance frameworks in a way that satisfies both internal security teams and external auditors.The monitoring and auditing capabilities of Compliance Manager in Security Command Center can fundamentally change how you define, monitor, and enforce your cloud compliance postures. What is Compliance Manager? Compliance Manager is a native SCC capability that uses software-defined cloud controls to assess, monitor, and actively enforce compliance across your Google Cloud infrastructure. https://docs.cloud.google.com/security-command-center/docs/compliance-manager-overviewInstead of relying on disconnected compliance dashboards, Compliance Manager maps Security Health Analytics (SHA) detectors directly to specific regulatory requirements, allowing you to see exactly where your workloads stand in real time. Three Operational Modes of Cloud ControlsCom
Hello everyone,I am seeking urgent guidance regarding a GCP project suspension. My account was recently suspended, and I received an email stating that the project was engaged in abusive activity consistent with "hijacked resources."The Situation:Access Denied: My production application is currently offline. Whenever I attempt to access the IAM & Admin or APIs & Services dashboard to investigate, I am automatically redirected to the suspension warning page. Unknown Leak: I have audited my frontend/backend/app environment variables (.env) but haven't found any obvious exposures. Account Lockout: Because I cannot access the IAM dashboard or Cloud Logging, I am unable to identify which credential is being abused or delete the compromised keys. Appeal Status: I submitted an appeal over a week ago, but I have not received a response, and my production app remains affected.My Questions:Is there a way to access Cloud Logging or Security Command Center via the SDK or a restricted conso