Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Deployment January 31th, 2022

Info

Assessment API - 10:31 UTC

Type: Improvement
Description: Added new API to get Assessment Executive Summery Report CSV.
Known limitations: N/A .
Affected Components

Status
titleAPI

Info

Protected Assets API - 08:31 UTC

Type: Improvement
Description: Added ability to sort and group K8S images by InsecureContent and Malware.
Known limitations: N/A .
Affected Components

Status
titlePROTECTED ASSETS API

Deployment January 30th, 2022

Info

Compliance Improvement - 19:30 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A .
Affected Components

Status
titleassessment history

Deployment January 27th, 2022

Info

Azure Virtual Machine API - 19:00 UTC
Type: Improvement
Description: AzureVirtualMachine API performance improvement.
Known limitations: N/A
Affected Components

Status
titleAPI

Info

Environments Page - Additional columns - 19:00 UTC

Type: Improvement
Description: Added Onboarding time and Platform columns.
Known limitations: N/A 
Affected Components:

Status
titleEnvironments page

Info

Users Page - New Table - 19:00 UTC

Type: Improvement
Description: Converted the table to the new concept.
Known limitations: N/A 
Affected Components:

Status
titleusers page

Info

Protected Assets and Events Page - Groups - 19:00 UTC

Type: Improvement
Description: Added support of expanding more than one group.
Known limitations: N/A 
Affected Components:

Status
titleevents page
Status
titleprotected assets page

Deployment January 26th, 2022

Info

GCP KMS - 11:20 UTC

Type: Improvement
Description: Added ‘iamPolicy’ and ‘cryptoKeys.iamPolicy’ properties in GCP KMS in compliance engine, protected assets and API.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

AWS EFS - 11:20 UTC

Type: Improvement
Description: Added ‘encryptionKeyArn’ property in AWS EFS in compliance engine and protected assets.
Case ID: DFT-1543
Known limitations: N/A 
Affected Components:

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Azure Application Security Group and Azure Application Gateway - 11:20 UTC

Type: Improvement
Description: Added paging support for Azure Application Security Group and Azure Application Gateway.
Case ID: DFT-1585
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS azure

Info

Azure SQL Server - 11:20 UTC

Type: Improvement
Description: Added ‘kind’ property in Azure SQL Server in compliance engine, protected assets and API.
Case ID: DFR-2085
Known limitations: N/A 
Affected Components:

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 12:00 UTC

Type: Improvement
Description: AWS CIS and GCP CIS rulesets enrichment. A complete list can be found here.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Deployment January 24th, 2022

Info

Billable Assets Report API - 19:00 UTC

Type: Improvement
Description: improve the performance of the Billable Assets Report API.
Known limitations: N/A .
Affected Components

Status
titleAPI

Deployment January 23th, 2022

Info

Shift Left Bug Fix - 18:00 UTC

Type: Bug Fix
Description: Going forward, Kubernetes Image Assurance alerts of type ImageScan will have the Entity Name updated to include the Image name instead of the Image SHA.
Known limitations: This fix will only affect new alerts.
Affected Components

Status
titleKubernetes
Status
titleimage assurance alerts

Deployment January 20th, 2022

Info

Shift Left Improvement - 13:40 UTC

Type: Improvement
Description: Each failed entity, in Terraform or CFT assessment run, will be enriched with its location in the file.
Known limitations: N/A 
Affected Components

Status
titleshift left

Info

Compliance Improvement - 07:00 UTC

Type: Improvement
Description: Internal Improvement.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine

Deployment January 19th, 2022

Info

AWS IAM Role, AWS IAM User, AWS ECS Instance & AWS ECS Task - 17:30 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS aws

Info

AWS IAM User - 17:30 UTC

Type: Bug Fix
Description: Fixed a bug in ‘relationType’ property in AWS IAM User in protected assets and compliance engine.
Known limitations: N/A 
Affected Components:

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

AWS ECS Task Definition - 17:30 UTC

Type: New Entities
Description: Added support for AWS ECS Task Definition in protected assets and compliance engine.
Known limitations: N/A 
Affected Components:

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 13:00 UTC

Type: Improvement
Description: AWS CIS and GCP CIS rulesets enrichment. A complete list can be found here.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Info

Compliance Improvement- 12:20 UTC

Type: Improvement
Description: Improvement of Database for HTTP Endpoint notifications.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titlenotifications
Status
titleHTTP Endpoint notification

Info

GCP Log Bucket - 12:00 UTC

Type: New Entities
Description: Added support for GCP Log Bucket in protected assets and compliance engine.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

GCP Network - 12:00 UTC

Type: Improvement
Description: Added ‘DnsPolicy’ property in GCP Network in compliance and protected assets.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Deployment January 18th, 2022

Info

AWS Cloud Trail - Lookup Events - 15:00 UTC
Type: Improvement
Description: Internal improvement of the data fetcher.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aWS

Info

AWS Onboarding - 12:30 UTC

Type: Improvement
Description:

  • Modified AWS Inspector read permissions of ‘CloudGuard-readonly-policy’ in AWS onboarding process.

  • Will support future integration with the new AWS Inspector.

  • Changed to:

    • inspector2:ListFindings

    • inspector2:BatchGetAccountStatus

Known limitations: N/A 
Affected Components

Status
titleAPI

Info

ServiceNOW Application - 9:00 UTC

Type: Improvement
Description: Added SNOW Rome version support.
Known limitations: N/A 
Affected Components

Status
titleServiceNOW application

Deployment January 17th, 2022

Info

Intelligence - 20:30 UTC

Type: Improvement
Description: Enrichment is now available for Azure assets without NSG directly attached to them.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Events Export API - 18:00 UTC

Type: Improvement
Description: Improve Events CSV Email
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Assessment Report - 17:00 UTC

Type: Bug Fix
Case ID: DFT-1656
Description: Fixed failed report content on export to CSV
Known limitations: N/A 
Affected Components

Status
titlereports
Status
titleexport

Info

Events Page - Export - Direct Download 17:00 UTC

Type: Improvement
Description: Added direct download support for exporting content less then 10,000 items
Known limitations: N/A 
Affected Components

Status
titleEvents
Status
titleexport

Info

Events page - 17:00 UTC

Type: Improvement
Case ID: DFR-1866
Description: Added action field column to show detect / Prevent
Known limitations: N/A 
Affected Components

Status
titleEvents

Info

API - 11:50 UTC

Type: Improvement
Description: Improved security layer of email report links - Export Findings to CSV + Notification of Scheduled Report
Known limitations: Previous links to this day, won’t be valid any more. 
Affected Components

Status
titleEvents
Status
titleNotification
Status
titlescheduled report

Deployment January 13th, 2022

Info

API - 14:50 UTC

Type: Improvement
Description: Improve Organizational Unit API performance.
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Intelligence - 12:30 UTC

Type: Bug Fix
Description: Fixed a bug where errors were displayed in several views for accounts newly onboarded to Intelligence.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Compliance API - 9:00 UTC

Type: Bug Fix
Description: Fix a bug when filtering events on platform and entityType.
Case ID: DFT-1673
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE API

Info

Compliance Engine - 9:00 UTC

Type: Improvement
Description: Improve Compliance Engine performance.
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE ENGINE

Info

Web Application Update - 08:40 UTC

Type: Improvement
Description: Major improvement in the GUI for the following pages: User, Role and Service Account.
Known limitations: N/A 
Affected Components

Status
titleApplication

Deployment January 12th, 2022

Info

Azure Api Management Service - 14:10 UTC

Type: Improvement
Description: Added ‘Sku’ property in Azure Api Management Service model in compliance and protected assets.
Case ID: DFR-2134
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS azure
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Azure Virtual Machine - 14:10 UTC

Type: Improvement
Description: Added ‘Extensions.Status’ property and fixed 'Extensions.TypeHandlerVersion' property in Azure Virtual Machine model in compliance and protected assets.
Case ID: DFT-1629
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS azure
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

GCP Network - 14:10 UTC

Type: Improvement
Description: Added ‘FirewallRules’ property in GCP Network model in compliance and protected assets.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 12:00 UTC

Type: Improvement
Description: New AWS CFT and GCP rules, rules fixes. A complete list can be found here.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Deployment January 11th, 2022

Info

Kubernetes - Image Assurance Retrospect - 17:30 UTC

Type: Bug Fix
Description:

  • Fixed a bug where the Retrospect failed to generate a new alert on newly discovered exploits, updated severity, and updated remediation.

  • Image Assurance Retrospect Mechanism, updates and generates new alerts when there is new information discovered on existing images. New information such as new exploits, updated severity, or updated remediation.

    • If a new vulnerability is discovered on existing images that have already been scanned, a new alert with the updated information will replace the old alert.

Known limitations: N/A 
Affected Components

Status
titleKubernetes
Status
titleImage Assurance

Info

Billing Report - 12:30 UTC

Type: Bug Fix
Description:

  • Error message will be displayed when user with role lower then Auditor is trying to export to csv an Asset Billing Report.

  • Bug fixed - User with Auditor permissions can view the same asset billing report information as user with Manage permission, instead of getting Internal Error in the CSV Report


Case ID: DFT-1685
Known limitations: N/A 
Affected Components

Status
titlebilling Report
Status
titlepermissions

Deployment January 10th, 2022

Info

Protected Assets - 21:30 UTC

Type: Bug Fix
Description: Fixed an issue with the format of Created Date for AWS IAM users in Protected Assets.
Known limitations: N/A 
Affected Components:

Status
titlePROTECTED ASSETS

Info

Intelligence - 21:30 UTC

Type: Internal release
Description: Internal release of features for upcoming CIEM solution.
Known limitations: N/A 
Affected Components:

Status
titleCIEM

Info

Intelligence - 21:30 UTC

Type: Internal release
Description: Internal release of features for upcoming GCP account activity support in Intelligence.
Known limitations: N/A 
Affected Components:

Status
titleINTELLIGENCE

Info

Compliance Engine - 08:50 UTC

Type: Improvement
Description: Internal improvement of the Compliance engine
Known limitations: N/A 
Affected Components:

Status
titleCOMPLIANCE ENGINE

Info

API - 06:40 UTC

Type: Improvement
Description: Internal improvement
Known limitations: N/A 
Affected Components:

Status
titleAPI

Deployment January 9th, 2022

Info

GCP Storage Bucket - 12:00 UTC

Type: Improvement
Description: Added ‘iamConfiguration’ and ‘retentionPolicy’ properties in GCP StorageBucket model in compliance and protected assets.
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Deployment January 8th, 2022

Info

Intelligence Rulesets Update - 13:00 UTC

Type: Improvement
Description: Rules fixes
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleIntelligence RULESETS

Deployment January 6th, 2022

Info

Kubernetes - Runtime Protection Network profiling - 16:30 UTC

Type: New Feature
Description:

  • The Runtime Protection agents will now also be able to monitor and enforce a workload’s network activities

  • This new feature is automatically added to new agents

  • Existing agents need to be upgraded to the latest version for the feature to become active

Known limitations: Once the network profiling feature is enabled all existing profiles will be reset and a new 24 hours learning period will commence.
Affected Components

Status
titleKubernetes
Status
titleruntime protection

Info

Kubernetes - Helm Chart 2.9.0 & New Agent versions - 08:30 UTC

Type: New Feature
Description:

  • New Image Assurance agent, version 2.4.0

    • Including ACR Conatiner Registry scan

  • New Inventory agent , version 1.4.0

    • Improvements

    • Support for OpenShift compliance

  • New Runtime daemon, version 0.0.666

    • CRIO support

    • Performance improvements

  • New Runtime policy, version 1.0.0

    • Improvements

    • Build using scratch image

  • New Flowlogs daemon, version 0.5.2

    • Improvements

  • New Admission-enforcer, version 1.3.0

    • GSL engine update

    • Prevention policy will now alert on all rules (previously it was stopped on the first hit)

Known limitations: N/A 
Affected Components

Status
titleKubernetes
Status
titleHelm

Deployment January 5th, 2022

Info

AWS CloudFront - 13:00 UTC

Type: Bug fix
Description: Fixed bug in indexing tags of AWS CloudFront in protected assets.
Case ID: DFT-1615
Known limitations: N/A 
Affected Components

Status
titlePROTECTED ASSETS

Info

Azure Locks - 13:00 UTC

Type: Bug fix
Description: Fixed bug in logic of Azure entities' locks list in compliance and protected assets.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Azure PostgreSQL - 13:00 UTC

Type: Improvement
Description: Added the following property in Azure PostgreSQL model in compliance and protected assets:
minimalTlsVersion, byokEnforcement, infrastructureEncryption, userVisibleState, replicationRole, masterServerId, replicaCapacity, publicNetworkAccess, privateEndpointConnections.
Case ID: DFR-2135
Known limitations: N/A 
Affected Components:

Status
titleDATA FETCHERS azure
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 12:00 UTC

Type: Improvement
Description: New AWS CFT rules. A complete list can be found here.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Deployment January 4th, 2022

Info

Compliance API - 19:00 UTC

Type: Bug fix
Description: fix a bug when exporting csv findings of Shiftleft, Alibaba and K8S accounts
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE API

Info

Compliance API - 15:50 UTC

Type: Improvement
Description: Create new API for getting assessments executive report
Known limitations: N/A 
Case ID: DFR-2000
Affected Components

Status
titleCOMPLIANCE API

Info

Compliance API - 10:00 UTC

Type: Improvement
Description: Create new API for exporting findings to CSV

  • Direct download

  • Getting download link

Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE API

Info

Kubernetes - VMWare Tanzu is now supported - 08:35 UTC

Type: New Feature
Description: VMWare Tanzu is now supported
Known limitations:

  • TKG v1.2 and up

  • TKGI v1.10 and up

Affected Components

Status
titleKuberentes
Status
titletanzu

Info

Kubernetes - RedHat OpenShift Container Platform is now supported - 08:35 UTC

Type: New Feature
Description:
RedHat OpenShift Container Platform can now be onboarded
CIS OpenShift Container Platform v4 Benchmark v1.1.0 ruleset has been added A complete list can be found here.
Known limitations:

  • Version v4.6 and up

  • For the Runtime Protection blade, the worker nodes running on RHCOS.

Affected Components

Status
titleKuberentes
Status
titleOpenShift

Info

Kubernetes - New Admission Control use cases have been added - 08:35 UTC

Type: Improvement
Description:
The following use cases have been added to Kubernetes Admission Control

  • Services should not expose SSH port

  • All capabilities are dropped in a Security Context

  • CVE-2020-8554:Services should not use "externalIPs"

  • Readiness Probe Not Configured

  • Liveness probe not configured

  • SELinux options should not be configured on containers

  • Custom hosts (/etc/hosts) configuration should be avoided

  • Containers should run using updated images

  • Do not use shared mount propagation

  • Host device path mounts should not be used

  • Ingress should restrict sources to avoid permissive access to services

  • Disable automounting API credentials

  • CVE-2021-25742: Ingress should not use unsafe annotations

  • CVE-2021-25742: Ingress Nginx ConfigMap should not use allow-snippet-annotations

Known limitations: N/A 
Affected Components

Status
titleKuberentes
Status
titleAdmission Control

Info

Compliance Engine - 08:20 UTC

Type: Improvement
Description: Internal improvement of the Compliance engine
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE ENGINE

Info

CloudSecurityGroup API - 07:45 UTC

Type: Bug Fix
Description: Fixed an issue in Security Group creation API that caused it to fail in some conditions.
Case ID: DFT-1663
Known limitations: N/A 
Affected Components

Status
titleAPI

Deployment January 2nd, 2022

Info

Dashboard - 21:00 UTC

Type: Bug
Description

  • DFT-1650, DFT-1651 - Fixed an issue where some users could not duplicate or update dashboards that contain charts.

Known limitations: N/A 
Affected Components

Status
titleDashboard

Info

Intelligence Rulesets Update - 14:00 UTC

Type: Improvement
Description: Rules fixes
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleIntelligence RULESETS

Info

Compliance Rulesets Update - 06:30 UTC

Type: Improvement
Description: New AWS rules. A complete list can be found here.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Info

AWS Onboarding - 11:00 UTC

Type: Improvement
Description:

  • Added AWS Inspector read permissions to ‘CloudGuard-readonly-policy’ in AWS onboarding process.

  • Will support future integration with the new AWS Inspector.

  • Added the following:

    • inspector2:List*

    • inspector2:Read*

Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Dashboard - 7:00 UTC

Type: Bug
Description

  • DFT-1605 - Trend widget throws an exception not loading data

Known limitations: N/A 
Affected Components

Status
titleDashboard

Deployment January 1st, 2022

Info

Application - 7:00 UTC

Type: Bug Fixes
Description

  • Fixed an issue where some users were not able to download the events report coming from the Infinity Portal.

  • Fixed an issue where the user was redirected to the dashboard page instead of their requested page upon login.

Known limitations: N/A 
Affected Components

Status
titleInfinity portal