Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Expand
titleDeployment October 31thDecember 30th, 2021
Info

API Intelligence - 2213:45 00 UTC

Type: ImprovementBug Fix
Description: Improvements for a new infrastructure.   Table in INTELLIGENCE tab under Assets\Environments now support AWS environments onboarded through Custom Onboarding
Known limitations: N/A 
Affected Components

Status
titleAPIINTELLIGENCE

Expand
titleDeployment October 28thDecember 29th, 2021

Info

Compliance GenericList API - 1209:20 UTC

Type: ImprovementNew Managed Lists
Description: Improvements for a new infrastructure.   Added new Managed List for AccountIds by plarform
Known limitations: N/A 
Case ID: DFR-963
Affected Components

Status
titleGENERIC LIST API
Status
titleCOMPLIANCE CORE
Status
titleCOMPLIANCE INTEGRATIONS

Info

AWS Security Groups

ENGINE

Info

Compliance Rulesets Update - 12:20 23 UTC

Type: Bug Fix
Description: Fixed edge cases that prevented Security Groups to be visible in the Security Groups page. email attached links to CloudGuard for Infinity Portal users.
Case ID: DFT-1678
Known limitations: N/A 
Affected Components

Status
titleemail notifications
Status
titleDATA FETCHERS AWSInfinity portal

Info

SNS Notification for China- 11:40 Compliance Rulesets Update - 12:20 UTC

Type: Bug FixImprovement
Description: Adding support to China accounts to send compliance SNS notification. New AWS and GCP rules. A complete list can be found here.
Case ID: DFR DFT-20911614
Known limitations: N/A 
Affected Components

Status
titlecompliance integrationsCOMPLIANCE RULESETS

Info

Billable Report Api - 08:40 Compliance Webhook API- 09:20 UTC

Type: New FeatureImprovement
Description: Added API to get a monthly billing report. 
Case ID: DFR-1849
  Improvements the Webhook integration API
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE WEBHOOK API

Info

GCP Firewall Rules API- 0805:00 30 UTC

Type: Bug FixImprovement
Description: Fixed edge cases that prevented data updates. 
Case ID: DFR-2098  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCPAPI

expandDeployment October 26th, 2021expandDeployment October 25th, 2021
Expand
titleDeployment October 27thDecember 28th, 2021

Info

Compliance Rulesets Update - 11:40

AWS Permissions Management - 15:00 UTC

Type: Improvement
Description:

Rules fixes. A complete list can be found hereCase ID: DFT-1223, DFT-1519, DFR-2086, DFT-1320, DFT-1428

Infrastructure change for AWS missing permissions management.
Known limitations: N/A 
Affected Components

Status
titleAPI
Status
title

COMPLIANCE RULESETS

DATA FETCHERS aws
Status
title

COMPLIANCE ENGINE

Info

Intelligence - 09:

00

15 UTC

Type:

Improvement

Internal Release
Description: Internal

improvements for data administration and performances

release in preparation for upcoming CIEM feature.
Known limitations: N/A 
Affected Components

Status
title

INTELLIGENCE

CIEM

Status
title

INTELLIGENCE

Info

Intelligence -

11

09:

00

15 UTC

Type:

Improvement

Internal Release
Description:

An email is automatically sent to CloudGuard users when Intelligence cannot retrieve logs from their storage place (support for additional use cases was added).

Internal release in preparation for upcoming support of GCP Account Activity in Intelligence
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Compliance

Intelligence -

08

09:

30

15 UTC

Type:

Improvement

Bug Fix
Description:

Improvement

Fixed error messages display in Intelligence
Known limitations: N/A 
Affected Components

Status
title

API

INTELLIGENCE

Info

Authentication - Reset password fix - 07:00

Intelligence - 09:15 UTC

Type: Bug Fix
Description:

  Fixed an issue that affected reset password flow in specific edge cases.
Case ID: DFT-1551

Fixed bug when number of events was calculated before all logs were loaded in Intelligence Account Activity and Network Traffic log tables.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Gcp API - 08:30 UTC

Type: Bug fix
Description: Fix logic relevant to the GcpProject API.
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

AWS EMR Cluster - 08:30 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A 
Affected Components: 

Status
titleDATA FETCHERS aws

Expand
titleDeployment October 24thDecember 27th, 2021
Info

Intelligence Billing Report - 12:00 UTC

Type: Improvement
Description: Network Traffic Logs - New columns available in csv export
When exporting network traffic logs from the portal, the csv now contains new columns: Src Address (IP address of the source), Src Type (External, Lambda…), Src Name (will be empty if the entity is not known by Cloudguard), Dst Address (IP address of the destination), Dst Type and Dst Name.Billing report - improved export file view. Reports for Azure accounts would be displayed by Resource group.
Case ID: DFT-2119
Known limitations: N/A 
Affected Components

Status
titleINTELLLIGENCE NETWORK TRAFFICAPI

Expand
titleDeployment October 21stDecember 26th, 2021
Info

Compliance Intelligence Rulesets Update - 1415:30 20 UTC

Type: Improvement
Description: Image Assurance - Reduce the delay between consecutive image scans.
Instead of a single image every 5 minutes, requests for image scans will now be sent from the backend to the scanning agent in batches. Rules fixes, adding new rulesets.
Case ID: N/A
Known limitations: N/A 
Affected Components

Status
Kubernetes Image Assurance
titleIntelligence RULESETS

Deployment October 19th, 2021GCP GSuite User & GCP GSuite Group - 17:00

Expand
titleDeployment December 23rd, 2021

Info

Compliance API-

12

13:

30

40 UTC

Type:

New Feature
Description: Admission Control GSL rule verification has been improved. Clicking on the verify button will test the rule based on the cluster's recent API calls history.
Users can now see if the rule violated any of the last 1000 events or the last 7 days of events (the smaller of the two).

Improvement
Description: new API - AssessmentHistoryV2/LastAssessmentResults/minimized - for getting last assessment with minimized entities
Known limitations: N/A 
Case ID: DFR-2145
Affected Components: 

Status
title

Kubernetes Admission Control

COMPLIANCE API

Info

Compliance

API- 12:30 UTC

Type:

New Feature

Improvement
Description:

The Runtime Protection feature creates Behavioral profiles for workloads. When creating rules and exclusions for profiles, the users can now set a parent process, this information is also shown in the rules and exclusions table as well.

  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components: 

Status
title

Kubernetes Runtime protection
Expand
titleDeployment October 20th, 2021
title
Info

API

Info

Compliance Webhook Integration- 11:15 UTC

Type:

Bug Fix

Improvement
Description:

  Support pagination  

 internal improvement in the compliance Webhook integration
Known limitations: N/A 
Affected Components

Status
title

DATA FETCHERS GCP

COMPLIANCE WEBHOOK INTEGRATION

Info

GCP Service Account

API-

14

10:

00

15 UTC

Type:

Bug Fix

Improvement
Description

Support pagination 
Case ID: DFT-1555 

Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
title

DATA FETCHERS GCP

API

Info

AWS

IAM SAML & AWS IAM Open ID - 

Inspector - 10:

30 UTC

00 UTC

Type:

 New Entities
Case ID: DFR-1299
Description: Added support for AWS IAM SAML & AWS IAM Open ID in protected assets and compliance engine

Improvement
Description: Updated regions for data fetching:

  • Added data fetching from “eu-west-2“ and “us-gov-west-1“.

  • Removed data fetching from “cn-north-1“ and “cn-northwest-1“.

Known limitations: N/

A


Affected Components:

    

 

Status
title

Compliance Engine  status

title

DATA FETCHERS

AWS  StatustitlePROTECTED ASSETS

aws

Info

Compliance Rulesets Update

API-

13

09:15 UTC

Type: Improvement
Description:

The first release of Azure HITRUST v9.5.0 and Source Code Assurance 1.0 rulesets, adding new rules for the Azure platform, fixing Azure and GCP rules. A complete list can be found here. Adding new CloudBots for AWS and Azure platforms.Case ID: DFR-1913

  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
title

COMPLIANCE RULESETS Expand

API

Info

Compliance

API-

12

08:30 UTC

Type:

Bug Fix
Case ID : DFT-1499
Description: Fixing a bug with AWS SSO authentication

Improvement
Description:  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
title

authentication

API

Intelligence - 17:00
Expand
titleDeployment December 22th, 2021
Info
Info

Compliance Rulesets Update - 1512:00 10 UTC

Type: Bug FixImprovement
Description: Fixing a bug with large email reports.
New GCP and CFT rules. A complete list can be found here.
Case ID: DFT-1665
Known limitations: N/A 
Affected Components

Status
titlereports
Status
titlecompliance
Status
titleNotifications

Expand
titleDeployment October 17th, 2021

COMPLIANCE RULESETS

Info

AWS EMR Cluster - 08:15 UTC

Type: Improvement
Description: Internal

Improvements
Status
titleINTERCOM

improvement.
Known limitations: N/A 
Affected Components

Status
title

ADMINO

DATA FETCHERS aws

Expand
titleDeployment October 14thDecember 21st, 2021

Info

Compliance Engine Intelligence - 1617:00 UTC
Type: Improvement Improvement
Description: Internal ImprovementThe new Azure Network Traffic onboarding via ARM will only create one Storage Account per region instead of one per NSG in case the NSG flow logs are not yet archived to a Storage Account.
Known limitations: N/A
Affected Components

Status
titlecompliance ENGINEINTELLIGENCE
Status
titleAZURE

Info

Compliance Engine Intelligence - 1517:00 UTC
Type: Improvement Improvement
Description: Internal ImprovementAdded pre-requisites of NSG flow logs in Version 2 in Azure Network Traffic onboarding.
Known limitations: N/A
Affected Components

Status
compliance ENGINE
titleINTELLIGENCE
Status
titleAZURE

Info

Compliance API Intelligence - 1117:30 00 UTC

Type: ImprovementBug Fix
Description: Internal Improvement.  Fixed error in instructions for Azure Account Activity onboarding
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE
Status
titlecompliance APIAZURE

Info

Posture Findings Exclusions  Intelligence - 1017:00 UTC
Type: Bug Fix
Case ID: DFT-1354
Description: Run Assessment when adding a new posture findings exclusion Improvement
Description: Added support for several possible configurations of NSGs and Storage Account in Azure Network Traffic onboarding.
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE
Status
titleCOMPLIANCE ENGINEAZURE

Expand
titleDeployment October 13thDecember 19th, 2021
Info

Fetchers Improvement Compliance Engine - 1613:00 30 UTC

Type: Improvement
Description: Internal Configuration Improvement  Added support for double quotes when using getResource method in GSL.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
Status
titleDATA FETCHERS AZURE
Status
titleDATA FETCHERS GCPCOMPLIANCE ENGINE

Info

Several Data Fetchers - 13:30 UTC
Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aws
Status
titleDATA FETCHERS azure
Status
titleDATA FETCHERS gcp
Status
titleDATA FETCHERS ALIalibaba

API Improvement - 15

Expand
titleDeployment December 17th, 2021

Info

AWS S3 Bucket

Intelligence -

12

11:

00

15 UTC

Type: Bug Fix

Case ID: DFT-1503
Description: Fix ‘objectLevelLogging’ property

Description:  Fixed a bug when the logs screen was stuck when an error was returned by the back-end API.
Known limitations: N/A 
Affected Components

Status
title

COMPLIANCE ENGINE
Expand
titleDeployment October 12th, 2021

INTELLIGENCE

Info

Fetchers Improvement

Intelligence -

14

11:

00

15 UTC

Type:

Improvement

Bug Fix
Description:

Internal Improvement.

  Fixed the date column in network traffic logs to show local time
Known limitations: N/A 
Affected Components

Status
title

DATA FETCHERS AWS

INTELLIGENCE

Info

Fetchers Permissions Handling Improvement - 09:00

Intelligence - 11:15 UTC

Type:

Improvement

Bug Fix
Description:

Internal Improvement

  Fixed a bug where number of items was not shown in log tables.
Known limitations: N/A 
Affected Components

Status
title

DATA FETCHERS Alibaba

INTELLIGENCE

Status
titleDATA FETCHERS Azure
Status
titleDATA FETCHERS gcp
Expand
titleDeployment October 11th, 2021
Info
Info

Intelligence - 11:15 UTC

Type: Bug Fix
Description:  Fixed a bug regarding the timeline in the activity and traffic explorers when there is a big amount of data.
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Info

Compliance API- 13:30 UTC

Type: Bug Fix
Description:  Fix Posture finding clearance on Policy deletion.
Known limitations: N/A 
Case ID: DFT-1439
Affected Components

Status
titleCOMPLIANCE ENGINE
Status
titleAPI

Info

Billing Report - 10:30 UTC

Type: Improvement
Description:

Internal Improvement

  Add normalized column to the exported file.
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Fetchers Improvement

Compliance Engine-

09

10:00 UTC

Type: Improvement
Description:  Internal

Improvement

improvements.
Known limitations: N/

A
Affected Components

Status
title

DATA FETCHERS AZURE

COMPLIANCE ENGINE

Expand
titleDeployment December 16th, 2021

Info

Compliance API-

07

13:

00

30 UTC

Type:

ImprovementDescription: Internal Improvement Webhook integration

Bug Fix
Description:  Fix Posture finding clearance on Policy deletion.
Known limitations: N/A 
Case ID: DFT-1439
Affected Components

Status
titleCOMPLIANCE ENGINE
Status
titleAPI

Info

Billing Report - 10:30 UTC

Type: Improvement
Description:  Add normalized column to the exported file.
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Compliance Engine- 10:00 UTC

Type: Improvement
Description:  Internal improvements.
Known limitations: N/A
Affected Components

Status
titleCOMPLIANCE ENGINE

Expand
titleDeployment December 15th, 2021

Info

Intelligence - 16:30 UTC

Type: Improvement
Description:  Internal deployment
Known limitations: N\A
Affected Components:  

Status
titleINTELLIGENCE
 

Info

GCP Log Based Metric - 14:15 UTC

Type: New Entity
Description:  Added support for GCP Log Based Metric in the compliance engine and protected assets.
Known limitations: N\A
Affected Components:  

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

GCP Alert Policy - 14:15 UTC

Type: New Entity
Description:  Added support for GCP Alert Policy in the compliance engine and protected assets.
Known limitations: N\A
Affected Components:  

Status
titleDATA FETCHERS GCP
 
Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Several Data Fetchers - 14:15 UTC
Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aws
Status
titleDATA FETCHERS azure
Status
titleDATA FETCHERS gcp
Status
titleDATA FETCHERS alibaba

Info

Azure Databricks Workspace - 14:15 UTC

Type: New Entity
Case ID: DFR-2127
Description:  Added support for Azure Databricks Workspace in the compliance engine.
Known limitations: N\A
Affected Components:  

Status
titleDATA FETCHERS AZURE
 
Status
titleCompliance Engine

Info

Azure SQL DB and Azure Data Warehouse - 14:15 UTC

Type: Improvement
Description: Added property ‘resourceGroup’ in Azure SQL DB and in Azure Data Warehouse model in compliance and protected assets.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

AWS Network Interface - 14:15 UTC

Type: Bug Fix
Description: Fix missing subnetId property in AWS Network Interface model in compliance and protected assets.
Case ID: DFT-1601
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 13:45 UTC

Type: Improvement
Description: The new release of the GCP CIS v1.1, the GCP CIS v1.2 and the AWS MITRE ATT&CK rulesets. New GCP and CFT rules. A complete list can be found here.
Case ID: DFT-1535
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Expand
titleDeployment December 13th, 2021
Info

API- 07:15 UTC

Type: Improvement
Description:  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI

Expand
titleDeployment December 12th, 2021
Info

Protected Assets - 13:00 UTC

Type: Improvement
Description: Internal change for error handling in the protected assets service.
Known limitations: N/A 
Affected Components

Status
titlePROTECTED ASSETS

Expand
titleDeployment December 8th, 2021

Info

AWS Glue Connection - 15:00 UTC

Type: Fix
Description: Remove unsafe password data from protected assets and compliance engine.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS
Status
titleDATA FETCHERS aws

Info

AWS EMR Cluster - 14:45 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS aws

Info

GCP VM Instance - 12:45 UTC

Type: Fix
Description: Fix missing Firewall inbound\outbound rules in protected assets and compliance engine..
Case ID: DFT-1633
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 11:15 UTC

Type: Improvement
Description: The new release of the Azure CIS v1.3.1 ruleset. New AWS, GCP and CFT rules. A complete list can be found here.
Case ID: -
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Expand
titleDeployment December 7th, 2021

Info

Billing Report - Export Improvement 15:00 UTC

Type: Improvement
Description:  Billing report export cosmetic improvements.
Case ID: DFT-1638
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Billing Report 13:00 UTC

Type: Bug Fix
Description:  Billing report export improvement.
Case ID: N/A 
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Compliance Notification API- 14:50 UTC

Type: Bug Fix
Description:  Fix create Notification with null WebhookPayloadFormat
Case ID: DFT-1638
Known limitations: N/A 
Affected Components

Status
titleCompliance NOTIFICATION API

Info

Compliance - 14:30 UTC

Type: Improvement
Description:  Internal Compliance pipeline improvement
Known limitations: N/A 
Affected Components

Status
titleCompliance

Info

Compliance API- 09:30 UTC

Type: Improvement
Description:  Change AssessmentHistoryV2/csv/{assessmentResultId} API on GCP Assessment to return ProjectNumber instead of ProjectId
Case ID: DFT-1378
Known limitations: N/A 
Affected Components

Status
titleCompliance API

Info

API- 07:30 UTC

Type: Improvement
Description:  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI

Expand
titleDeployment December 6th, 2021

Info

Dashboard - Refactor Kubernetes Image Assurance Policy APIs15:00 UTC
Type: Improvement
Description:

  • Released new APIs for ImageAssurance Policy that use a clearer and more organized flow. Relevant APIs

    • KubernetsImageAssurancePolicy

    • ContainerRegistryImageAssurancePolicy (Container Registry is still in EA)

Known limitations: N/A
Affected Components

Status
titleKubernetes
Status
titleContainer registry scanning

Info

Dashboard - 13:00 UTC
Type: Bug Fix
Description: Trying to create a widget dashboard of type “Trend Change Summary” or “Trend Line With Change Summary” did not work.
Known limitations: N/A
Affected Components

Status
titleDashboard

Expand
titleDeployment December 5th, 2021
Info

Compliance Engine - 10:00 UTC
Type: Improvement
Description: Internal change in the external findings mechanism to improve performance in the compliance engine.
Known limitations: N/A
Affected Components

Status
titleCompliance Engine

Info

Cloud Instance API - 10:00 UTC
Type: Improvement
Description: CloudInstance API performance improvement.
Known limitations: N/A
Affected Components

Status
titleAPI

Expand
titleDeployment December 3rd, 2021

Info

Intelligence - 10:15 UTC
Type: Bug Fix
Description: Fixed an issue with the way Intelligence rules were presented in the CloudGuard Portal
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Info

Intelligence - 10:15 UTC
Type: New Feature
Description: Added ability to group and sort in Account Activity and Network traffic log tables.
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Expand
titleDeployment December 2nd, 2021
Info

Assessment History - Adding entity links to the report - 14:30 UTC

Type: Bug Fix
Description: Adding links to each entity no matter if it passed or fail.
Case ID: DFT-1623, DFT-1588
Known limitations: N/A 
Affected Components

Status
titleAssessment history

Expand
titleDeployment December 1st, 2021

Info

Compliance Rulesets Update - 14:15 UTC

Type: Improvement
Description: New AWS and CFT rules. A complete list can be found here.
Case ID: -
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Info

Compliance API - 12:30 UTC

Type: Bug Fix
Description: Fixed a bug with license activation
Case ID: DFT-1619
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Compliance API - 12:30 UTC

Type: Improvement
Description: Added Cloudbot section to Ruleset API
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Intelligence - 8:15 UTC

Type: Bug Fix
Description: Fixed an issue where a few deprecated rules were still displayed in the portal.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Expand
titleDeployment November 30th, 2021

Info

AWS EMR Cluster - 14:30 UTC
Type: Improvement
Description: Internal improvement
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aws

Info

Clarity & GcpPubSub APIs - 13:45 UTC
Type: Improvement
Description: Internal improvements for the following calls:
Clarity API → google-security-groups & google-networks
GcpPubSub API → topics by cloudAccountId
Known limitations: N/A
Affected Components

Status
titleAPI

Info

Azure Entities - 13:45 UTC
Type: Improvement
Case ID: DFR-2090
Description: Added support for all types of service tags in networkSecurityGroup's inboundRules.source\outboundRules.Destination field in protected assets and compliance engine for the following Azure entities:
SqlServer, RedisCache, StorageAccount, Subnet, NetworkSecurityGroup, LoadBalancer, VirtualMachine, Vnet & NetworkInterface.
Known limitations: N/A
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Expand
titleDeployment November 29th, 2021

Info

Compliance API - 14:00 UTC

Type: Improvement
Description: Improve exclusion mechanism to support faster findings exclusion
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

API- 12:00 UTC

Type: Improvement
Description:  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI

Expand
titleDeployment November 25th, 2021

Info

Intelligence - 16:45 UTC
Type: Bug Fix
Description: Fixed a bug where the time range selected was being changed when moving between Activity and Traffic Explorer.
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Info

Registration Page - Improved error messages - 13:30 UTC
Type: Improvement
Description: Added human readable error messages to the registration page.
Known limitations: N/A
Affected Components

Status
titleUI

Info

Cloud IAM Role API - 12:30 UTC
Type: Improvement
Case ID: DFT-1590
Description: CloudIamRole API performance improvement when passing ‘roleArns’ as parameter.
Known limitations: N/A
Affected Components

Status
titleAPI

Expand
titleDeployment November 24th, 2021

Info

Intelligence - 12:30 UTC

Type: Bug Fix
Description: Fixed bug where Intelligence rulesets were not shown in the portal if no account was onboarded to CloudGuard.
Known limitations: N/A
Affected Components:

Status
titleIntelligence
 

Info

AWS Inspector - 12:30 UTC

Type: Improvement
Description: Update list of supported regions.
Known limitations: N/A
Affected Components:

Status
titleDATA FETCHERS aws
 

Info

AWS EMR Cluster - 11:45 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components:

Status
titleDATA FETCHERS aws
 

Info

Compliance Rulesets Update - 11:00 UTC

Type: Improvement
Description: The first release of the Azure ITSG-33 ruleset, rules fixes. A complete list can be found here.
New CloudBots were added. AWS CFT rules were added to the GSL website.
Case ID: DFR-1257
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Info

AWS API Gateway - 11:45 UTC

Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components:

Status
titleDATA FETCHERS aws
 

Info

Azure Resource Group - 09:45 UTC

Type: Improvement
Description: Show also inherited locks (from subscription) for a resource group in protected assets and compliance engine.
Case ID: DFT-1456
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titlePROTECTED ASSETS

Info

GCP API Key - 09:45 UTC

Type: New Entities
Description: Added support for GCP API Key in protected assets and compliance engine.
Known limitations: N/A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS GCP
 
Status
titlePROTECTED ASSETS

Info

CloudRoute53HostedZone & CloudRoute53RecordSetGroup API - 08:30 UTC

Type: Improvement
Description: Added new APIs for AWS Route53 Hosted Zones & AWS Route53 Record Set Groups.
Case ID: DFR-2123
Known limitations: N/A 
Affected Components

Status
titleAPI

Expand
titleDeployment November 23rd, 2021

Info

Cloud IAM Policy API - 13:00 UTC
Type: Improvement
Case ID: DFT-1590
Description: CloudIamPolicy API performance improvement when passing ‘roleArns’ as parameter.
Known limitations: N/A
Affected Components

Status
titleAPI

Info

Intelligence - 11:30 UTC
Type: Bug Fix
Description: Fixed issue in GSL with NOT operator
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE
Status
titleGSL

Info

New agents and Helm chart - 2.8.0 released - 12:00 UTC
Type: New Feature
Description:

  • New Image Assurance agent, version 2.0.0: Add support for ACR scanning.

  • New Admission Control Policy agent version 1.0.1, Enforcer agent version1.2.2: Collect data on historical API calls for improved verification (validate Admission Control rules based on operation history).

  • Address Helm install warnings by removing deprecated Kubernetes objects.

Known limitations: N/A 
Affected Components:  

Status
titleKubernetes
Status
titleHelm

Expand
titleDeployment November 18th, 2021

Info

Intelligence - 17:30 UTC
Type: Improvement
Description: Internal improvements

Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Info

Compliance API - 17:30 UTC
Type: Improvement
Description: Improve IAC Assessments result

Known limitations: N/A
Affected Components

Status
titleAPI

Info

Enrichment Engine - 15:00 UTC
Type: Bux Fix
Description: Fixed issue with Security Group enrichment

Known limitations: N/A
Affected Components

Status
titleINTELLIGENCE

Info

New Early Availability Helm chart released - 2.8.0: ACR scan support, Admission Control assessment history, improvements for k8s 1.19+ - 13:30 UTC
Type: New Feature
Description:

  • Image Assurance 2.0.0: add ACR scan support

  • Admission Control policy 1.0.1, Admission Control enforcer 1.2.2: collect data for improved verification

  • Remove deprecated objects referenced to remove warnings during deployment.

Known limitations: N/A
Affected Components

Status
titleKubernetes
Status
titleHelm

Info

Block misconfigured Kubernetes environments - clusters that are onboarded multiple times using the same ClusterID - 13:30 UTC
Type: New Feature
Description:

  • A detection mechanism for Kubernetes clusters on-boarding misconfiguration is added

  • The mechanism detects cases of multiple clusters accidentally onboarded with the same clusterID

  • Detection of such an event is presented in Audit Logs and the cluster's status indications

Known limitations: N/A
Affected Components

Status
titleKubernetes

Info

Added ShiftLeft Image entities - 13:00 UTC
Type: New Feature
Description: ShiftLeftImage entities were added to the Protected Assets page and to the API /api/kubernetes/imageAssurance/image/general

Known limitations: N/A
Affected Components

Status
titleKubernetes
Status
titleShiftLeft
Status
titleImage Assurance

Info

New Admission Control use case to address CVE-2021-25742: Ingress-nginx custom snippets allows retrieval of secrets - 12:30 UTC
Type: Enhancement
Description: A security issue was discovered in ingress-nginx (CVE-2021-25742) where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

Added 2 Use-cases:

  1. Ingress should not use unsafe annotations

    1. This rule can prevent the exploitation of CVE-2021-25742

  2. Ingress Nginx ConfigMap should not use allow-snippet-annotations

    1. This rule can prevent changing the Nginx configuration to be vulnerable to CVE-2021-25742

Known limitations: N/A
Affected Components

Status
titleKubernetes
Status
titleAdmission Control

Info

Improved Workload Protection Audit logs - 12:00 UTC
Type: Enhancement
Description:

  • New audit logs for Runtime Protection configuration changes

  • New audit logs when enabling/disabling features

  • Admission Control audit title “Admission Control Event” changed to “Kubernetes Admission Control”
    Known limitations: N/A
    Affected Components

    Status
    titleKubernetes
    Status
    titleRuntime protection
    Status
    titleAdmission Control

Info

Add support for parent process in Runtime Protection rules and exclusions - 11:30 UTC
Type: New Feature
Description: When creating rules and exclusions for Runtime Protection profiles, the users can now set a parent process. This information is also shown in the rules and exclusions tables as well.
Known limitations: N/A
Affected Components

Status
titleKubernetes
Status
titleRuntime protection

Info

Cloud Instance API - 11:00 UTC
Type: Bug Fix
Case ID: DFT-1589
Description: Cloud Instance API bug fix for EC2 classic.
Known limitations: N/A
Affected Components

Status
titleAPI

Info

API- 09:00 UTC

Type: Improvement
Description:  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI

Expand
titleDeployment November 17th, 2021
Info

All Data Fetchers - 14:00 UTC
Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aws
Status
titleDATA FETCHERS azure
Status
titleDATA FETCHERS gcp
Status
titleDATA FETCHERS alibaba

Info

Compliance Rulesets Update - 11:00 UTC

Type: Improvement

Description: The first release of the AWS CIS Foundations v. 1.4.0 ruleset, adding new rules to the AWS CIS Foundations v. 1.3 rulesets, adding new rules to AWS CloudFormation ruleset, rules fixes. A complete list can be found here.

New CloudBots were added

Case ID: DFT-1582, DFR-2045

Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Info

GCP GSuite User - 09:30 UTC
Type: Improvement
Description: Added support for new field Languages to GCP GSuite User on protected assets and compliance engine.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titleDATA FETCHERS GCP
Status
titlePROTECTED ASSETS

Expand
titleDeployment November 16th, 2021
Info

Compliance - 11:30 UTC

Type: Improvement
Description:  General improvements. 
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

AzureManagement, AzureGenericEntity, AzureActivityLog, AzureSqlServer - 09:45 UTC
Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS azure

Info

Intelligence - 09:30 UTC
Type: New Feature
Description: Added “Remove Intelligence” button for Azure environments. The button can be found under Assets\Environments, within the specific environment’s page. Clicking on it and confirming will off-board the environment from Intelligence (both Account Activity and Network Traffic).
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCe

Info

Intelligence - 09:30 UTC

Type: Bug FiIx
Description:  Unsupported GSL query will now display an error in the UI.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Intelligence - 09:30 UTC

Type: Improvement
Description:  New grid implementation in Account Activity and Network Traffic log tables (benefits: endless scroll, reorder/resize columns, etc.)
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Expand
titleDeployment November 14th, 2021
Info

Intelligence - 18:50 UTC
Type: Improvement
Description: Updated API documentation for Intelligence
Known limitations: N/A
Affected Components

Status
titleINTELLIGENCe
Status
titleAPI DOCUMENTATION

Info

AWS Cloud Trail - Lookup Events - 16:00 UTC
Type: Improvement
Description: Improved data fetcher performance.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aWS

Info

Azure Data Fetchers - 11:00 UTC
Type: Improvement
Description: Internal improvement.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS azure

Info

Intelligence - 9:15 UTC
Type: Improvement
Case ID:
Description: Added link to online help in email warning users that Intelligence cannot retrieve their logs from their storage place.
Known limitations: N/A 
Affected Components:  

Status
titleINTELLIGENCE

Info

Intelligence - 9:15 UTC
Type: Improvement
Case ID:
Description: Improvements for move to new infrastructure.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENce

Expand
titleDeployment November 11th, 2021
Info

Compliance- 18:00 UTC
Type: Bug Fix
Case ID: DFT-1439
Description: Added ability to export large amount of events as CSV
Known limitations: N/A 
Affected Components:  

Status
titleEvents
Status
titlecompliance

Info

Intelligence - 10:15 UTC
Type: Bug Fix
Case ID:
Description: Fixed a bug in GSL query for “in” function.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENce
Status
titleGSL

Expand
titleDeployment November 10th, 2021
Info

GCP VM Instance - 18:45 UTC
Type: Improvement
Case ID: DFR-2024
Description: Added multiple properties to GCP VM Instance on protected assets and compliance engine.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
titleDATA FETCHERS GCP
Status
titlePROTECTED ASSETS

Info

AWS Cloud Trail - Lookup Events - 14:00 UTC
Type: Improvement
Description: Improved paging and throttling handling.
Known limitations: N/A
Affected Components

Status
titleDATA FETCHERS aWS

Info

AWS Network Firewall - 13:00 UTC
Type: Improvement
Case ID: DFT-1533
Description: Added support for AWS Network Firewall to the following regions: af-south-1, ap-east-1, ap-northeast-1, ap-northeast-2, ap-south-1, ap-southeast-1, ap-southeast-2, cn-north-1, cn-northwest-1, us-gov-east-1, us-gov-west-1, ca-central-1, eu-central-1, eu-north-1, eu-south-1, eu-west-2, eu-west-3, me-south-1, sa-east-1, us-east-2, us-west-1.
Known limitations: Not supporting the following regions: cn-north-1, cn-northwest-1, us-gov-east-1, us-gov-west-1
Affected Components

Status
titleDATA FETCHERS aWS

Info

AWS Network Firewall - 13:00 UTC
Type: Improvement
Case ID: DFR-1468
Description: Added 'firewallPolicy' property to AWS Network Firewall on protected assets and compliance engine.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
Status
compliance API
titleDATA FETCHERS aWS
Status
titlePROTECTED ASSETS

Info

Compliance API Rulesets Update - 0711:00 30 UTC

Type: Improvement

Description: Internal ImprovementAdding new rules to AWS CloudFormation ruleset, rules fixes. A complete list can be found here.

Known limitations: N/A 
Affected Components

Status
titlecompliance APICOMPLIANCE RULESETS

Expand
titleDeployment October 10thNovember 4th, 2021
Info

Intelligence Compliance - 1816:00 20 UTC

Type: Improvement
Description: Onboarding Azure network traffic logs (a.k.a Azure flow logs) is now done using a custom ARM template. After assigning an additional IAM role to the CloudGuard application and selecting the Network Security Groups to onboard, the system will generate an ARM template for the customer to deploy. The template will handle the requirements for onboarding to Intelligence. This new onboarding replaces the previous onboarding for Azure network traffic logs. It is available to all customers.  Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI
Status
titleINTELLIGENCE ONBOARDING

Info

AWS SNS Platform Application, AWS Events Rule, AWS System Manager Parameter, AWS Kinesis Firehose, AWS Custom Domain Name - 16:00

Info

Compliance API - 10:40 UTC

Type: Bug FixImprovement
DescriptionSupport pagination bug fix for events empty value filter
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
 
API

expandDeployment October 7th, 2021
Expand
titleDeployment November 3rd, 2021
Info

Fetchers Improvement - 16:00 Azure Activity Log Monitor - 14:30 UTC

Type: Improvement
Description: Internal Improvement  Enriched Azure Storage Account information in Azure Activity Log Monitor on protected assets and compliance engine.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP

Compliance Engine
 
Status
title

PROTECTED ASSETS

Type: Improvement
Description: Internal Improvement Webhook integration
Info

Compliance API - 18:00 UTC

Azure Container Instance -  14:30 UTC

Type: New Entities
Case ID: DFR-1262
Description: Added support for Azure Container Instance in protected assets and compliance engine.
Known limitations: N/

A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS azure
 
Status
title

compliance API

PROTECTED ASSETS

Info

Compliance

API

Rulesets Update -

17

12:

00 UTCType: Improvement
Description: Internal Improvement adding a TTL.

30 UTC

Type: Improvement

Description: Adding new rules to AWS CloudFormation ruleset, rules fixes. A complete list can be found here. New CloudBots were added.

Case ID: DFT-1069
Known limitations: N/A 
Affected Components

Status
title

compliance API

COMPLIANCE RULESETS

Expand
titleDeployment November 2nd, 2021
Info
Compliance API - 15

Azure Storage Blob Containers - 10:00 UTC

Type: Improvement
Description: Internal

Improvement

data fetcher logic improvement.
Known limitations: N/A 
Affected Components

Status
title

compliance API

DATA FETCHERS AZURE

Expand
titleDeployment November 1st, 2021
Info
Continuous posture

Intelligence -

15

13:

00

30 UTC

Type:

 Bug Fix

Improvement
Description:

Fix a bug on ruleset save operation

We improved both quality and accuracy of geolocation data for account activity and network traffic logs.
Known limitations: N/A 
Affected Components

Status
title

ui

INTELLIGENCE

  status

API
Expand
title
Deployment October 31th, 2021
Info
Compliance

API -

05

22:

00

45 UTC

Type: Improvement
Description:

Internal Improvement.

Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
title

compliance

API

Expand
titleDeployment October 28th, 2021

Info

Compliance - 12:20 UTC

Type: Improvement
Description: Improvements for a new infrastructure. 
Known limitations: N/A 
Affected Components

Status
titleAPI
Status
titleCOMPLIANCE CORE
Status
titleCOMPLIANCE INTEGRATIONS

Info

AWS Security Groups - 12:20 UTC

Type: Bug Fix
Description: Fixed edge cases that prevented Security Groups to be visible in the Security Groups page. 
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS

Info

SNS Notification for China- 11:40 UTC

Type: Bug Fix
Description: Adding support to China accounts to send compliance SNS notification. 
Case ID: DFR-2091
Known limitations: N/A 
Affected Components

Status
titlecompliance integrations

Info

Billable Report Api - 08:40 UTC

Type: New Feature
Description: Added API to get a monthly billing report. 
Case ID: DFR-1849
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

GCP Firewall Rules - 08:00 UTC

Type: Bug Fix
Description: Fixed edge cases that prevented data updates. 
Case ID: DFR-2098
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP

Expand
titleDeployment October 27th, 2021
Info

Compliance Rulesets Update - 11:40 UTC

Type: Improvement

Description: Rules fixes. A complete list can be found here

Case ID: DFT-1223, DFT-1519, DFR-2086, DFT-1320, DFT-1428
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Expand
titleDeployment October 26th, 2021
Info

Intelligence - 09:00 UTC

Type: Improvement

Description: Internal improvements for data administration and performances.
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Expand
titleDeployment October 25th, 2021
Info

Intelligence - 11:00 UTC

Type: Improvement
Description: An email is automatically sent to CloudGuard users when Intelligence cannot retrieve logs from their storage place (support for additional use cases was added).
Known limitations: N/A 
Affected Components

Status
titleINTELLIGENCE

Info

Compliance - 08:30 UTC

Type: Improvement
Description: Improvement
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Authentication - Reset password fix - 07:00 UTC

Type: Bug Fix
Description:  Fixed an issue that affected reset password flow in specific edge cases.
Case ID: DFT-1551
Known limitations: N/A 
Affected Components

Status
titleAPI
 

Expand
titleDeployment October 24th, 2021
Info

Intelligence - 12:00 UTC

Type: Improvement
Description: Network Traffic Logs - New columns available in csv export
When exporting network traffic logs from the portal, the csv now contains new columns: Src Address (IP address of the source), Src Type (External, Lambda…), Src Name (will be empty if the entity is not known by Cloudguard), Dst Address (IP address of the destination), Dst Type and Dst Name.
Known limitations: N/A 
Affected Components

Status
titleINTELLLIGENCE NETWORK TRAFFIC

Expand
titleDeployment October 21st, 2021
Info

Compliance - 14:30 UTC

Type: Improvement
Description: Image Assurance - Reduce the delay between consecutive image scans.
Instead of a single image every 5 minutes, requests for image scans will now be sent from the backend to the scanning agent in batches.
Known limitations: N/A 
Affected Components

Status
titleKubernetes Image Assurance

Info

Compliance - 12:30 UTC

Type: New Feature
Description: Admission Control GSL rule verification has been improved. Clicking on the verify button will test the rule based on the cluster's recent API calls history.
Users can now see if the rule violated any of the last 1000 events or the last 7 days of events (the smaller of the two).
Known limitations: N/A 
Affected Components:

Status
titleKubernetes Admission Control

Info

Compliance - 12:30 UTC

Type: New Feature
Description: The Runtime Protection feature creates Behavioral profiles for workloads. When creating rules and exclusions for profiles, the users can now set a parent process, this information is also shown in the rules and exclusions table as well.
Known limitations: N/A 
Affected Components:

Status
titleKubernetes Runtime protection

Expand
titleDeployment October 20th, 2021
Info

GCP GSuite User & GCP GSuite Group - 17:00 UTC

Type: Bug Fix
Description:  Support pagination 
Case ID: DFT-1423
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP
 

Info

GCP Service Account - 14:00 UTC

Type: Bug Fix
Description:  Support pagination 
Case ID: DFT-1555
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP
 

Info

AWS IAM SAML & AWS IAM Open ID -  10:30 UTC

Type: New Entities
Case ID: DFR-1299
Description: Added support for AWS IAM SAML & AWS IAM Open ID in protected assets and compliance engine.
Known limitations: N/A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS AWS
 
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 13:15 UTC

Type: Improvement

Description: The first release of Azure HITRUST v9.5.0 and Source Code Assurance 1.0 rulesets, adding new rules for the Azure platform, fixing Azure and GCP rules. A complete list can be found here. Adding new CloudBots for AWS and Azure platforms.

Case ID: DFR-1913
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Expand
titleDeployment October 19th, 2021
Info

Compliance - 12:30 UTC

Type: Bug Fix
Case ID : DFT-1499
Description: Fixing a bug with AWS SSO authentication
Known limitations: N/A 
Affected Components

Status
titleauthentication

Info

Compliance - 15:00 UTC

Type: Bug Fix
Description: Fixing a bug with large email reports.
Known limitations: N/A 
Affected Components

Status
titlereports
Status
titlecompliance
Status
titleNotifications

Expand
titleDeployment October 17th, 2021

Info

Intelligence - 17:00 UTC

Type: Improvement
Description: Internal Improvements.
Known limitations: N/A 
Affected Components

Status
titleADMINO
Status
titleINTERCOM

Expand
titleDeployment October 14th, 2021

Info

Compliance Engine - 16:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance ENGINE

Info

Compliance Engine - 15:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance ENGINE

Info

Compliance API - 11:30 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Posture Findings Exclusions  - 10:00 UTC

Type: Bug Fix
Case ID: DFT-1354
Description: Run Assessment when adding a new posture findings exclusion.
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE ENGINE

Expand
titleDeployment October 13th, 2021
Info

Fetchers Improvement - 16:00 UTC

Type: Improvement
Description: Internal Configuration Improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
Status
titleDATA FETCHERS AZURE
Status
titleDATA FETCHERS GCP
Status
titleDATA FETCHERS ALI

Info

AWS S3 Bucket - 12:00 UTC

Type: Bug Fix
Case ID: DFT-1503
Description: Fix ‘objectLevelLogging’ property
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE ENGINE

Expand
titleDeployment October 12th, 2021
Info

Fetchers Improvement - 14:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS

Info

Fetchers Permissions Handling Improvement - 09:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS Alibaba
Status
titleDATA FETCHERS Azure
Status
titleDATA FETCHERS gcp

Expand
titleDeployment October 11th, 2021
Info

API Improvement - 15:30 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Fetchers Improvement - 09:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AZURE

Info

Compliance API - 07:00 UTC

Type: Improvement

Description: Internal Improvement Webhook integration.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Compliance API - 07:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Expand
titleDeployment October 10th, 2021
Info

Intelligence - 18:00 UTC

Type: Improvement
Description: Onboarding Azure network traffic logs (a.k.a Azure flow logs) is now done using a custom ARM template. After assigning an additional IAM role to the CloudGuard application and selecting the Network Security Groups to onboard, the system will generate an ARM template for the customer to deploy. The template will handle the requirements for onboarding to Intelligence. This new onboarding replaces the previous onboarding for Azure network traffic logs. It is available to all customers.
Known limitations: N/A 
Affected Components

Status
titleAPI
Status
titleINTELLIGENCE ONBOARDING

Info

AWS SNS Platform Application, AWS Events Rule, AWS System Manager Parameter, AWS Kinesis Firehose, AWS Custom Domain Name - 16:00 UTC

Type: Bug Fix
Description:  Support pagination 
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
 

Info

Fetchers Improvement - 16:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP

Expand
titleDeployment October 7th, 2021

Info

Compliance API - 18:00 UTC

Type: Improvement
Description: Internal Improvement Webhook integration.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Compliance API - 17:00 UTC

Type: Improvement
Description: Internal Improvement adding a TTL.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Compliance API - 15:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Continuous posture - 15:00 UTC

Type: Bug Fix
Description: Fix a bug on ruleset save operation.
Known limitations: N/A 
Affected Components

Status
titleui
  
Status
titleAPI

Info

Compliance API - 05:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 23 ,2021

Deployment October 6th, 2021

Info

Compliance Rulesets Update - 10:15 UTC

Type: Improvement

Description: The first release of CIS Kubernetes Benchmark v1.20 ruleset, fixing Azure rules. A complete list can be found here

Case ID: DFR-2041
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

Info

Compliance Rulesets Update - 10:30 UTC

Type: Bug Fix
Description: Running Kubernetes node will now appear when filtering for billable assets.
Known limitations: N/A 
Affected Components

Status
titleKubernetes

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment October 4 ,2021
Info

Assessment report - Failed tests by fix - 15:00 UTC

Type: Bug Fix
Description: fix to populate failed by severity value
Known limitations: N/A 
Affected Components

Status
titleUI

Info

Compliance API - 15:00 UTC

Type: Improvement
Description: Internal configuration change
Known limitations: N/A 
Affected Components

Status
titleAPI

Info

Compliance Rulesets Update - 12:15 UTC

Type: Improvement

Description: Fixing AWS rules. A complete list can be found here

Case ID: DFT-1342, DFT-1539
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

Info

AWS SQS - 10:00 UTC

Type: Bug Fix
Case ID: DFT-1458
Description:  Support pagination 
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
 

Info

Internal changes for several components - 10:00 UTC

Type: Improvement
Description:  Internal improvement
Known limitations: N/A 
Affected Components

Status
titleALL SYSTEM
 


Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 29 ,2021

Info

Compliance Rulesets Update - 10:30 UTC

Type: Improvement

Description: Fixing Azure rules. A complete list can be found here

Case ID: DFT-1467
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

Info

Protected Assets - Alibaba Entities - 11:00 UTC

Type: Improvement
Description:

  • Added 'Status' as additional field to Alibaba ECS Instance entity in protected assets.

  • Added 'DBInstanceStatus' as additional field to Alibaba RDS DB Instance entity in protected assets.

  • Alibaba ECS Instance 'Billable Asset' property is set to 'Yes' in case 'Status' is 'Running'.

  • Alibaba RDS DB Instance 'Billable Asset' property is set to 'Yes' in case 'DBInstanceStatus' is 'Running'.

Known limitations: N/A 
Affected Components:  

Status
titleprotected assets
 
Status
titleAPI
 
Status
titleDATA FETCHERS ALI

Info

Serverless - Obsolete dotnetcore2.1 FSP injector changes - 17:00 UTC

Type: New Feature
Description: Add/remove auto-protect feature from webapp UI won't be supported for dotnetcore2.1 runtime.
Cloud Formation template has been changed. the new version: 21
Known limitations: N/A 
Affected Components

Status
titleserverless
 
Status
titleserverless cloud formation

Info

Serverless - FSP add support for graviton2 - 17:00 UTC

Type: New Feature
Description: Cloudguard FSP Support for AWS Lambda running on Graivton2 processors
FSP has been changed. the new version: 1.5.62
Known limitations: N/A 
Affected Components

Status
titleserverless
 
Status
titleserverless runtime protection

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 13 ,2021

Info

Compliance Rulesets Update - 16:00 UTC

Type: Improvement

Description: Azure and GCP rules removal. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 9 ,2021

Info

Compliance Rulesets Update - 16:00 UTC

Type: Improvement

Description:  Adding new rules to the Azure best practices ruleset. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

Info

Serverless - Generate Obsolete Runtime Task - 15:00 UTC

Type: Improvement
Description: For the functions with runtimes, that have reached end of support from AWS, an ObsoleteRuntimeTask will be created to notify the user that the account has the functions with unsupported runtimes. The task will have an information how to resolve that.

Please visit the link below for information on runtime end of support dates.
https://docs.aws.amazon.com/lambda/latest/dg/runtime-support-policy.html

Known limitations: N/A 
Affected Components:   

Status
titleserverless
  

Info

Serverless - Dot-net auto protect bug fix - 15:00 UTC

Type: Bug Fix
Description: Update Dot-net FSP instrumentation libraries to latest version.
FSP has been changed. the new version: 1.5.60
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless runtime protection

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 5 ,2021

Info

Azure Redis - 14:30 UTC

Type: Improvement
Description: Internal improvement in error handling.

Known limitations: N/A  
Affected Components:   

Status
titleDATA FETCHERS AZURE

Info

Google Cloud Account - 13:30 UTC

Type: Improvement
Description: Added new property "ProjectNumber" in protected assets and compliance engine.

Known limitations: N/A  
Affected Components:   

Status
titleDATA FETCHERS GCP
Status
titleCOMPLIANCE ENGINE
Status
titleprotected assets

Info

AWS SSM Instance Information - 13:30 UTC

Type: Improvement
Description: Removed redundant property "LastPingDateTime" in protected assets and compliance engine.

Known limitations: N/A  
Affected Components:   

Status
titleDATA FETCHERS AWS

Info

Data Fetchers  - 13:30 UTC

Type: Improvement
Description: Internal improvement in multiple data fetchers.

Known limitations: N/A  
Affected Components:   

Status
titleDATA FETCHERS AWS
Status
titleDATA FETCHERS AZURE
Status
titleDATA FETCHERS GCP

Info

Compliance Rulesets Update - 10:00 UTC

Type: Improvement

Case ID: SR-352, SR-346
Description:  Adding new rules to the Azure best practices ruleset. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment June 23,2021




Info

Compliance Rulesets Update - 15:00 UTC

Type: Improvement
Description:  Updating best practices rulesets, changing the name of Alibaba ruleset. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment June 13,2021




Info

Compliance Rulesets Update - 12:45 UTC

Type: Improvement
Description:  Fix for D9.AWS.CRY.05. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment June 2,2021




Info

Kubernetes Agent Status Enchantments - 16:30 UTC

Type: Improvement
Description: The Kubernetes agent status have been refactored with faster and more detailed Agent deployment status information.
Known limitations: N/A 
Affected Components

Status
titlekubernetes




Info

Compliance Rulesets Update - 12:45 UTC

Type: Improvement
Description:  The first release of the Azure New Zealand Information Security Manual (NZISM) v.3.4 rulesets and fix duplicated rules. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets




Info

Azure Storage Account - 11:15 UTC

Type: Improvement 
Case ID: DFR-1465
Description:

  • Added 'performance' property in the compliance engine

  • Added 'replication' property in the compliance engine

Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AZURE

Info

Azure Virtual Machine - 11:15 UTC

Type: Improvement 
Case ID: DFR-1465, DFR-1680
Description:

  • Added 'extensions' property in the compliance engine

  • Added 'availabilityZones' property in the compliance engine

Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AZURE

Info

AWS Cloud Front - 11:15 UTC

Type: Improvement 
Description: Added property 'protectedByShield' to AWS Cloud Front entity.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 




Info

AWS Network Load Balancer - 11:15 UTC

Type: Improvement 
Description: Added property 'protectedByShield' to AWS NLB entity.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 




Info

AWS Application Load Balancer - 11:15 UTC

Type: Improvement 
Description: Added property 'protectedByShield' to AWS ALB entity.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 




Info

AWS ELB - 11:15 UTC

Type: Improvement 
Description: Added property 'protectedByShield' to AWS ELB entity.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 




Info

Alibaba SLB - 11:15 UTC

Type: New Entity
Case ID: DFR-1506
Description: Added support for Alibaba Server Load Balancer in protected assets and compliance engine.
Known limitations: N\A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS ALI
 
Status
titlePROTECTED ASSETS




Info

Alibaba Auto Scaling Group- 11:15 UTC

Type: New Entity
Case ID: DFR-1512
Description: Added support for Alibaba Auto Scaling Group in protected assets and compliance engine.
Known limitations: N\A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS ALI
 
Status
titlePROTECTED ASSETS


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment May 26,2021




Info

Compliance Rulesets Update - 12:45 UTC

Type: Improvement
Description:  Adding new rules to new vendor preview ruleset. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment May 19,2021




Info

New Cloud Vendor Support - 17:00 UTC

Type: New Entity
Description:  Added support for new entities in the compliance engine
Known limitations: N/A 
Affected Components:  

Status
titleprotected assets
 
Status
titleDATA FETCHERS
  
Status
titleCOMPLIANCE




Info

AWS IAM Data Fetchers - 17:00 UTC

Type: Improvement
Description: Infrastructure improvement
Known limitations: N\A
Affected Components:    

Status
titleDATA FETCHERS AWS
       




Info

Compliance Rulesets Update - 12:00 UTC

Type: Improvement
Description:  Adding new rules to new vendor preview ruleset. Removing D9.AWS.NET.69. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Apr 05,2021




Info

New Cloud Vendor Support - New Infrastructure - 17:00 UTC

Type: Improvement
Description:  Adding new infrastructure in order to support new cloud vendor.
Known limitations: N/A 
Affected Components

Status
titleAPI
 
Status
titleprotected assets
 
Status
titleDATA FETCHERS
  
Status
titleCOMPLIANCE




Info

GCP Filestore Instance - 16:30 UTC

Type: New Entity
Case ID: DFR-1558
Description: Added support for GCP Filestore Instance in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

AWS Data Fetchers - 14:00 UTC

Type: Bug Fix
Description: Fixed an issue with missing permissions handling for AWS entities: NatGateway, RDSDBSnapshot.
Known limitations:  N\A
Affected Components

Status
titleDATA FETCHERS AWS




Info

Compliance Rulesets Update - 12:00 UTC

Type: Improvement
Description:  Rules added to Azure and GCP best practices rulesets. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Mar 10,2021




Info

New Cloud Vendor Support - New Infrastructure - 12:00 UTC

Type: Improvement
Description:  Adding new infrastructure in order to support new cloud vendor.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
 
Status
titleAPI




Info

Compliance Rulesets Update - 12:40 UTC

Type: Improvement
Description:  Rules added to Azure CIS v1.1,v1.2, and v1.3 rulesets. and Azure CIS v1.2 enrichment. New and fix rules for GCP rulesets. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Mar 07,2021




Info

Azure Storage Account - 11:30 UTC

Type: Improvement
Case ID: DFR-1485
Description: Added 'privateEndpointConnections' property for Azure StorageAccount entity in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AZURE




Info

Compliance Rulesets Update - 10:30 UTC

Type: Improvement
Description:  The first release of Azure CIS v1.3 ruleset and Azure CIS v1.2 enrichment. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Feb 16,2021

Info

AWS SQS and SNS - 11:00 UTC

Type: Bug Fix
Case ID: DFT-1079
Description: Populate 'cryptoKey' property for keys without alias name in compliance engine.
Known limitations: N\A
Affected Components:  

Status
titleCompliance Engine

Info

Compliance Rulesets Update - 9:20 UTC

Type: Improvement
Description:  A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Feb 10,2021


Info

Azure Subnet - 12:00 UTC

Type: Improvement
Case ID: DFR-1450
Description:  Added 'delegationsList' property for Azure Subnet in the compliance engine
Known limitations: N\A
Affected Components:  

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AZURE

Info

AWS CloudTrail - Organization Trails - 10:30 UTC

Type: Improvement
Case ID: DFT-1042
Description:

  • Added support for Organization level trails for member accounts.

  • Added 'isOrganizationTrail' property to CloudTrail entity.

Known limitations: Tags are not supported for organization level trails on member accounts.
Affected Components

Status
titleProtected assets
 
Status
titleDATA FETCHERS AWS
 
Status
titleCompliance Engine

Info

Compliance Rulesets Update - 10:20 UTC

Type: Improvement
Description:  Fix two AWS IAM rules. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Feb 3,2021

Info

New Service Now Application - 20:30 UTC

Type: Improvement
Description: New application with new features and certified for Paris Version, find it here
Known limitations: N\A
Affected Components:    

Status
titleServiceNOW Application
       

Info

Internal configuration improvement - 19:30 UTC

Type: Improvement
Description:  Internal configuration improvement
Known limitations: N\A
Affected Components:    

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AWS
 
Status
titleDATA FETCHERS AZURE
 
Status
titleDATA FETCHERS GCP
 
Status
titleDATA FETCHERS K8S
 
Status
titleAPI
  

Info

Compliance Rulesets Update - 11:00 UTC

Type: Improvement
Description:  The first release of Azure CIS Foundations v. 1.2.0. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 27,2021

Info

Exclusions page - New Dialog - 12:30 UTC

Type: Improvement
Case ID: DFR-1212
Description: Adding new improved dialog.
Known limitations: N\A
Affected Components

Status
titleui
 
Status
titleexclusions

Info

Dashboard - Export fix - 12:30 UTC

Type: Bug Fix
Case ID: DFT-1043
Description: Fixing the Dashboard export.
Known limitations: N\A
Affected Components

Status
titleui
 
Status
titledashboards

Info

Environments page - Remove instance column - 12:30 UTC

Type: Improvement
Case ID: DFR-1453
Description: Removing the instance column.
Known limitations: N\A
Affected Components

Status
titleui
 
Status
titleEnvironments

Info

Kubernetes Onboarding - Blades rename - 12:30 UTC

Type: Improvement
Case ID: DFR-1239
Description: Renamed blades.
Known limitations: N\A
Affected Components

Status
titleui
 
Status
titlekubernetes

Info

Compliance  Improvement - 12:00 UTC

Type: Internal Improvement
Description:  External finding improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance engine




Info

Compliance Rulesets Update - 11:00 UTC

Type: Improvement
Description:  A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 20,2021




Info

Compliance Rulesets Update - 13:45 UTC

Type: Improvement
Description:  A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets




Info

AWS Onboarding - New infra structure - 13:00 UTC

Type: Improvement
Description:  Adding new infra structure in order to support new future features. 
Known limitations: N/A 
Affected Components

Status
titleAPI
 
Status
titleAWS Onboarding




Info

Add "Sync Now" support for Azure Load Balancer - 13:00 UTC

Type: Improvement
Description: Azure load balancer fetching supports "Sync Now" Functionality.
Known limitations: N/A
Affected Components:   

Status
titleDATA FETCHERS AZURE
   


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 4,2021


Info

AWS Application Load Balancer and Network Load Balancer  - 12:30 UTC

Type: Improvement
Case ID: DFT-658
Description: Additional properties are supported in compliance engine for AWS Application Load Balancer and Network Load Balancer
Known limitations:  N/A
Affected Components:  

Status
titleDATA FETCHERS AWS
 
Status
titleCompliance Engine
 

Info

Compliance Rulesets Update - 10:30 UTC

Type: Improvement
Description:  The first release of the Azure Security Benchmark ruleset. New rules were added to Azure CloudGuard Best Practices reuleset and some GCP rules fixes. A complete list can be found here
Known limitations: N/A 
Affected Components

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 3,2021

Info

Shift Left - New Infrastructure - 16:00 UTC

Type: Improvement
Description:  Added internal infrastructure to support future features for Shift Left.
Known limitations: N\A
Affected Components:     

Status
titlewebapp
 
Status
titleCompliance core

Info

Data fetching services - 11:00 UTC

Type: Improvement
Description:  Change internal configuration for performance improvements.
Known limitations: N\A
Affected Components:    

Status
titleAll data fetching components
 

...

Settings