Deployment June 28, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: The first Release of the AWS CSA CCM v4 Ruleset; The first release of the Alibaba CIS v1.0 Ruleset; The first release of the K8S GKE CIS v1.4 ruleset; French support for GCP best practices; New AWS and Azure rules. A complete list can be found here. Case ID: IN-7955, DFT-2595, DFT-2585, DFT-2367, DFT-2404, DFR-2316
|
Deployment June 28, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Policy unassociation will publish a closing alert with a status pass
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Add support for Aws WorkSpace services for Mumbai region in AWS
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: The first Release of the AWS CSA CCM v4 Ruleset; The first release of the Alibaba CIS v1.0 Ruleset; The first release of the K8S GKE CIS v1.4 ruleset; French support for GCP best practices; New AWS and Azure rules. A complete list can be found here. Case ID: IN-7955, DFT-2595, DFT-2585, DFT-2367, DFT-2404, DFR-2316
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: A new endpoint was added to fetch data about Oracle compartments:
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Azure Storage Account ‘table’ and ‘queue’ Encryption flags show the correct value. Previously, encryption on 'table' and 'queue' was enabled by default when creating a storage account in Azure. However, now we have the option to choose not to enable encryption for these components.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: KMS aliases in China region were not updated.
|
Deployment June 27, 2023
Info | ||||||
---|---|---|---|---|---|---|
Description: Fixed an issue where disabled AWS regions showed up in protected assets table, and caused an error when trying to access them. From now on disabled region will not be available in the protected asset. |
Deployment June 26, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Support for GKE Autopilot (except for Runtime Protection)
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Configure agents with node-critical and cluster-critical priority classes by default (improved support for clusters with small nodes)
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Support multiple DaemonSet configurations per node pool
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Runtime Protection: keep running if EBPF probe can't be built/loaded; multiple optimizations
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Inventory: Improved support for large inventory of Kubernetes resources
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Change imageScan.mountPodman default to false (reduce dependencies on node configuration)
|
Info | ||||||
---|---|---|---|---|---|---|
Description: OCI Network Load Balancer now correctly shows connected network security group ids |
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Support the Network Exposure risk modifier for Azure Storage Account.
|
Deployment June 25, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed an issue where the “GcpIamGroup” entity was causing assessment failures.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: A connector was added to the Azure “ApplicationGateway” entity, allowing to query its relation to “RegionalWAF” entity directly.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: “New” labels were removed from the GSL builder UI, for 30 days old entities.
|
Deployment June 21, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: The first Release of the AWS CIS Controls v8 Ruleset; New AWS rules. A complete list can be found here. Case ID: IN-7818
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Added “imageDetails” property for the CloudInstance API.
|
Deployment June 18, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed a bug in Alibaba ECS Instance, where Is Running column in the protected assets did not show the status.
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for ‘encryptionConfig’ property in AWS EksCluster in Compliance Engine & Protected Assets.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for "AWS X-Ray" in compliance engine and protected assets. A total of 3 new entities were added: XRayGroup, XRaySamplingRule, XRayEncryptionConfig.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for "AWS MemoryDB for Redis" in compliance engine and protected assets. A total of 4 new entities were added: MemoryDbCluster, MemoryDbSnapshot, MemoryDbUser, MemoryDbAcl.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for "AWS Neptune" in compliance engine and protected assets. A total of 4 new entities were added: NeptuneGlobalCluster, NeptuneCluster, NeptuneClusterSnapshot, NeptuneInstance.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for "AWS CodeArtifact" in compliance engine and protected assets. Two new entities were added: CodeArtifactDomain, CodeArtifactRepository.
|
Deployment June 15, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed an issue with nested aggregations counters in protected-assets group-by-properties API.
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added validation of S3 Access Points when measuring the IAM exposure of S3 Buckets.
|
Deployment June 14, 2023
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added "Azure AD Conditional Access Named Locations" support in the compliance engine and protected assets.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added "Azure AD Conditional Access Policies" support in the compliance engine and protected assets.
|
Info | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for ‘iamDatabaseAuthenticationEnabled’ property in AWS RDS in Compliance Engine & Protected Assets.
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed Large CIEM events and findings are missed.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Update testing following sanity test fails to improve stability and improve performance
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Corrected string 'now' to account.lastUsed in “src/app/users-management/service-accounts/service-accounts.ctrl.js“
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Removed old protected asset page for all users and set the new one as default.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: The first release of the AKS CIS v1.3.0 Ruleset; New Azure CIS rules; DFT fix; A complete list can be found here. Rule Deprecation D9.AZU.MON.03 : Property in azure is no longer supported/exists Rule Deprecation D9.AWS.LOG.09: Duplicate Rule Case ID: IN-7890, DFR-2802, DFT-2597, DFT-2367
|
Deployment June 12, 2023
Info | ||||||
---|---|---|---|---|---|---|
Description: KMS keys in China region were not updated. |
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Added data fetching for S3 multi-region Access Points using ListMultiRegionAccessPoints AWS API.
|
Info | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: The value of hubIpAddresses property in Azure Firewall entity was empty. Fixed it to contain the data.
|
Deployment June 11, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed a wrong condition that forced the filterPanel to change for every environment.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Added OCI Autonomous Database to billable assets.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: For customers with a large number of IAM roles the API call (https://api.dome9.com/v2/CloudIamRole) resulted with an error. This issue is now fixed.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: All of cloudGuard Emails are now being sent under CheckPoint Domain (@checkpoint.com), where it was previously under dome9 domain (@dome9.com) except User gets Locked and Account Created using MSP
|
Deployment June 8, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Added a new measurement for AWS S3 Bucket that shows their IAM exposure (Public/Private).
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed an issue with the aggregations counter in protected-assets search API.
|
Deployment June 7, 2023
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for new regions in AWS in Compliance Engine and Protected Assets: Hyderabad (ap-south-2), Jakarta (ap-southeast-3), Melbourne (ap-southeast-4), Zurich (eu-central-2) & Spain (eu-south-2).
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for ‘keyPolicy’ and ‘encryption.requireInfrastructureEncryption’ properties in Azure Storage Account in Compliance Engine & Protected Assets.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for ‘enableRbacAuthorization’ property in Azure Key Vault in Compliance Engine & Protected Assets.
|
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added support for "AWS Document DB" in Compliance Engine and Protected Assets - 4 new entities were added: DocDbCluster, DocDbClusterSnapshot, DocDbGlobalCluster, DocDbInstance.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: New AWS rules; DFT fix; Support for the EKS autopilot ruleset. A complete list can be found here. Case ID: IN-7818, DFT-2479
|
Deployment June 5, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Fixed a bug that caused assessments failures related to Azure ADAccessReviewsScheduleDefinition. Case ID: DFT-2587
|
Deployment June 4, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Added data fetching for S3 Access Points using ListAccessPoints AWS API.
|
Deployment June 1, 2023
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Switch AC default policy to the new default ruleset. Admission Control default policy has been updated to include only high value security rules, and reduced alerts.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Return time zone in iso date format from the APIs. A complete list can be found here.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Deploy RP partial profiling code. A complete list can be found here.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Agent status report CSV api. A complete list can be found here.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Allow offboarding through old controller (Terraform). A complete list can be found here.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: Workloads Images redesign, Kubernetes Version in Environment Table. A complete list can be found here.
|
Deployment June 1, 2023
Info | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Description: Added new property under “properties“ called “anonymousPullEnabled” to Azure ContainerRegistry entity.
|
Info | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description: We have added support for adding ERM related condition in the GSL. Each entity will have its relevant ERM data available through the “riskModifiers” property.
|