Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Tip

Welcome to CloudGuard Native (Dome9) Release Notes

 For RSS feeds, click here.

...

Expand
titleDeployment October 21th, 2021
Info

Compliance - 12:30 UTC

Type: Improvement
Description: Image Assurance - Reduce the delay between consecutive image scans.
Instead of a single image every 5 minutes, requests for image scans will now be sent from the backend to the scanning agent in batches.
Known limitations: N/A 
Affected Components

Status
titleKubernetes Image Assurance

Info

Compliance - 15:00 UTC

Type: New Feature
Description: Admission Control GSL rule verification has been improved. Clicking on the verify button will test the rule based on the cluster's recent API calls history.
Users can now see if the rule violated any of the last 1000 events or the last 7 days of events (the smaller of the two).
Known limitations: N/A 
Affected Components:

Status
titleKubernetes Admission Control

Expand
titleDeployment October 20th, 2021
Info

GCP GSuite User & GCP GSuite Group - 17:00 UTC

Type: Bug Fix
Description:  Support pagination 
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP
 

Info

GCP Service Account - 14:00 UTC

Type: Bug Fix
Description:  Support pagination 
Case ID: DFT-1555
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS GCP
 

Info

AWS IAM SAML & AWS IAM Open ID -  10:30 UTC

Type: New Entities
Case ID: DFR-1299
Description: Added support for AWS IAM SAML & AWS IAM Open ID in protected assets and compliance engine.
Known limitations: N/A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS AWS
 
Status
titlePROTECTED ASSETS

Info

Compliance Rulesets Update - 13:15 UTC

Type: Improvement

Description: The first release of Azure HITRUST v9.5.0 and Source Code Assurance 1.0 rulesets, adding new rules for the Azure platform, fixing Azure and GCP rules. A complete list can be found here. Adding new CloudBots for AWS and Azure platforms.

Case ID: DFR-1913
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE RULESETS

Expand
titleDeployment October 19th, 2021
Info

Compliance - 12:30 UTC

Type: Bug Fix
Case ID : DFT-1499
Description: Fixing a bug with AWS SSO authentication
Known limitations: N/A 
Affected Components

Status
titleauthentication

Info

Compliance - 15:00 UTC

Type: Bug Fix
Description: Fixing a bug with large email reports.
Known limitations: N/A 
Affected Components

Status
titlereports
Status
titlecompliance
Status
titleNotifications

Expand
titleDeployment October 17th, 2021

Info

Intelligence - 17:00 UTC

Type: Improvement
Description: Internal Improvements.
Known limitations: N/A 
Affected Components

Status
titleADMINO
Status
titleINTERCOM

Expand
titleDeployment October 14th, 2021

Info

Compliance Engine - 16:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance ENGINE

Info

Compliance Engine - 15:00 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance ENGINE

Info

Compliance API - 11:30 UTC

Type: Improvement
Description: Internal Improvement.
Known limitations: N/A 
Affected Components

Status
titlecompliance API

Info

Posture Findings Exclusions  - 10:00 UTC

Type: Bug Fix
Case ID: DFT-1354
Description: Run Assessment when adding a new posture findings exclusion.
Known limitations: N/A 
Affected Components

Status
titleCOMPLIANCE ENGINE

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment September 9 ,2021


Info

Compliance Rulesets Update - 16:00 UTC

Type: Improvement

Description:  Adding new rules to the Azure best practices ruleset. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


Info

Serverless - Generate Obsolete Runtime Task - 15:00 UTC

Type: Improvement
Description: For the functions with runtimes, that have reached end of support from AWS, an ObsoleteRuntimeTask will be created to notify the user that the account has the functions with unsupported runtimes. The task will have an information how to resolve that.

Please visit the link below for information on runtime end of support dates.
https://docs.aws.amazon.com/lambda/latest/dg/runtime-support-policy.html

Known limitations: N/A 
Affected Components:   

Status
titleserverless
  


Info

Serverless - Dot-net auto protect bug fix - 15:00 UTC

Type: Bug Fix
Description: Update Dot-net FSP instrumentation libraries to latest version.
FSP has been changed. the new version: 1.5.60
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless runtime protection


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment August 30 ,2021

Info

Azure Cosmos DB - 15:00 UTC

Type: Improvement
Case ID: DFR-2028
Description: Added the following properties to Azure Cosmos DB in compliance engine.

  • isVirtualNetworkFilterEnabled

  • keyVaultKeyUri

  • privateEndpointConnections

  • publicNetworkAccess

  • virtualNetworkRules

Known limitations: N/A  
Affected Components:  

Status
titleprotected assets
 
Status
titleCOMPLIANCE ENGINE
Status
titleDATA FETCHERS AZURE

Info

Serverless - fix list append - 16:00 UTC

Type: Bug Fix
Description: Bug fix in k8s whitelist creation
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  

Info

Serverless - profile according to callstack info  - 16:00 UTC

Type: Improvement
Description: Add support for callstack profiling and enforcement in Kubernetes - parent process/process that generate network activity.
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  

Info

Serverless - intercept csharp function with harmony - 16:00 UTC

Type: Improvement
Description: Intercept azure function using Harmony
FSP has been changed. the new version: 1.5.59
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless runtime protection

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment August 12, 2021

Info

AWS IAM User - 11:30 UTC

Type: Bug Fix
Case ID: DFT-1359
Description: Set consistent order for the IAM access keys in compliance engine 
Known limitations: N/A 
Affected Components

Status
titlecompliance engine
    

Info

AWS Red Shift & AWS IAM User - 11:30 UTC

Type: Improvement 
Description: Improve error handling in the compliance engine.
Known limitations: N/A 
Affected Components

Status
titlecompliance engine
 

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment August 11,2021

Info

Serverless - Added support for kafka and mq triggers - 15:00 UTC

Type: Improvement
Description: Added support for kafka and mq triggers when generating suggested roles .
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-eventsourcemapping.html
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  

Info

Serverless - Proact - Get token from env var - 15:00 UTC

Type: Improvement
Description: You can now use `CLOUDGUARD_ACCESS_TOKEN` environment variable to provide the token to cloudguard tool.
Earlier only config file and command line parameters were supported.
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless proact

Info

Serverless - get function errors - HF - 15:00 UTC

Type: Bug Fix
Description: Serverless lambda errors (fsp injector, log subscription, inside vpc)
Serverless azure function app errors
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  

Info

Serverless - WRP auto identify os distribution - 15:00 UTC

Type: Improvement
Description: Implement loader which responsible for identifying container OS, and initialize appropriate (per OS) libosfsp.so
FSP has been changed. the new version: 1.5.52
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless runtime protection

Info

Serverless - FSP node14.x support aws - 15:00 UTC

Type: Improvement
Description: AWS is obsoleting node10.x runtime. We have removed Cloudguard FSP support for node10.x runtime and added support for node14.x. It is recommended to use latest nodejs runtime to continue protecting your functions with FSP.
FSP has been changed. the new version: 1.5.57
Known limitations: N/A 
Affected Components:   

Status
titleserverless
  
Status
titleserverless runtime protection

Info

AWS IAM Credentials Report - 14:00 UTC

Type: Bug Fix
Description: Fixed an internal issue that caused a failure to generate the credentials report in some cases.
Known limitations: N/A 
Affected Components:   

Status
titleDATA FETCHERS AWS
  

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment August 9,2021

Info

Azure Insights - 12:00 UTC

Type: Improvement
DescriptionInfra Improvement for Azure Insights data fetcher.
Known limitations: N\A
Affected Components:  

Status
titleDATA FETCHERS AZURE

Info

Shiftleft - Ignoring un relevant file types- 9:30 UTC
Type: Improvement
Description: Internal change in order to ignore not relevant files.
Known limitations: N/A 
Affected Components

Status
titleshiftleft
     

...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment July 21 ,2021



Info

Alibaba RAM Password Policy - 17:00 UTC

Type: Bug Fix
Description: Rename property from 'ramPolicyPasswordId' to 'policyPasswordId' in compliance engine
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS ALI
 
Status
titleCompliance Engine
  



Info

Alibaba KMS - 17:00 UTC

Type: Bug Fix
Description: Change 'automaticRotation' property from date time to string type in compliance engine
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS ALI
 
Status
titleCompliance Engine
  



Info

Support AWS Osaka Japan Region - 17:00 UTC

Type: Improvement
Description: Added support for Osaka region.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS
 
Status
titleCompliance Engine
 
Status
titleAPI
 
Status
titleSECURITY GROUP MANAGEMENT


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment June 24,2021




Info

AWS Application and Network Load Balancer - 16:00 UTC

Type: Improvement
Description:  Internal performance improvement
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS AWS




Info

Alibaba RDS - 13:00 UTC

Type: Improvement
Description: Adjust db type and version enrichment fetching for Alibaba RDS.
Known limitations: N\A
Affected Components:  

Status
titleDATA FETCHERS ALI
 




Info

AWS Application Auto Scaling Policy - 13:00 UTC

Type: New Entity
Case ID: DFR-1653
Description: Added support for AWS Application Auto Scaling Policy in protected assets and compliance engine.
Known limitations: N\A
Affected Components:    

Status
titleCompliance Engine
  
Status
titleDATA FETCHERS AWS
 
Status
titlePROTECTED ASSETS




Info

EntityFetchStatus API - 13:00 UTC

Type: Improvement
Description: Internal performance enhancement for the GET request in EntityFetchStatus API.
Known limitations: N\A
Affected Components

Status
titleAPI




Info

Service Account - 13:00 UTC

Type: Improvement
Case ID: DFT-1321
Description: Allow to manage service accounts via SSO JIT users.
Known limitations: N\A
Affected Components

Status
titleAPI


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment May 31,2021




Info

Intercom - 16:45 UTC

Type: Bug Fix
Description: Added default value for 'registered by' property.
Known limitations: N/A 
Affected Components

Status
titleINTERCOM
 




Info

Support Alibaba Region - China Guangzhou - 15:30 UTC

Type: Improvement
Description: Added support for China Guangzhou region.
Known limitations: N/A 
Affected Components

Status
titleDATA FETCHERS ALI
 
Status
titleCompliance Engine




Info

Update Image Risk Score - 12:30 UTC

Type: Improvement
Description: ImageScan result will now feature an Image Risk Score value in the CVSS format of 0-10.0.
Image Risk Score will denote an image’s overall risk potential.
Known limitations: N/A 
Affected Components

Status
titleKubernetes
 


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Apr 20,2021




Info

Serverless - optimise se q flow - 14:00 UTC

Type: Improvement 
Description: Optimize security events handling flow, to prevent delay of processing and display.
Known limitations:  N\A
Affected Components

Status
titleserverless
 




Info

Serverless - Azure python post deploy instrumentation - 14:00 UTC

TypeNew Feature
Description: FSP can now be added to an already deployed Azure function app. This support is currently enabled for Python runtime (Linux containers).
Known limitations:  N\A
Affected Components

Status
titleserverless
 




Info

Serverless - Azure post deploy premium - 14:00 UTC

Type: Improvement 
Description: Added support for Azure post deploy functionality for premium and app service plans.
Known limitations:  N\A
Affected Components

Status
titleserverless
 




Info

Serverless - Add dynamic signatures fetch - 14:00 UTC

TypeNew Feature
Description: Dynamic update of k8s signatures from Check Point Research team.
Known limitations:  N\A
Affected Components

Status
titleserverless
 




Info

AWS S3 Bucket - 14:00 UTC

Type: Improvement 
Description: Added property 'arn' to AWS S3Bucket entity.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 




Info

GCP IAM Group - 12:30 UTC

Type: Bug Fix
Description: Fixed an issue that caused GcpIamGroup.groupData property to be empty.
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP IAM User - 10:30 UTC

Type: Improvement 
Description:  

  • Added 'roles' property in the compliance engine. 
    This property holds all the roles assigned to the user directly on the onboarded project.

  • Added 'userData.groups' property in the compliance engine.
    This property includes holds all groups the user is member in and in the same domain.

Known limitations:  Roles are not include organization inheritance
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP IAM Role - 10:30 UTC

Type: New Entity 
Description:  Added support for GCP Project IAM Role (custom and predefined) including the role permissions in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP VM Instance- 10:30 UTC

Type: Improvement 
Description:  Added 'sourceImage' and 'sourceImageId' properties for each GCP VM Instance Disk in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP Disk - 10:30 UTC

Type: New Entity
Description:  Added support for GCP Disk in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP Image - 10:30 UTC

Type: Improvement
Description:  Added 'creationTimestamp' property for GCP Image in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

GCP Project - 10:30 UTC

Type: Improvement
Case ID: DFR-1698
Description:  Added 'enabledServices' property for GCP Project in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

Azure Function App and Web App - 10:30 UTC

Type: Improvement
Case ID: DFR-1572
Description:  Added 'appServicePlan' property for Azure Function App and Web App in the compliance engine
Known limitations:  N\A
Affected Components

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS AZURE


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Mar 15,2021




Info

Compliance Backend Functionality enhancement - 14:00 UTC

Type: Improvement
Description:  Adding Backend functionality in order to support a new cloud vendor.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
 
Status
titleAPI


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Mar 14,2021




Info

FSP version visibility - 08:00 UTC

Type:  New Feature
Case ID:  PROT-713
Description:  Adding a new visibility for each AWS lambda that’s use FSP, to get the FSP version.
The purpose of this feature is that in the next step we will have the ability to set the FSP version manually.
Known limitations:  N/A
Affected Components

Status
titleserverless



Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Mar 10,2021




Info

New Cloud Vendor Support - New Infrastructure - 12:00 UTC

Type: Improvement
Description:  Adding new infrastructure in order to support new cloud vendor.
Known limitations: N/A 
Affected Components

Status
titleCompliance Engine
 
Status
titleAPI




Info

Compliance Rulesets Update - 12:40 UTC

Type: Improvement
Description:  Rules added to Azure CIS v1.1,v1.2, and v1.3 rulesets. and Azure CIS v1.2 enrichment. New and fix rules for GCP rulesets. A complete list can be found here
Known limitations: N/A 
Affected Components

Status
titlecompliance rulesets


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 21,2021




Info

Azure Event Hub Namespace - 13:30 UTC

Type: New Entity
Case Id: DFR-1401
Description: Added support for Azure Event Hub Namespace in the compliance engine
GSL Examples:

  • Ensure that Azure EventHubNamespace is encrypted:

    EventHubNamespace should not have encryption.keyVaultProperties isEmpty()

Known limitations:  N/A
Affected Components:   

Status
titlecompliance engine
 
Status
titledata fetchers azure




Info

AWS Update Credentials API - 13:30 UTC

Type: Bug Fix
Case Id: DFT-1057
Description: Fixed an issue for handling empty cloud account in user based credentials.
Known limitations: N/A.
Affected Components:  

Status
titleAPI


...

Panel
borderColorgrey
bgColor#F7F7F7
titleColorpink
titleBGColor#012038
borderStylesolid
titleDeployment Jan 14, 2021




Info

PREVIEW

Log.ic - Azure Activity Logs - 15:30 UTC

Type: New Feature
Description: Added Log.ic support on Azure Storage, Audit, Signin, Activity Logs.
Known limitations: Currently in Early Availability 
Affected Components

Status
titlelogic




Info

GCP App Engine - 11:00 UTC

Type: New Entity
Case ID: DFR-608
Description: Added support for GCP App Engine in the compliance engine
GSL Examples:

  • Ensure that GCP AppEngine utilizes Identity-Aware Proxy:       
       AppEngine should have iap.enabled=true


Known limitations:  N/A
Affected Components:   

Status
titleCompliance Engine
 
Status
titleDATA FETCHERS GCP




Info

Azure HDInsight - 11:00 UTC

Type: Improvement
Case ID: DFR-1436
Description: Region and location properties were converted into lower case strings
Known limitations:  N/A
Affected Components:  

Status
titleDATA FETCHERS AZURE
 
Status
titleCompliance Engine
 


...