2024

Last updated: Oct 1, 2026


December

Release 52

(SAST) New rules:

  • F359 Java MongoDB Hardcoded Secret
  • F359 Java MySQL Hardcoded Secret
  • F359 Java OkHttp Hardcoded Secret

Release 51

  • (SCA) Malware packages tagged: Fluid Attacks tags the packages in Supply chain in which it detects malware.
  • (SCA) Split environment dependencies: Identify if dependencies are related to production or development environments.
  • (SCA) SBOM export: Include Docker packages in SBOM export file.
  • (ASPM) Environments migration: The migration modal has an option to search for the necessary root.
  • (ASPM) Rename: Change 'Vulnerabilities' to 'Injected' and 'Supply chain' to 'Inherited' for added clarity.

Release 50

  • (Integrations) Jira Security module: The Security feature of Jira shows all the vulnerabilities.
  • (SAST) New rules:
    • F332 Java Unsafe TLS Renegotiation
    • F151 Java Telnet Request
    • F372 Java Insecure HTTP Open Connection
    • F007 Java CSRF Unrestricted Request Mapping
    • F372 Java Insecure HTTP Request
    • F372 Java Insecure HTTP Components
  • (ASPM) Component improvements: Ghost buttons, section header, and tabs.
  • (SCA) Docker packages in SBOM: The SBOM file includes Docker packages.
  • (ASPM) ZR column: An indicator of requested ZR is available in the Locations table.
  • (ASPM) Scope table: Show what Roots and Environments have active events.

Release 49

  • (ASPM) Improved table export names: Exported CSV files have meaningful names, with the organization or group name and a timestamp.
  • (ASPM) Country is deprecated: The Country field is optional when you create an organization.
  • (SAST) New rules:
    • F016 Java Unsafe SSL/TLS Protocol
    • F148 Java Insecure FTP Client
    • F372 Java Insecure Spring HTTP Request
    • F007 Java Insecure FTP Session Factory

November

Release 48

  • (ASPM) Centralized report download: Access all your downloadable files through the new Downloads button in the platform header. These files include executive and technical vulnerability reports. Fluid Attacks plans to add SBOMs and other resources in the future. Monitor the status of each download and download files again easily.
  • (ASPM) Improved CSV repos import: Add connection method and priority in the CSV file, and get an example CSV file. Improved error messages.
  • (ASPM) Custom priority: Use reachability attribute as a prioritization criterion.
  • (Reachability) New rule: CSharp CVE-2021-43045
  • (SAST) New rules:
    • Java insecure channel
    • Java null cipher
    • Python hc aes key
    • Java anonymous ldap bind

Release 47

  • (ASPM/CSPM) Status validation for cloud environments: A new Status column in the Environments table shows open events for AWS, Azure, or GCP environments. This helps you address misconfigurations promptly.
  • (ASPM/SBOM) Updated labels for vulnerable components: The label 'Issues identified' in Supply chain changed to 'Vulnerable' to make it clear that security risks exist. Vulnerabilities will display the 'Reachable' label.
  • (SAST) New rule: Java unsafe default HTTP client.

Release 46

  • (SBOM/SAST) Reachability analysis: This release adds a feature that examines direct dependencies in the Supply chain section to identify exploitable vulnerabilities. This helps you prioritize remediation efforts for dependency issues.
  • (ASPM) Custom vulnerability prioritization: Use the Priority feature in the Policies section to rank vulnerabilities by impact, exploitability, and more. You can adjust the ranking to the requirements of your organization.
  • (ASPM) Enhanced event reporting: Events specify the affected environments. Improved root and environment tables also help you prioritize.
  • (CSPM) New rules:
    • AWS Document DB Cluster TLS Disabled
    • AWS EKS Unrestricted CIDR
    • AWS DAX Cluster Without Encryption at Rest
    • AWS Unencrypted ECR Repository
    • AWS RDS Unencrypted DB Cluster Snapshot
    • AWS RDS Unencrypted DB Snapshot
    • AWS ALB Does Not Drop Invalid Header Fields
    • AWS Public Accessible DMS Replication
    • AWS CloudFront Distribution Viewer Policy Allows HTTP
    • AWS ALB HTTP Not Redirected to HTTPS
    • AWS Document DB Without Audit Logs
    • AWS RDS DB Cluster Logs Disabled
    • AWS RDS DB Instance Logs Disabled
    • AWS Global Accelerator Flow Logs Disabled
    • AWS Neptune DB Instance Logs Disabled
    • AWS MSK Cluster Logging Disabled
    • AWS Workspaces Has Volume Encryption Disabled
    • AWS Route53 Transfer Lock Disabled
    • AWS SageMaker Training Job Intercontainer Encryption
    • AWS SageMaker Notebook Instance Encryption
    • AWS Athena Workgroup Query Results Not Encrypted
  • (SAST) New rules:
    • Python flask log injection
    • JS express SSRF
    • TS express SSRF
    • Python insecure redirect
    • Python AWS hardcoded credentials
    • CSharp SQL conn hardcoded secret
    • CSharp insecure x509 cert 2
    • CSharp hardcoded credentials
    • Python flask hardcoded secret key
  • (Reachability) New rule: Java CVE-2021-37573

Release 45

  • (SCA) Docker image scanning: Scan Docker images from all standard registries and get detailed SBOMs with the related security issues in the Supply chain section.
  • (ASPM) Vulnerability closing reasons: View detailed reasons for closed vulnerabilities in the Tracking and Analytics sections.
  • (ASPM) Expanded permissions for Events tab: User Managers and Vulnerability Managers have access to the Events tab in the To do section. This gives them a complete view of the issues when they manage multiple groups.
  • (ASPM) Automatic filename formatting: When a user uploads a file, the platform formats the filename to prevent issues and vulnerabilities.
  • (SAST) New rules:
    • CSharp insecure fspickler des
    • CSharp dir entry hardcoded secret

October

Release 44

Release 43

  • (ASPM) Supply chain section: Separated affected and unaffected third-party dependencies from the Vulnerabilities section for easier prioritization. Users can filter components by the repository that Fluid Attacks tests.
  • (ASPM) Temporary acceptance: The selected dates must obey the established policies.
  • (ASPM) New events in webhooks: Added closed events and vulnerabilities to webhooks.
  • (CSPM) New rules:
    • AWS RDS Instance TLS Disabled
    • AWS RDS Cluster TLS Disabled
    • AWS OpenSearch Domain Insecure TLS Version
    • AWS MSK Client Broker TLS Disabled
    • AWS MSK Broker Broker TLS Disabled
    • AWS Unrestricted Access to MSK Brokers
    • AWS ECR Repository Exposed
    • AWS OpenSearch Domain Exposed
    • AWS RDS Instance Backup Retention Period
    • AWS RDS Cluster Backup Retention Period
    • AWS ElastiCache Replication Group WO Auto Backups
    • AWS ElastiCache Replication Backup Retention Period
    • RDS Unrestricted Cluster Groups
    • Backup Vault Policy Allow Delete Recovery Points
    • AWS Bedrock Guardrails No Sensitive Info Filter
    • AWS Event Bridge Default Event Bus Exposed
    • AWS Lambda URL Without Authentication
    • AWS Lambda Function Exposed
    • AWS Comprehend Analysis Without Encryption
    • AWS EBS Public Snapshot
    • AWS EKS Unencrypted Secrets
    • AWS EMR Has Not Config
    • AWS OpenSearch Without Encryption at Rest
    • AWS OpenSearch Domain Node to Node Encryption
    • AWS Glue Catalog Without Encryption at Rest
    • AWS Kinesis Stream Without Encryption at Rest
    • AWS MQ Broker Publicly Accessible
    • AWS MSK Cluster Is Publicly Accessible
    • AWS Neptune DB Instance Without Encryption at Rest
    • AWS CloudFront Traffic Allows HTTP
    • AWS OpenSearch Domain Allows HTTP
    • AWS CloudFront Is Not Protected With WAF
    • AWS Cloud Trail Delivery Failing
    • AWS Config Referencing Missing S3 Bucket
    • AWS EKS Cluster Logging Disabled
    • AWS Beanstalk Persistent Logs
    • AWS OpenSearch Without Audit Logs
    • AWS MQ Broker Logs Disabled
    • AWS Route53 DNS Query Logging Disabled.
  • (Reachability) New rules:
  • (SAST) New rules:
    • Apk unprotected exported receivers
    • Apk unprotected exported services
    • Docker insecure context directory

Release 42

Release 41

September

Release 40

Release 39

Release 38

  • (ASPM) Mailmap management: Manage developer data directly in the platform to prevent billing issues.
  • (ASPM) Free trial restrictions: Users from existing client organizations can no longer start free trials. This change prevents confusion with reports.
  • (Reachability) New rule: Python CVE-2024-39303
  • (SAST) New rule: Improper certificate validation default.

Release 37

August

Release 36

Release 35

  • (CSPM) New rules:
    • AWS API Gateway Insecure TLS Version
    • AWS ACM Certificate Expired
    • AWS API Gateway Cache Encryption Disabled
    • AWS App Mesh Virtual Gateway TLS Disabled
    • AWS App Mesh Virtual Gateway Access Logging Disabled
  • (SAST) New rules:
    • Java insecure cors web view
    • Java declare insecure trust manager
    • Java insecure biometric auth
    • TS sequelize injection
    • JS JWT secret insecure source
    • TS JWT secret insecure source
    • Docker weak SSL TLS
    • Docker insecure builder sandbox
    • Docker insecure cleartext protocol
    • Docker weak hash algorithm
    • Docker insecure network host

Release 34

  • (ASPM) First-letter search in dropdowns: To filter the available options of a dropdown menu, type the first letters of the name or identifier of the item that you want.
  • (ASPM) Branch and URL change: Added the option to change the branch and URL of roots in some cases.
  • (ASPM) Improved root moving notifications: Group members get accurate messages when a user moves roots.
  • (ASPM) Enhanced mailmap management: Made multiple enhancements to the mailmap to prevent errors and make alias management better.
  • (SAST) New rules:
    • TS XSS pug from file
    • TS unvalidated xml parsed in vm
    • TS file unauthorized access
    • CSharp XXE resolver
    • CSharp insecure cbc iv
    • Docker sensitive mount
    • Curl insecure certificates

Release 33

  • (ASPM) Compliance CSV export: New CSV report that shows the relationship between the unmet security requirement and the location of the non-compliance.
  • (SAST) New rules:
    • Android apk keyboard cache exposure
    • TS NoSQL injection ternary
    • JS NoSQL injection ternary
    • CSharp technical info leak
    • CSharp token validation checks
    • CSharp code injection

Release 32

(CSPM) New rule: Azure app service mutual TLS is disabled.

July

Release 31

Release 30

  • (ASPM) CVSS migration: Complete the change to version 4.
  • (ASPM) AWS Marketplace: Make the integration in the AWS Marketplace available.
  • (CSPM) New rules:
    • AWS S3 Log delivery write access
    • AWS EC2 Instance has multiple network interfaces
  • (SAST) New rules:
    • JS/TS cookie service sensitive info
    • CSharp log injection
    • CSharp insecure elliptic curve
    • PHP insecure elliptic curve

Release 29

  • (ASPM) CVSS Update: Change from CVSS 3.1 to version 4 in policies.
  • (ASPM) Root removal option: Let users remove a new root directly from the current step.
  • (ASPM) Exposure column: Include "Exposure" in the Technical Report.
  • (ASPM) Branch flexibility: Let a group have the same repository with a different branch, if one of the repositories is inactive.
  • (CSPM) New rule: AWS EC2 Instance using IMDS V1.
  • (SAST) New rules:
    • PHP discloses server version
    • PHP insecure expiration time
    • PHP server leaks errors
    • PHP HTTP only disabled

Release 28

  • (ASPM) Access granted: Include the granted role in the notification.
  • (CSPM) New rules:
    • Azure SQL DB Transparent Encryption Is Disabled
    • Azure VM Scale Set Does Not Have Zonal Redundancy
  • (SAST) New rules:
    • TF K8s Host IPC Enabled
    • TF K8s Host Network Enabled
    • TF K8s HostPID Enabled
    • TF K8s Host Path Volumes
  • (DAST-WEB) New rule:
    • X permitted cross-domain policies.

Release 27

  • (ASPM) Webhooks: Relocate to the Integrations Hub.
  • (ASPM) New ASPM: Launch the platform's new design for external users.
  • (SAST) New rules:
    • TF K8s Container Without Context
    • TF K8s Host Process Enabled
  • (DAST-WEB) New rules:
    • Unsafe HTTP X-Frame options
    • CDN vulnerable element
    • Access control any origin
    • HTTP error in response

June

Release 26

  • (ASPM) Token management: Use SecretStorage to keep tokens secure.
  • (CSPM) New rules:
    • Azure DB PSQL Flex Server Insecure TLS Version
    • Azure Redis Cache Allows Connections Without SSL
    • Azure DB PSQL Flex Server Firewall Allows Public Access
    • Azure DB PSQL Flex Server Connection Throttling Disabled
  • (SAST) New rules:
    • TF K8s Check Run as User
    • TF K8s Check Privileged Used
    • TF K8s Check If Sys Admin Exists
    • JS hardcoded key hmac
    • TS hardcoded key hmac
    • TF K8s host network enabled
    • TF K8s hostpid enabled
    • TF K8s host process enabled
    • TF K8s host path volumes
    • PHP insecure SSL/TLS stream
    • PHP sensitive HTTP sent
    • CSharp http only cookie

Release 25

(SAST) New rules:

  • TF K8s Check Add Capability
  • TF K8s Root Filesystem Read Only
  • TF K8s Check Seccomp Profile
  • TF K8s Check Drop Capability
  • TF K8s Check If Capability Exists
  • TF K8s SA Token Enabled
  • TF K8s SA Token Enabled
  • TF K8s Image Has Digest
  • TS NoSQL injection
  • JS NoSQL injection
  • PHP insecure SSL TLS HTTP

Release 24

  • (ASPM) Migrate authors: The authors' data is available in the platform.
  • (ASPM) GitLab integration: Add integration with GitLab.
  • (ASPM) Azure DevOps integration: Add integration with Azure DevOps.
  • (CSPM) New rules:
    • Azure API Mgmt Uses the Triple DES Cipher Algorithm
    • Azure MongoDB NSG Allows Unrestricted Access
    • Azure MS SQL Server NSG Allows Unrestricted Access
    • Azure MySQL NSG Allows Unrestricted Access
    • Azure NetBIOS NSG Allows Unrestricted Access
    • Azure Oracle Database NSG Allows Unrestricted Access
    • Azure PostgreSQL DB NSG Allows Unrestricted Access
    • Azure VMs NSG Allows Unrestricted Access
    • Azure RPC NSG Allows Unrestricted Access
    • Azure SMTP NSG Allows Unrestricted Access
    • Azure SSH NSG Allows Unrestricted Access
    • Azure UDP Ports NSG Allows Unrestricted Access
  • (SAST) New rules:
    • TF K8s Allow Privilege Escalation Enabled
    • TF K8s Root Container
    • TF Kubernetes Insecure Port
  • (SCA) New rule: Poetry toml deps.
  • (DAST-WEB) New rules:
    • SSL certificate expired
    • SSL self-signed certificate
    • SSL wrong cn
    • SSL wildcard certificate

Release 23

  • (ASPM) Vulnerability remediation: Write a complete guide for the remediation of vulnerabilities.
  • (ASPM) Token workflow: Update the process to make and renew DevSecOps tokens.
  • (CSPM) New rules:
    • Azure API Mgmt SVC Does Not Use a Managed Identity
    • Azure Key Vault Admin Permissions on Keys
    • Azure Search Service Public Network Access Is Enabled
  • (SAST) New rules:
    • PHP insecure mcrypt
    • PHP insecure OpenSSL

May

Release 22

  • (ASPM) Safe vulnerabilities tracking: Monitor safe vulnerabilities and specify the cause of their closure.
  • (ASPM) VM permissions: Change the permissions of vulnerability managers that are related to roots management.
  • (AGENT) Specific path argument: Add an argument to specify and analyze paths in a repository.
  • (CSPM) New rules:
    • Azure DB PSQL Flexible Server SSL Disabled
    • Azure Data Lake Allows Access from Any Source
    • Azure Synapse Firewall Allows Public Access
    • Azure Cosmos DB Public Network Access Is Enabled
    • Azure DataFactory Public Network Access Is Enabled
    • Azure API Mgmt SVC Public Network Access Is Enabled
    • Azure Key Vault Public Network Access Is Enabled
  • (SAST) New rules:
    • C Sharp SQL injection request
    • PHP XML parser

Release 21

  • (ASPM) Table sorting: Add sort options for the items in the Jira table.
  • (ASPM) Credentials table usage info: Show which credentials are in use in the credentials table.
  • (SAST) New rules:
    • PHP generates insecure token
    • PHP uses sha1 in query

Release 20

  • (ASPM) WhatsApp OTP: Send the OTP through WhatsApp when users add or update their mobile number.
  • (CSPM) New rules:
    • Azure API Mgmt Front Insecure TLS Version
    • Azure Subscription Does Not Have a Locking Resource Manager
    • Azure App Service HTTP2 Is Disabled
    • Azure Subscription Has at Least Two Owners
    • Azure Search Service Does Not Use a Managed Identity
    • Azure Search Service Insufficient Replicas Configured
    • Azure Search Service Has Insufficient Replicas Configured
  • (SAST) New rules:
    • APK task hijacking
    • APK clear text traffic
    • PHP SQL leak errors
    • PHP insecure file upload
    • PHP unsafe path traversal
    • PHP excessive access mode
    • PHP technical info leak
    • PHP weak random
    • PHP insecure deserialization
  • (DAST-WEB) New rules:
    • Cont sec pol frame ancestors
    • Cont sec pol wild uri
    • Cont sec pol missing obj
    • Cont sec pol missing script
    • Cont sec pol unsafe line
    • Cont sec pol hosts jsonp
    • Missing referrer policy
    • Strict transport low max age
    • Strict transport includes subdomains
    • X content type options nosniff

Release 19

  • (ASPM) Expanded export columns: Add new columns to the DevSecOps view table and include them in the related CSV export.
  • (ASPM) Nickname edition: Let customers edit the nicknames of Git roots.
  • (ASPM) Vulnerability filters: Add filters to the API to sort and classify vulnerabilities.
  • (ASPM) Grouped vulnerabilities: Show a summary of vulnerabilities grouped by technique in the result log.
  • (CSPM) New rule: Azure Dev Portal has Auth Methods Inactive.
  • (SAST) New rules:
    • JS hardcoded credentials in test
    • TS hardcoded credentials in test

April

Release 18

  • (SAST) CLI using parameters: Let users run the CLI with configurable parameters.
  • (SAST) New rules:
    • JS command injection serialize
    • JS exposed private key
    • TS exposed private key
    • JS sensitive info in endpoint
    • TS sensitive info in endpoint
    • TS xml parser inside context
    • PHP unsafe XSS content

Release 17

  • (ASPM/AGENT) Execution details: Include the status at the end of the execution in the Execution details. This status shows if the agent broke the build.
  • (ASPM) Secrets management: Let other users get permissions to manage secrets in environment URLs.
  • (ASPM) Tables management: Add a marker that tells users when the table does not show some columns.
  • (ASPM) Environments management: Close vulnerabilities automatically when a user removes the related environment.
  • (CSPM) New rules:
    • Azure DB for MySQL Flex Servers Insecure TLS Version
    • Azure Role-Based Access Control on Key Vault Is Not Enabled
    • Azure Function App with Admin Privileges
    • Azure Role Actions Is a Wildcard
    • Azure App Service Allows HTTP Traffic
    • Azure API Not Enforce HTTPS
    • AZ Subscription Not Allowed Resource Types Policy
    • Azure App Service Does Not Use a Managed Identity
    • Azure Function App Logging Is Disabled
    • Azure Keys Expiration Date Is Not Enabled
    • Azure Secret Expiration Date Is Not Enabled
    • Azure App Service Always On Is Not Enabled
    • Azure Batch Jobs Runs in Admin Mode
    • Azure Function App Use Not Host Keys
    • Azure Publicly Exposed Funct App
  • (SAST) New rules:
    • TS express accepts any mime
    • JS express accepts any mime
    • JS insecure cors origin
    • TS insecure cors origin
    • GitHub actions without hash

Release 16

  • (ASPM) Warning message: Display a warning message when a user deactivates a root with related environments.
  • (CSPM) New rules:
    • Azure DB MySQL firewall allows public access
    • Azure DB MySQL SSL disabled
    • Storage lifecycle is not defined
    • Azure DB SQL insecure audit retention period
    • Azure DB SQL extended audit disabled
    • Azure DB SQL firewall allows public access
  • (SAST) New rules:
    • PHP hardcoded init vector
    • PHP hardcoded password
    • PHP insecure hash
    • TS local file inclusion
    • TS open redirect
    • JS hardcoded password
    • TS hardcoded password
    • TS sensitive info in params

Release 15

  • (IDE) Jira integration: Give access to all the vulnerability information directly in the IDE.
  • (ASPM) Require OTP for login: Add a security measure to decrease the related risks.
  • (ASPM) Delete group: Send an email notification when a user removes a group.
  • (CSPM) New rules:
    • Azure DB PostgreSQL connection throttling disabled
    • Azure DB PostgreSQL SSL disabled
    • Azure DB PostgreSQL insecure TLS version
    • Azure DB PostgreSQL log settings disabled
    • Azure DB PostgreSQL log checkpoints disabled
    • Azure DB PostgreSQL firewall allows public access
    • Azure DB PostgreSQL insecure log retention
  • (SAST) New rules:
    • HTML uses innerhtml
    • JS file size limit missing
    • TS file size limit missing
    • JS directory listing
    • TS directory listing
    • JS error handler enabled
    • TS error handler enabled

Release 14

  • (ASPM) Simplify free trial: Decrease the number of steps to start a free trial.
  • (ASPM) Notifications subjects: Update notification subjects for improved clarity.
  • (ASPM) Group created notifications: Add notifications to keep users updated on group creation events.
  • (SCA) SCA reports in lock files: Publish SBOMs for Fluid Attacks components.
  • (SCA) Fluid Attacks SBOMs: Publish SBOMs for Fluid Attacks components.
  • (CSPM) New rules:
    • Azure VM encryption at host disabled
    • Azure AKS has rbac disabled.
  • (SAST) New rules:
    • PHP insecure encrypt AES
    • PHP remote command execution
    • PHP has empty catch

March

Release 13

  • (ASPM/AGENT) Technical debt policy: Add a grace period before the agent breaks the build because of new vulnerabilities.
  • (SAST) Analyze PHP code: Let the scanner analyze PHP code.
  • (CSPM) New rules:
    • Azure AKS API server allows public access
    • Azure AKS has kubernet network plugin
    • Azure storage not enabled infrastructure encryption
  • (SAST) New rule: PHP basic authentication.
  • (SCA) New rules:
    • Gradle wrapper properties
    • CycloneDX JSON deps
    • SPDX JSON deps

Release 12

  • (SCA) Standard format: Make sure that SBOMs obey the format requirements of Fluid SBOM.
  • (ASPM) Approve ZR: Address the misuse of ZR requests by customers who try to bypass build failures.
  • (CSPM) New rules:
    • Azure AKS has enable local accounts
    • Azure AKS is not using the latest version
    • Azure container registry is not using replication
  • (SAST) New rules:
    • PHP info leak errors
    • Java insecure engine cipher SSL
    • Docker compose ssh pass
  • (SCA) New rules:
    • Gemfile missing package lock
    • Erlang missing package lock
    • Cargo missing package lock
    • Conan missing package lock
    • Pipfile missing package lock
    • Composer missing package lock
    • Nuget missing package lock

Release 11

  • (ASPM) Plans' names: Update and standardize the names of plans.
  • (ASPM) Videos on evidence: Add one more field to upload video files as evidence into findings.
  • (ASPM) Connector notifications: Send email alerts when a secure connector goes offline.
  • (ASPM) Environment secrets: Add an indicator to show the existence of secrets on the Environment URL.
  • (SCA) Lock files: Add support for lock files.
  • (SCA) Gradle wrapper: Add SCA support for gradle-wrapper.properties.
  • (CSPM) New rules:
    • Azure blob soft deleted disabled
    • Azure network app gateway waf is disabled
    • Azure network watcher not enabled
    • Azure network flow log insecure retention period
    • Azure network group using port ranges
    • Azure firewall network rules unrestricted
    • Azure network firewall app rules unrestricted
    • Azure container registry admin user enabled
    • Azure network out of date OWASP rules
    • Azure insecure TLS version
    • Azure allows FTP deployments
    • Azure key vault soft delete retention
    • Azure remote debugging enabled
    • Azure authentication is not enabled.
  • (SAST) New rules:
    • PHP insecure cors
    • DB credentials exposed in code
    • Java credentials exposed in code
    • Swift credentials exposed in code
    • Python credentials exposed in code
  • (SCA) New rule: Nuget pkgs lock json.

Release 10

  • (ASPM) Org/group policy: Update policy to address temporary acceptance of vulnerabilities based on CVSS scores.
  • (ASPM) Vulnerabilities evidence: Let users submit larger files as evidence.
  • (ASPM) Events alert: Add a color-coded circle indicator to flag groups with pending events.
  • (SCA) Vulnerabilities prioritization: Integrate EPSS scoring into SCA advisories and vulnerability assessments.
  • (CSPM) New rules:
    • TF allows priv escalation by policy versions
    • Azure network ftp ingress not restricted
    • Azure network dns ingress not restricted
    • Azure network cifs ingress not restricted
    • Azure network rdp ingress not restricted
    • Azure network ssh ingress not restricted
    • Azure network group allows public access
    • Azure network telnet ingress not restricted
    • Azure network icmp ingress not restricted
    • Azure network https ingress not restricted
    • Azure network http ingress not restricted
    • Azure disabled accidental purge
  • (SAST) New rule: PHP uses eval.
  • (SCA) New rules:
    • Pipfile lock
    • Pipfile deps

February

Release 9

  • (ASPM) Exclusions as Code: Make EaC functionality available for all SKIMS modules.
  • (ASPM) Organization analytics: Make sure that the CSV files that users download from Analytics graphics include complete and applicable information for all groups in the organization.
  • (ASPM) Secrets modal: Replace the dropdown for "Secret Description" with a dedicated column in the Secrets modal.
  • (ASPM) Reattacks overhaul: Add checks to prevent reattack reviews on outdated locations or files.
  • (ASPM) Notifications: Update notification wording regarding resolved vulnerabilities for improved clarity.
  • (SAST) Multi-file scanning for SAST rules.
  • (CSPM) New rules:
    • Azure storage account not enforcing latest TLS
    • Azure storage account allows public network access
    • Azure Redis public network access enabled
    • Azure Redis authnotrequired enable
    • Azure Redis insecure TLS version
    • Azure Redis insecure port
    • Azure storage account Microsoft bypass
    • Azure containers soft deleted disabled
    • Azure Redis firewall allows public access

Release 8

  • (ASPM) Closing date filter: Let users specify a range of closing dates for the custom technical reports of groups.
  • (ASPM) Root nickname: Display the nickname of the root of a vulnerability.
  • (CSPM) New rules:
    • Azure blob containers are public
    • Azure storage account allows public blobs

Release 7

  • (ASPM) Webhooks: Let the platform integrate with all applications that support the webhook standard.
  • (ASPM) Move roots in batch: Let users move roots in batches to keep the ToE updated and organized.

Release 6

January

Release 5

Release 4

Release 3

Release 2

Release 1

(ASPM) Add links to breadcrumbs: Add links to breadcrumbs for easier navigation in the documentation.

On this page