Qualys VM: CCF Connector Adds Vulnerability Intelligence Stream

Qualys VM Knowledge Base solution now includes a Codeless Connector Framework (CCF) implementation for automated vulnerability data ingestion alongside the existing legacy connector. Read More →

TheHive Connector: Production-Ready with Enhanced Custom Fields Mapping

TheHive CCF connector promoted to General Availability with improved custom fields processing, removing preview limitations for security incident management workflows. Read More →

ASIM AlertEvent Parser: Microsoft Defender XDR Missing AlertOriginalStatus Field Restored

Critical data fidelity fix restores missing AlertOriginalStatus field in Microsoft Defender XDR ASIM AlertEvent parser, resolving alert status visibility gap. Read More →

Microsoft Security Copilot Solution Released to General Availability

Microsoft Security Copilot solution v3.0.2 transitions from preview to GA with connector availability status updated. Read More →

Detection Template Validation: connectorId Enforcement Added to Review Process

Detection authoring guidelines now require validation of connectorId values against the official repository allowlist to prevent invalid connector references. Read More →

Recorded Future: IOC Enrichment Noise Reduction via Risk Score Thresholding

Added configurable RiskScoreThreshold parameter to prevent low-risk IOCs from generating incident comments. Read More →

Okta Single Sign-On: ARM Template Compliance Fix for SessionId Variable

Resolved ARM TTK validation error by parameterizing hardcoded SessionId reference in deployment template. Read More →

BitSight Solution: Metadata Fix for Content Hub Publishing Issue

BitSight solution publishing restored after solution ID metadata correction. Read More →

Microsoft A365 Observability Connector: Explicit SecurityAdmin Requirement Removed

Microsoft removed the explicit SecurityAdmin requirement from the A365 Observability connector, but GlobalAdmin — the highest privilege level in Azure AD — is still required. This is not a reduction in required privilege. Read More →

Imperva Cloud WAF: Production Ready CCF Connector with Standard Tables

Imperva Cloud WAF CCF connector migrates from private preview custom tables to public preview standard tables. Read More →

SentinelOne Connector: Template Cleanup for JSON Schema Compliance

Code hygiene fix removes redundant null values from CCF connector configuration. Read More →

Cyren-SentinelOne Playbook: Credential Parameter Security Compliance Fix

Fixed Policy 300.4.1.1 violation by securing credential parameters in the Cyren-SentinelOne threat intelligence integration Playbook. Read More →

Tenable VM Parser: CVSS 4.0 and VPR v2 Field Mapping Restores Missing Vulnerability Scoring Data

Tenable VM vulnerability parser now extracts CVSS 4.0 vector components and VPR v2 threat intelligence previously unmapped from ingested vulnerability scans. Read More →

D3 Smart SOAR: Version Bump to 3.1.0 for Partner Center Resubmission

Version increment from 3.0.0 to 3.1.0 to enable Partner Center to detect previously submitted fixes including pagination improvements and branding updates. Read More →

Corelight: Enhanced Data Fidelity for Network Aggregation Events

Fixes field mapping inconsistencies in Corelight aggregation parsers that caused data loss and adds aggregation filtering to the Data Explorer workbook. Read More →

Lookout Mobile Threat Defense: ARM Template Certification Fix

Partner Center certification blocker resolved with single bracket correction in ARM deployment template. Read More →

Microsoft Security Copilot: Six New Detections for AI Assistant Abuse

New analytic rules target jailbreak attempts, external access, plugin tampering, and file upload disabling - covering major AI security attack vectors. Read More →

Google Workspace Reports Connector Promoted to General Availability

Google Workspace Reports CCF connector exits preview status with updated OAuth configuration guidance. Read More →

New Attack Surface Management Solution: blacklens.io Brings External Threat Visibility to Microsoft Sentinel

blacklens.io Attack Surface Management platform now available in Content Hub with webhook-based alert ingestion and automated incident creation. Read More →

Anomalous Single Factor Sign-in Detection: Version Metadata Update

Version bump to 1.0.6 for Anomalous Single Factor Sign-in detection rule with no logic changes. Read More →