<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Changelog on sentinelchangelog.net</title><link>http://sentinelchangelog.net/posts/</link><description>Recent content in Changelog on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Wed, 03 Jun 2026 17:34:45 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>BitSight Solution: Support Tier Changed to Partner</title><link>http://sentinelchangelog.net/posts/2026-06-03-pr-14397/</link><pubDate>Wed, 03 Jun 2026 17:34:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-03-pr-14397/</guid><description>BitSight solution support tier updated from Microsoft to Partner with version downgrade to 3.2.0.</description></item><item><title>Microsoft Agent Identities Connector: New Entra Non-Human Identity Asset Visibility (Preview)</title><link>http://sentinelchangelog.net/posts/2026-06-03-pr-14326/</link><pubDate>Wed, 03 Jun 2026 06:01:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-03-pr-14326/</guid><description>Agent 365 solution adds new Microsoft Agent Identities connector for tracking agent blueprints and non-human identity assets across four data tables.</description></item><item><title>ASIM Authentication Parsers: Palo Alto Data Fidelity Fix for DvcIpAddr Field</title><link>http://sentinelchangelog.net/posts/2026-06-02-pr-14396/</link><pubDate>Tue, 02 Jun 2026 21:22:50 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-02-pr-14396/</guid><description>ASIM Authentication parsers for Palo Alto PAN-OS and GlobalProtect now correctly populate DvcIpAddr field, fixing data fidelity gap.</description></item><item><title>Cisco Umbrella CCF: Public Preview Expands Data Visibility with 10 New Log Tables</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14378/</link><pubDate>Mon, 01 Jun 2026 14:34:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14378/</guid><description>New Codeless Connector Framework introduces comprehensive log coverage across DNS, web traffic, cloud firewall, admin audit, DLP, file events, IPS, VPN and Zero Trust access for enhanced threat detection.</description></item><item><title>Oracle Cloud Infrastructure CCF Connector: IAM Permissions Guidance Added</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14347/</link><pubDate>Mon, 01 Jun 2026 05:33:21 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14347/</guid><description>OCI connector UI updated with explicit IAM policy requirements for stream consumption authorization alongside API signing key authentication.</description></item><item><title>Slack Audit Solution: Enhanced Detection Logic and Alert Enrichment</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</link><pubDate>Mon, 01 Jun 2026 04:39:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</guid><description>Slack Audit analytic rules, hunting queries, and workbook upgraded with improved KQL logic, custom alert details, and enhanced entity mappings for stronger workspace monitoring.</description></item><item><title>ASIM Parser Development Automation: GitHub Copilot Skills for Accelerated Detection Engineering</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14383/</link><pubDate>Fri, 29 May 2026 23:39:29 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14383/</guid><description>GitHub Copilot agent skills now automate the complete ASIM parser creation workflow, reducing parser development time from days to hours for security engineers.</description></item><item><title>42Crunch API Protection: Critical Migration from Legacy HTTP Collector to CCF Push Connector</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14210/</link><pubDate>Fri, 29 May 2026 16:38:05 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14210/</guid><description>Migration addresses deprecated HTTP Data Collector API by implementing CCF OAuth2/Entra ID ingestion — deployments on legacy connector face imminent data loss.</description></item><item><title>Entra ID Post-Credential Activity Detection: Service Principal Staging and Privileged Role Escalation</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</link><pubDate>Fri, 29 May 2026 10:56:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</guid><description>Three new hunting queries target Midnight Blizzard-style persistence patterns — service principal credential staging, privileged role assignments to new accounts, and Temporary Access Pass abuse.</description></item><item><title>Azure Security Benchmark Solution: Enhanced Detection Logic and Incident Enrichment (v3.0.5)</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-13905/</link><pubDate>Fri, 29 May 2026 08:53:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-13905/</guid><description>Azure Security Benchmark solution updated to v3.0.5 with improved compliance monitoring logic, proper data connector declarations, and enhanced incident alert details.</description></item><item><title>Gentlemen Ransomware Campaign: New Hunting Queries for EtherRAT/TukTuk IOCs and Web3 C2 Infrastructure</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14338/</link><pubDate>Fri, 29 May 2026 08:24:12 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14338/</guid><description>Two hunting queries added targeting Gentlemen ransomware campaign artifacts including payload hashes and decentralized Web3/SaaS C2 infrastructure used by EtherRAT and TukTuk malware.</description></item><item><title>Logstash Output Plugin: Version 2.2.1 with Enhanced Logging and Security Warnings</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14359/</link><pubDate>Fri, 29 May 2026 08:08:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14359/</guid><description>Microsoft Sentinel Logstash plugin updated to v2.2.1 with improved batch logging and comprehensive security warnings for vulnerable Logstash versions.</description></item><item><title>Workspace Usage Report Workbook: Version 1.6.5 Metadata Update</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14353/</link><pubDate>Fri, 29 May 2026 08:07:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14353/</guid><description>Workspace Usage Report workbook bumped to v1.6.5 with updated description mentioning Microsoft Sentinel and Defender support.</description></item><item><title>LockBit Hunting Query: ActiveMQ Exploit IoC Detection Added</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</link><pubDate>Fri, 29 May 2026 05:32:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</guid><description>New hunting query provides hash-based detection for LockBit ransomware artifacts deployed via Apache ActiveMQ CVE-2023-46604 exploitation.</description></item><item><title>CrowdStrike API Connector: Multi-Domain Support for Enterprise Deployments</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14370/</link><pubDate>Thu, 28 May 2026 20:59:38 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14370/</guid><description>CrowdStrike API connector now supports multiple domain configurations with unique aliases, enabling organizations to ingest data from different CrowdStrike instances simultaneously.</description></item><item><title>Airlock Digital Solution: Application Control Visibility for Endpoint Security</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14330/</link><pubDate>Thu, 28 May 2026 17:08:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14330/</guid><description>New CCF connector enables ingestion of Airlock Digital application control logs, providing execution monitoring and file activity visibility to detect unauthorized software execution.</description></item><item><title>AWS Security Hub Compliance Workbook: Comprehensive Security Posture Visualization Now Available</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-13870/</link><pubDate>Thu, 28 May 2026 12:40:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-13870/</guid><description>New AWS Security Hub compliance workbook provides executive dashboards and operational analytics for security findings, compliance tracking, and multi-account posture management.</description></item><item><title>NordStellar CCF Push Connector: Real-time Threat Intelligence Integration Now Available</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14198/</link><pubDate>Thu, 28 May 2026 12:05:41 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14198/</guid><description>New NordStellar solution delivers real-time threat intelligence and exposure monitoring via CCF Push architecture to unified NordStellar_CL table.</description></item><item><title>Entra ID Identity Boundary Expansion: Three New Hunting Queries for Stealthy Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</link><pubDate>Thu, 28 May 2026 11:14:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</guid><description>Added three hunting queries targeting identity boundary expansion techniques in Entra ID that escalate privileges without creating new accounts.</description></item><item><title>AWS S3 and CrowdStrike Connectors: Non-Analytics Tier Query Support for Basic/Auxiliary Plans</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14264/</link><pubDate>Thu, 28 May 2026 10:37:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14264/</guid><description>AWS S3 and CrowdStrike Falcon S3 Data Replicator connectors now support Usage table fallback queries for deployments using Basic/Auxiliary Log Analytics plans.</description></item><item><title>Bitdefender GravityZone Solution v3.0.1 Adds Incident Analytics for Endpoint and Email Protection</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-13299/</link><pubDate>Thu, 28 May 2026 05:19:38 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-13299/</guid><description>Complete Microsoft Sentinel solution integrating Bitdefender GravityZone multi-vector threat detection with DCR-based ingestion and XDR correlation.</description></item><item><title>ASIM AlertEvent Support Added for Bitdefender GravityZone Security Platform</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-13330/</link><pubDate>Thu, 28 May 2026 05:16:16 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-13330/</guid><description>New parsers enable normalization of Bitdefender GravityZone alert data into Microsoft Sentinel ASIM schema for unified threat detection.</description></item><item><title>Sonrai Security CCF Connector: New Cloud Security Posture Visibility</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14360/</link><pubDate>Wed, 27 May 2026 23:10:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14360/</guid><description>Sonrai Security compliance tickets now integrate directly with Microsoft Sentinel through a new CCF push connector.</description></item><item><title>BitSight: Function App to CCF Migration Restores Third-Party Risk Visibility</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14356/</link><pubDate>Wed, 27 May 2026 19:04:26 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14356/</guid><description>Legacy Function App connector replaced with two CCF connectors for independent security statistics and events ingestion.</description></item><item><title>VMware Workspace ONE: New CCF Connector for UEM Device and Application Visibility</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14258/</link><pubDate>Wed, 27 May 2026 15:42:07 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14258/</guid><description>VMware Workspace ONE Unified Endpoint Management platform now available in Microsoft Sentinel via CCF connector for device compliance monitoring and shadow IT detection.</description></item><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Entra ID Account Takeover: Three-Query Hunting Pack for Post-Compromise Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</link><pubDate>Wed, 27 May 2026 13:41:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</guid><description>Adds hunting pack targeting device code phishing, service principal persistence, and bulk password resets by privileged actors.</description></item><item><title>BadUSB HID Injection Detection: New Hunt for PowerShell via Windows Run Dialog</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14336/</link><pubDate>Wed, 27 May 2026 13:38:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14336/</guid><description>Adds hunting query to detect hardware keystroke injectors spawning PowerShell through explorer.exe with evasion patterns.</description></item><item><title>Microsoft Entra ID OAuth Consent Query: Fixing Zero-Result Bug in High-Risk Permission Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</link><pubDate>Wed, 27 May 2026 13:38:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</guid><description>Corrects broken hunting query that returned no results due to incorrect property name filter.</description></item><item><title>Cloudflare CCF Workbook: Fixed Field Mapping for New CCF Schema</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14246/</link><pubDate>Wed, 27 May 2026 10:09:18 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14246/</guid><description>Corrected workbook queries to use normalized ASIM fields from Cloudflare CCF connector, resolving visualization errors from legacy field references.</description></item><item><title>Hunting Query: Ephemeral Code Signing Certificates for Malware-Signing-as-a-Service Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</link><pubDate>Wed, 27 May 2026 08:59:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</guid><description>New hunting query identifies short-lived code signing certificates (≤14 days) on non-developer endpoints to detect Fox Tempest MSaaS operations.</description></item><item><title>Hunting Query: Rootkit Network Evasion Detection via Firewall-EDR Telemetry Delta</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</link><pubDate>Wed, 27 May 2026 08:36:31 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</guid><description>New hunting query detects kernel-level rootkits bypassing EDR network telemetry by comparing perimeter firewall logs against Microsoft Defender for Endpoint data streams.</description></item><item><title>Google Threat Intelligence Solution: Custom Connector Deployment Prerequisites Clarified</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14267/</link><pubDate>Wed, 27 May 2026 06:35:46 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14267/</guid><description>Solution metadata updated to warn customers that Playbooks require manual deployment of the GTI custom Logic Apps connector before use.</description></item><item><title>GitHub Actions Security: npm Scripts Disabled and Workflow Permissions Tightened</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14324/</link><pubDate>Wed, 27 May 2026 06:10:29 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14324/</guid><description>CI hardening prevents npm lifecycle script execution and restricts slash-command dispatch to authorized repository members only.</description></item><item><title>Defender for Endpoint: Cryptographic Identity Baselining Hunting Query for Process Network Anomalies</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14333/</link><pubDate>Tue, 26 May 2026 09:05:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14333/</guid><description>New hunting query detects first-time network connections by processes using cryptographic signer baselining to defeat DLL sideloading and BYOTA attacks.</description></item><item><title>ASIM AssetEntity Schema: Three New Fields Added in v1.0.0 Release</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14312/</link><pubDate>Tue, 26 May 2026 08:18:37 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14312/</guid><description>ASIM AssetEntity schema upgraded to v1.0.0 with three new fields for enhanced entity correlation and snapshot tracking.</description></item><item><title>Entra ID Attack Chain Correlation: Three New Hunting Queries for Sequential Compromise Patterns</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</link><pubDate>Tue, 26 May 2026 08:14:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</guid><description>Three hunting queries detect multi-event attack chains in Entra ID—privileged role grants followed by SP credential additions and MFA disabling followed by sign-ins from unknown IPs.</description></item><item><title>Phishing Detection: Raw IP URLs in Delivered Email</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14340/</link><pubDate>Tue, 26 May 2026 06:30:21 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14340/</guid><description>New hunting query identifies delivered emails using raw IPv4 addresses as URL domains to detect phishing campaigns bypassing domain reputation systems.</description></item><item><title>Entra ID Hunting Pack: Defense Weakening and Privilege Abuse Detection</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</link><pubDate>Tue, 26 May 2026 06:12:52 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</guid><description>Three hunting queries targeting silent defense weakening techniques and off-hours privilege escalation in Entra ID environments.</description></item><item><title>LSASS Credential Dumping: Resilient Behavioral Detection Pack Added</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14341/</link><pubDate>Tue, 26 May 2026 05:29:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14341/</guid><description>Three new hunting queries detect LSASS memory dumping using behavioral physics rather than brittle timing or tool names.</description></item><item><title>BloodHound Enterprise: Logo Update Aligns Solution Branding</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14254/</link><pubDate>Tue, 26 May 2026 05:11:32 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14254/</guid><description>Updated BloodHound Enterprise solution logo to current SpecterOps branding.</description></item><item><title>Fortinet FortiGate Playbook: Function App Authentication Security Hardening</title><link>http://sentinelchangelog.net/posts/2026-05-25-pr-14316/</link><pubDate>Mon, 25 May 2026 06:58:27 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-25-pr-14316/</guid><description>Playbook Function App authentication level upgraded from anonymous to function-level to close security exposure.</description></item><item><title>Cyren Defender Threat Intelligence: New IP and Malware URL Ingestion for Microsoft Sentinel</title><link>http://sentinelchangelog.net/posts/2026-05-25-pr-14121/</link><pubDate>Mon, 25 May 2026 05:24:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-25-pr-14121/</guid><description>Content Hub solution adds Cyren threat intelligence feeds for IP reputation and malware URL indicators via automated Logic App playbook.</description></item><item><title>Entra ID Workload Identity and Privileged Role Hunting Pack: Three New Detection Queries</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</link><pubDate>Thu, 21 May 2026 12:50:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</guid><description>New hunting pack targeting workload identity abuse and privileged role assignment anomalies with coverage gaps for service principal credential theft and PIM bypass techniques.</description></item><item><title>ETW-Resistant .NET Fileless Injection Detection via Kernel-Level CLR Loading</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</link><pubDate>Thu, 21 May 2026 12:14:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</guid><description>New hunting query detects fileless .NET execution even when attackers patch ETW by monitoring kernel-level .NET runtime DLL loading in native processes and untrusted paths.</description></item><item><title>CrowdStrike Content Doctor Enhancement: Improved Detection Logic and Alert Customization</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14268/</link><pubDate>Thu, 21 May 2026 12:01:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14268/</guid><description>Content Doctor improvements to CrowdStrike Falcon detection rules enhancing KQL logic, MITRE mappings, and alert presentation for critical/high severity detections.</description></item><item><title>Microsoft Defender XDR: New Hunting Query for Delegate Mailbox Phish Reporting Analysis</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</link><pubDate>Thu, 21 May 2026 04:14:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</guid><description>New hunting query helps identify the actual user who reported a phishing message when recipients and actors differ in delegate or shared mailbox scenarios.</description></item><item><title>OpenAI Connector: Migration to ASIM Standard Improves AI Monitoring Normalization</title><link>http://sentinelchangelog.net/posts/2026-05-20-pr-14277/</link><pubDate>Wed, 20 May 2026 22:32:31 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-20-pr-14277/</guid><description>OpenAI chat completions data now ingests to ASimAgentEventLogs standard table, enabling standardized AI usage monitoring and cross-product correlation.</description></item><item><title>SailPoint IdentityNow: Publisher Migration to Microsoft Public Preview</title><link>http://sentinelchangelog.net/posts/2026-05-20-pr-14297/</link><pubDate>Wed, 20 May 2026 15:59:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-20-pr-14297/</guid><description>SailPoint IdentityNow solution metadata updated for Microsoft-published Public Preview release with no functional changes to identity monitoring capabilities.</description></item><item><title>New Cyren-CrowdStrike Threat Intelligence Solution: Automated IOC Sync for Enhanced Threat Detection</title><link>http://sentinelchangelog.net/posts/2026-05-20-pr-13658/</link><pubDate>Wed, 20 May 2026 09:16:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-20-pr-13658/</guid><description>Logic App playbook now available to automatically sync Cyren IP reputation and malware URL indicators to CrowdStrike Falcon for streamlined threat blocking.</description></item></channel></rss>