1.6.0
The CyberOptix CTEM Platform 1.6.0.
Cloud Exposure
Asset rules. Applications can now be tied to cloud assets by rule rather than one at a time. Rules resolve in the background and keep resolving as your estate changes, so an application's asset list stays current instead of ageing from the moment it was set.
One tag store across clouds. Tags from every connected cloud now live in a single store, so a tag rule written once behaves identically whether the asset is in AWS or Azure. Previously each cloud kept its own, and a rule that worked in one silently did nothing in the other.
Documentation
The documentation site has been rebuilt. Three changes you will notice:
- It is organised around what you are trying to do, rather than mirroring the application's menu - with a Concepts section covering the model underneath every screen: assets, severity, scoping, and remediation SLAs.
- The API reference is grouped by product domain and matches the names used in the product, rather than by internal service names.
- Deployment has its own section, covering scanners, appliances, collectors and the integrator.
Corrections worth calling out, because they affected documented procedures that could not work as written:
- The scanner service list omitted
scanner-dast.service. Following the old documentation enabled five of six services, and dynamic application security testing never ran. - The scanner link command was documented with
-org_id; the flag is-organization_id. - The syslog collector's listening port was documented as fixed. It is configurable.
- Red Hat installation instructions have been removed. The edge components are Ubuntu Server 24.04 only.
Release notes and security bulletins
This note is the first in a new Release notes feed, alongside a separate Security bulletins feed. Both carry RSS.
Every production release will have a note from here on, enforced by the release pipeline rather than by anyone remembering. See the release note policy for what that commits us to.