Change Log
Release notes and version history for the ThreatSabre NSPM platform, including new features, improvements, and bug fixes.
2026-09-28 (v1.22.0) - Platform
- Added: Agent version is now reported on the Agent page.
- Added: You can now add a description to an Agent.
- Changed: Agent versions older than the most recent version seen for an agent are now rejected. To downgrade, you must explicitly reset the last seen version to allow an older version to connect.
- Changed: When a user's session times out, they are now logged out of the app with a message stating that the session expired. Logging back in returns the user to the last page they visited.
- Changed: The selector for adding devices to groups now matches other parts of the application.
2026-09-19 (v1.21.0) - Platform
- Added: Partial assessments — when a scan cannot evaluate every rule, the Device Summary shows a Partial assessment notice with the unassessed rule IDs and the time of the last full assessment. Previous findings for those rules are kept; a first missing assessment does not create a passing result. A later complete scan clears the notice.
- Changed: When a scan does not include license or support-expiry data, Device Summary labels those fields as unknown rather than "no entitlements".
2026-09-13 (v1.20.0) - Platform
- Changed: The Recent Alerts widget on the dashboard now groups events to show more useful information.
- Fixed: The Support Contract help icon now stays on the same line as the card title on the device page.
2026-09-12 (v1.19.0) - Platform
- Added: Branding — tenant admins can set a “Managed by” identity and a default organization logo, and choose how each owned organization is shown (tenant default, organization name, or a custom logo). Branding appears in the app header and on generated reports.
- Added: First-organization setup — new tenants are guided through creating their first organization, with optional user-group access and branding. New tenants no longer start with an automatic All Members group.
- Changed: Tenant Admin is simpler when adding further organizations and members. Creating an organization now includes optional group access in the same wizard, and inviting a user lets you set their role and groups up front.
- Changed: Tenant membership and organization access are now explicit. When you invite someone you choose their tenant role and user groups; you can manage a member’s groups and a group’s members from Tenant Admin. Assigning a group to an organization (including a shared organization) uses only the permission profiles allowed for that organization.
- Changed: Dashboard widgets now open the matching filtered device table when you click through (for example by grade or risk). Search, filters, sort and page are kept in the URL, so the browser Back button returns you to the previous view instead of resetting it. The same URL can be bookmarked or shared.
2026-08-20 (v1.18.0) - Platform
- Added: Configuration and Policy notifications can now be configured to alert only on specific rules.
2026-08-20 (v1.17.0) - Platform
- Changed: Internal improvements to device processing to support upcoming features. No change to existing behaviour.
2026-08-17 - Rule Set
- Fixed: Resolved an issue where some service objects would not correctly resolve when mapping attack surfaces.
2026-08-16 - Rule Set
- Fixed: Resolved an issue where a deny policy could incorrectly trigger some rules.
- Fixed: Resolved an issue where VIP Groups did not correctly resolve when evaluating firewall policies with VIPs.
- Fixed: Resolved an issue where licenses in an "expires_soon" state were being treated as expired.
2026-08-15 (v1.16.2) - Platform
- Fixed: The Enterprise SSO tenant admin UI now makes clear that enabling SSO requires a support ticket.
2026-08-12 - Rule Set
- Added: Rules for August monthly security advisories:
- FG-IR-26-161 (Stack Buffer Overflow in WAD): Config-aware — gated on explicit web proxy with SOCKS. Reported as not applicable when explicit web proxy is disabled, unsupported on the model, or enabled with SOCKS disabled, and rated Medium when SOCKS is enabled (unauthenticated code execution against the WAD daemon).
- FG-IR-26-162 (UI DoS Attack): Config-aware — gated on the admin GUI (HTTP/HTTPS). Reported as not applicable when the GUI is disabled, rated by GUI exposure (up to Medium when internet-facing; Low for private or limited untrusted reachability), and de-escalated when the GUI is restricted to trusted hosts (unauthenticated slow HTTP denial-of-service).
2026-08-11 (v1.16.1) - Platform
- Fixed: Enterprise SSO (SAML) settings were missing from tenant admin; they are now shown.
2026-08-11 (v1.16.0) - Platform
- Added: Enterprise SSO (SAML) — sign in with your company identity provider using SAML 2.0, with IdP group-to-user-group and role mappings applied on every login.
2026-07-26 (v1.15.0) - Platform
- Added: New Report: Monthly Summary — shows the current state of the Organization or Group, along with the major events and new security advisories over the last calendar month.
- Changed: New report styling — the appearance of reports has been updated with a simpler theme better suited to PDF/printed reports.
- Changed: The Dashboard has been updated with new widgets to show more information, including "Devices by Health Grade" and "ThreatSabre Connectivity". The previous three cards showing a breakdown of Devices by Peak Severity across Vulnerabilities, Configuration, and Lifecycle have been consolidated into a single card.
- Changed: The Agents page has been updated to show more information about the status of the agent and its sub-devices.
2026-07-26 (v1.15.0) - Platform
- Added: New Report: Monthly Summary — shows the current state of the Organization or Group, along with the major events and new security advisories over the last calendar month.
- Changed: New report styling — the appearance of reports has been updated with a simpler theme better suited to PDF/printed reports.
- Changed: The Dashboard has been updated with new widgets to show more information, including "Devices by Health Grade" and "ThreatSabre Connectivity". The previous three cards showing a breakdown of Devices by Peak Severity across Vulnerabilities, Configuration, and Lifecycle have been consolidated into a single card.
- Changed: The Agents page has been updated to show more information about the status of the agent and its sub-devices.
2026-07-13 (v1.14.3) - Platform
- Changed: Per-device Attack Surface is now shown on the Device Summary page.
- Changed: Added an Attack Surface information note to attack surface views explaining what it means and that it does not impact the device score. Where attack surface exposure is against best practice, a separate configuration rule is triggered.
- Changed: Improved the onboarding wizard — the Connect step is simplified with a single token panel and Quick Start install commands (with a softer wait/recheck instead of a hard timeout), so you can install the agent quickly without referring to documentation. Agent names are now validated strictly on create, and the Devices step adds a Status column and a "hide offline" filter.
- Changed: Along with ThreatSabre Agent v0.2.2, the platform now tracks online/offline status from FortiManager. Status appears in the onboarding wizard and inventory screen, and polling behaviour for offline devices is improved.
- Fixed: Offline device status could loop between discovered and rejected, logging each change.
- Fixed: deviceType was incorrectly updated, creating audit logs.
2026-07-18 (v0.2.2) - Agent
- Changed: When discovering FortiManager, the agent now reports the connected status of all devices; previously it included a device as long as it was a real device. The platform uses this detail to display connection status during onboarding and to control which devices are polled and when.
2026-07-17 (v1.0.2) - Agent Install Script
- Changed: Improved validation of the input token to avoid proceeding with the install on copy/paste errors.
- Fixed: Formatting issues on some terminals.
2026-07-15 - Rule Set
- Fixed: SD-WAN Zones were not correctly analysed when reviewing local-in-policy for Attack Surface.
2026-07-14 - Rule Set
- Added: Rules for July monthly security advisories:
- FG-IR-26-148 (Stack Buffer Overflow in Log Report): Config-aware — severity is driven by admin GUI (HTTP/HTTPS) exposure. It stays Medium where the GUI is reachable from untrusted networks, and de-escalates to Low when the GUI is restricted to trusted hosts or is fully covered by local-in virtual patching (exploitation also requires privileged admin access and defeating memory protections).
- FG-IR-26-150 (SSL-VPN Reflected XSS): Config-aware — gated on the agentless / web-mode SSL-VPN portal. Reported as not applicable when SSL-VPN is disabled, rated by portal exposure (up to Medium when public-facing), and de-escalated when the portal is fully protected by local-in virtual patching.
- FG-IR-26-151 (Path traversal in CLI command allows deletion of root file system): Statically de-escalated from Medium to Low due to the physical access plus authenticated (privileged) access requirement.
- FG-IR-26-152 (Header injection in Web Filter warning page): Left at the vendor's Low rating — exploitation requires a valid web filter override token plus user interaction, and no vendor workaround exists, so no configuration-based exception is applied.
- FG-IR-26-153 (Header injection in captive portal authentication form): Left at the vendor's Low rating — exploitation requires a man-in-the-middle position plus user interaction, so no configuration-based exception is applied.
- FG-IR-26-154 (Buffer overread in authd and wad daemon): Left at the vendor's Medium rating — the affected authentication/proxy surface can't be reliably determined from configuration, and exploitation requires an authenticated session.
2026-07-13 (v1.14.1) - Platform
- Added: Daily limit on the number of rescans per device (20), which resets at midnight UTC.
2026-07-11 (v1.14.0) - Platform
- Added: API Users (API Phase 1) — support for API token-based authentication. API users and tokens can be created and managed in the tenant management section (requires the Tenant Admin or Owner permission profile). Regular user groups can be assigned to API users to control org access and permissions. Currently this can be used against the internal API endpoints designed for the UI. The next phase will introduce documented, versioned API calls that won't change without API version control.
2026-07-10 - Rule Set
- Added: TS-CFG-XHIKK9 (IPsec PQC key exchange not configured) — checks whether IPsec VPN phase 1 settings use post-quantum hybrid key exchange (ADDKE).
- Added: TS-CFG-NYBXTT (Deprecated VPN cipher in use) — checks whether IPsec VPN tunnels use cryptographic algorithms below NIST transition requirements.
- Fixed: TS-CFG-AFH48P failed to read webfilter category IDs on FMG-based captures.
2026-07-01 - Rule Set
- Changed: Updated attack surface rules to improve the accuracy of reporting in certain circumstances.
2026-06-30 (v1.13.0) - Platform
- Added: Notifications system (beta) — you can now set up notifications for events such as a new vulnerability impacting your devices.
2026-06-22 - Rule Set
- Added: TS-CFG-CBXU7V (Fabric interface exposure exceeds recommended limits) — reports when a fabric interface is exposed to the public Internet.
- Added: TS-CFG-DPQ3F2 (SSL-VPN virtual patching) — reports when Virtual Patching is not enabled for SSL-VPN.
- Added: TS-CFG-EZCF6L (Admin SSH virtual patching) — reports when available Admin SSH access paths are not protected by Virtual Patching.
- Added: TS-CFG-XQCWF2 (Admin HTTPS virtual patching) — reports when available Admin HTTPS access paths are not protected by Virtual Patching.
- Added: TS-CFG-LVLFHV (HTTP Access enabled) — reports when Admin HTTP is enabled and not forwarding to HTTPS.
- Changed: TS-CFG-HRCMJD (Admin SSH exposure exceeds recommended limits) — now reports on exposure to all non-trusted networks; risk is now dynamic based on exposure.
- Changed: TS-CFG-NWGPFN (Admin GUI exposure exceeds recommended limits) — now reports on exposure to all non-trusted networks; risk is now dynamic based on exposure.
2026-06-22 (v0.2.1) - Agent
- Fixed: Issue with FortiManager v8.0 API responses, some API calls were getting dropped due to API changes
- Fixed: Issue where batch requests with large configs against slow FortiManager could time out. New commands and defaults added to address this issue.
- Changed: Default timeout for batched API calls against FortiManager is now 90 seconds (previously 10). This can now be configured by setting
FMG_BATCH_TIMEOUT_MSin agent.conf - Changed: FortiManager calls are now batched to a maximum of 12 API calls, previously unlimited. This can now be configured by setting
FMG_BATCH_MAX_CALLSin agent.conf
2026-06-08 (v1.12.0) - Platform
- Added: New Report: Recent Vulnerability Summary — shows recent vulnerabilities and, if they've affected any devices, summarises the impact, so you can quickly see how new vulnerabilities affect your environment and prioritise actions.
- Added: New Report: Device Report Card — a PDF version of the per-device Device Report Card.
- Changed: Minor updates to the display of the per-device Device Report Card.
2026-06-05 (v1.11.0) - Platform
- Added: New Report: Vulnerability Impact Summary — shows all the vulnerabilities impacting your environment with a summary of impacted devices and associated risk.
2026-05-26 (v1.10.0) - Platform
- Added: New Device Report Card feature.
- Added: New device scoring/grading system. This introduces a more robust system for ranking devices when sorting the highest priority devices for the dashboard.
- Changed: Several UI tweaks to support the new device grading system and report card feature.
2026-05-15 - Processing
- Fixed: Reworked public/private IP logic to better deal with non-RFC 1918 addressing which is non routable on the public internet. This resolves some isses when test addressing was used on interfaces and would lead to an incorrect result in several rules. This also required the "Full Internet" threshhold to be reduced as the total number of IP's condsidered public wes reduced.
2026-05-10 (v1.9.4) - Platform
- Fixed: Exceptions were not parsed when displaying the Vulnerabilities or Configuration Issues views; these views now display correctly, taking exceptions into consideration.
- Fixed: You can now search for "Organization" in the Applies To options when creating an exception.
- Changed: Minor changes to how the Vulnerabilities and Configuration Issues views are displayed.
- Changed: Removed the "Send Broadcast" feature from notifications; this capability will now only be used for sending system notifications, not user-to-user notifications.
2026-05-04 (v1.9.2) - Platform
- Fixed: Onboarding FortiOS 6.2, 6.4 and 7.0 devices via FortiManager failed; these versions can now be onboarded successfully.
2026-04-26 (v1.9.0) - Platform
- Added: Tenant overviews, Phase 1 — overview of all orgs under a tenant. Initial views include a dashboard overview and a vulnerability view that shows how a vulnerability affects devices across all organisations in a tenant.
- Added: Device Onboarding Wizard — a new mode for onboarding devices that guides you through the process and provides feedback on what is happening and what to do next.
- Added: The Alerts page now has advanced filtering options.
- Changed: Tenant/org selection has moved to the left-hand menu.
- Changed: Tenant management features have moved to the tenant overview section.
- Changed: Data tables now default to 50 items per page and can be expanded up to 1,000 items per page.
- Changed: The Attack Surface page now sorts by overall severity.
- Fixed: Several cache invalidation issues that forced a screen refresh to see information you had just added. Notably, this affected:
- Expiring exceptions from the exception screen
- Expiring exceptions, then viewing the dashboard
- Creating a group, then trying to select it in the group selector
- Fixed: When viewing exceptions, only the issue ID was shown; the full description is now shown along with the ID.
- Fixed: When creating an exception for a group, the group ID was shown; the group name is now displayed.
- Fixed: The Vulnerability Detail page listed non-onboarded devices, which had no collected detail and only showed a warning. The page now only lists fully onboarded devices.
2026-04-19 (v1.0.1) - Agent Install Script
- Added: ARM64 support, tested on Raspberry Pi 4 with Raspberry Pi OS.
- Fixed: Install script no longer fails on minimal Debian LXC containers.
2026-04-11 (v1.8.0) - Platform
- Added: New vulnerability report.
- Added: Filtering capability for the Device History page.
- Changed: Vulnerability Detail page now displays devices that are not running affected versions.
- Changed: Improved UI display of alerts.
- Fixed: Alerts now correctly display both the name and description of issues.
2026-04-03 (v1.7.0) - Platform
- Added: Rule information widget - when looking at rules in a device summary there is now a book icon for each rule, clicking this will show information about the rule included what the rule is detected and why it matters.
2026-03-30 (v1.6.0) - Platform
- Added: FortiManager Cloud support — new agent device type supported (requires ThreatSabre Agent v0.2.0 or greater).
- Added: GUI support for configuring Trusted Networks. Trusted Networks are used when evaluating Attack Surface and Vulnerability rules.
2026-03-30 (v0.2.0) - Agent
- Added: FortiManager Cloud support.
2026-03-19 (v1.5.1) - Platform
- Fixed: After the v1.5.0 update the Group Selector was not correclty populating. Group Selector now correctly populates with available groups rather than being empty.
- Fixed: After the v1.5.0 update the datepicker when creating exceptions didn't let you select a data, this was due to a update in the UI framework (Radix UI). This is now fixed.
2026-03-15 (v1.5.0) - Platform
- Added: Multi-Tenancy — organize and manage multiple organisations from a single account.
- Changed: Badges now have a rounded style while Buttons have a square style to make these elements easier to distinguish at a glance.
- Changed: Options unavailable due to insufficient permissions are now clearly indicated.
2026-02-06 (v0.3.1) - Platform
- Changed: Vulnerabilities that affect the entire device are now displayed for VDOMs. Exposure details will be hidden when viewing or running a report on a VDOM to prevent information leaking from other VDOMs on the device. The message displayed above vulnerabilities in the VDOM view has been updated to reflect this.
- Added: Device count is now shown on the "Device Groups" page for each group.
- Added: Minimizing the sidebars will now collapse them to icons, allowing you to still navigate the site while using less screen space.
- Added: You can now add device aliases to give devices a more meaningful name than the hostname and VDOM name currently displayed. This can be set on the Device Summary page and will be used throughout the application and in reports.
- Added: When onboarding devices you can now select a group for the onboarded devices at the same time.
- Added: You can now onboard multiple agent devices at once by importing a CSV file.
- Fixed: The incorrect failed-authentication message that briefly appeared during login will no longer be displayed.
- Fixed: When applying a group filter to the dashboard, the alerts section will now reflect that group. (Note: group filters still do not apply to the dedicated alerts page. This is a known issue.)
- Fixed: Invites are now sent and processed correctly.
- Fixed: Minor changes to rule set.
2026-01-27
- Added: Support for many attack surface types (RADIUS Accounting, TELNET Interface, BGP Interface, FGFM Interface, Security Fabric Connection, SNMP Interface, FortiToken Mobile Interface, IPSEC VPN Interface).
- Changed: In the Add Agent Device form, renamed "hostname" to "Agent Device URL".
- Changed: In the dashboard, renamed "Virtual Devices" to "VDOMs" for clarity.
- Fixed: Support information for PAYG-licensed devices (AWS, Azure, GCP, etc.).
- Fixed: Onboarding issue where multiple devices with VDOMs discovered at the same time from a FortiGate agent device could have VDOMs assigned to the wrong parent device.
- Fixed: Minor tweaks to rules.
2026-01-22
- Added: Reports — two reports are now available, with more reports and widgets to come soon.
- Added: Vulnerability sorting on the Device Summary page — you can now sort vulnerabilities by vendor severity, risk, or ID. (Next update will include public disclosure date as well.)
- Added: Device Scan Status widget on the Device Summary page — shows last polled time, status, and allows rescan directly from this page.
- Fixed: The incorrect End of Order and End of Engineering support dates were being shown on the Device Summary page.
- Fixed: Exceptions were not applying correctly when assigned to device groups and under some circumstances would not reflect correctly in the dashboard or device list views.
- Fixed: Several small UI updates and fixes.