Skip to content

Release Notes - New Features & Bug Fixes

πŸ“§ Email Security

✨ Enhancement

  • Mark the Email Security Connector as generally available. The connector's operations and OCSF objects are now GA, and its API reference no longer carries the in-development label.

πŸŽ“ Security Awareness

✨ Enhancement

  • Add training_campaign_uid to the Synqly OCSF 1.8.0 enrollment object, identifying the training campaign an enrollment belongs to, and populate it in the KnowBe4 Security Awareness Training (KSAT) provider. The attribute is set only when the enrollment is not already nested inside a training campaign, such as a user's campaign enrollments.

πŸ” Vulnerability Management

✨ Enhancement

  • Add a finding.title filter (eq, in) to CrowdStrike Spotlight Query Findings for looking up findings by CVE ID.

  • Make Qualys query_assets and query_findings do a bounded amount of work per request and return a resumable cursor. Both operations filter client-side, so on a large tenant with a selective filter a single request could previously outrun the request deadline, lose all progress, and retry indefinitely. Each request now fetches one Qualys page and returns whatever survives filtering β€” possibly fewer than limit, or none β€” with a cursor that resumes exactly where it stopped. If the deadline is reached mid-page, query_findings returns the partial results and a resumable cursor rather than an error. Cursors issued before this release continue to work.

πŸ› Bug Fix

  • Fix CrowdStrike Spotlight findings using the CVE as finding.uid, which gave every host with the same CVE the same finding identity. finding.uid is now the Spotlight vulnerability-on-host instance ID. This is a breaking change: finding.uid queries that pass a CVE no longer match β€” filter on finding.title instead. A finding.uid[eq] or finding.uid[in] lookup cannot be combined with other filters, returns no cursor, honors limit, and accepts at most 1000 IDs.

  • Fix several Qualys pagination defects: query_findings restarting at the first page on every resumed request and returning duplicate or skipped rows, query_assets re-requesting the same page indefinitely when a hostname or MAC filter matched nothing on it, and hostname and MAC filters being silently dropped on resumed pages so unfiltered devices were returned.

  • Reduce Qualys query_findings memory use on large tenants by decoding detection pages as they stream in rather than buffering each page in full first.

  • Set Horizon3 NodeZero vulnerabilities[].is_exploit_available directly from Horizon3's own has_exploit flag, including false, rather than inferring it from CISA KEV status. Last week's change populated the field only for KEV-listed findings, so most findings with a known exploit β€” including every H3-* advisory β€” carried no value. KEV status remains available independently on xattributes.cisa_kev.

  • Restrict Horizon3 NodeZero finding.supporting_data[].src_url to the screenshot image link on query_findings. It previously fell back to the URL of the page NodeZero captured, often a customer-internal host, which consumers downloading src_url could not tell apart from an image. The captured page URL now appears on target_url.


πŸ‘€ Identity Management

πŸ› Bug Fix

  • Fix Okta identity_query_audit_log scheduled operations failing every run once they had caught up. Without an upper bound, Okta treats a System Log query as an endless polling request whose empty pages always carry a next link, so the run was ended as making no progress. Every System Log request now carries an upper bound β€” the requested end time, or the current time if none was given β€”, so a caught-up pull ends normally and the next run resumes from its checkpoint. Okta rate limiting (429) is now retried after Okta's rate limit reset, rather than reported as a 502 and resent immediately.

  • Fix Microsoft Entra ID identity_query_audit_log failing with a Graph 400 when the requested start time is older than Graph's roughly 30-day audit log retention. A start time past retention is now moved up to the retention boundary, including in cursors persisted before this release, and the adjustment is reported as a problem message on the response. A range that ends before retention returns an empty page.


πŸ“Š SIEM & Sink

✨ Enhancement

  • Answer explicitly ordered Google SecOps query_events requests whose time window exceeds Google's 1,000,000-row search limit, instead of returning a 400 asking the caller to narrow the range. Synqly splits the window into time slices that each fit under the limit and walks them in sort order behind a single cursor. A window that cannot be split still returns a 400, now with a message saying why. Passthrough queries with an explicit order over the limit now return a partial result with a truncation problem rather than failing, and that problem no longer implies the retained rows are the first N in the requested order.

πŸ› Bug Fix

  • Default SIEM query_events to newest first (time descending) when order is omitted, and treat a bare order=time as descending. This matches what every SIEM provider that supports ordering already returned; the API reference previously documented ascending as the default. It also fixes a malformed sort being sent to CrowdStrike Falcon LogScale when no direction was given.

  • Retry transient 5xx errors from Rapid7 during log search pagination instead of failing the whole query. Any status other than 200 or 202 previously ended a long pagination run immediately, even when a retry would have succeeded.


βš™οΈ Core

✨ Enhancement

  • Validate AWS STS role configuration when it is declared. A malformed role ARN, an external ID, session name, or duration outside what STS accepts, or an endpoint that is not an absolute http(s) URL now fails with an error naming the field, rather than as a 400 from AWS on the first sync.

  • Report the duplicated field value when adding an organization member fails because the username is already in use, instead of only the member ID.

πŸ› Bug Fix

  • Report a refused connection to a provider as 502 instead of 400, matching how dropped and reset connections are already reported. The caller's request was not at fault. The problem type integration/connectivity/connection-refused is unchanged. Because 5xx responses are retryable by convention, SDK clients using default retry behavior will now retry these requests.

  • Fix scheduled operations getting stuck re-delivering the same records every run. Sub-second cursors were sent to providers truncated to whole seconds, so the newest record was returned again on every run and the cursor never advanced. Separately, when a schedule's cursor field never changes β€” for example, findings ordered by finding.first_seen_time on a stable fleet β€” each run re-delivered the whole data set. Cursors now keep their full precision, and a schedule that delivers records without advancing its cursor has its next run pushed out to 12 hours rather than repeating a full pull every interval.

  • Preserve a provider's original HTTP status and error details when errors are passed up through the engine. Several code paths re-created errors from their message text, which discarded the status and could produce misleading error responses.

  • Report a provider response that breaks off mid-body as a failure instead of an empty successful result, and strip credentials embedded in request URLs β€” such as API keys passed as query parameters β€” from error messages.

  • Reduce engine memory use by retaining provider response bodies only on requests that use a meta function that reads them, such as api/response.

πŸ›‘οΈ Security Improvements

  • Restrict credential PATCH requests to a defined set of JSON Patch shapes: the add, remove, and replace operations, targeting /name, /fullname, /expires, or a /config field. The copy, move, and test operations, and any other path, are now rejected with a 400. This closes a path through which an authorized user, using a valid organizational token, could expose stored secret material using the patch operation.

  • Fix authorization gaps in credential retrieval. The credential lookup endpoint and retrieval of a credential by UUID now check that the calling token is authorized for that credential, rather than accepting any valid organization token.

  • Fix token scoping so a token restricted to specific accounts cannot mint a token with broader access. POST /v1/tokens, token refresh, and token reset now require every requested account ID to be within the caller's own scope, and an account-scoped caller can no longer request an environment or label scope. A caller scoped to several accounts can now mint a token for a subset of them, which was previously rejected.


πŸ“š SDK Releases

Latest Versions

  • Released Synqly SDK versions: 2.0.67, 2.0.68, 2.0.69, 2.0.70

🚒 Synqly Embedded

✨ Enhancement

  • Update the billing export guide to lead with a kubectl port-forward to the embedded service and the organization token logon, since almost all Embedded customers run on Kubernetes via Helm. Username and password logon moves to its own section, and the guide now states the export window of the 12 most recent completed months.

Latest Release: v0.1.159

  • Service Image Tag: embedded-2026.09.28
  • Service Image Tag (NO FIPS): embedded-2026.09.28-no-fips
  • Release Date: September 28, 2026