Skip to content

Parallels Awingu introduces version 5.5

On June 21st 2023, we released Parallels Awingu 5.5!. The latest version of our secure unified workspace offers enhanced security options and other innovations that further enrich your investment.

What is available in this release and why should you upgrade to Parallels Awingu 5.5?

The key features delivered in Parallels Awingu 5.5 focus on security and maintenance.

New certificate settings for external HTTPS requests

Starting with Parallels Awingu 5.5, customers are now able to have granular control on the certificates used for external HTTPS requests used by the following features: audit logging, reverse proxied web applications, WebDAV with SSL, and SSO metadata.

External requests can now be granularly controlled by verifying identity and only allowing trusted services, or deliberately choosing to allow the connection to an unverified/untrusted service. In addition, administrators can now add certificates for identity verification.

Organizations that rely on internal certificates issued by internal certificate authorities or self-signed certificates can use such certificates for the HTTPS requests to external services. In addition, administrators can manage those requests either by allowing or disallowing external HTTP requests to internal services.

Maintenance

As with most minor releases, bug fixes are included in this release. If you previously reported issues to Parallels Awingu technical support that were deemed to be bugs, they have likely been remedied as part of this release. Find an overview of all changes in the Parallels Awingu 5.5 release notes.

Upgrading to Parallels Awingu 5.5

Parallels Awingu 5.3 and earlier are no longer supported as of this update, so it is critical that you upgrade earlier versions immediately. Upgrading is a straightforward process and is performed right within the admin console. Consult the release notes for instructions on upgrading to Parallels Awingu 5.5.

Parallels Awingu 5.5 is a minor release, and product development is underway for an upcoming major release that will include a variety of enhancements. For further details about Parallels Awingu 5.5, please consult the admin guide.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Lowering your energy costs – ESET’s contribution to greener IT practices

Running a business has become more costly since inflation and the rise of energy prices facilitated a new age of cost-saving measures so businesses could still keep their profits to a certain degree.

This all is underlined by a continuous move to Cloud-backed solutions, which should help companies with lowering their infrastructural, network, staffing, and location costs (for those hosting their own data centers, they can take up a lot of space, as well as use a lot of energy).

But the consideration should not only be placed towards lowering business costs, as the current trends suggest a shift toward greener IT practices in general, which in themselves can at first sight be seen as a more costly move; however, the truth is elsewhere.

How green IT improves business sustainability

Under the term Green IT, or green computing, we mean the practice of using environmentally sustainable design, manufacturing, use and disposal of computers, chips and other technology to limit their harmful impact on the environment. This includes a planned reduction in carbon emissions, and energy demands, promoting sustainability through the use of renewable materials and a circular economy.

For businesses, this means approving practices such as potentially outsourcing certain parts of their company needs, such as IT, as in that case the costs incurred for, let’s say, data center maintenance, goes to the other company. However, the effectiveness of the business should not be negatively impacted, as such a transaction serves two purposes – to make the company more effective by delegating IT tasks to professionals (such as network cybersecurity), it also lowers the businesses energy footprint, reducing its direct impact on the environment.

Practically, it also creates cost savings. Feel free to check out ESET’s cloud management cost calculator, which should convince any business about the benefits of moving from on-premises to cloud-based solutions.

With the saved money, businesses will be freer to invest in further practices to comply with future laws calling for further green transitional measures, such as those indicated by the European Union, or certificates requiring sound environment-friendly practices.

For enterprises, the green transition also changes the makeup of their supply-chains

Outsourcing is just one way how to change a company’s supply chain, but as more and more companies will start to move towards greener practices, the logistical side of decision-making will require rethinking contemporary business practices.

Enterprises have also started to lay off people due to cost-cutting measures, which makes sense; a person’s salary per year can, depending on their role, be quite large, but so can their responsibilities. As a consequence, the enterprise can inherently lose brain-power and skilled workers, which they would need to rehire or redistribute their work, creating more internal pressure within the company itself, lowering its capacity to respond to a variety of issues that might arise, IT-related incidents including.

With green practices, costs can be reduced in a way, in which the company does not lose its edge. Suppose that instead of firing employees, they could invest in more remote-work practices, lowering the firm’s energy and building demands, saving on energy bills, rents, parking, and more.

One easy step toward green practices is to turn devices and things off. Equipment such as printers, ACs, Monitors, and lights, should be powered down when not used.  Sales and marketing departments have a role to play in green IT, too. Picking equipment that will last and consumes the least amount of energy necessary for the task to be performed are both ways to reduce the carbon footprint of IT. For example, remote workers tend to use notebooks, which use less energy than laptops, and laptops use less energy than desktop computers.

Just by focusing on trying to procure supply chain companies based on their environmental practices and protections goes a long way toward transitioning an enterprise toward increased sustainability, cascading best practices down the chain.

Going further, your company could also get a certificate, according to the ISO 14001 standard, which demarcates and maps out a framework that a company or organization can follow to set up an effective environmental management system.  Designed for any organization, regardless of its activity or sector, it can provide assurance to company management and employees as well as external stakeholders that environmental impact is being measured and improved.

How can ESET factor in green decision-making

At ESET, our products are continuously improved, focusing on areas deemed important for current practices. As far as the environment is concerned, ESET offers cloud-based services for businesses through its ESET PROTECT Platform, which helps reduce costs as there is no additional need for hardware, software, app patching, or personnel.

With our enterprise-focused offerings, such as ESET PROTECT Elite and MDR, we enable businesses with resource allocation, as our MDR solutions can help skilled IT personnel already overwhelmed with other tasks manage their security, reducing risk and allowing for business continuity, making business complexity more manageable. All in all, ESET, with its 30 years of independent cybersecurity operations worldwide, has huge experience in protecting clients across all sectors – and very specific expertise in a range of industries and verticals.

Using ESET solutions allows you to leverage that experience, protecting the progress required by the green transition, for a greener and more sustainable future.\

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET announces significant updates for ESET PROTECT Platform to help businesses keep ahead of attackers

The addition of Vulnerability and Patch Management powered by OPSWAT, enables businesses to tighten their defenses

BRATISLAVA, June 19, 2023 —  ESET, a global leader in cybersecurity, today announces the upcoming availability of a significant enhancement to its unified cybersecurity platform, ESET PROTECT. The enhancement is designed to address both current and future digital security challenges for businesses worldwide. ESET has partnered with OPSWAT, a global leader in IT, OT and ICS critical infrastructure cybersecurity solutions to bring integrated vulnerability and patch management into the ESET PROTECT Platform. ESET Vulnerability and Patch Management has been added to existing ESET PROTECT Complete along with a brand-new tier – ESET PROTECT Elite – to better safeguard small and midsize businesses (SMBs) struggling to keep up with a constantly evolving threat landscape and ensure their systems are correctly patched.*

With centralized management from the ESET PROTECT Cloud console, organizations can easily assess security threats and manage patches across the entire network, ensuring timely detection and remediation of the latest zero-day vulnerabilities. Automated scanning and a wide range of filtering options enable organizations to quickly identify and focus on the security issues that mean the most to them. Further, with automatic and manual patching options, businesses can ensure that their endpoints are updated with the latest security patches in a timely manner.

“Due to the inefficiencies of legacy solutions, many SMBs struggle with managing patches and updates across their entire network. This leaves their endpoints open to attack. Plus, they find it difficult to identify and prioritize vulnerabilities based on severity,” comments Michal Jankech, Vice President of SMB and MSP Segment, ESET. “SMBs want an easy-to-use solution that will keep them safe. The customizable patching policies in ESET Vulnerability and Patch Management give businesses of all sizes flexibility and control so that their endpoints can be optimally patched promptly. This helps them minimize the risk of attack and ensures they can adhere to increasingly stringent cybersecurity insurance or regulatory requirements, plus meet the standard required for various ISO certifications.”

ESET Vulnerability and Patch Management scans thousands of popular applications, such as Adobe Acrobat, Mozilla Firefox, and Zoom Client, for over 35,000 common vulnerabilities and exposures (CVEs). These automated scans can be scheduled using fully customizable vulnerability exception settings. Vulnerabilities can be filtered and prioritized based on exposure score, severity, and score over time. Through the ESET PROTECT Platform’s cloud-based console, businesses can raise reports on the most vulnerable software and affected devices. It boasts multi-language support and only a light demand on IT infrastructure.

ESET Vulnerability and Patch Management provides a constantly evolving inventory of patches with patch name, version of the app, CVE, patch severity/importance, and affected applications. Businesses can launch immediate updates and begin patching via customizable options or manually when a patch has been identified. They can simplify the patching process further by prioritizing critical assets and scheduling the remainder to off-peak times to avoid disruption. Organizations can take advantage of the Vulnerability and Patch Management multitenancy functionality to enjoy full visibility over the entire network, yet be focused on a dedicated area.

ESET’s unified cybersecurity platform, ESET PROTECT, is a single-pane-of-glass cloud console that provides centralized visibility, management, and insight. The ESET PROTECT Platform integrates balanced breach prevention, detection, and response capabilities with the company’s industry-leading managed and professional services and threat intelligence. It is simple, modular, adaptable, and continuously innovated. With the launch of ESET PROTECT Elite, there are now five subscription tiers to the ESET PROTECT Platform for businesses of all sizes:

  • ESET PROTECT Entry – an entry-level solution with competitive pricing that includes endpoint protection, server security, and the ESET PROTECT Cloud console.
  • ESET PROTECT Advanced – providing first-class endpoint protection with advanced threat defense technology and full disk encryption.
  • ESET PROTECT Complete – includes the new ESET Vulnerability and Patch Management capability, cloud application protection, and mail security to minimize cyber risks.
  • New ESET PROTECT Elite – provides increased visibility and decreased cyber risks, ESET Vulnerability and Patch Management, ESET’s native extended detection and response (XDR) capability, plus robust multifactor authentication.
  • ESET PROTECT MDR – an enterprise-grade solution that provides complete cyber risk management, robust threat hunting, and world-class ESET expertise on call. ESET PROTECT MDR combines the capabilities of the ESET PROTECT Elite tier with ESET managed security and professional services.

“As cyberattacks keep evolving and the industry becomes increasingly complex, our enterprise-grade offerings have transitioned to reflect changing business needs and a transitioning threat landscape,” adds Jankech. “Businesses of all sizes are increasingly finding it difficult to detect and patch vulnerabilities promptly to keep ahead of the bad guys. We are here to help. With the launch of ESET Vulnerability and Patch Management, we provide a pathway to swift remediation, helping keep disruption, and costs, down to a minimum for businesses.”

“We’re excited about this new step in our longstanding partnership with ESET. They’ve demonstrated consistent leadership in delivering best-of-breed security to the SMB market. Our endpoint technology helps protect over 150 million endpoints worldwide through our enterprise partners. ESET is a perfect partner to leverage our technology in the SMB market” commented Chad Loeven, OPSWAT’s Vice President of Business Development.

*For ESET end users this functionality will be technically enabled in late July 2023.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

June 2023: What’s New?

“What’s New?” is a series of blog posts covering recent changes to Comet in more detail. This article covers the latest changes in Comet Voyager over June 2023. 

There were six Comet software releases during June – two in our quarterly 23.5.x Thebe release series, plus four releases in the 23.6.x Voyager release series.

Policy-linked Protected Items

Comet has a comprehensive Policy system that allows you to apply rules to entire sets of customers at a time, such as restricting their ability to open the desktop app or restricting what features and settings can be used.

One of the existing Policy options allowed you to create a Protected Item that would be applied by default to all new devices that register in the account. However, it was limited to when the device was registered for the first time, it only defined the default settings, and after that the Protected Item could drift from what was configured in the policy. Having a default value that can then change is an important use case, but over time, we heard feedback that people would like these default Protected Items to remain tied to the policy version. In Comet 23.6.0, we made that possible.

You can choose whether the Policy Protected Item applies only for new devices, or if it remains linked to the policy after creation. This allows you to configure a Protected Item for a specific application, file-path, or integration target; apply it by default to all users of the Policy; and still be able to change those settings centrally for all users of that policy.

This was a highly popular request on our Feature Voting page. Thank you to all the partners who shared their support for this feature. If you haven’t seen this system before, the Feature Voting system allows you to upvote existing requests, raise new requests, discuss features with other Comet partners, and get notified when a change happens in the product. We look at this system often to help guide the priority of new development.

Extended admin permission options

As an administrator, when configuring permissions for other administrator accounts, additional options are now available.

These new options allow you restrict the capabilities of other administrators. This is intended for the use case of tenant administrators, or limited-permission administrators of a shared Comet Server. The use cases are varied but are often from the perspective of restricting the visibility of the Comet branding for white-label purposes.

  • You can hide the Server History and Server Info widgets from the homepage, including Comet’s version numbers and update information. This simplifies the main screen for the limited-permission administrators who would be unable to act upon this information;
  • You can enforce that the target administrator is unable to create new Storage Vaults via Storage Templates or via custom storage; and
  • You can filter and restrict which cloud storage providers are available for these limited-permission administrators to use.

This work was also inspired from our Feature Voting system. Thanks to everyone for your patience as we combined several separate requests to refine down the essential requirements for this use case.

These features are also available in the Comet Server API and in our latest SDK releases for PHP, Ruby, Javascript / Typescript, Go, and C# / .NET.

New minimum system requirements for macOS

From Comet Backup 23.6.3 onwards, your customers must have macOS 10.13 High Sierra (2017) or later to continue running new versions of Comet Backup.

If your customers are still using macOS 10.11 El Capitan (2015) or 10.12 Sierra (2016), the last releases that can be run on these older versions of macOS are the Comet 23.5.x Thebe series, or 23.6.2 Voyager. These versions of macOS are no longer receiving security updates and we would recommend that all end-users upgrade if possible.

There is no change to Comet Server’s minimum OS requirements as we do not offer Comet Server on macOS. It is safe to use the bulk deployment system in Comet Server to continue deploying software updates to all macOS customers – the affected users will skip the install and remain on their currently installed version of Comet Backup.

We last upgraded the minimum macOS version back in September 2022. We expect to be able to keep the 10.13 baseline for a longer period of time.

“Run when PC starts” now includes Sleep

Comet has long supported a “Run when PC starts” option in the job schedule settings. This option is highly useful for laptops that are often offline or sleeping, where a regularly scheduled backup job is unlikely to occur at the odd moments when the device is online. By running a backup job immediately when the PC boots, the device is more likely to complete a successful backup job.

However, recent versions of Windows have expanded how widely “Fast Startup” is applied across different PCs, to the point that a Windows laptop will often not restart, but only simulate a restart via hibernation-related techniques. This has a negative effect on the “Run when PC starts” option as it was only triggered via a full restart, which is not the default behavior in current versions of Windows.

As a result, we have extended the “Run when PC starts” option to count waking up from sleep as “starting the PC”. This is more in keeping with the behavior of current-generation laptop computers and it should make the option work as-expected in more cases. Compared to the old behavior, it is likely that additional backup jobs could be run unexpectedly, but our expectation is that this is not a bad thing, and the result will be more reliable overall.

Comet Server web interface enhancements

The 23.5 Thebe release last month included a major redesign of the Comet Server web interface. We’ve continued to build upon this throughout June in the 23.6.x Voyager series with many enhancements for server operators.

One area of focus was on ease-of-use. When configuring a Protected Item for Application Aware Writer, Hyper-V, or Microsoft Exchange, you can now use the top-right button to remotely browse the customer’s PC to select items for backup. Compared to finding individual virtual machine IDs, this is a significant improvement to the ease-of-use of this feature.

Additionally, when saving changes in the Settings page, the page will now intelligently wait for settings to be applied, instead of leaving you at a web browser refresh screen. This makes for a much more intuitive and user-friendly experience. The Comet Server web interface will now also warn you more clearly about invalid bucket names for cloud storage.

There was also a particular focus on performance enhancements for the Comet Server web interface. Loading the web interface should be snappier and with fewer loading spinners, as the necessary information is able to be loaded in parallel, as well as reused from previous lookups. The Quick Search area is now faster and has a new design style. When remotely controlling a connected device to start a restore job, the restore job will reuse information known by the web interface instead of recalculating it, resulting in a restore job that starts faster and finishes faster.

A third area of focus throughout the month was on fixing known issues that have been reported. Thank you to all partners who reported issues – the latest 23.5.x and 23.6.x updates should have addressed all the web interface issues raised to this point.

CometCon 2023

Following on from last year’s successful event, we hosted another week-long meetup with Comet team members from all over the country. With a strong focus on technical talks, networking, and a special coffee-tasting event, everyone had a great week! I’d like to extend a special thank you to our guest speakers!

That’s all for this month – the blog will return next month with more news about all the latest changes to Comet.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

runZero 3.9: Set measurable goals, find urgent issues, and preview of Attack Surface Management!

What’s new with runZero 3.9? 

Goals!

runZero Professional and Enterprise customers can now use Goals to set time-bound and query driven targets that are customizable to what matters most to your team. Huge thanks to all of the folks who provided feedback on this feature during the public preview phase.

Goals can be created based on any queryable attribute within runZero. This includes standard fields like operating system versions, end-of-life status, exposed services and protocols, as well as new fields like asset risk, criticality, and ownership. If you can query for it in runZero, it can now be a Goal!

Common goals include:

  • Managing expiring TLS certificates
  • Tracking end-of-life devices and operating systems
  • Remediating Critical Risk on assets within a set timeframe
  • Keeping open management services off of your public facing assets

Attack Surface Management preview

Attack Surface Management (ASM) is the process of discovering, classifying, and assessing the risks across different surfaces of your IT infrastructure. Although runZero supports ASM efforts through external scanning, internal RFC 1918 discovery, and integrations, the platform did not offer a unified workflow or dashboard until now.

The preview version of ASM provides a simple path to define different attack surfaces throughout your organization, providing an overview of risk and coverage along with several custom goals to monitor and communicate your progress. This feature will be in preview until August and will launch publicly as part of runZero 4.0.

If you are a runZero Enterprise customer and are interested in reviewing this feature and providing feedback, please reach out to your CSE or or runZero Support. Participants will be asked to complete a short feedback form after reviewing the feature. You can find additional information about our preview program in the Preview Program FAQ.

Rapid Responses

The runZero research team has shared three new Rapid Response posts since 3.8. These posts cover critical, actively exploited vulnerabilities:

Protocol improvements

runZero now supports the InterMapper and Room Alert protocols, as well as legacy protocols such as time, daytime, chargen, and quote of the day.

runZero’s printer support has been improved, enabling protocol detection on ports normally associated with direct print services. This change allows for more accurate detection of Elastic Search, Neo4J, and LogStash services.

In addition to the changes above, runZero now consistently normalizes the AirPlay protocol fields and gathers even more details using the DNS protocol.

Fingerprint improvements

New fingerprints were added for products by Allen-Bradley, Alma, Amazon, Apple, Avaya, Avigilon, Avocent, Axess TMC, Bodot, Bond, Canon, Canonical, Cisco, ComNet, Dell, Digital Loggers, Eaton, Epson, F5, Fedora, FreeBSD, Fortinet, Google, Hanwha Techwin, Honeywell, HP, HPE, IBM, Johnson Controls, Konica Minolta, LG, Lidarr.Audio, LinkTap, Microsoft, MikroTik, Moxa, NetBSD, Oracle, Panasonic, Philips, Pioneer, Poly, Progress Software, Proxim Wireless, Proxmox, Radwin, Red Hat, RetailNext, Riverbed, Rocky, Samsung, Schneider Electric, Scientific, ScreenBeam, Siemens, Sierra Wireless, SMC Networks, Sony, Standard Networks, SUSE, Tait Communications, Traficon, Tulip, VivoTek, Western Digital, Vasion, Xiaomi, ZeeVee, and ZKTeco.

See runZero 3.9 in action

Release notes

The runZero 3.9 release includes a rollup of all the 3.8.x updates, which includes all of the following features, improvements, and updates.

New features

  • runZero goals are now generally available. With runZero goals, users are able to create and monitor progress toward achieving security initiatives.
  • Improved the goal progress chart display to work in various browser sizes.
  • Goals now shows a pending calculation banner when goal metrics have not been calculated yet.
  • Added source_count and custom_integration_count as searchable fields.
  • Saved queries can now be created for tasks.
  • The search keyword recur_last_task_status is now supported on the task pages.
  • Improved the display of dashboard charts so that no partial rows, other than the last row, are visible to the user regardless of the number of charts displayed.
  • Improved fingerprinting of Fortinet device firmware.
  • Optimized database utilization and improved performance.

Product improvements

  • Non-runZero asset sources can now be removed from assets via the asset details or asset inventory pages.
  • Equivalent emails are now accepted for email updates.
  • Dashboard cards for Asset Source and Custom Integrations should now correctly show only the top 10 counts for each, with a View more link added.
  • A warning is now displayed if a Query is not attached to a Goal.
  • Users with Viewer permission can now see and use the Sites page.
  • Improved reliability of scans so they should stall less frequently.
  • The activation email should display properly in a broader range of email clients.
  • Improved operating system fingerprinting via SNMP Installed Software listing.
  • The status indicator in the explorer datagrid now has text describing the status.
  • External Asset Report Include screenshots toggle now requires that Include asset details is checked.
  • External Asset Report now hides the Top certificate authorities section if Include TLS certificate details is not checked.
  • Outlier calculations have been adjusted for performance and now include the TLS stack.
  • Event rules that result in asset modifications now complete faster.
  • The Npcap driver has been updated to version 1.75.
  • Improved device type identification of Windows Server assets.

Integration improvements

  • Improved SentinelOne matching to improve asset merging.
  • AWS credential validation now always shows the results for each service.

New vulnerability queries

  • Hardware: End-of-Life Cisco Small Business Switches
  • Policy: Sun Solaris sadmind RPC service
  • Policy: HashiCorp Consul (unauthenticated)
  • Policy: Cisco Smart Install service
  • Policy: CNCF etcd v2 (unauthenticated)
  • Unpatched: Click Modular Router shell (unauthenticated)
  • Unpatched: HID VertX/Edge controllers vulnerable to command_blink_on command execution

Bug fixes

  • A bug causing Cisco 8xx Industrial Routers as well as Catalyst 94xx/95xx switches to be incorrectly merged has been fixed.
  • A bug where the autocomplete drop down would not always appear on top of other elements has been resolved.
  • A bug where integration sources in dashboard views are displayed as IDs instead of names has been resolved.
  • A bug where data grid search text would propagate to other data grids has been resolved.
  • A bug causing some text inputs to display an autocomplete user experience when it was not intended was resolved.
  • A bug that could allow merging AWS, Azure, and GCP assets has been resolved.
  • A bug which omitted some SNMPv3 scan attributes has been resolved.
  • A bug which caused some project creations to return a 404 error page has been resolved.
  • A bug causing incorrect HTTP response codes for the /org/metrics/{site_id} API endpoint has been resolved.
  • A bug which cleared the organizations table screen when sorted has been resolved.
  • A bug preventing vulnerabilities from sorting correctly on CVSS columns has been resolved.
  • A bug where scan tasks on hosted zones couldn’t be stopped has been resolved.
  • A bug preventing vulnerabilities from sorting correctly on CVSS columns has been resolved.
  • A bug that could result in excessive memory usage has been resolved.
  • A bug that resulted in certain models of Cisco routers being incorrectly merged has been resolved.
  • A bug in which AWS probes fail when run outside of an AWS EC2 environment has been resolved.
  • A bug which prevented IPv6 UDP SYN scans from working on FreeBSD and OpenBSD systems has been addressed.
  • A bug where autocomplete suggestions would not update consistently has been resolved.
  • A bug causing the “download task button” to show for tasks without a log has been resolved.
  • A bug that could cause the SNMP probe to panic in rare scenarios has been resolved.
  • A bug that could cause the SNMP probe to stall scans in rare scenarios has been resolved.
  • A bug that caused scans to take longer than expected or stall in rare scenarios has been resolved.
  • A bug that could prevent the organization dropdown from being clickable has been resolved.
  • A bug that could prevent the rpcbind probe from completing successfully was resolved.
  • A bug with copying some connector tasks has been resolved.
  • A bug causing some connectors to be labeled as scans has been resolved.
  • A bug causing the API /org/hosted-zones endpoint to return an empty list of hosted zones has been resolved.
  • A bug that could result in an invalid asset ownership assignment has been resolved.
  • A bug that could prevent a RUMBLE_CONSOLE override from working in the Explorer configuration has been resolved.
  • A bug that prevented sites with more than 1000 subnets from being saved has been resolved.
  • A bug that could result in odd dashboard chart behavior has been resolved.
  • A bug that required self-hosted users to configure SMTP before setting up their initial account has been resolved.
  • A bug that caused some scan task errors to be displayed twice has been resolved.
  • A bug that could prevent bogus services from certain firewalls from being completely filtered has been resolved.
  • A bug where Asset queries for exact strings was performing a fuzzy search has been fixed.
  • A bug that could cause malformed auto-populated LDAP thumbprints for LDAP credentials has been resolved.
  • A bug that prevented credential validation errors from displaying after verification in the console has been resolved.
  • A bug where searching via clicking on a tag would not return the correct results has been resolved.
  • A bug where multiple subtasks were incorrectly created for the same parent task has been resolved.
  • A bug where filters were not retained when importing a Nessus scan configuration has been resolved.
  • A bug that prevented copying of some connector tasks has been resolved.
  • A bug with linking to the update page on some connector tasks has been resolved.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.