Features Introduced in December 2023
Learn what’s new on Prisma® Cloud in December 2023.
New Features Introduced in December 2023
Announcement
FEATURE
DESCRIPTION
Prisma Cloud Darwin Release
The Prisma Cloud Darwin Release is here for Prisma Cloud environments on app, app3, app.eu, app2.eu except app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.
With this change, your tenant will be updated with the new intuitive user interface and rich set of security capabilities.
Connect with your Customer Success team for more details.
When you are upgraded to the Darwin release, refer to the Enterprise Edition documentation.
New Features
FEATURE
DESCRIPTION
IAM Policy Scanner Enhancement
Secure the Infrastructure
23.12.1
IAM Policy Scanner now includes enhancements to improve alert accuracy. This may result in some alerts briefly closing and reopening.
API Ingestions
The 23.12.1 release does not include any API Ingestions.
New Policies
NEW POLICIES
DESCRIPTION
New Policies to Configuration Build Policies
Starting from this release 2 new policies are added to Config policies of subtype Build. Here are the policies:
AWS CloudFront attached WAFv2 WebACL is not configured with AMR for Log4j Vulnerability
Software Composition Analysis (SCA) findings
In addition, 6 new policies integrated with CI/CD Risks are added by default to Prisma Cloud console and visible Governance.
BitBucket private repository made public.
Unrotated organization secrets in GitHub Actions.
Unrotated repository secrets in GitHub Actions.
CircleCI pipeline uses an unpinned container image.
Azure Pipelines uses an unpinned container image.
Secrets found in logs of a GitLab CI pipeline.
Impact- Impact- You will view policy violations for these policies on Prisma Cloud switcher Application Security > Projects in CI/CD Risks with CI/CD module enabled on Application Security > Settings.
Azure Virtual Machine (Linux) does not authenticate using the SSH keys
Changes - The policy name is being updated to reflect the latest changes.
Current Policy Name - Azure instance does not authenticate using the SSH keys
Impact- No impact on alerts.
Policy Updates
POLICY UPDATES
DESCRIPTION
Enhancements to Terraform GitHub and GitLab policies for Configuration Build Policies
Changes - The policy name is being updated to reflect the latest changes.
Current Policy Name - * GitHub Actions Environment Secrets not Encrypted * GitHub repository doesn’t have vulnerabilities alerts enabled * Gitlab project commits are not signed * Gitlab project does not prevent secrets * Gitlab project has less than 2 approvals
Impact- No impact on alerts.
New domain for Application Security Policy Reference Guide
Changes - Starting from this release all policy documentation will be available on Prisma Cloud Application Security Policy Reference.
Impact- No impact on alerts.
Azure Virtual Machine (Linux) does not authenticate using the SSH keys
Changes - The policy name is being updated to reflect the latest changes.
Current Policy Name - Azure instance does not authenticate using the SSH keys
Impact- No impact on alerts.
Policy Deletions
Docker GitHub repository is not private
Changes - This policy is deleted because the GitHub policies are modified in GitHub Policies.
Impact - No impact on alerts.
IAM Policy Updates
The following IAM out-of-the-box (OOTB) policies are updated in Prisma Cloud:
POLICY NAME
Current RQL
Updated RQL
Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions
Changes— The policy name will be updated.
Current Name— Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions
Updated Name— Azure VM instance associated managed identity with Azure built-in roles of Owner permissions
NA
AWS IAM policy allows Privilege escalation via PassRole & CodeBuild permissions
AWS IAM policy allows Privilege escalation via PassRole & CodeStar project permissions
AWS IAM policy allows Privilege escalation via PassRole & Data Pipeline permissions
AWS IAM policy allows Privilege escalation via PassRole & EC2 permissions
AWS IAM policy allows Privilege escalation via PassRole & Glue create job permissions
AWS IAM policy allows Privilege escalation via PassRole & Glue development endpoint permissions
AWS IAM policy allows Privilege escalation via PassRole & Glue update job permissions
AWS IAM policy allows Privilege escalation via PassRole & Lambda create & invoke Function permissions
AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & Event source mapping permissions
AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & add permissions
AWS IAM policy allows Privilege escalation via PassRole & SageMaker create processing job permissions
AWS IAM policy allows Privilege escalation via PassRole & SageMaker create training job permissions
New Compliance Benchmarks and Updates
COMPLIANCE BENCHMARK
DESCRIPTION
Support for MITRE ATT&CK Cloud IaaS v13 & v14
23.12.1
Prisma Cloud now supports the MITRE ATT&CK Cloud IaaS v13 & v14 compliance standard. This framework includes Att&ck Tactics, Techniques and sub-techniques that attackers can leverage to compromise cloud applications and infrastructure.
You can now view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
Changes in Existing Behavior
FEATURE
DESCRIPTION
Checkov update for SCA Security scanning
Secure the Source
23.12.1
Ensure Checkov or Bridgecrew CLI is updated to version 2.2.234 or later. Support for earlier versions is no longer supported.
Checkov CLI upgrade
Secure the Source
23.12.1
The Checkov CLI has been upgraded to Checkov 3.0. The upgrade impacts a few known changes:
Level Up: This capability has been removed. This change is non-disruptive and affects only Bridgecrew standalone sign ups.
Multi-Signatures: Multi-signatures in Python checks are being removed. This will only impact custom Python policies using this method.
Deprecating flags for Suppression and Fix: CLI command of
--skip-fixesand--skip-suppressionsare being deprecated. Instead--skip-downloadis a recommended command.API Key Restriction and Repo-ID Parameter: Scans with API keys will now require the --repo-id parameter for repository scans allowing for easier platform mapping.
Enhanced Argument Handling: The way to specify frameworks and skip frameworks will align to other flags where multiple values can be listed (like --check). For example:
--framework terraform,arm..Pyston Docker Build Deprecation: The Pyston Docker build has been depreciated due to increasing complexities in support. The regular Checkov image will still be available for use.
REST API Updates
CHANGE
DESCRIPTION
Compliance Posture APIs
23.12.1
The following new endpoints are available for the Compliance Posture API:
Asset Explorer and Reports APIs
23.12.1
The following new endpoints are available for the Asset Explorer and Reports API:
Asset Inventory APIs
23.12.1
The following new endpoints are available for the AAsset Inventory APIs:
Deprecation Notices
Deprecate the aggregated and rest fields
The aggregated and rest macros from the webhook custom JSON alerts are being deprecated and replaced by AggregatedAlerts and Dropped macros respectively.
Deprecate AccountID macro from the Alerts payload
The AccountID macro in the Alerts payload is deprecated and replaced by the AccountIDs macro.
End of Support Notifications
Support for Cloud Native Network Segmentation (CNNS)
The ability to create CNNS policies that Defenders use to limit traffic from containers and hosts is being removed. The configuration settings on the console (Runtime Security > Defend > CNNS) and the corresponding APIs for CNNS will be removed in v32.00. Radar has a container and a host view, where you can view the network topology for your containerized apps and hosts respectively, and this will continue to be available.
Last updated
Was this helpful?

