Features Introduced in October 2023
Learn what’s new on Prisma® Cloud in October 2023.
New Features Introduced in October 2023
New Features
FEATURE
DESCRIPTION
Cloud Discovery and Exposure Management
Secure the Infrastructure
23.10.2
Cloud Discovery and Exposure Management is a new subscription that uses machine learning to discover internet-exposed and unmonitored assets within your cloud infrastructure, and enables you to secure these exposed assets with a single click. The assets are seamlessly onboarded to Prisma Cloud.
When you subscribe, the Discovery and Exposure Management dashboard provides visibility into your attack surface and surfaces the top risks and exposure by country . The findings on Inventory > Unmanaged Assets enable you to investigate further based on the insights about your shadow assets exposed to the internet and enhance your security posture.

Code to Cloud Dashboard
Secure Code to Cloud
23.10.2
Prisma Cloud’s Code to Cloud Dashboard provides you with a comprehensive assessment of the health of your cloud security posture. Highlights include:
Latest Events Tracker— Alerts you to potential threat activity across your software development lifecycle.
Code & Build, Deploy, Runtime Inventory— Track and view risks and vulnerabilities identified in every phase of the software development lifecycle.
Custom Collections— Group asset views to focus on specific teams, business units or applications.

Compute Workloads in Asset Inventory
Secure the Infrastructure
23.10.2
Prisma Cloud Asset Inventory now includes a summarized view of Compute Workloads (containers images and hosts) across your entire workload for discovery, risk assessment, and securing the runtime.

The findings on Inventory > Compute Workloads help you to assess the impact of the vulnerable container images and hosts on your application lifecycle, identify the top impacting vulnerabilities based on critical CVEs, and identify the Cloud providers for the vulnerable hosts along with the other metadata.
Vulnerabilities Dashboard
Secure Code to Cloud
23.10.2
The Vulnerabilities Dashboard gives you a holistic graphical view of all the vulnerabilities across your entire application lifecycle and narrows them down to the most critical and urgent ones, and the ones that are actionable. You get an overview of the top impacting vulnerabilities based on the CVEs, and the vulnerabilities impact by your app lifecycle in a CBDR view.

The CBDR graph findings help you assess the vulnerable assets in your environment and make informed decisions to remediate or mitigate the risks.
Vulnerability Search on Investigate
Secure Code to Cloud
23.10.2
The vulnerable where RQL clause helps you to investigate the vulnerable assets in Prisma Cloud to assess the risk and take actions to remediate and mitigate the vulnerabilities.

For example, with this vulnerable where RQL clause you can find all assets affected by a CVE ID, vulnerabilities with a CVSS score larger than 9, and vulnerabilities that are Exploitable, Patchable, and in Use.
Refer to the Vulnerabilities Query Attributes.
API Endpoints Inventory
Secure the Runtime
23.10.2
Prisma Cloud Inventory now includes continuous discovery of all the API endpoints in your environment. This discovery helps you to prioritize the risks and understand your security posture as well as attack vectors.

The Inventory > API Endpoints gives insights into the discovered endpoints with details on URL Path, the HTTP method, assets relationship, services, Cloud accounts, risk factors, the workload the API endpoints are associated with, and the discovery method.
The API risk profiling gives you insights on policies violated, findings, risk factors indicators, and the associate workload on which the endpoint is hosted.
Prisma Cloud uses existing WAAS runtime rules (agent-based and agentless) to scan traffic and AWS API Gateway configurations within your deployment to list the API endpoints.
Prioritize and Remediate Risks
Secure Code to Cloud
23.10.2
Prisma Cloud Attack Path Analysis identifies and collects a wide range of security signals to assist with risk prioritization. These signals include vulnerabilities in cloud resources, public exposure of resources to the internet, overly permissive credentials, and threat context, such as potentially malicious traffic or IP addresses.
By intelligently analyzing and correlating these signals, along with considering the business context of an application or data at risk, Prisma Cloud can guide your security teams to address the most critical risks first. This level of prioritization ensures that your organization can focus on securing your most valuable assets while minimizing the risk of data breaches or other threats. Prisma Cloud helps you identify the Attack Paths, which are presented in a graph view and offer valuable security context to protect your assets against high-risk threats.

Application Asset
Secure the Source
23.10.2
Application Asset queries are added to the Search and Investigate page, providing a graphical representation (graph) of your software development life cycle (SDLC) and enabling you to conduct a comprehensive analysis of security issues throughout your engineering environment. You will gain valuable insights into the assets in your environment and understand the relationships between them.

Repository Application Graph
Secure the Source
23.10.2
Added the option to access the Repository Application Graph through a dedicated sidecar. You can access this sidecar by selecting a repository in the repository inventory table of the Repositories page.
Removed query functionality from the Repository Application Graph.

Inventory - IaC Resources
Secure the Source
23.10.2
Prisma Cloud introduces inventory management for IaC Resources on the console (Inventory > IaC Resources). The inventory gives you a comprehensive list of interconnected frameworks across diverse cloud accounts and repositories, delivering enhanced visibility into cloud resource management through the console.

GCP Drift Detection and Drift Alerts
Secure the Source
23.10.2
Prisma Cloud provides support for Terraform to GCP Drift Detection, enabling you to identify instances when configurations for resources on the Google Cloud Platform deviate from the Terraform specifications in your version control system (VCS). Additionally, you will receive alerts for any divergence of your resources from your Terraform configurations, enabling you to uphold consistency and security, ensuring that your infrastructure aligns with your desired configuration.
Selective Scan for Organization Member Accounts
Secure the Infrastructure
23.10.2
Prisma Cloud introduces selective Agentless scanning for workloads and serverless functions for the member accounts within an organization for AWS, GCP and Azure. You can selectively enable or disable agentless or serverless scanning for individual member accounts or choose to scan the entire organization. By being selective you can incrementally add accounts for scanning and choose whether to scan all accounts in the organization or just some accounts.
Enable Organization Scan to scan all the accounts in the organization

Support for New Region on AWS
Secure the Infrastructure
23.10.2
Prisma Cloud now ingests data for resources deployed in the Israel region on AWS.
To review a list of supported regions, select Inventory > Assets, and choose Cloud Region from the filter drop-down.

Security Fix
HTTP/2 Rapid Reset Attack Vulnerability (CVE-2023-44487)
Secure the Runtime
30.02.137
This security update in v31.02.137 for Runtime Security addresses the HTTP/2 Rapid Reset Attack Vulnerability (CVE-2023-44487).
Go updated from 1.20.8 to 1.20.10 (https://go.dev/doc/devel/release#go1.20.10).
Go package "golang.org/x/net" was updated to version 0.17.0 (https://github.com/advisories/GHSA-4374-p667-p6c8).
The "nghttp2" package (installed in the Defender/Console images) updated by Red Hat (https://access.redhat.com/errata/RHSA-2023:5837).
Action - You do not need to make any updates to Compute console or the deployed Defenders.
API Ingestions
SERVICE
API DETAILS
AWS DataSync
23.10.2
aws-datasync-task-execution
Additional permissions required:
datasync:ListTaskExecutionsdatasync:DescribeTaskExecutiondatasync:ListTagsForResource
The Security Audit role includes the permissions.
AWS Transfer Family
23.10.2
aws-transfer-family-security-policy
Additional permissions required:
transfer:DescribeSecurityPolicytransfer:DescribeServertransfer:ListServers
The Security Audit role includes the permissions.
AWS WAF
23.10.2
aws-waf-v2-rule-group
Additional permissions required:
wafv2:GetRuleGroup
You must manually add or update the CFT template to enable the permission.
Azure AD B2C
23.10.2
azure-active-directory-b2c-tenants
Additional permission required:
Microsoft.AzureActiveDirectory/b2cDirectories/read
The Reader role includes the permission.
Update Azure Application Gateway
23.10.2
azure-application-gateway
The resource JSON for this API has been updated to include the defaultPredefinedSslPolicy field. The field defines the default TLS policy to use.
Google Vertex AI AIPlatform
23.10.2
gcloud-vertex-ai-aiplatform-feature-store
Additional permissions required:
aiplatform.featurestores.listaiplatform.featurestores.getIamPolicy
The Viewer role includes the permissions.
Google Vertex AI AIPlatform
23.10.2
gcloud-vertex-ai-aiplatform-metadata-store
Additional permission required:
aiplatform.metadataStores.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
23.10.2
gcloud-vertex-ai-aiplatform-tensor-board
Additional permission required:
aiplatform.tensorboards.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
23.10.2
gcloud-vertex-ai-aiplatform-index-endpoint
Additional permission required:
aiplatform.indexEndpoints.list
The Viewer role includes the permission.
OCI Cloud Guard
23.10.2
oci-cloudguard-target
Additional permissions required:
CG_TARGET_INSPECTCG_TARGET_READ
You must update the Terraform template to enable the permissions.
New Policies
New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.
Policy Updates
POLICY UPDATES
DESCRIPTION
Policy Updates—RQL
GCP Kubernetes Engine Clusters have Network policy disabled
23.10.2
Changes— The RQL has been updated as per the current network policy settings for GCP Kubernetes Engine Clusters.
Current RQL—
Updated RQL—
Severity— Low
Policy Type— Config
Impact— Low. Existing alerts where the cluster is configured with ADVANCED_DATAPATH will be resolved as Policy_Updated. New alerts will be generated where it checks for Calico Kubernetes Network policy not being configured.
Changes in Existing Behavior
FEATURE
DESCRIPTION
Enhancement to Code Security Dashboards
Secure the Source
23.10.2
From this release Code Security Dashboard (Dashboard > Code Security) will support the Latest Code Review Scans widget to provide insights into real-time monitoring of coding errors, and security vulnerabilities.

REST API Updates
CHANGE
DESCRIPTION
Code to Cloud APIs
The following new endpoints are added to get data that is used for plotting the deploy and runtime trends on the Code to Cloud dashboard:
List Deploy Trend - GET /c2c/api/v1/deploy/trend
List Runtime Trend - GET /c2c/api/v1/runtime/trend
Command Center APIs
The following new endpoints are available for the Command Center API:
List Total Alerts by Severity - POST /api/v1/summary/{swimlane-type}
List Top N Assets - POST /api/v1/top-assets/{swimlane-type}
List Top Policies - POST /api/v1/top-policies/{swimlane-type}
Cloud Discovery and Exposure Management APIs
New endpoints are available in the Cloud Discovery and Exposure Management category to onboard cloud accounts and get details about the exposed or unmanaged assets.
Collection APIs
The following new endpoints are added to manage collections which is a logical group of assets:
Get Collection by ID - GET /entitlement/api/v1/collection/{id}
Update Collection- PUT /entitlement/api/v1/collection/{id}
Delete Collection - DELETE /entitlement/api/v1/collection/{id}
Get All Collections - GET /entitlement/api/v1/collection
Create Collection - POST /entitlement/api/v1/collection
Updates to Cloud Account APIs
A new parameter, defaultMemberState, is added to the following endpoints:
Add Cloud Account (Azure) - POST /cas/v1/azure_account
Update Cloud Account (Azure)- PUT /cas/v1/azure_account/{account_id}
Add Cloud Account (AWS) - POST /cas/v1/aws_account
Update Cloud Account (AWS)- PUT /cas/v1/aws_account/{id}
Add Cloud Account (GCP) - POST /cas/v1/gcp_account
Update Cloud Account (GCP) - PUT /cas/v1/gcp_account/{id}
Deprecation Notice
Feature
Description
Date Filter Support
Secure the Infrastructure
This deprecation was first announced in the Look Ahead that was published with the 23.10.1 release.
The Date filter is being deprecated on Inventory > Assets, Asset Explorer, and Compliance > Overview.
With the 23.10.2 release, the date filter will no longer be supported. With this change, links in Compliance reports that were generated before 23.10.2 will be removed.
Data Dashboard
Secure the Infrastructure
This deprecation was first announced in the Look Ahead that was published with the 23.10.1 release.
The Data Dashboard is being deprecated on Dashboards > Data.
With the 23.10.2 release, the widgets in the Data dashboard will be available in a custom dashboard. To view the Data Security information, you will be able to create a custom dashboard and add the data security widgets.
Removal of deprecated AWS, GCP, and Azure Cloud Types in CSPM Cloud Accounts API
Secure the Infrastructure
This deprecation was first announced in the Look Ahead that was published with the 23.6.1 release.
The following endpoints no longer support the AWS, GCP, and Azure cloud types:
The following APIs released previously, provide the same functionality separately for each cloud type.
AWS APIs released in 23.3.1:
Azure APIs released in 23.4.1:
GCP APIs released in 23.4.2:
Supply Chain Graph
Secure the Code
From this release, the Application Security > Supply Chain page is no longer available as a standalone page. The package dependency tree will be added to the Application Graph on Investigate in a future release.
Use Application Security > Projects for insights into vulnerabilities within open-source packages
Development Pipelines
Secure the Code
From this release Application Security > Development Pipelines is no longer available as a standalone page. For Code Reviews details, use the Latest Code Review Scans widget on Dashboard > Code Security.
Last updated
Was this helpful?

