> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-march-2025.md).

# Features Introduced in March 2025

Learn what’s new on Prisma® Cloud in March 2025.

* [Enhancements](#enhancements)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)

## Enhancements

| **Feature**                                                                                                                                                                                                             | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Cloud Discovery Enhancements</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p>                               | <ol><li><strong>AWS Fargate for Amazon ECS:</strong> Cloud Discovery now includes data about ECS Fargate containers, including their defended/undefended status.</li><li><strong>Azure Container Instances (ACI):</strong> Cloud Discovery now includes data for all containers in container groups. Previously, data for only the first container was included.</li><li><strong>Google Cloud Run:</strong> Cloud Discovery now includes data for all containers in GCP Cloud Run container groups. Previously, no data was collected and shown for containers in GCP Cloud Run.</li><li><p><strong>Identify Account ID attribution for app-embedded defenders used for defending CaaS assets:</strong> The Account ID was previously available for ECS Fargate and Google Cloud Run. This release adds the support for displaying the Account ID for ACI as well. With this release:</p><ol><li>ECS Fargate and GCP Cloud Run: the Account ID was already shown for: i) Fargate defenders; and ii) App-embedded defenders installed on GCP Cloud Run.</li><li><p>Azure Container Instances (ACI): In this release, Account ID is shown for app-embedded defenders installed on ACI containers after you perform the following steps for each container:</p><ol><li>Upgrade the defender to the Quinn release.</li><li>Create a managed identity.</li><li>Assign the Reader role to the newly created managed identity.</li><li>Assign the newly created managed identity to the container group.</li></ol></li></ol></li></ol>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Jira Authentication Update for Prisma Cloud Runtime Alerts</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p> | <p>Jira Cloud has deprecated Basic Authentication with passwords and now requires API tokens for authentication. When integrating Prisma Cloud Runtime with Jira as an alert provider, you must use an API token instead of a username-password combination.</p><p><strong>Required Actions</strong></p><p>To set up a new alert profile for Jira Cloud users, do the following:</p><ol><li><p>Generate an API token from your Jira Cloud account.</p><p>For more information, see <a href="https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/">Manage API tokens for your Atlassian account</a> topic in Jira Documentation site.</p></li><li><p>Save the token in Prisma Cloud’s Credentials Store and use this new credential when adding a new Jira Alert profile.</p><p>For more information, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/runtime-security/alerts/jira#adding-api-tokens-in-credentials-store-for-jira-cloud-authentication">Adding Jira Cloud Credentials</a> topic in the Prisma Cloud Admin Guide.</p></li></ol><p>To update an existing alert profile for Jira Cloud users, do the following:</p><ol><li><p>Generate an API token from your Jira Cloud account.</p><p>For more information, see <a href="https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/">Manage API tokens for your Atlassian account</a> topic in the Jira Documentation site.</p></li><li><p>Update the credentials by replacing the password with the API token.</p><p>For more information, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/runtime-security/alerts/jira#updating-jira-cloud-credentials-to-use-an-api-token">Updating Jira Cloud Credentials</a> topic in the Prisma Cloud Admin Guide.</p></li></ol><p>To set Up a new alert profile for Jira Data Center (DC) users, do the following:</p><ol><li><p>Generate a personal access token from your Jira DC account.</p><p>For more information, see <a href="https://confluence.atlassian.com/enterprise/using-personal-access-tokens-1026032365.html">Using Personal Access Tokens</a> topic in the Jira Documentation site.</p></li><li>Configure the credentials using Basic Authentication with your username and the personal access token as the password when adding a new Jira Alert profile. For more information, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/runtime-security/alerts/jira#adding-api-tokens-in-credentials-store-for-jira-dc-authentication">Adding Jira DC Credentials</a> topic in the Prisma Cloud Admin Guide.</li></ol>                                                                                                                                                                       |
| <p><strong>Better utilization of vendor-specific feeds</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p>                | <p>The National Vulnerability Database (NVD) provides a valuable baseline CVSS score for vulnerabilities. However, vendors often have a more granular understanding of how a specific vulnerability impacts their implementation of a component. This allows them to provide a more accurate CVSS score, especially when considering environmental factors and the specific ways their product utilizes the vulnerable component. In some cases, vendor-specific vulnerability feeds may have the latest CVSS scores before they are reflected in NVD.</p><p>This release leverages additional data from vendor-specific vulnerability feeds, such as those from RedHat, Photon OS, and Ruby Gems, and implements several improvements in the extraction and reporting of CVSS scores. These changes provide more accurate and timely CVSS scores, reflecting the latest vendor-specific mitigations, configurations, and environmental impacts.</p><p><strong>RedHat Security Feed:</strong></p><ul><li>Previously, if a CVE had a CVSS score of 0 in the RedHat security feed, we used the CVSS score provided by NVD for that CVE.</li><li>Now, we use the CVE data and the CVSS score provided by the RedHat feed even if the CVSS score is 0 in the RedHat feed. This ensures that we consider RedHat’s specific assessment, which might indicate a mitigated or non-impactful vulnerability in their context.</li></ul><p><strong>Photon OS Security Feed:</strong></p><ul><li>Previously, we extracted CVSS scores for CVEs from the NVD for Photon OS vulnerabilities.</li><li>Now, we use the CVSS scores provided in the Photon OS security feed. This allows us to reflect Photon OS-specific mitigations and impacts more accurately.</li></ul><p><strong>Ruby Gems Security Feed:</strong></p><ul><li>Previously, we ignored the CVSS scores reported by RubySec (<a href="https://github.com/rubysec"><https://github.com/rubysec></a> and <a href="https://github.com/rubysec/ruby-advisory-db"><https://github.com/rubysec/ruby-advisory-db></a>) and used the values from NVD.</li><li>Now, we use the CVSS values provided in the Ruby Advisory DB. This ensures we capture the precise impact and mitigations for Ruby Gems vulnerabilities as assessed by RubySec.</li></ul><p><strong>Amazon Linux Security Feed:</strong></p><ul><li>Previously, we extracted CVSS scores for Amazon Linux vulnerabilities/CVEs from the NVD.</li><li>Now, we use the CVSS scores provided in the Amazon Linux security feed. This allows us to reflect Amazon Linux-specific mitigations and impacts more accurately.</li></ul><p><strong>Fallback to NVD CVSS Scores</strong></p><p>If the vendor feed does not provide a CVSS value for any CVE, then the CVSS value from the NVD will be used. This ensures that we always have a CVSS score to guide our risk assessment and mitigation efforts.</p> |
| <p><strong>Customization for Scanning Amazon Machine Images (AMIs)</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p>    | <p>Prisma Cloud now offers on-prem users greater flexibility in selecting AMIs.</p><p>For on-prem users, the following environment variables enable customization:</p><ul><li><code>AGENTLESS\_USE\_CUSTOM\_AMI</code> – Enables or disables the use of custom AMIs.</li><li><code>AGENTLESS\_CUSTOM\_AMI\_PER\_REGION</code> – Specifies custom AMIs per AWS region</li></ul><p><strong>Example Configuration:</strong></p><p><code>AGENTLESS\_USE\_CUSTOM\_AMI=true</code> <code>AGENTLESS\_CUSTOM\_AMI\_PER\_REGION='{"us-east-1":"ami-005fc0f236362e99f"}'</code></p><p>In this example, the custom AMI (<code>ami-005fc0f236362e99f</code>) is used in the 'us-east-1' region.</p><p><strong>Behavior Based on Configuration:</strong></p><ul><li>If <code>AGENTLESS\_USE\_CUSTOM\_AMI</code> is <code>false</code>, Prisma Cloud falls back to the previous scanner image, which is Ubuntu 20.04.</li><li>If <code>AGENTLESS\_USE\_CUSTOM\_AMI</code> is set to <code>true</code> but <code>AGENTLESS\_CUSTOM\_AMI\_PER\_REGION</code> is not set, Prisma Cloud uses the LaunchDarkly (LD) custom AMI list.</li><li>If <code>AGENTLESS\_USE\_CUSTOM\_AMI</code> is not set, Prisma Cloud defaults to the LD custom AMI list.</li><li>For Cloud (SaaS) users, no action is required—Prisma Cloud automatically selects the latest optimized AMI.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## Changes in Existing Behavior

| **Feature**                                                                                                                                                                                                 | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Removal of Stale Hosts and Images</p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p>                               | We’re implementing a fix that will remove outdated assets that are no longer protected by a Defender. These assets should have been automatically deleted previously, but were not. With this update, you might notice that certain stale assets are no longer present in your inventory. As a result, you might also see a reduction in vulnerabilities and compliance findings due to their removal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p>System Requirements: Changes to supported systems and platforms</p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.00.137</mark></p> | <p>The following changes have been made to the system requirements:</p><p><strong>Support added for WAAS</strong></p><ol><li>WAAS with Defender (AWS): Node.js 22</li><li>WAAS with Defender (AWS): Python 3.13</li></ol><p><strong>Support removed for WAAS</strong></p><ol><li>WAAS with Defender (AWS): Node.js 16</li><li>WAAS with Defender (AWS): Python 3.8</li></ol><p><strong>Support removed for Auto Defend</strong></p><ol><li>Auto-Defend (AWS): Node.js 16</li><li>Auto-Defend (AWS): Python 3.8</li></ol><p><strong>Support added for Runtime Protection</strong></p><ol><li>Runtime protection with Defender (AWS): Node.js 22</li><li>Runtime protection with Defender (AWS): Python 3.13</li></ol><p><strong>Support removed for Runtime Protection</strong></p><ol><li>Runtime protection with Defender (AWS): Node.js 16</li><li>Runtime protection with Defender (AWS): Python 3.8</li></ol><p><strong>Support added for x86 Operating Systems</strong></p><ol><li>Alma Linux 8</li><li>Alma Linux 9</li><li>Bottlerocket OS 1.20.5</li><li>Talos OS 1.9.4</li></ol><p><strong>Support removed for x86 Operating Systems</strong></p><ol><li>Talos OS 1.3.0</li><li>Talos OS 1.3.3</li><li>Talos OS 1.5.1</li><li>Talos OS 1.5.3</li><li>Talos OS 1.5.5</li><li>Talos OS 1.6.0</li><li>Talos OS 1.6.1</li><li>Talos OS 1.6.4</li><li>Talos OS 1.6.6</li><li>Talos OS 1.6.6</li><li>Talos OS 1.7.2</li><li>Talos OS 1.7.5</li><li>Talos OS 1.7.6</li><li>Talos OS 1.8.0</li><li>Talos OS 1.8.2</li></ol><p><strong>Support added for x86 Orchestrators</strong></p><ol><li>Azure Kubernetes Service (AKS) v1.29.13 Linux (Mariner)</li><li>Elastic Container Service (ECS) 1.87.1 Linux</li><li>Elastic Kubernetes Service (EKS) v1.32.1-eks-5d632ec Linux</li><li>Elastic Kubernetes Service (EKS) Bottlerocket v1.32.0-eks-2e66e76 Linux</li><li>Google Kubernetes Engine (GKE) v1.32.1-gke.1489001 Linux</li><li>Google Kubernetes Engine (GKE) autopilot v1.31.6-gke.1020000 Linux</li><li>Lightweight Kubernetes (k3s) v1.31.5+k3s1 Linux</li><li>OpenShift 4.17</li><li>RKE v1.31.5 Linux</li><li>RKE2 v1.32.1+rke2r1 Linux</li><li>VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) v1.30.7+vmware.1 Ubuntu 22.04.1 LTS</li></ol><p><strong>Support removed for x86 Orchestrators</strong></p><ol><li>Azure Kubernetes Service (AKS) v1.27.9 Linux</li><li>Azure Kubernetes Service (AKS) v1.28.9 Linux</li><li>Azure Kubernetes Service (AKS) v1.29.2 Linux</li><li>Azure Kubernetes Service (AKS) v1.30.3 Linux</li><li>Azure Kubernetes Service (AKS) v1.28.5 Linux</li><li>Azure Kubernetes Service (AKS) v1.29.2 Linux</li><li>Azure Kubernetes Service (AKS) v1.29.7 Linux (Mariner)</li><li>Azure Kubernetes Service (AKS) v1.31.1 Windows</li><li>Azure Kubernetes Service (AKS) v1.30.4 Windows</li><li>Azure Kubernetes Service (AKS) v1.30.3 Windows</li><li>Azure Kubernetes Service (AKS) v1.29.0 Windows</li><li>Azure Kubernetes Service (AKS) v1.28.15 Linux</li><li>Azure Kubernetes Service (AKS) v1.29.7 Linux (Mariner)</li><li>Azure Kubernetes Service (AKS) v1.28.15 Linux</li><li>Azure Kubernetes Service (AKS) v1.29.7 Linux (Mariner)</li><li>Elastic Container Service (ECS) 1.86.2 Linux</li><li>Elastic Container Service (ECS) 1.86.3 Linux</li><li>Elastic Kubernetes Service (EKS) v1.28.1-eks-43840fb</li><li>Elastic Kubernetes Service (EKS) v1.28.1-eks-43840fb Linux</li><li>Elastic Kubernetes Service (EKS) v1.29.0-eks-5e0fdde Linux</li><li>Elastic Kubernetes Service (EKS) v1.30.0-eks-036c24b Linux</li><li>Elastic Kubernetes Service (EKS) v1.28.1-eks-43840fb Linux</li><li>Elastic Kubernetes Service (EKS) v1.29.0-eks-5e0fdde Linux</li><li>Elastic Kubernetes Service (EKS) v1.30.0-eks-036c24b Linux</li><li>Elastic Kubernetes Service (EKS) Bottlerocket v1.29.1-eks-61c0bbb Linux</li><li>Elastic Kubernetes Service (EKS) Bottlerocket v1.30.0-eks-fff26e3 Linux</li><li>Google Kubernetes Engine (GKE) v1.27.12-gke.1115000 Linux</li><li>Google Kubernetes Engine (GKE) v1.28.8-gke.1095000 Linux</li><li>Google Kubernetes Engine (GKE) v1.29.7-gke.1104000 Linux</li><li>Google Kubernetes Engine (GKE) autopilot v1.29.7-gke.1104000 Linux</li><li>Google Kubernetes Engine (GKE) 1.27.12-gke.1115000 Linux</li><li>Google Kubernetes Engine (GKE) 1.28.8-gke.1095000 Linux</li><li>Google Kubernetes Engine (GKE) v1.29.7-gke.1104000 Linux</li><li>Google Kubernetes Engine (GKE) v1.30.3-gke.1225000 Linux</li><li>Google Kubernetes Engine (GKE) autopilot v1.30.3-gke.1639000 Linux</li><li>Google Kubernetes Engine (GKE) 1.27.12-gke.1115000 Linux</li><li>Google Kubernetes Engine (GKE) 1.28.8-gke.1095000 Linux</li><li>Google Kubernetes Engine (GKE) v1.29.7-gke.1104000 Linux</li><li>Google Kubernetes Engine (GKE) v1.30.5-gke.1443001 Linux</li><li>Google Kubernetes Engine (GKE) autopilot v1.31.1-gke.1678000 Linux</li><li>Google Kubernetes Engine (GKE) 1.28.15-gke.1159000 Linux</li><li>Google Kubernetes Engine (GKE) autopilot v1.31.3-gke.1006000 Linux</li><li>Kubernetes (k8s) v1.28.10 Linux</li><li>Lightweight Kubernetes (k3s) v1.30.0+k3s1 Linux</li><li>Lightweight Kubernetes (k3s) v1.31.0+k3s1 Linux</li><li>OpenShift 4.14</li><li>RKE v1.30.3 Linux</li><li>RKE v1.30.4 Linux</li><li>RKE v1.30.4 Linux</li><li>RKE v1.31.2 Linux</li><li>RKE2 v1.29.3+rke2r1 Linux</li><li>RKE2 v1.29.3+rke2r1 Linux</li><li>RKE2 v1.31.2+rke2r1 Linux</li><li>RKE2 v1.31.2+rke2r1 Linux</li><li>TalOS 1.7.6 Talos</li><li>VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) v1.26.5+vmware.1 Ubuntu 22.04.1 LTS</li><li>VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) v1.28.7+vmware.1 Ubuntu 22.04.1 LTS</li></ol><p><strong>Support added for ARM orchestrators</strong></p><ol><li>Elastic Kubernetes Service (EKS) v1.32.1-eks-5d632ec.arm</li><li>Google Kubernetes Engine (GKE) 1.32.1-gke.1489001.arm</li><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.30.9-gke.1046000</li></ol><p><strong>Support removed for ARM orchestrators</strong></p><ol><li>Elastic Container Service (ECS) 1.86.2</li><li>Elastic Container Service (ECS) 1.86.3</li><li>Elastic Kubernetes Service (EKS) v1.29.0-eks-5e0fdde.arm</li><li>Elastic Kubernetes Service (EKS) v1.30.0-eks-036c24b.arm</li><li>Google Kubernetes Engine (GKE) v1.29.7-gke.1104000.arm</li><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.29.7-gke.1104000.arm</li><li>Google Kubernetes Engine (GKE) v1.30.5-gke.1443001</li><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.30.5-gke.1014001</li><li>Google Kubernetes Engine (GKE) 1.31.1-gke.2105000</li><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.30.6-gke.1125000</li><li>Elastic Kubernetes Service (EKS) v1.29.0-eks-5e0fdde</li><li>Elastic Kubernetes Service (EKS) v1.30.0-eks-036c24b</li></ol> |

## API Ingestions

| **Service**                                                          | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Cognito**                                                   | <p><strong>aws-cognito-identity-pool-role</strong></p><p>Additional permissions needed:</p><ul><li><code>cognito-identity:ListIdentityPools</code></li><li><code>cognito-identity:GetIdentityPoolRoles</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                     |
| **Amazon Connect**                                                   | <p><strong>aws-connect-instance-user</strong></p><p>Additional permissions needed:</p><ul><li><code>connect:ListUsers</code></li><li><code>connect:DescribeUser</code></li><li><code>connect:ListInstances</code></li></ul><p>The Security audit role includes the <code>connect:ListUsers</code> permissions.</p>                                                                                                                  |
| **Amazon Connect**                                                   | <p><strong>aws-connect-instance-security-profile</strong></p><p>Additional permissions needed:</p><ul><li><code>connect:ListSecurityProfiles</code></li><li><code>connect:DescribeSecurityProfile</code></li><li><code>connect:ListInstances</code></li></ul><p>The Security audit role includes the <code>connect:ListInstances</code> permissions.</p>                                                                            |
| <mark style="background-color:orange;">Update</mark> **Amazon EC2**  | <p><strong>aws-ec2-describe-images</strong></p><p>Additional permission needed:</p><ul><li><code>ec2:DescribeImageAttribute</code></li></ul><p>The Security audit role includes the permission.</p><p>Also, the JSON resource for this API includes a new <code>imageAttributes</code> field.</p>                                                                                                                                   |
| <mark style="background-color:orange;">Update</mark> **Amazon EC2**  | <p><strong>aws-ec2-describe-vpcs</strong></p><p>Additional permission needed:</p><ul><li><code>ec2:DescribeImageAttribute</code></li><li><code>ec2:DescribeVpcAttribute</code></li></ul><p>The Security audit role includes the permission.</p><p>This update requires the new permission`ec2:DescribeVpcAttribute` be added in addition to the existing permission.</p>                                                            |
| **Amazon EC2**                                                       | <p><strong>aws-ec2-instance-connect-endpoint</strong></p><p>Additional permission needed:</p><ul><li><code>ec2:DescribeInstanceConnectEndpoints</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                             |
| **Amazon EC2**                                                       | <p><strong>aws-ec2-image-block-public-access-state</strong></p><p>Additional permission needed:</p><ul><li><code>ec2:GetImageBlockPublicAccessState</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                         |
| **Amazon EC2**                                                       | <p><strong>aws-ec2-snapshot-block-public-access-state</strong></p><p>Additional permission needed:</p><ul><li><code>ec2:GetSnapshotBlockPublicAccessState</code></li></ul><p>The Security audit role does not include the permission. You must manually add the permission in the CFT template to enable it.</p>                                                                                                                    |
| **Amazon EventBridge Pipes**                                         | <p><strong>aws-event-bridge-pipe</strong></p><p>Additional permissions needed:</p><ul><li><code>pipes:ListPipes</code></li><li><code>pipes:DescribePipe</code></li></ul><p>The Security audit role does not include the permissions. You must manually add the permissions in the CFT template to enable them.</p>                                                                                                                  |
| **Amazon RDS**                                                       | <p><strong>aws-rds-db-instance-automated-backup</strong></p><p>Additional permission needed:</p><ul><li><code>rds:DescribeDBInstanceAutomatedBackups</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                        |
| **Amazon RDS**                                                       | <p><strong>aws-rds-db-proxy</strong></p><p>Additional permission needed:</p><ul><li><code>rds:DescribeDBProxies</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                             |
| **Amazon RDS**                                                       | <p><strong>aws-rds-db-proxy-target</strong></p><p>Additional permissions needed:</p><ul><li><code>rds:DescribeDBProxies</code></li><li><code>rds:DescribeDBProxyTargets</code></li><li><code>rds:DescribeDBProxyTargetGroups</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                               |
| <mark style="background-color:orange;">Update</mark> **Amazon RDS**  | <p><strong>aws-rds-describe-db-instances</strong></p><p>The JSON resource for the API will be updated to include a new field <code>latestRestorableTime</code>.</p>                                                                                                                                                                                                                                                                 |
| **Amazon S3**                                                        | <p><strong>aws-s3-storage-lens-configuration</strong></p><p>Additional permission needed:</p><ul><li><code>s3:ListStorageLensConfigurations</code></li></ul><p>The Security audit role does not include the permission. You must manually add the permission in the CFT template to enable it.</p>                                                                                                                                  |
| **Amazon SNS**                                                       | <p><strong>aws-sns-subscriptions-by-topic</strong></p><p>Additional permissions needed:</p><ul><li><code>sns:ListTopics</code></li><li><code>sns:ListSubscriptionsByTopic</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                                  |
| **Amazon SQS**                                                       | <p><strong>aws-sqs-message-move-task</strong></p><p>Additional permissions needed:</p><ul><li><code>sqs:ListQueues</code></li><li><code>sqs:ListMessageMoveTasks</code></li></ul><p>The Security audit role only includes the <code>sqs:ListQueues</code> permission. You must manually include the <code>sqs:ListMessageMoveTasks</code> permission in the CFT template to enable it.</p>                                          |
| <mark style="background-color:orange;">Update</mark> **AWS Glue**    | <p><strong>aws-glue-connection</strong></p><p>Additional permission needed:</p><ul><li><code>glue:GetTags</code></li></ul><p>The Security audit role includes the permission.</p><p>Also, the JSON resource for this API includes <code>tags</code> field.</p>                                                                                                                                                                      |
| **AWS Glue**                                                         | <p><strong>aws-glue-blueprint</strong></p><p>Additional permissions needed:</p><ul><li><code>glue:ListBlueprints</code></li><li><code>glue:GetBlueprint</code></li></ul><p>The Security audit role does not include the permissions. You must manually add the permissions in the CFT template to enable them.</p>                                                                                                                  |
| **AWS Glue**                                                         | <p><strong>aws-glue-blueprint-run</strong></p><p>Additional permissions needed:</p><ul><li><code>glue:GetBlueprintRuns</code></li><li><code>glue:GetBlueprintRun</code></li></ul><p>The Security audit role does not include the permissions. You must manually add the permissions in the CFT template to enable them.</p>                                                                                                         |
| **AWS Lambda**                                                       | <p><strong>aws-lambda-function-event-invoke-config</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListFunctions</code></li><li><code>lambda:GetFunctionEventInvokeConfig</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                            |
| **AWS Lambda**                                                       | <p><strong>aws-lambda-versions-by-function</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListFunctions</code></li><li><code>lambda:ListVersionsByFunction</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                          |
| **AWS Lambda**                                                       | <p><strong>aws-lambda-function-concurrency</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListFunctions</code></li><li><code>lambda:GetFunctionConcurrency</code></li></ul><p>The Security audit role only includes the <code>lambda:ListFunctions</code> permission. You must manually include the <code>lambda:GetFunctionConcurrency</code> permission in the CFT template to enable it.</p>              |
| **AWS Lambda**                                                       | <p><strong>aws-lambda-runtime-management-config</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListFunctions</code></li><li><code>lambda:GetRuntimeManagementConfig</code></li></ul><p>The Security audit role only includes the <code>lambda:ListFunctions</code> permission. You must manually include the <code>lambda:GetRuntimeManagementConfig</code> permission in the CFT template to enable it.</p> |
| <mark style="background-color:orange;">Update</mark> **AWS Regions** | <p><strong>aws-region</strong></p><p>The JSON resource for the API is updated to include a new field <code>accountId</code>.</p>                                                                                                                                                                                                                                                                                                    |
| <mark style="background-color:orange;">Update</mark> **AWS Regions** | <p><strong>aws-region</strong></p><p>The resource output of the API aws-region includes the new field <code>accountId</code>.</p>                                                                                                                                                                                                                                                                                                   |
| **Azure API Management Services**                                    | <p><strong>azure-api-management-service-authorization-server</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/authorizationServers/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                    |
| **Azure API Management Services**                                    | <p><strong>azure-api-management-service-backend</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/backends/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                             |
| **Azure API Management Services**                                    | <p><strong>azure-api-management-service-openid-connect-provider</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/openidConnectProviders/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                               |
| **Azure API Management Services**                                    | <p><strong>aazure-api-management-service-user</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/users/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                  |
| **Azure Kubernetes Service**                                         | <p><strong>azure-kubernetes-connected-cluster</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Kubernetes/connectedClusters/Read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                            |
| **Azure CDN**                                                        | <p><strong>azure-frontdoor-standardpremium-origin-groups-origin</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Cdn/profiles/read</code></li><li><code>Microsoft.Cdn/profiles/origingroups/read</code></li><li><code>Microsoft.Cdn/profiles/origingroups/origins/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                     |
| **Azure Network Manager**                                            | <p><strong>azure-network-manager-static-members</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Network/networkManagers/read</code></li><li><code>Microsoft.Network/networkManagers/networkGroups/read</code></li><li><code>Microsoft.Network/networkManagers/networkGroups/staticMembers/read</code></li></ul><p>The Reader role includes the permissions.</p>                                            |
| **Azure Network Manager**                                            | <p><strong>azure-network-manager-security-admin-configuration</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Network/networkManagers/read</code></li><li><code>Microsoft.Network/networkManagers/securityAdminConfigurations/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                        |
| **Azure Network Manager**                                            | <p><strong>azure-network-manager-network-group</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Network/networkManagers/read</code></li><li><code>Microsoft.Network/networkManagers/networkGroups/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                     |
| **Azure Recovery Services**                                          | <p><strong>azure-recovery-service-site-recovery-protected-item</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.RecoveryServices/Vaults/read</code></li><li><code>Microsoft.RecoveryServices/vaults/replicationProtectedItems/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                         |
| **Azure Storage**                                                    | <p><strong>azure-storage-account-blob-container</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Storage/storageAccounts/read</code></li><li><code>Microsoft.Storage/storageAccounts/blobServices/containers/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                          |
| **Azure Storage**                                                    | <p><strong>azure-storage-account-file-service-property</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.Storage/storageAccounts/read</code></li><li><code>Microsoft.Storage/storageAccounts/fileServices/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                              |
| **Google Data Catalog**                                              | <p><strong>gcloud-data-catalog-tag-template</strong></p><p>Additional permissions needed:</p><ul><li><code>datacatalog.catalogs.searchAll</code></li><li><code>datacatalog.tagTemplates.get</code></li><li><code>datacatalog.tagTemplates.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                             |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>AWS Lightsail bucket accessible to unmonitored cloud accounts</strong></td><td><p><strong>Policy Description—</strong> AWS Lightsail buckets with permissions granted to unmonitored cloud accounts pose a significant security risk. These buckets, offering internet-accessible storage, could be compromised if unauthorized accounts gain access.</p><p>Lightsail buckets provide object storage, allowing data retrieval from anywhere. Granting 'read' access to unmonitored cloud accounts introduces a substantial risk. Attackers might exploit this misconfiguration to exfiltrate sensitive data or inject malicious content, potentially leading to data breaches or system compromise.</p><p>To mitigate this risk, restrict access to Lightsail buckets to only explicitly trusted and monitored cloud accounts. Only trusted and monitored cloud accounts should possess the necessary permissions.</p><p>Regularly review and audit bucket permissions, removing access for any unmonitored or untrusted accounts. Implement robust monitoring and alerting to detect any unauthorized access attempts.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-lightsail-storage-bucket' AND json.rule = 'readonlyAccessAccounts is not empty and _AWSCloudAccount.isRedLockMonitored($.readonlyAccessAccounts[*]) is false'`
</code></pre></td></tr><tr><td><strong>AWS Lightsail bucket publicly readable</strong></td><td><p><strong>Policy Description—</strong> Publicly readable objects in AWS Lightsail buckets expose sensitive data to unauthorized access, increasing the risk of data breaches and reputational harm.</p><p>AWS Lightsail provides object storage through buckets, enabling data storage and retrieval. A misconfiguration allowing public readability exposes all stored data. Untrusted parties can freely access this information, leading to data exfiltration, intellectual property theft, and financial losses.</p><p>To mitigate this risk, enforce the principle of least privilege. Restricting bucket access to authorized users is crucial for maintaining data confidentiality and integrity.</p><p>Configure bucket permissions to be private, only granting access to specific users or groups needing it. Regularly review and audit bucket access controls to detect and address any misconfigurations promptly.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-lightsail-storage-bucket' AND json.rule = accessRules.getObject equal ignore case public as X; config from cloud.resource where api.name = 'aws-s3control-public-access-block' AND json.rule = blockPublicAcls is false or blockPublicPolicy is false or ignorePublicAcls is false or restrictPublicBuckets is false as Y; filter '$.X.arn contains $.Y.accountId' ; show X;
</code></pre></td></tr><tr><td><strong>AWS Lightsail bucket object versioning is disabled</strong></td><td><p><strong>Policy Description—</strong> AWS Lightsail buckets lacking object versioning are susceptible to data loss and unauthorized modification. Disabling this feature removes the ability to revert to previous versions of objects after accidental deletion or malicious alteration.</p><p>Lightsail buckets provide object storage, allowing data access from anywhere. Object versioning creates version history for every object stored. Without versioning, accidental deletion or malicious overwrites result in permanent data loss, severely impacting data integrity and potentially leading to business disruption or data breaches. Attackers could exploit this misconfiguration to permanently delete or modify critical data.</p><p>To mitigate this risk, enable object versioning on all AWS Lightsail buckets, this ensures data recoverability, protecting against accidental or malicious actions and mitigating the risk of significant data loss.</p><p>Regularly review bucket configurations to ensure object versioning remains active. Implement robust access control mechanisms.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-lightsail-storage-bucket' AND json.rule = objectVersioning does not equal ignore case Enabled
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS CloudTrail is not enabled with multi-trail and not capturing all management events</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to reduce false positives when both management events and network activity events are configured.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name= 'aws-cloudtrail-describe-trails' AND json.rule = 'isMultiRegionTrail is true and includeGlobalServiceEvents is true' as X; config from cloud.resource where api.name= 'aws-cloudtrail-get-trail-status' AND json.rule = 'status.isLogging equals true' as Y; config from cloud.resource where api.name= 'aws-cloudtrail-get-event-selectors' AND json.rule = '(eventSelectors[*].readWriteType contains All and eventSelectors[*].includeManagementEvents equal ignore case true) or (advancedEventSelectors[*].fieldSelectors[*].equals contains "Management" and advancedEventSelectors[*].fieldSelectors[*].field does not contain "readOnly" and advancedEventSelectors[*].fieldSelectors[*].field does not contain "eventSource")' as Z; filter '($.X.trailARN equals $.Z.trailARN) and ($.X.name equals $.Y.trail)'; show X; count(X) less than 1
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name= 'aws-cloudtrail-describe-trails' AND json.rule = 'isMultiRegionTrail is true and includeGlobalServiceEvents is true' as X; config from cloud.resource where api.name= 'aws-cloudtrail-get-trail-status' AND json.rule = 'status.isLogging equals true' as Y; config from cloud.resource where api.name= 'aws-cloudtrail-get-event-selectors' AND json.rule = '(eventSelectors[*].readWriteType contains All and eventSelectors[*].includeManagementEvents equal ignore case true) or (advancedEventSelectors[?any(name exists and name contains "Management events selector" and fieldSelectors[*].field does not contain "readOnly" and fieldSelectors[*].field does not contain "eventSource")]exists)' as Z; filter '($.X.trailARN equals $.Z.trailARN) and ($.X.name equals $.Y.trail)'; show X; count(X) less than 1
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Existing alerts where all management event is configured and the event selector is configured as part of network activity event will be resolved.</p></td></tr><tr><td><strong>Azure Container Registry with anonymous authentication enabled</strong></td><td><p><strong>Changes—</strong> The policy RQL will be updated to trigger an alert on Azure container registry when anonymous pull is enabled, resolving false alerts.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-container-registry' AND json.rule = (skuName contains Standard or skuName contains Premium) and properties.provisioningState equal ignore case Succeeded and properties.anonymousPullEnabled is false
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-container-registry' AND json.rule = (skuName contains Standard or skuName contains Premium) and properties.provisioningState equal ignore case Succeeded and properties.anonymousPullEnabled is true
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> High</p><p><strong>Impact–</strong> High. Existing alerts where the anonymous pull is disabled will be resolved and new alerts will be generated where the anonymous pull is enabled.</p></td></tr><tr><td><strong>GCP Load balancer HTTPS target proxy is not configured with QUIC protocol</strong></td><td><p><strong>Changes—</strong> The policy RQL policy will be updated in the case of regional internal load balancers.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-target-https-proxies' AND json.rule = 'quicOverride does not contain ENABLE'
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-target-https-proxies' AND json.rule = 'quicOverride does not contain ENABLE' as X; config from cloud.resource where api.name = 'gcloud-compute-internal-lb-backend-service' as Y; filter 'not ($.Y.usedBy[*].reference contains $.X.urlMap)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Existing alerts for regional internal application load balancer will be resolved.</p></td></tr><tr><td><strong>Instance affected by Spring Cloud Function SpringShell vulnerability is exposed to network traffic from the internet [CVE-2022-22963]</strong></td><td><p><strong>Changes—</strong> The policy RQL policy will be updated to consider internet network traffic as the source.</p><p><strong>Current RQL–</strong></p><pre><code>network from vpc.flow_record where bytes > 0 AND source.resource IN (resource where finding.type IN ( 'Host Vulnerability' ) AND finding.source IN ( 'Prisma Cloud' ) AND finding.name IN ('CVE-2022-22963')) AND destination.publicnetwork IN ('Internet IPs', 'Suspicious IPs')
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>network from vpc.flow_record where bytes > 0 AND dest.resource IN (resource where finding.type IN ( 'Host Vulnerability' ) AND finding.source IN ( 'Prisma Cloud' ) AND finding.name IN ('CVE-2022-22963')) AND source.publicnetwork IN ('Internet IPs', 'Suspicious IPs')
</code></pre><p><strong>Policy Type–</strong> Network</p><p><strong>Policy Severity–</strong> Critical</p><p><strong>Impact–</strong> Low.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Cloud Security Assurance Program**                         | <p>Prisma Cloud now supports the latest version of Cloud Security Assurance Program (CSAP). This compliance standard supports five different levels - IaaS, SaaS Standard, SaaS Simplified, Low and Low SaaS. CSAP aims to boost confidence among public and private sector users, promoting secure cloud adoption and enhancing overall national cybersecurity.</p><p>You can now access this built-in standard and related policies on the <strong>Compliance > Standards</strong> page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.</p> |
| **\[Update] Korea – Information Security Management System** | <p>New Policy mappings are added to Korea – Information Security Management System (ISMS) compliance standard.</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **\[Update] NIST CSF v2.0**                                  | <p>New Policy mappings are added to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) v2.0 compliance standard.</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                   |

## REST API Updates

| **REST API**                                          | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Perform Event Search API**                          | <p>The request body for <strong>Perform Event Search</strong> - <a href="https://pan.dev/prisma-cloud/api/cspm/search-events">POST /search/event</a> has been updated.</p><p>Possible values for sort fields are updated from upper case to lower case.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Support CaaS Specification References Field**       | A new `hasCAASSpecReferences` query parameter has been introduced to [Get Registry Scan Results](https://pan.dev/compute/api/get-registry/), [Download Registry Scan Results](https://pan.dev/compute/api/get-registry-download/) and [Get Registry Image Names](https://pan.dev/compute/api/get-registry-names/) APIs to enable registry image filtering deployed as part of CaaS specifications (AWS Fargate, GCP Cloud Run, ACI). This parameter only applies to Prisma onboarded accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Support Images Field**                              | A new `images` query parameter has been added to the [Get Discovered Cloud Entities](https://pan.dev/compute/api/get-cloud-discovery-entities/) API to filter cloud-discovered entities by the container image names defined in a CaaS specification (AWS Fargate Task Definition, GCP Cloud Run, ACI). This parameter only applies to Prisma onboarded accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Support Service Field**                             | A new `service` parameter has been introduced to the [Get Discovered Cloud Entities](https://pan.dev/compute/api/get-cloud-discovery-entities/) API response to specify the discovered GCP Cloud Run service name. This parameter only applies to Prisma onboarded accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Support CaaS Specification References Total Field** | A new `caasSpecReferencesTotal` parameter has been introduced to [Get Host Scan Results](https://pan.dev/compute/api/get-hosts/), [Get Image Scan Results](https://pan.dev/compute/api/get-images/), [Get Impacted Container Compliance Policy](https://pan.dev/compute/api/get-policies-compliance-container-impacted/), [Get Impacted VMs Compliance Policy](https://pan.dev/compute/api/get-policies-compliance-vms-impacted/), [Host App Firewall Policy Impacted](https://pan.dev/compute/api/get-policies-firewall-app-host-impacted/), [Get Impacted Host Vulnerability Policy](https://pan.dev/compute/api/get-policies-vulnerability-host-impacted/), [Get Impacted Image Vulnerability Policy](https://pan.dev/compute/api/get-policies-vulnerability-images-impacted/), [Get Registry Scan Results](https://pan.dev/compute/api/get-registry/) and [Get VM Image Scan Results](https://pan.dev/compute/api/get-vms/) APIs to specify the referenced number of CaaS specifications (AWS Fargate Task Definition, GCP Cloud Run, ACI). This parameter only applies to Prisma onboarded accounts. |
| **Support for a Amazon Fargate Task Definition**      | A new Enum value `aws-fargate-task-definition` has been added to `shared.ScanResultType` schema to specify a new scan result type of Amazon Fargate Task Definition. This parameter only applies to Prisma onboarded accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-march-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
