This release adds 3 notable features for engineering teams evaluating rollout.
Published 1mo
Forensics & Incident Response
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
agent-ai-cli
agent-security
ci-cd
claude-code
cloud
codex
+7 more
cursor
detection-engineering
endpoint-security
mobile-device-management
security
security-information-and-event-management
security-tools
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryUpdates Other, rules, and Bug Fixes across a mixed release.
Full changelog
Changelog
Features
- 0bc83d7ee7814ee741f93fb0b73cf14e63b6596c feat(rules): add 18 threat-detection rules across 6 categories (#237)
- 3fd8581bfe7b481c62bdd54d154c68fd3446472d feat(rules): add 3 credential-access rules — k8s, gpg, password managers
- 42924b0aa7b2b60d757e4c6e85b8b9ae65ca2fbc feat(rules): add 3 sensitive-edit rules — SSH keys, /etc/hosts, container/IaC
- 0891ab8e84b8804cccf333dbe89aa34b5ab53570 feat(rules): add 6 rules across risky-command, context-exfiltration, source-control
- 8c83eeec8e356a5fdf256e00ffadc794f0877446 feat(rules): add 6 threat rules — agent-control, resource-consumption, approval-abuse
Bug Fixes
- b7f90c147d3803369ce0ca4e299aea5cebfb611f fix(rules): add unshare short-flag detection (-m/-n/-p/-i/-u/-C/-A/-r)
- ccbd9560725c82407d57d8250a6a4f3efe9dd8a3 fix(rules): allow sudo anchor on ssh-tunnel-egress
- 29bdb56f16458653472b40c7cd7707ac3615a343 fix(rules): anchor approval-bypass -rf/-fr flags to rm-like binary basename
- a7b237dafcfafdc71a4e3f7e6a6372148e8fa318 fix(rules): detect top-level /tmp and /var redirects in disk-fill-attempt
- 29a77217425dfa3b295e06276998203cb4ebd189 fix(rules): drop disjunct 2 in archive-then-upload to require archiver-pipe-curl shape
- bce3d674054d18500bce0116528b73b25ad9adf4 fix(rules): extend sandbox-escape launchers to nohup/setsid/command/exec
- ff1b9f8d9fd3f469ad23867f28793930998656f2 fix(rules): require token boundaries on protected-branch names
- 2e8a27c949d59d42bdc457d825061ae973b6c4af fix(rules): tighten approval-bypass rm-anchor to require /tmp/ path prefix
- 4bfcf42a369530d4118ba4fac93023a58c4926f4 fix(rules): tighten kubernetes-secret-file-read token path patterns
- 6006da80888b12bdbe9bc8bc61a27ded87be25d6 fix(rules): tighten modprobe module-name match against info subcommands
Other
- 682cf7435ce52b1bbe1266f613ad3f6c872b9311 Add opt-in content capture to inventory with redaction (#239)
- 3b60e455f3ff90ab105573e104cde3e66ac54f39 Add opt-in full-content capture to endpoint inventory
- 19dce12901c00a7bd65fddd663fab7ac705059cd Extend MCP event schema (#238)
- c814fdda9287f13c6aa825538430f010c1ccfd04 Update agent instructions to include packaging vector (#235)
- c2a32a44252f810675d92bbb184dba5fcd3891c5 Update detection docs page (#236)
- a47ad256daddfcb887d07f2dc7c24fe330addcef Update onboarding docs, add script to sign + notarize packages (#233)
- 715a5d12b4609c6367c1cc047dce36ab91c0e6e6 Update onboarding tag (#234)
- e315184e47c5f250b5766f2a3465d28da862c551 docs(detections): document 18 new threat rules across 6 categories
- d6822b163273fda66c68437d57ac3a77abda2ab4 extend mcp schema
- b44dacc0156d9195e13d85db73ab966948f59b90 fix duplicate events
- 0e654b1c554eb796f773434781aa1bb55b814b48 fix json rpc id lookups
- 53d9a9db0792a2a0bf074a02c93d8d9d20c16027 fix redaction
- 6640be300218662082edf1e062d28465c9d1c6ca fix redirects
- 49a42c6c671860bafc5f29f546273c5748867d0f post tool testing
- d2196b490156909a300eb3aa9c44a2be05f9701f update content
- b6dd4940545cf9ce386584152a56536f94c6d475 update docs
- 21d61dd844bcf7ef82fa112ae411147fc1d039ff update docs
- fa42de613bbc15c5a1663978df491cbae8cab5d8 update docs, add script to notarize
- 8143f84e0db6011490bfd95f64608dfa88c45cc7 update instrs
- 67a9a9a68d194ceeba34e5d9eb22747f3b09f28c update tag
Installation
Homebrew (macOS/Linux)
brew tap asymptote-labs/tap
brew install beacon
Manual Download
Download the appropriate archive for your platform from the assets below, extract it, and add the binary to your PATH.
Quick Start
beacon endpoint install
beacon endpoint status
beacon endpoint wazuh print-config
Threat detection rules
beacon ships with a small built-in baseline. Install the full threat-rule
pack (attached as threat-rules.tar.gz below) and scan your local telemetry:
beacon rules pull https://github.com/asymptote-labs/agent-beacon/releases/download/v0.0.75/threat-rules.tar.gz
beacon rules list
beacon scan
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Beacon
All releases →Related context
Related tools
Earlier breaking changes
- v0.0.54 Require cloud run ID before upload
Beta — feedback welcome: [email protected]