Platform Engineering
IaC, container orchestration, service mesh, and internal developer platforms.
Config change
Breaking upgrade
Untrusted Terraform security hardening
v7.67.0
(1mo)
FIX: FALSE-PASS CRITICAL
v7.47.0
(1mo)
OIDC RBAC bypass fix
v8.2.2
(2mo)
CVE fix + bug fixes
v2.24.5
(2mo)
Azure identity hardening
v2.29.13
(2mo)
Security fixes + Go upgrade
v2.31.12
(2mo)
CVE security fixes
v2.32.2
(2mo)
CVE-2026-33814 fix
v2.33.3
(2mo)
CVE fixes
Breaking changes
- Secrets scanner now reports only the first multiline regex match per file, reverting previous behavior that reported all matches.
⚠ Upgrade required
- Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
- CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
- Cisco Secure Access Analytics analytic story using firewall telemetry
- Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
Security fixes
- Patched vulnerable frontend dependencies (#15661)
Security fixes
- Fixed access token renewal bypassing important checks
- Blocked callback URLs with javascript: and data: protocols
Notable features
- Admins can now revoke user passkeys
- Added auth method claim (amr) to OIDC tokens
- Added TLS support for HTTP/2 server
Get this as a security brief. Track Platform Engineering releases straight to your inbox.