Jan 07, 202525.1.7

Release Summary

InsightCloudSec is pleased to announce release version 25.1.7. This release includes expanded source document support, new Query Filters and Insights, and a resource renaming.

New Permissions: AWS

The following permission were missing and are required to support the API Gateway resource.

  • "apigateway:GET"
Details for self-hosted customers

New

  • Added the following Query Filters:
    • Cloud Account GCP CIS Monitoring Missing
    • Cloud Account GCP CIS Notification Channels Missing
    • Cloud Account GCP CIS Alerting Missing
    • Cloud Account without DLP Enabled
  • Added source document support for AWS IAM Certificates.
  • Added the following Insights:
    • Cloud Account without DLP Enabled

Improved

  • Updated API Keys Not Rotated Within 90 Days Insight to include a generic multi-cloud overview section and include Center for Internet Security (CIS) remediation steps.
  • Updated Cloud User Assigned Service Account User/Service Account Admin Permissions Insight for CIS remediation steps.
  • Updated Encryption Key Exposed To Public Insight for CIS remediation steps.
  • Updated Cloud User Assigned Service Account User/Service Account Token Creator Permissions for CIS remediation steps.
  • Updated Cloud User Without KMS Separation of Duties for CIS remediation steps.
  • Updated Cloud Credential For Disabled API for CIS remediation steps.
  • Discontinued calculating risk scores for the Threat Findings, Threat Finding Resources, Recommendations, and Recommendation Findings resources.
  • Updated the Google Cloud Platform (GCP) Network Firewall resource name to Firewall Rule to more accurately reflect GCP's nomenclature.
  • Added a Create Database Instance Snapshot action for GCP Database Instance resources in the Inventory > Resources view.
  • Added a policy processor to the Infrastructure as Code (IaC) scanner.

Fixed

  • Fixed an issue that was preventing the Send Email Summary with Details CSVs Bot Action from operating on Instance data.
  • Added missing "apigateway:GET" permission to the AWS onboarding script.
  • Fixed the Container Instance resource ID for Kubernetes resources that are not removable.
  • Fixed an issue that caused Host Vulnerability Assessment (HVA) to re-assess instances even though they had been assessed recently.