About patch releases
About patch releases
- Rolled out via xCloud - These updates are applied automatically and become available in your xorlab environment without any action required.
- Available via upgrade - For SaaS customers, updates are deployed gradually during scheduled maintenance windows. For on-premise customers, a manual upgrade is required.
Rolled out via xCloud
- [SA-16173] Rules: Add new high-confidence rule
SPAM_untrusted_domain_only_inbound_matches_popular_service_not_popular_auth(ACTIVEby default). This rule catches more phishy spam, e.g., where the spammer impersonates Galaxus. - [SA-16305] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_sender_global_reputation_low(ACTIVEby default). This rule catches more invoice-based phishing. - [SA-16348] Rules: Improve our internal scores for certain payment providers to reduce FP.
Available via upgrade
- [SA-16126] MTA, XCC, Dana: Address issue which causes host upgrades to fail if not enough space is available on the
/bootpartition. - [SA-16349] MTA: The ConfigClient is now more resilient against corrupted or otherwise incomplete meta-info files.
- [SA-16268] XCC: Expert config editor prevents invalid
roleMappinginauth.yml.
Rolled out via xCloud
- [SA-16173] Rules: Add new high-confidence rule
SPAM_untrusted_domain_only_inbound_matches_popular_service_not_popular_auth(ACTIVEby default). This rule catches more phishy spam, e.g., where the spammer impersonates Galaxus. - [SA-16236] Rules: Improve
PHISHING_untrusted_domain_only_inbound_sender_global_reputation_low_matches_keywordto catch more phishing. - [SA-16291] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_untrusted_only_inbound_forged_replyto_non_configured_ccsend(ACTIVEby default). This rule improves detection for package delivery phishing. - [SA-16305] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_sender_global_reputation_low(ACTIVEby default). This rule catches more invoice-based phishing. - [SA-16348] Rules: Improve our internal scores for certain payment providers to reduce FP.
Available via upgrade
Rolled out via xCloud
- [SA-16236] Rules: Improve
PHISHING_untrusted_domain_only_inbound_sender_global_reputation_low_matches_keywordto catch more phishing.
Available via upgrade
- [SA-16321] Core: Fixed a regression introduced in 11.0.6 that could cause sender authenticity to be evaluated incorrectly, resulting in legitimate senders being marked as unauthentic.
- [SA-16288] UI: Fixed the Abuse Mailbox chart tooltip so it stays above the legend and updates its value correctly when hovering between priority segments.
Rolled out via xCloud
- [SA-10215] MTA: Introduce trustedMta config option
typeto better control how and when to trust received-headers. - [SA-16291] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_untrusted_only_inbound_forged_replyto_non_configured_ccsend(ACTIVEby default). This rule improves detection for package delivery phishing.
Available via upgrade
- [SA-16289] MTA: Address CVE-2026-14266 in
7zip. - [SA-16170] XCC: Fixed an issue where the sender could appear as unauthenticated in the UI due to inconsistent letter casing.
Rolled out via xCloud
- [SA-16043] Rules: Add new high-confidence rule
PHISHING_untrusted_domain_only_inbound_matches_multiple_delivery_keywords_short_body(ACTIVEby default). This rule enables us to catch more package delivery phishing. - [SA-16093] Rules: Add new rule
BEC_bcc_only_only_media_files_link_subdomain_provider_cloud_storage(ACTIVEby default). This rule improves our ability to catch BEC cases, where the attacker host the payload on a cloud storage provider. - [SA-16203] Rules: Add new high-confidence rule
PHISHING_untrusted_domain_only_inbound_sender_global_reputation_low_matches_keyword(ACTIVEby default). This rule catches more invoice phishing.
Available via upgrade
- [SA-5450] MTA: Add a
mta-down-gracefulshell utility which first blocks new traffic, drains the queues and then shuts-down the MTA. - [SA-16094] MTA: Enforced a stricter input size limit for URL extraction to improve resource utilization and prevent timeouts.
- [SA-16106] MTA: Fixed an issue that could cause attachments to be skipped during analysis under certain conditions.
- [SA-16197] UI: Fix a bug where long images were displayed in full size without the ability to scroll them.
Rolled out via xCloud
- [SA-16043] Rules: Add new high-confidence rule
PHISHING_untrusted_domain_only_inbound_matches_multiple_delivery_keywords_short_body(ACTIVEby default). This rule enables us to catch more package delivery phishing. - [SA-16093] Rules: Add new rule
BEC_bcc_only_only_media_files_link_subdomain_provider_cloud_storage(ACTIVEby default). This rule improves our ability to catch BEC cases, where the attacker host the payload on a cloud storage provider. - [SA-16203] Rules: Add new high-confidence rule
PHISHING_untrusted_domain_only_inbound_sender_global_reputation_low_matches_keyword(ACTIVEby default). This rule catches more invoice phishing.
Available via upgrade
Rolled out via xCloud
Available via upgrade
- [SA-16111] MTA, XCC, Dana: Fix issues with background package management commands interfering with ones running in the foreground.
- [SA-16143] MTA, XCC: Trust “DigiCert Global Root CA”, which was recently removed from Mozilla’s list of trusted roots. M365 services, notably MTAs require us to still trust this root.
- [SA-16142] MTA: Fix an issue that caused analysis results to be too large to be published to XCC.
Rolled out via xCloud
Available via upgrade
- [SA-16142] MTA: Fix an issue that caused analysis results to be too large to be published to XCC.
- [SA-16143] MTA, XCC: Trust “DigiCert Global Root CA”, which was recently removed from Mozilla’s list of trusted roots. M365 services, notably MTAs require us to still trust this root.
Rolled out via xCloud
- [SA-15996] Rules: Add new high-confidence rule
SPAM_ml_only_inbound_non_reputable_link_with_path_no_local_reputation(ACTIVEby default). This rule catches various kinds of spam messages from only-inbound senders. - [SA-16029] Rules: Add new high-confidence rule
SPAM_only_inbound_low_reputation_one_shortened_link(ACTIVEby default). This rule targets mass online pharmacy spam. - [SA-16086] Rules: Add new high-confidence rule
PHISHING_ml_topic_invoice_account_issue_package_delivery_displayname_similar_to_popular(ACTIVEby default). This rule catches phishing attempts where the sender tries to appear to be a renowned service.
Available via upgrade
- [SA-16074] XCC: Fix a mismatch where we had the tag
#noauthbut the UI showed the sender as authenticated. - [SA-16087] XCC: Fixed duplication issue that caused three malware entries to display when resolving a case via the dropdown menu.
- [SA-16096] XCC: Resolve an issue where the UI would show a sender as not authenticated, even though the tag
#authis also present. - [SA-16109] XCC: Fixed bug that prevented users with role
xcc_tenant_analystto use the user interface. - [SA-16118] XCC: Fixed issue that caused email templates to not to be hot-reloaded.
- [SA-16077] UI: Fixed a bug where, in some cases, both the current message and the empty state were shown in the similar list if the search had no matches.
- [SA-16078] UI: Fixed a regression where clicking on a folders would not collaps/espand it.
- [SA-16119] UI: Fixed issue that prevented the saved search time range to be shown.
- [SA-16052] UI: Fixed a bug that could cause one image to be skipped when using the arrow keys to navigate to the next/previous image.
- [SA-16079] UI: Fixed a layout issue where the reported icon was displayed wrongly in similar list.
- [SA-16095] UI: Fixed an issue causing images to flicker in Firefox in some instances.
Rolled out via xCloud
- [SA-15996] Rules: Add new high-confidence rule
SPAM_ml_only_inbound_non_reputable_link_with_path_no_local_reputation(ACTIVEby default). This rule catches various kinds of spam messages from only-inbound senders. - [SA-16029] Rules: Add new high-confidence rule
SPAM_only_inbound_low_reputation_one_shortened_link(ACTIVEby default). This rule targets mass online pharmacy spam. - [SA-16086] Rules: Add new high-confidence rule
PHISHING_ml_topic_invoice_account_issue_package_delivery_displayname_similar_to_popular(ACTIVEby default). This rule catches phishing attempts where the sender tries to appear to be a renowned service.
Available via upgrade
- [SA-16008] XCC: Restored
Europe/Zurichas the default time zone for quarantine digests. Due to a regression, new schedules were incorrectly created in UTC. - [SA-16064] XCC: Fixed DMARC alignment computation in the UI. Some emails with authenticated senders were incorrectly displayed as failing authentication.
- [SA-16074] XCC: Fix a mismatch where we had the tag
#noauthbut the UI showed the sender as authenticated. - [SA-16096] XCC: Resolve an issue where the UI would show a sender as not authenticated, even though the tag
#authis also present.
Highlights
- [SA-5068] UI: Users with self-service quarantine access can now archive quarantined emails to keep their view clean. The archived messages are hidden from the main view but remain accessible at any time.
- [SA-14132] UI: Onboarding a new Microsoft 365 tenant can now start immediately using retrospective email scanning. This feature allows xorlab to scan historical email traffic to initialize relationship scores and reputations right away, reducing the learning period and false positives in early deployment.
- [SA-6123] XCC: Allow lists, block lists, and VIP lists can now be managed programmatically via REST API. All changes done via APIs are scoped, token-authenticated, and audit-logged.
UX improvements and fixes
- [SA-14961] UI: Improved error reporting for case isolation, showing a specific error message when isolation fails because the target mailbox is on-premises, disabled, or deleted.
- [SA-15191] UI: Removed double scrollbars appearing in message lists.
- [SA-15353] UI: Fixed a bug where loading more results after entering an invalid query displayed a page error.
- [SA-15384] UI: Removed the label from the actions column header in the self-service quarantine attachment list.
- [SA-15385] UI: Fixed an inconsistency where two different delete icons were used across the UI.
- [SA-15438] UI: Removed an unnecessary data reload that occurred after closing the unlock message dialog.
- [SA-15755] UI: Improved the attachments table to expand and better fill the available space.
- [SA-15787] UI: Add the ability to open a link on a new tab on sidebar submenus by using the middle button (or Ctrl+Click).
- [SA-15788] UI: Fixed a bug where clicking a dashboard link would reset the selected tenant.
- [SA-15794] UI: Removed the tooltip animation for the open case priorities chart.
- [SA-15840] UI: Fixed a bug where a long mail subject could break the layout.
- [SA-15875] UI: Added missing column padding in blocklist/allowlist dialogs.
Multi-Tenancy improvements
- [SA-12705] XCC: Case isolation can now be configured for multiple tenants.
- [SA-14149] Core: Added per-tenant tuning of several message processing parameters.
- [SA-15237] Core: Added native support for tenant-specific rules and rule profiles.
Detection improvements
- [SA-11086] Core: Improved detection for resource-intensive archives like zip bombs.
- [SA-15131] Rules: Ensure
#deliverand#benigntags are set properly on emails with directionexternal.
Breaking changes
-
[SA-14193] MTA: This release removes the internal
unboundDNS resolver. This breaking change affects on-prem customers only; SaaS customers are not affected. All DNS requests are now resolved via the DNS server configured on the host. In standard on-prem configurations, no action is required. To verify whether your setup is affected:- Open
activeguard/core/startup_cfg/unbound.confin the Expert Editor. - If the file does not contain an active
forward-zoneentry, no action is required. - If such an entry exists, compare the configured
forward-addrwith the host DNS server by runningresolvectl statuson any MTA and checkingCurrent DNS Server. If it is not the same, contact support@xorlab.com.
- Open
- [SA-6123] XCC: Lists exceeding 10’000 entries will now be automatically truncated. If any of your lists is affected, please contact support@xorlab.com to have the maximum limit adjusted and the previous content restored.
-
[SA-12205] XCC: When using the M365 Abuse Mailbox, emails reported by users as “Not Junk” will now be auto-resolved as benign (with precedence over campaigns). No report acknowledgment or feedback will be sent to the user for these cases. To revert to the previous behavior, follow the instructions.
Reported phishing simulation emails are unaffected: they are still auto-resolved and feedback is still sent.
In addition, xorlab now sets these tags for M365 Abuse Mailbox reports:
#reportedasnotjunk,#reportedasjunk,#reportedasphishing. -
[SA-12205] XCC: The tags
#simulationand#recipientdroppedcannot be used anymore in campaigns. Existing campaigns with those tags will still work as before, but marked as deprecated in the GUI. -
[SA-15254] XCC: Simplification of Auth configuration (
auth.yml). Support for multiple file-based data sources in a username-password auth backend has been dropped. With this release, only one file-based data source is supported. By default, the file-based data source is enabled with the users specified in thepasswordFile.ymlfile. No action is required. Existing configuration will be migrated into a conforming state. -
[SA-15293] XCC: The
xcc.ymlsettingfrontend.triageDefaultSelection.classificationhas been removed. No action is required. -
[SA-15119] Rules: The
exploitverdict has been merged intomalware. As of this release, theexploitverdict and the#exploittag have been removed. For any cases where theexploitverdict was assigned, xorlab will now fall back to themalwareverdict. Similarly, any attachment transformation policies that are configured forexploitwill fall back to the configuredmalwarepolicy. -
[SA-15207] Rules: Removal of the
monitoring_mode.propertiesrule profile For setups that are configured to run in Monitoring mode and themonitoring_mode.propertiesprofile is configured inactive_guard.yml(underrules→params), the automatic migration will replace it withdefault_actions.properties. This changes some default decision actions as follows:- The medium confidence filter/policy action changes from
DELIVERtoQUARANTINE - The medium confidence impersonation action changes from
DELIVERtoQUARANTINE - The medium confidence VIP fraud action changes from
DELIVERtoQUARANTINE
- The medium confidence filter/policy action changes from
Bugfixes and improvements
- [SA-14836] MTA: Prevent Postfix from performing SMTP requests using IPv6 leading to error logs.
- [SA-15003] MTA: Fix “Postfix down” alerts, postfix_exporter now restarts unhealthy log sources.
- [SA-15006] MTA: Address a changed metric label affecting the Postfix queue size alert and the MTA monitoring dashboard.
- [SA-15025] MTA: Improve Postfix SMTP security defaults.
- [SA-15105] MTA: In this release, we disabled additional authentication methods that were not following the DMARC RFC. By default, these methods are now disabled because they caused senders to be authenticated when sent via certain cloud mailer services, even though they should not be considered authenticated under DMARC.
- [SA-15338] MTA: Fix problem where tenant assignment would fail in monitoring mode in certain cases.
- [SA-15458] MTA: Overhauled envelope extraction configuration to switch between inline and monitoring mode.
- [SA-15556] MTA: Adjust rspamd default configuration. Reduce number of retries when querying 3rd party DNS lists.
- [SA-15945] MTA: Fix issue where rspamd would not fully recover after a start or config update if the backend was temporarily unavailable.
- [SA-11966] XCC: Auth now supports TOTP-based multi-factor authentication for users specified in the password file.
- [SA-15284] XCC: Fix redacted subject being visible during PENDING state.
- [SA-15395] XCC: Users with an unknown or no tenant assignment are now able to store some user settings (e.g. the UI theme).
- [SA-15545] XCC: Introduce a new audit trail event
audit.xcc_instance_metrics.submitted, which is triggered when the metrics are submitted to xorlab. - [SA-15717] XCC: Fix issue where pending release requests where not marked as approved if approval was bypassed by an release action.
Rolled out via xCloud
Available via upgrade
- [SA-15913] Dana: Reduced exposure of potentially sensitive information by no longer logging certain HTTP request headers.
- [SA-16008] XCC: Restored
Europe/Zurichas the default time zone for quarantine digests. Due to a regression, new schedules were incorrectly created in UTC. - [SA-16061] XCC: Fixed an issue introduced with the release 11 upgrade where the first counter lookup always returned 0, causing tags such as
#domainfirstcontactto be applied to emails from known senders. - [SA-16064] XCC: Fixed DMARC alignment computation in the UI. Some emails with authenticated senders were incorrectly displayed as failing authentication.
Rolled out via xCloud
- [SA-15960] Rules: Disabled spam classifier training during mail imports, as classifiers are shared across tenants.
- [SA-15970] Rules: Improved IBAN detection (see
#ibantag).
Available via upgrade
- [SA-16013] Dana: Ensure packages are properly upgraded to prevent startup failures caused by outdated AppArmor profiles.
- [SA-15885] XCC: Ensure proper sanitization of attacker-controlled content in quarantine digests.
- [SA-16017] XCC: Fixed intermittent counter update failures caused by a database constraint violation.
Rolled out via xCloud
-
[SA-14440] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_untrusted_nonreputable_body_matches_multiple_urgency_keywords_popular_service(ACTIVEby default). This rule catches more account issue phishing. -
[SA-15328] Rules: Add a new high-confidence rule
PHISHING_unknown_never_delivered_cloudmailer_autogenerated_keywords(ACTIVEby default) to catch phishing sent via abused cloud mailing services. -
[SA-15544] Rules: Add new high confidence rule
PHISHING_domain_only_inbound_html_short_link_image_short_body(ACTIVEby default). This rule improves our ability to catch more “account problem” phishing. -
[SA-15754] Rules: Add a new high-confidence rule
PHISHING_non_reputable_only_inbound_popular_displayname_guarded_subject(ACTIVEby default). This rule targets phishing disguised as notifications from popular services. -
[SA-15754] Rules: Add a new high-confidence rule
SPAM_only_inbound_phishing_keywords_video(ACTIVEby default). This rule targets video-based spam messages. -
[SA-15822] Rules: Add a new high-confidence rule
MALWARE_only_inbound_noauth_ole(ACTIVEby default) to catch malware embedded in Office documents. -
[SA-15833] Rules: Add two new high-confidence rules (
ACTIVEby default):SPAM_untrusted_very_young_domain_link_count_is_exactly_one: Blocks spam coming from very young sender domainsPHISHING_untrusted_freemail_very_young_domain: Blocks phishing coming from very young sender domains
-
[SA-15835] Rules: Add a new high-confidence rule
PHISHING_untrusted_only_inbound_body_displaytext_document_signature_keyword_link_with_no_reputation(ACTIVEby default). This rule targets document-signing phishing. -
[SA-15835] Rules: Add a new high-confidence rule
SPAM_untrusted_noreputation_popular_displayname_link_mismatches_from_domain(ACTIVEby default). This rule targets spam where the sender attempts to impersonate a popular service. - [SA-15903] Rules: Treat VHD and VHDX disk images as malware.
-
[SA-15905] Rules: Add a new high-confidence rule
SPAM_only_inbound_obfuscated_text(ACTIVEby default) to catch malicious emails applying various obfuscation techniques. -
[SA-15921] Rules: Update and improve the existing rule
EXTORTION_nonreputable_untrusted_match_multiple_keywords. With this change, it catches even more extortion cases. -
[SA-16004] Rules: Add a new high-confidence rule
PHISHING_only_inbound_freemail_file_scheme(ACTIVEby default) to catch a wave of credential stealing phishing using thefile:URI scheme.
Available via upgrade
- [SA-15556] MTA: Adjust rspamd default configuration. Reduce number of retries when querying 3rd party DNS lists.
- [SA-15945] MTA: Fix issue where rspamd would not fully recover after a start or config update if the backend was temporarily unavailable.
- [SA-15840] UI: Fixed a bug where a long mail subject could break the layout.
- [SA-15871] UI: Fixed tree view item highlighting in Expert Editor.
- [SA-15934] UI: Fixed the formula displayed in the time saved panel.
Rolled out via xCloud
-
[SA-14440] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_untrusted_nonreputable_body_matches_multiple_urgency_keywords_popular_service(ACTIVEby default). This rule catches more account issue phishing. -
[SA-15328] Rules: Add a new high-confidence rule
PHISHING_unknown_never_delivered_cloudmailer_autogenerated_keywords(ACTIVEby default) to catch phishing sent via abused cloud mailing services. -
[SA-15544] Rules: Add new high confidence rule
PHISHING_domain_only_inbound_html_short_link_image_short_body(ACTIVEby default). This rule improves our ability to catch more “account problem” phishing. -
[SA-15754] Rules: Add a new high-confidence rule
PHISHING_non_reputable_only_inbound_popular_displayname_guarded_subject(ACTIVEby default). This rule targets phishing disguised as notifications from popular services. -
[SA-15754] Rules: Add a new high-confidence rule
SPAM_only_inbound_phishing_keywords_video(ACTIVEby default). This rule targets video-based spam messages. -
[SA-15822] Rules: Add a new high-confidence rule
MALWARE_only_inbound_noauth_ole(ACTIVEby default) to catch malware embedded in Office documents. -
[SA-15833] Rules: Add two new high-confidence rules (
ACTIVEby default):SPAM_untrusted_very_young_domain_link_count_is_exactly_one: Blocks spam coming from very young sender domainsPHISHING_untrusted_freemail_very_young_domain: Blocks phishing coming from very young sender domains
-
[SA-15835] Rules: Add a new high-confidence rule
PHISHING_untrusted_only_inbound_body_displaytext_document_signature_keyword_link_with_no_reputation(ACTIVEby default). This rule targets document-signing phishing. -
[SA-15835] Rules: Add a new high-confidence rule
SPAM_untrusted_noreputation_popular_displayname_link_mismatches_from_domain(ACTIVEby default). This rule targets spam where the sender attempts to impersonate a popular service. - [SA-15903] Rules: Treat VHD and VHDX disk images as malware.
-
[SA-15905] Rules: Add a new high-confidence rule
SPAM_only_inbound_obfuscated_text(ACTIVEby default) to catch malicious emails applying various obfuscation techniques. -
[SA-15921] Rules: Update and improve the existing rule
EXTORTION_nonreputable_untrusted_match_multiple_keywords. With this change, it catches even more extortion cases. -
[SA-16004] Rules: Add a new high-confidence rule
PHISHING_only_inbound_freemail_file_scheme(ACTIVEby default) to catch a wave of credential stealing phishing using thefile:URI scheme.
Available via upgrade
Rolled out via xCloud
-
[SA-15491] Rules: Add new high-confidence rule
SPAM_untrusted_sender_only_inbound_shortened_short_body(ACTIVEby default). This rules improves our ability to catch spam using shortened links. -
[SA-15687] Rules: Add new high-confidence rule
SPAM_untrusted_recipient_is_non_personal_address_address_type_count_high(ACTIVEby default). This rule target mass spam where the spammer has a ton of recipients as TO or CC. -
[SA-15691] Rules: Add two new rules (
ACTIVEby default):PHISHING_ml_untrusted_matches_popular_service_link_domain_mismatch: The rule improves our ability to detect phishing attacks impersonating popular services.SPAM_untrusted_sender_only_inbound_body_matches_popular_service_urgency_keyword: The rule improves our ability to detect phishy spam mentioning popular services.
-
[SA-15709] Rules: Add new rule
MALWARE_cracked_new_domain_doc_link(ACTIVEby default). This rule improves our ability to block malware attacks, where the attacker tries to hide the malware behind an encrypted attachment. -
[SA-15816] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_displaytext_contains_only_caps(ACTIVEby default). This rule enables us to block more invoice phishing attacks.
Available via upgrade
- [SA-15732] MTA: Improved the detection of auto-generated emails.
-
[SA-15615] UI: Fixed time range picker issues:
- Dashboard no longer scrolls to the bottom after selecting a new time range.
- Picker no longer appears offscreen in the Similar tab.
- [SA-15696] UI: Fixed an issue that caused a text field’s background to turn white after selecting an option in the browser autocomplete popup.
- [SA-15717] XCC: Fixed an issue where pending release requests were not marked as approved if approval was bypassed by a release action.
Rolled out via xCloud
- [SA-15491] Rules: Add new high-confidence rule
SPAM_untrusted_sender_only_inbound_shortened_short_body(ACTIVEby default). This rules improves our ability to catch spam using shortened links. - [SA-15687] Rules: Add new high-confidence rule
SPAM_untrusted_recipient_is_non_personal_address_address_type_count_high(ACTIVEby default). This rule target mass spam where the spammer has a ton of recipients as TO or CC. - [SA-15691] Rules: Add two new rules (
ACTIVEby default):PHISHING_ml_untrusted_matches_popular_service_link_domain_mismatch: The rule improves our ability to detect phishing attacks impersonating popular services.SPAM_untrusted_sender_only_inbound_body_matches_popular_service_urgency_keyword: The rule improves our ability to detect phishy spam mentioning popular services.
- [SA-15709] Rules: Add new rule
MALWARE_cracked_new_domain_doc_link(ACTIVEby default). This rule improves our ability to block malware attacks, where the attacker tries to hide the malware behind an encrypted attachment. - [SA-15816] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_displaytext_contains_only_caps(ACTIVEby default). This rule enables us to block more invoice phishing attacks.
Available via upgrade
- [SA-15732] MTA: Improve the detection of auto-generated emails.
Rolled out via xCloud
-
[SA-15333] Rules: Add new high-confidence rules (
ACTIVEby default):PHISHING_only_inbound_displayname_matches_keyword_subject_urgentaddresses phishing cases that create a sense of urgency.PHISHING_only_inbound_non_reputable_displayname_matches_partner_link_mismatchcatches phishing cases with mismatched links in the name of a partner organization.PHISHING_topic_invoice_only_inbound_non_reputable_displayname_popular_or_partner_or_guardedaddresses invoice phishing in the name of partner organizations.
-
[SA-15393] Rules: Add new high-confidence rule
SPAM_nonreputable_young_domain_new_link_dangerous_file_type_subject_phishing_keyword(ACTIVEby default). This rule improves spam detection for emails from non-reputable senders with dubious links. -
[SA-15444] Rules: Add new high-confidence rules
PHISHING_topic_invoice_only_inbound_display_text_phishing_keywordsandSPAM_freemail_only_inbound_calendar_file_suspicious_link(ACTIVEby default). The rules catch cases of invoice phishing and calendar invite spam. -
[SA-15526] Rules: Add a new high-confidence rule
SPAM_topic_invoice_only_inbound_non_reputable_public_suffix_no_reputation(ACTIVEby default). This rule targets unwanted mails inquiring about the status of an invoice. -
[SA-15569] Rules: Add a set of new rules (all
ACTIVEby default)PHISHING_ml_matches_guarded_name_file: Targets phishing attacks impersonating a guarded sender.SPAM_topic_invoice_untrusted_sender_only_inbound_link_count_suspicious_is_exactly_one: Targets link-based phishy spam talking about invoices.PHISHING_body_matches_popular_service_urgency_invoice: Targets invoice phishing attacks impersonating a popular service.EXTORTION_untrusted_sender_only_inbound_multiple_extortion_keywords_not_file_not_link: Targets extortion attacks where there’s no link or attachment.
-
[SA-15702] Rules: Add new high-confidence rule
SPAM_untrusted_only_inbound_replyto_not_from_displayname_matches_popular_service_non_configured_ccsend(ACTIVEby default). This rule improves spam detection for ccsend abusers.
Available via upgrade
- [SA-15445] UI: Fix a bug that prevented to perform bulk actions to the current message in the similar tab.
- [SA-15550] MTA, XCC: Fix issue where mails would be stuck in publishing because of excessively large
message-idmail headers. - [SA-15554] XCC: Remove the non-functional auto completion suggestion
file.type:mail. - [SA-15647] UI: Fix the search in the Actions page.
Rolled out via xCloud
- [SA-13856] Rules: Improved newsletter detection heuristics.
-
[SA-15333] Rules: Add new high-confidence rules (
ACTIVEby default):PHISHING_only_inbound_displayname_matches_keyword_subject_urgentaddresses phishing cases that create a sense of urgency.PHISHING_only_inbound_non_reputable_displayname_matches_partner_link_mismatchcatches phishing cases with mismatched links in the name of a partner organization.PHISHING_topic_invoice_only_inbound_non_reputable_displayname_popular_or_partner_or_guardedaddresses invoice phishing in the name of partner organizations.
-
[SA-15393] Rules: Add new high-confidence rule
SPAM_nonreputable_young_domain_new_link_dangerous_file_type_subject_phishing_keyword(ACTIVEby default). This rule improves spam detection for emails from non-reputable senders with dubious links. -
[SA-15444] Rules: Add new high-confidence rules
PHISHING_topic_invoice_only_inbound_display_text_phishing_keywordsandSPAM_freemail_only_inbound_calendar_file_suspicious_link(ACTIVEby default). The rules catch cases of invoice phishing and calendar invite spam. -
[SA-15462] Rules: Add new high-confidence rule
SPAM_cloudmailer_only_inbound_non_reputable_reply_to_not_from(ACTIVEby default). This rule addresses spam emails attachments of forged catalogs for used cars and machines. -
[SA-15508] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_invoice_marketing_non_reputable_reply_to_not_from(ACTIVEby default). This rule addresses phishing cases that are sent through marketing cloud mailers. -
[SA-15526] Rules: Add a new high-confidence rule
SPAM_topic_invoice_only_inbound_non_reputable_public_suffix_no_reputation(ACTIVEby default). This rule targets unwanted mails inquiring about the status of an invoice. -
[SA-15569] Rules: Add a set of new rules (all
ACTIVEby default)PHISHING_ml_matches_guarded_name_file: Targets phishing attacks impersonating a guarded sender.SPAM_topic_invoice_untrusted_sender_only_inbound_link_count_suspicious_is_exactly_one: Targets link-based phishy spam talking about invoices.PHISHING_body_matches_popular_service_urgency_invoice: Targets invoice phishing attacks impersonating a popular service.EXTORTION_untrusted_sender_only_inbound_multiple_extortion_keywords_not_file_not_link: Targets extortion attacks where there’s no link or attachment.
-
[SA-15702] Rules: Add new high-confidence rule
SPAM_untrusted_only_inbound_replyto_not_from_displayname_matches_popular_service_non_configured_ccsend(ACTIVEby default). This rule improves spam detection for ccsend abusers.
Available via upgrade
Rolled out via xCloud
- [SA-13856] Rules: Improved newsletter detection heuristics.
- [SA-15462] Rules: Add new high-confidence rule
SPAM_cloudmailer_only_inbound_non_reputable_reply_to_not_from(ACTIVEby default). This rule addresses spam emails attachments of forged catalogs for used cars and machines. - [SA-15508] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_invoice_marketing_non_reputable_reply_to_not_from(ACTIVEby default). This rule addresses phishing cases that are sent through marketing cloud mailers.
Available via upgrade
[SA-15506] XCC: Fix permission issue during auto host migration which prevented the upgrade from versions prior to 10.0.8.Rolled out via xCloud
- [SA-14856] Rules: Improved newsletter detection heuristics.
- [SA-15107] Rules: Add new high-confidence rule
SPAM_ml_popular_displayname(ACTIVEby default). This rule catches spam sent in the name of popular brands. - [SA-15258] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_non_reputable_sender_contains_guarded_doc_link(ACTIVEby default). This rule improves our ability to block phishing emails, where the attachment contains a document phishing link. - [SA-15340] Rules: Detect MS Office vulnerability CVE-2026-21509 with a new YARA rule
YARA_cve_2026_21509(ACTIVEby default). Matches can be found by searching for the tag#cve_2026_21509after the upgrade. This rule catches documents that might exploit CVE-2026-21509. - [SA-15364] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_only_inbound_non_reputable_reply_to_not_from(ACTIVEby default). This rule catches package-delivery phishing with reply-to address mismatches. - [SA-15456] Rules: Add new high-confidence rule
PHISHING_cloud_mailer_non_reputable_only_inbound_display_text_signature_keyword(ACTIVEby default). This rule catches document review and document signing phishing. - [SA-15475] Rules: Mark the rule
BEC_html_with_script_small_phishy_body_and_subjectasPASSIVEto avoid false positives.
Available via upgrade
- [SA-15408] MTA: Lower log level when email address parsing fails in specific cases when running in monitoring mode.
- [SA-15409] XCC: Fix issue causing the upgrade script to fail attempting to commit configuration changes.
- [SA-15353] UI: Fix a bug where a page error is displayed when trying to load more results and an invalid query was typed.
Rolled out via xCloud
- [SA-14856] Rules: Improved newsletter detection heuristics.
- [SA-15107] Rules: Add new high-confidence rule
SPAM_ml_popular_displayname(ACTIVEby default). This rule catches spam sent in the name of popular brands. - [SA-15258] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_non_reputable_sender_contains_guarded_doc_link(ACTIVEby default). This rule improves our ability to block phishing emails, where the attachment contains a document phishing link. - [SA-15340] Rules: Detect MS Office vulnerability CVE-2026-21509 with a new YARA rule
YARA_cve_2026_21509(ACTIVEby default). Matches can be found by searching for the tag#cve_2026_21509after the upgrade. This rule catches documents that might exploit CVE-2026-21509. - [SA-15364] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_only_inbound_non_reputable_reply_to_not_from(ACTIVEby default). This rule catches package-delivery phishing with reply-to address mismatches. - [SA-15456] Rules: Add new high-confidence rule
PHISHING_cloud_mailer_non_reputable_only_inbound_display_text_signature_keyword(ACTIVEby default). This rule catches document review and document signing phishing. - [SA-15475] Rules: Mark the rule
BEC_html_with_script_small_phishy_body_and_subjectasPASSIVEto avoid false positives.
Available via upgrade
- [SA-15353] UI: Fix a bug where a page error is displayed when trying to load more results and an invalid query was typed.
Rolled out via xCloud
-
[SA-15251] Rules: Add new high confidence rules (
ACTIVEby default):SPAM_ml_calendar_filefor catching attacks based on calendar invites.PHISHING_only_inbound_non_reputable_qr_code_link_and_keywords_html_body_with_data_urlfor catching QR code phishing attacks.PHISHING_only_inbound_non_reputable_voicemail_keywordsfor catching voicemail phishing attacks.PHISHING_topic_account_issue_only_inbound_non_reputable_in_filefor catching account issue phishing attacks.
Available via upgrade
- [SA-15338] MTA: Fix issue where recipient-based tenant assignment would not honor the
recipientRetrievalStrategyconfiguration. - [SA-15293] UI: Fixed issue causing setting wrong classification and template selection data when resolving cases and creating campaigns.
- [SA-15372] UI: Fixed issue which caused wrong number formatting on Firefox.
- [SA-15356] XCC: Standardized timezone handling. The
xcc_backendcontainer now uses UTC by default, which may affect log timestamps.
Rolled out via xCloud
-
[SA-15251] Rules: Add new high confidence rules (
ACTIVEby default):SPAM_ml_calendar_filefor catching attacks based on calendar invites.PHISHING_only_inbound_non_reputable_qr_code_link_and_keywords_html_body_with_data_urlfor catching QR code phishing attacks.PHISHING_only_inbound_non_reputable_voicemail_keywordsfor catching voicemail phishing attacks.PHISHING_topic_account_issue_only_inbound_non_reputable_in_filefor catching account issue phishing attacks.
Available via upgrade
Rolled out via xCloud
- [SA-14255] Rules: Fixed a bug where senders added to the medium/high trust list while using a cloud mailer were still incorrectly treated as low-trusted.
-
[SA-15161] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_package_delivery_cloudmailer_replyto_freemail(ACTIVEby default). This rule catches phishing attempts claiming an issue with the target’s account. -
[SA-15209] Rules: Add two new high-confidence rules (
ACTIVEby default). The rules block popular service impersonations and document signing phishing:SPAM_untrusted_only_inbound_displayname_popular_suspicious_link_with_path_partPHISHING_untrusted_non_reputable_document_signature_keywords_with_data_url
Available via upgrade
-
[SA-15007] MTA: Fix Postfix exporter label format in alerts for monitored_mta:
- The values for the metrics label
lewere changed from integral to decimal numbers. For example, the value10was changed to10.0. This prevents previous value selectors, such asle="10"from matching any value. It has to be migrated tole="10.0". - An automatic migration will update these values in the file
/monitored_mta/prometheus/alert/activeguard_alerts.yml. - However, if your instance has manual modifications in this file, then manual updates might be required. The migration only modifies values that were shipped with the original installation.
- The values for the metrics label
-
[SA-15204] MTA: Fix issue where yaml files in expert editor path
/shared/email_templates/style/where not properly validated. - [SA-15255] MTA: Fix issue where a software module was initialized too late. This would lead to unexpected problem when recovering unfinished messages from before a shutdown.
- [SA-15241] UI: Fix a bug where a saved search could not show the checkboxes in some cases.
- [SA-15282] UI: Fix issue that prevented to show current set action for a campaign and that accidentally sent feedbacks even if set otherwise.
- [SA-15284] XCC: Fix an issue which led to errors, when an analyst tried to bulk release a message for which user already requested a release.
Rolled out via xCloud
- [SA-14255] Rules: Fixed a bug where senders added to the medium/high trust list while using a cloud mailer were still incorrectly treated as low-trusted.
-
[SA-15161] Rules: Add new high-confidence rule
PHISHING_topic_account_issue_package_delivery_cloudmailer_replyto_freemail(ACTIVEby default). This rule catches phishing attempts claiming an issue with the target’s account. -
[SA-15209] Rules: Add two new high-confidence rules (
ACTIVEby default). The rules block popular service impersonations and document signing phishing:SPAM_untrusted_only_inbound_displayname_popular_suspicious_link_with_path_partPHISHING_untrusted_non_reputable_document_signature_keywords_with_data_url
Available via upgrade
- [SA-15241] UI: Fix a bug where a saved search could not show the checkboxes in some cases.
Rolled out via xCloud
- [SA-14745] Rules: Add new high-confidence rules
PHISHING_topic_account_issue_invoice_only_inbound_displayname_popularandPHISHING_only_inbound_non_reputable_links_popular_displayname(ACTIVEby default) to catch new phishing waves using forged notification emails in the name of popular services. - [SA-15159] Rules: Add new high-confidence rule
SPAM_only_inbound_bcc_only_forwarded_reply_to(ACTIVEby default). This rule blocks spam mails forwarded through another service, such as Gmail. - [SA-15227] Rules: Add new high-confidence rule
PHISHING_popular_auth_bcc_only_env_from_non_configured_m365_domain(ACTIVEby default). This rule blocks phishing mails forwarded through Microsoft infrastructure.
Available via upgrade
- [SA-15116] MTA, XCC: Fix issue where a configuration change in monitoring would not cause a hot-reload of the configuration.
- [SA-15180] MTA: Fix problem where results are not properly published in case a tenant was deleted while processing a message.
- [SA-15250] MTA, XCC: Address multiple CVEs in OpenSSL, such as CVE-2025-15467.
- [SA-15144] UI: Change the Release icon in the Quarantine portal, which was the old icon used for Releasing a message.
Rolled out via xCloud
- [SA-14745] Rules: Add new high-confidence rules
PHISHING_topic_account_issue_invoice_only_inbound_displayname_popularandPHISHING_only_inbound_non_reputable_links_popular_displayname(ACTIVEby default) to catch new phishing waves using forged notification emails in the name of popular services. - [SA-15159] Rules: Add new high-confidence rule
SPAM_only_inbound_bcc_only_forwarded_reply_to(ACTIVEby default). This rule blocks spam mails forwarded through another service, such as Gmail. - [SA-15227] Rules: Add new high-confidence rule
PHISHING_popular_auth_bcc_only_env_from_non_configured_m365_domain(ACTIVEby default). This rule blocks phishing mails forwarded through Microsoft infrastructure.
Available via upgrade
- [SA-15250] MTA, XCC: Address multiple CVEs in OpenSSL, such as CVE-2025-15467.
Rolled out via xCloud
-
[SA-15055] Rules: Add a new high-confidence rule
PHISHING_only_inbound_cloudmailer_high_to_address_count_replyto_not_from(ACTIVEby default). This rule addresses a wave of phishing delivered through reputable cloud mailers. -
[SA-15068] Rules: Add 2 new high confidence rules (
ACTIVEby default). Both rules target phishing, where the attacker misused cloud mailer infrastructure:PHISHING_topic_account_issue_package_delivery_replyto_domain_not_equal_from_domain_cloudmailerPHISHING_untrusted_replyto_domain_not_equal_from_domain_sender_account_name_character_count_gt_25
-
[SA-15022][SA-15108] Rules: Add new high-confidence BEC rules
BEC_cloudstorage_new_domain_multiple_document_signature_keywordsandBEC_bcc_only_document_signature_keywords_all_caps_displaytext(ACTIVEby default). Both rules address attacks sent from compromised accounts. -
[SA-15134] Rules: Add a new high-confidence rule
PHISHING_no_auth_no_reputable_link_displayname_or_subject_popular_or_guarded_urgency_keywords(ACTIVEby default). This rule addresses phishing from unauthenticated senders that try to appear as a popular service or an organization-internal sender. -
[SA-15155][SA-14991] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_to_address_type_count_large(ACTIVEby default). This rule improves our ability to detect and block invoice phishing.
Available via upgrade
- [SA-14916] MTA: Do not send encrypted attachments to the text extraction service.
- [SA-15003] MTA: Fix “Postfix down” alerts, postfix_exporter now restarts unhealthy log sources.
- [SA-15074] UI: Fixed wrong update of the URL parameters when removing the last active search filter.
- [SA-14906] XCC: Fix issue which prevented the proxy configuration from being applied in
m365GraphApi. - [SA-15071] XCC: Fix for missing updates to counters and models when a quarantine release request gets approved.
Rolled out via xCloud
-
[SA-15055] Rules: Add a new high-confidence rule
PHISHING_only_inbound_cloudmailer_high_to_address_count_replyto_not_from(ACTIVEby default). This rule addresses a wave of phishing delivered through reputable cloud mailers. -
[SA-15068] Rules: Add 2 new high confidence rules (
ACTIVEby default). Both rules target phishing, where the attacker misused cloud mailer infrastructure:PHISHING_topic_account_issue_package_delivery_replyto_domain_not_equal_from_domain_cloudmailerPHISHING_untrusted_replyto_domain_not_equal_from_domain_sender_account_name_character_count_gt_25
-
[SA-15022][SA-15108] Rules: Add new high-confidence BEC rules
BEC_cloudstorage_new_domain_multiple_document_signature_keywordsandBEC_bcc_only_document_signature_keywords_all_caps_displaytext(ACTIVEby default). Both rules address attacks sent from compromised accounts. -
[SA-15134] Rules: Add a new high-confidence rule
PHISHING_no_auth_no_reputable_link_displayname_or_subject_popular_or_guarded_urgency_keywords(ACTIVEby default). This rule addresses phishing from unauthenticated senders that try to appear as a popular service or an organization-internal sender. -
[SA-15155][SA-14991] Rules: Add new high-confidence rule
PHISHING_topic_invoice_untrusted_domain_only_inbound_to_address_type_count_large(ACTIVEby default). This rule improves our ability to detect and block invoice phishing.
Available via upgrade
- [SA-14916] MTA: Do not send encrypted attachments to the text extraction service.
- [SA-14906] XCC: Fix issue which prevented the proxy configuration from being applied in
m365GraphApi. - [SA-15071] XCC: Fix for missing updates to counters and models when a quarantine release request gets approved.
Rolled out via xCloud
- [SA-14993] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_cloud_mailer_subject_guarded_document_signature_keywords(ACTIVEby default) to catch phishing attempts claiming to share an internal document. - [SA-14997] Rules: Add new high-confidence rule
PHISHING_no_auth_new_domain_phishy_displayname(ACTIVEby default) to catch more phishing sent by unauthenticated senders. - [SA-15018] Rules: Add new high-confidence rule
PHISHING_untrusted_common_phishing_link_displayname_popular_phishing_keywords(ACTIVEby default) to block emails that promise a free gift in the name of a popular brand. - [SA-15026] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_subject_guarded_multiple_keywords(ACTIVEby default) to address more phishing cases that claim to share an internal document. - [SA-15056] Rules: Add new high-confidence rule
PHISHING_google_application_integration(ACTIVEby default). This rule blocks a new attack, coming from an authenticated Google Application Integration service. - [SA-15064] Rules: Add new high-confidence rule
PHISHING_only_inbound_html_mostly_image_test_subject(ACTIVEby default). This rule blocks a wave of AI-translated Swiss German phishing cases. - [SA-15070] Rules: Require an untrusted sender for the rule
PHISHING_nonreputable_sender_unknown_never_delivered_urgency_keywords_suspicious_linkto trigger. Adding a specific sender to the low-trusted sender list now prevents this rule from triggering.
Available via upgrade
- [SA-14782] UI: Fix a bug where the filters could change position when adding a new filter.
- [SA-14878] UI: Fix an issue where the selected tenant resets when navigating to specific configuration in the admin section.
- [SA-14971] UI: Improve the Expert Editor dialogs by avoiding scrollbars for long filenames.
- [SA-14926] UI: Disable similar content filter menu item when the suggested filter is present.
- [SA-14998] UI: The verdicts and status search fields are now auto-focused when opening the filter.
- [SA-15029] UI: Fix a bug where the comment was sent even if “No Feedback” option was selected in resolve dialog.
- [SA-14746] XCC: Prevent error log in case of insufficient permissions while using auto-login links.
- [SA-14795] XCC: Improvements around the DB queries for messages scheduled for deletion.
- [SA-15003] MTA: Fix mail log rotation to avoid postfix down alerts.
- [SA-15091] MTA: Fix out of bounds access when processing sudomain provider lists.
Rolled out via xCloud
- [SA-14993] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_cloud_mailer_subject_guarded_document_signature_keywords(ACTIVEby default) to catch phishing attempts claiming to share an internal document. - [SA-14997] Rules: Add new high-confidence rule
PHISHING_no_auth_new_domain_phishy_displayname(ACTIVEby default) to catch more phishing sent by unauthenticated senders. - [SA-15018] Rules: Add new high-confidence rule
PHISHING_untrusted_common_phishing_link_displayname_popular_phishing_keywords(ACTIVEby default) to block emails that promise a free gift in the name of a popular brand. - [SA-15026] Rules: Add new high-confidence rule
PHISHING_untrusted_only_inbound_subject_guarded_multiple_keywords(ACTIVEby default) to address more phishing cases that claim to share an internal document. - [SA-15056] Rules: Add new high-confidence rule
PHISHING_google_application_integration(ACTIVEby default). This rule blocks a new attack, coming from an authenticated Google Application Integration service. - [SA-15064] Rules: Add new high-confidence rule
PHISHING_only_inbound_html_mostly_image_test_subject(ACTIVEby default). This rule blocks a wave of AI-translated Swiss German phishing cases. - [SA-15070] Rules: Require an untrusted sender for the rule
PHISHING_nonreputable_sender_unknown_never_delivered_urgency_keywords_suspicious_linkto trigger. Adding a specific sender to the low-trusted sender list now prevents this rule from triggering.
Available via upgrade
- [SA-14746] XCC: Prevent error log in case of insufficient permissions while using auto-login links.
- [SA-14795] XCC: Improvements around the DB queries for messages scheduled for deletion.
- [SA-15091] MTA: Fix out of bounds access when processing sudomain provider lists.
Rolled out via xCloud
- [SA-14399] Rules: Add new
PHISHING_untrusted_only_inbound_document_signature_keywords_link_with_no_reputation(ACTIVEby default). This rule will catch more document signature phishing. - [SA-14855] Rules: Add new high-confidence rule
SPAM_ml_untrusted_only_inbound_non_reputable_link(ACTIVEby default) to block more spam. - [SA-14932] Rules: Add high confidence rule
PHISHING_topic_invoice_matches_office_interaction_document_signature_keyword(ACTIVEby default). This rule blocks more invoice phishing, where the attack is attached as an office document. - [SA-14944] Rules: Add new high-confidence rule
PHISHING_sender_unknown_never_delivered_cloud_mailer_displayname_popular(ACTIVEby default) to block phishing mails sent through reputable cloud services. - [SA-14959] Rules: Add new high-confidence rule
PHISHING_sender_unknown_never_delivered_cloud_mailer_displayname_popular(ACTIVEby default) to block phishing mails disguised as bounce messages. - [SA-15005] Rules: Add new high-confidence rule
PHISHING_untrusted_nonreputable_body_matches_voicemail_password_popular_guarded_email(ACTIVEby default). The rule catches more voice mail phishing impersonating popular services. - [SA-15024] Rules: Fix for a missing space in default subject rewrites. An earlier update introduced a bug where subject rewrites were missing the space between the prefix and the subject. E.g., the subject would become
[SPAM]Subjectinstead of[SPAM] Subject.
Available via upgrade
- [SA-15006] MTA: Address changed metric label, affecting the Postfix queue size alert and the MTA monitoring dashboard.
- [SA-15030] MTA: Address critical CVEs (CVE-2025-54988, CVE-2025-66516) in Tika.
- [SA-13868] XCC: Avoid updating the relationship score when a campaign is set up to deliver the message with a malicious verdict. This avoids the build-up of trust for campaigns that, e.g., only do a subject rewrite instead of quarantining the messages.
- [SA-14864] XCC: Prevent error log on case isolation when repeatedly trying to isolate a message.
Rolled out via xCloud
- [SA-14399] Rules: Add new
PHISHING_untrusted_only_inbound_document_signature_keywords_link_with_no_reputation(ACTIVEby default). This rule will catch more document signature phishing. - [SA-14855] Rules: Add new high-confidence rule
SPAM_ml_untrusted_only_inbound_non_reputable_link(ACTIVEby default) to block more spam. - [SA-14932] Rules: Add high confidence rule
PHISHING_topic_invoice_matches_office_interaction_document_signature_keyword(ACTIVEby default). This rule blocks more invoice phishing, where the attack is attached as an office document. - [SA-14944] Rules: Add new high-confidence rule
PHISHING_sender_unknown_never_delivered_cloud_mailer_displayname_popular(ACTIVEby default) to block phishing mails sent through reputable cloud services. - [SA-14959] Rules: Add new high-confidence rule
PHISHING_sender_unknown_never_delivered_cloud_mailer_displayname_popular(ACTIVEby default) to block phishing mails disguised as bounce messages. - [SA-15005] Rules: Add new high-confidence rule
PHISHING_untrusted_nonreputable_body_matches_voicemail_password_popular_guarded_email(ACTIVEby default). The rule catches more voice mail phishing impersonating popular services. - [SA-15024] Rules: Fix for a missing space in default subject rewrites. An earlier update introduced a bug where subject rewrites were missing the space between the prefix and the subject. E.g., the subject would become
[SPAM]Subjectinstead of[SPAM] Subject.
Available via upgrade
- [SA-14999] MTA: Prepare MTAs for the upcoming release-11 trust model changes.
- [SA-15006] MTA: Address changed metric label, affecting the Postfix queue size alert and the MTA monitoring dashboard.
- [SA-12808] XCC: Mail header additions triggered via rules are now mentioned in the detail view in tab
Classifiers & Rules. - [SA-14864] XCC: Prevent error log on case isolation when repeatedly trying to isolate a message.
- [SA-13868] XCC: Avoid updating the relationship score when a campaign is set up to deliver the message with a malicious verdict. This avoids the build-up of trust for campaigns that, e.g., only do a subject rewrite instead of quarantining the messages.
- [SA-14864] XCC: Improve error message when quarantine release fails in SSQ portal.
Rolled out via xCloud
- [SA-12158] Rules: Add new high-confidence rules
SPAM_topic_sexual_content_package_delivery_non_reputable_linksandSPAM_ml_adult_keywords_non_reputable_links_state(ACTIVEby default). Additionally, broaden the existingSPAM_ml_topic_sexual_contentrule and improveADAPT_spam_confidence_low_image_only. These changes help with catching ongoing spam waves that promote adult products. - [SA-14155] Rules: Add new high-confidence rule
PHISHING_reputable_freemail_forged_reply_to_shortened_embedded_link(ACTIVEby default) to catch more phishing sent via reputable services. - [SA-14443] Rules: Add new high-confidence rule
SPAM_untrusted_non_reputable_only_inbound_very_young_sender(ACTIVEby default) to block spam from newly registered domains. - [SA-14443] Rules: Disable
PHISHING_common_domainsas it is redundant with other rules. - [SA-14778] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_untrusted_sender_only_inbound_one_suspicious_link(ACTIVEby default). This rule improves our ability to block package delivery phishing. - [SA-14847] Rules: Add new high-confidence rule
PHISHING_address_parsing_error_matches_phishing_keyword_no_auth(ACTIVEby default). The rule blocks more unauthenticated phishing. - [SA-14868] Rules: Add new high-confidence rule
PHISHING_sender_is_social_network_subject_matches_urgency_multiple_phishing_keywords(ACTIVEby default). This rule improves our ability to block phishing attacks sent from legit Meta infrastructure. - [SA-14903] Rules: Add new high-confidence rule
SPAM_untrusted_non_reputable_domain_only_inbound_link_without_dns(ACTIVEby default). The rule catches spam waves that attempt to evade detection by making the link domain resolve only after delivery.
Available via upgrade
- [SA-14850] XCC: Intermediate validation errors in
auth.ymltriggered via expert configuration editor should not be logged as ERROR. - [SA-14852] MTA: Extract a few more relevant properties from iCalendar files. With the additional properties, we can better detect calendar invite impersonation.
- [SA-14904] MTA: Add attribute
pipelineto audit log message types:trace.msg_analysis.start,trace.msg_analysis.resume,trace.msg_analysis.complete,trace.msg_verdict. - [SA-14907] MTA, XCC: Upgrade
containerdto addressrunCvulnerability CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881. - [SA-14561] UI: In the authentication status next to the
FROMaddress, avoid showing failed or passed checks that did not directly contribute to the authentication status of theFROMaddress. The previous behavior lead to confusion about the exact reason why theFROMis considered authenticated or not. - [SA-14885] UI: Fix an issue that automatically unticked the Rerpot Misclassification checkbox when writing a comment in the resolve dialog.
- [SA-14913] UI: Fix issue that made the time range selection date-picker to be mis-placed when choosing a custom date.
- [SA-14946] UI: Fix an issue where the empty state in Abuse mailbox card was not centered.
Rolled out via xCloud
- [SA-12158] Rules: Add new high-confidence rules
SPAM_topic_sexual_content_package_delivery_non_reputable_linksandSPAM_ml_adult_keywords_non_reputable_links_state(ACTIVEby default). Additionally, broaden the existingSPAM_ml_topic_sexual_contentrule and improveADAPT_spam_confidence_low_image_only. These changes help with catching ongoing spam waves that promote adult products. - [SA-14155] Rules: Add new high-confidence rule
PHISHING_reputable_freemail_forged_reply_to_shortened_embedded_link(ACTIVEby default) to catch more phishing sent via reputable services. - [SA-14443] Rules: Add new high-confidence rule
SPAM_untrusted_non_reputable_only_inbound_very_young_sender(ACTIVEby default) to block spam from newly registered domains. - [SA-14443] Rules: Disable
PHISHING_common_domainsas it is redundant with other rules. - [SA-14778] Rules: Add new high-confidence rule
PHISHING_topic_package_delivery_untrusted_sender_only_inbound_one_suspicious_link(ACTIVEby default). This rule improves our ability to block package delivery phishing. - [SA-14847] Rules: Add new high-confidence rule
PHISHING_address_parsing_error_matches_phishing_keyword_no_auth(ACTIVEby default). The rule blocks more unauthenticated phishing. - [SA-14868] Rules: Add new high-confidence rule
PHISHING_sender_is_social_network_subject_matches_urgency_multiple_phishing_keywords(ACTIVEby default). This rule improves our ability to block phishing attacks sent from legit Meta infrastructure. - [SA-14903] Rules: Add new high-confidence rule
SPAM_untrusted_non_reputable_domain_only_inbound_link_without_dns(ACTIVEby default). The rule catches spam waves that attempt to evade detection by making the link domain resolve only after delivery.
Available via upgrade
- [SA-14850] XCC: Intermediate validation errors in
auth.ymltriggered via expert configuration editor should not be logged as ERROR. - [SA-14561] UI: In the authentication status next to the
FROMaddress, avoid showing failed or passed checks that did not directly contribute to the authentication status of theFROMaddress. The previous behavior lead to confusion about the exact reason why theFROMis considered authenticated or not. - [SA-14907] MTA, XCC: Upgrade
containerdto addressrunCvulnerability CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
Rolled out via xCloud
- [SA-11326] Rules: Add new
PHISHING_ml_sender_account_name_character_count_large_document_signature_keyword(ACTIVEby default). This rule will catch more document signature phishing. - [SA-11326] Rules: Update
SPAM_ml_young_senderto catch even more spam from young senders. - [SA-14839] Rules: Re-enable
#malwareand#exploitfor use in campaigns.
Available via upgrade
- [SA-14800] XCC: Fix issue where messages with recipients containing
=characters would end up in stateSMTP ERROReven though they were delivered successfully. - [SA-14802] XCC: Fix issue which prevented users with global analyst permissions to see quarantines specified outside of the tenant they are belonging to.
- [SA-14813] XCC: Fixed issue that moved signed received headers at the top of the headers list.
- [SA-14786] MTA: Fix issue when calculating
result_publish_latencywhile changing the time zone offset (daylight saving time). When applied, this bugfix may cause the metric to temporarily spike.. - [SA-14792] MTA, XCC: Fix issue preventing us from displaying rDNS information when it would be available.
- [SA-14820] MTA: Fix issue where a special payload could trigger an out of memory situation, forcing Core to restart.
- [SA-14832] MTA, XCC: Upgrade Docker Compose to address CVE-2025-62725.
- [SA-14835] MTA: Fix issue where lengthy pipeline repository init fails leaving the system with no working scan pipelines.
- [SA-14827] MTA: Improve error handling fo results in case of an abrupt shutdown.
- [SA-14843] MTA: Improve error handling for results which can not be published to xcc.
Rolled out via xCloud
-
[SA-11326] Rules: Add new
PHISHING_ml_sender_account_name_character_count_large_document_signature_keyword(ACTIVEby default). This rule will catch more document signature phishing. -
[SA-11326] Rules: Update
SPAM_ml_young_senderto catch even more spam from young senders. -
[SA-14765] Rules: A set of new and improved rules to address various phishing and spam cases (all high-confidence and
ACTIVEby default):PHISHING_untrusted_non_reputable_subject_guarded_or_popular_suspicious_linkPHISHING_untrusted_only_inbound_displayname_and_subject_popularSPAM_untrusted_only_inbound_displayname_popular_each_link_nonreputableSPAM_untrusted_only_inbound_qr_code_link_similar_to_popular
Available via upgrade
- [SA-14720] MTA: Fix problem where mta would report an error about delayed log messages after restart even though this was not the case.
- [SA-14786] MTA: Fix problem when calculating
result_publish_latencywhile changing the time zone offset (daylight saving time). When applied, this bugfix may cause the metric to temporarily spike.. - [SA-14792] MTA, XCC: Fix issue preventing us from displaying rDNS information when it would be available.
- [SA-14820] MTA: Fix issue where a special payload could trigger an out of memory situation, forcing Core to restart.
- [SA-14827] MTA: Improve error handling fo results in case of an abrupt shutdown.
- [SA-14832] MTA, XCC: Upgrade Docker Compose to address CVE-2025-62725.
- [SA-14835] MTA: Fix issue where lengthy pipeline repository init fails leaving the system with no working scan pipelines.
- [SA-14843] MTA: Improve error handling for results which can not be published to xcc.
- [SA-14727] UI: Fix issue where the wrong tooltip was shown for headers marked as possibly forged.
- [SA-14766] UI: Fix issue that prevented the correct automation rate from being shown in the dashboard.
- [SA-14800] XCC: Fix issue where messages with recipients containing
=characters would end up in stateSMTP ERROReven though they were delivered successfully. - [SA-14804] XCC: Fix bug in permission check for case isolation.
- [SA-14802] XCC: Fix issue which prevented users with global analyst permissions to see quarantines specified outside of the tenant they are belonging to.
- [SA-14813] XCC: Fixed issue that moved signed received headers at the top of the headers list.
Highlights
- [SA-9095] Core: Support iCalendar file analysis: URL extraction, content matching, and attachment extraction. This change addresses the uptick in phishing attacks using
.icsfiles. - [SA-5498] UI: The resolve case dialog has a new layout. Benign/malicious toggles were removed, replaced with a searchable template and verdict selector.
- [SA-9843] XCC: On campaign creation, the query will be checked for any tags that are not supported. E.g., if the query contains the tag
#quarantine, it is now not possible to create a campaign. This additional validation ensures that only tags that are set before campaign rules can be used in campaign queries.
UX improvements and fixes
- [SA-9843] XCC: Adding a user tag to a message is now prevented if that tag has the same name as a built-in tag. This prevents confusion between user tags and tags that are assigned by xorlab rules.
- [SA-12566] UI: Report misclassification is only auto-selected when resolving a case where the chosen verdict is different from the one initially assigned.
- [SA-13944] UI: A new column in the main list view shows the overall relationship score between sender and recipient.
- [SA-13991] UI: The dashboard “Email Security” box tooltips and counts now only reflect blocked, subject-rewritten, or bannered messages.
- [SA-14368] UI: The dashboard header side panels with explanation details have been redesigned. They now contain detail explanations and breakdowns for the model computations, the explanations are accessible via blue-highlighted rows.
- [SA-14454] UI: The similarity tab now uses the “same sender” default filter if no similar content is found.
- [SA-14456] UI: The similarity tab now suggests predefined filters with counts, they can be clicked to activate immediately.
- [SA-14449][SA-14450][SA-14468] UI: Blacklist/whitelist dialogs were refreshed with a cleaner, more intuitive structure.
- [SA-14580] UI: Fix a bug where the browser back button was not working while showing the error page.
- [SA-14595] UI: Fix a bug where the relationship tooltip was flickering in certain cases.
- [SA-14631] UI: Improve error message when trying to adding reserverd tags.
- [SA-14665] UI: Only one empty filter of the same type can be added to the search bar. When trying to add a filter which is already part of the searchbar but it is empty, the previous filter will be moved to the end and reopened.
- [SA-14666] UI: Fix a bug where in certain cases the search history remained open.
- [SA-14686] UI: Encrypted files no longer have orange background.
- [SA-14669] UI: Improve the search in the list configurator.
- [SA-14671] UI: Show the table header for the relationship score column in the message lists.
- [SA-14690] UI: Fix Abuse Mailbox chart layout for small screens.
- [SA-14692] UI: Clicking outside the image or video, while the preview dialog is open, will close it.
- [SA-14707] UI: Fix a bug where the Abuse Mailbox was displaying a really tiny in some cases.
- [SA-14708] UI: Fix a bug where the url params were not cleared in some conditions.
- [SA-14710] UI: Fix a bug where dragging multiple files into the dropzone caused infinite loading.
- [SA-14711] UI: Fix a bug where the table action buttons would disappear from the attachemnts table.
- [SA-14712] UI: Fix damages prevented calculations.
- [SA-14713] UI: A wrong page was displayed after fixing a deprecated campaign.
- [SA-14716] UI: Fix a bug where the autocomplete glitched when the pointer was over the list and arrow down was pressed.
- [SA-14728] UI: Fix a bug where long email addresses were not displayed correctly in the relationship tooltip.
Multi-Tenancy improvements
- The parameter
authTenantIdinsideguarded_tenants.ymlis now considered deprecated. While it is still supported, we recommend to usenameinstead. All features that rely onauthTenantIdwill usenameif noauthTenantIdis specified.
Detection improvements
-
[SA-6528][SA-9095] Core: Support URL extraction, content matching, and attachment extraction for iCalendar files. This change addresses the uptick in phishing attacks using
.icsfiles. -
[SA-14563] Rules: Added two new tags that will empower SOCs to use previous actions (isolaton and release) in e.g. campaigns:
#senderisolated: Set if a message from the same email address (FROM) has previously been isolated.#senderreleased: Set if a message from the same email address (FROM) has previously been released from quarantine.
Breaking changes
-
[SA-9843] XCC: The tag
#quarantineand#delivercannot be used anymore in campaigns. Existing campaigns with those tags will still work, but marked as deprecated in the GUI. -
[SA-14395] XCC: This concerns only xorlab M365 integrations. The file
client_access_cidrcontaining M365 IPs has been cleaned up:- All M365 IPs have been moved into a hidden
client_access_m365_cidrfile that is managed now by xorlab (viaag_global). client_access_cidris now empty and can be used on-demand likeclient_access.- If you added custom entries in
client_access_cidr, save them before the upgrade to apply them afterward again.
- All M365 IPs have been moved into a hidden
-
[SA-14398] Rules: This change updates the behavior of
fp_low.properties, by removing the following entries:FILTER_executable_state=PASSIVEFILTER_flash_state=PASSIVEFILTER_iso_state=PASSIVEFILTER_legacy_archive_state=PASSIVEFILTER_shortcut_state=PASSIVEFILTER_windows_script_state=PASSIVE
FILTER-ruleswill now beACTIVEby default, even iffp_low.propertiesis activated. To continue with the old behavior, please add the above state-entries tolocal.properties. -
[SA-14420] XCC: The property
bccFallbackDomaininguarded_tenants.ymlhas been removed and is now replaced implicitly by the first guarded domain entry. This only affects the domain shown in the tenant selection dialog in multi-tenant environments. -
[SA-14541] Rules: This release removes the verdict
UNTRUSTED, which was only applied to outgoing messages. -
[SA-14541] Rules: The verdict
TRUSTEDis now only applied when there is a high enough level of trust between the sender and the recipient. In previous releases, messages would also get the verdictTRUSTEDif the sender domain had enough local reputation.
Bugfixes and improvements
- [SA-14170] MTA: Bugfix problem where password cracking would fail for zip files with unusual names. This could have lead to situations where mails could not be released via Attachment Unlock.
- [SA-14423] MTA: Fix issue where results could not be published properly to xcc after a processing timeout.
- [SA-14402] XCC: Upgrade Elastic stack from major version 7 to major version 8.
- [SA-14598] XCC: Improve performance of message and quarantine cleanup.
- [SA-14606] MTA: Silence processing error when analzying excessively large image files.
- [SA-14609] XCC: Bugfix problem where config was reloaded even tough the authentication service was still starting up.
- [SA-14651] MTA: Bugfix problem where pdf files with excessive numbers of embedded objects would cause delays.
- [SA-14660] XCC: Upgrade redis dependency to mitigate
CVE-2025-49844. - [SA-14720] MTA: Fix problem where mta would report an error about delayed log messages after restart even though this was not the case.
Rolled out via xCloud
-
[SA-14601] Rules: Add new high-confidence rule
PHISHING_untrusted_embedded_shortened_cloud_storage_is_exactly_one(ACTIVEby default). This rule targets phishing emails where the attacker uses a combination of embedded and shortened links. -
[SA-14613] Rules: Add new high-confidence rule
PHISHING_untrusted_nonreputable_voicemail_keywords(ACTIVEby default). This rule addresses phishing emails claiming that the target has a recorded voicemail. -
[SA-14616] Rules: A set of new and improved rules to address various phishing and spam cases (all high-confidence and
ACTIVEby default):PHISHING_topic_package_delivery_untrusted_only_inbound_links_non_reputablePHISHING_untrusted_non_reputable_only_inbound_cloudstorage_linkPHISHING_untrusted_only_inbound_body_and_subject_multiple_keywords_popular_displayname_and_linksPHISHING_untrusted_only_inbound_common_phishing_link_without_reputationPHISHING_untrusted_only_inbound_matches_keywords_body_contains_unicode_block_elementsSPAM_untrusted_only_inbound_html_mostly_image_data_url
-
[SA-14619] Rules: Add new high-confidence rule
PHISHING_untrusted_non_reputable_only_inbound_cloudstorage_with_document_signature_keywords(ACTIVEby default). This rule addresses phishing emails asking to sign a document. -
[SA-14739] Rules: Add new rules
BEC_bcc_only_html_short_link_display_text_matches_keywordandBEC_bcc_only_cloud_storage_link_embedded_link(ACTIVEby default). These rules block attacks from compromised accounts claiming to share an important document. -
[SA-14756] Rules: Add new high-confidence rule
SPAM_ml_topic_sexual_content(ACTIVEby default). This rule ensures that explicit sexual content is blocked. -
[SA-14776] Rules: Update
SPAM_nonreputable_multiple_adult_keywords_all_links_negligible_reputationto block more spam.
Available via upgrade
- [SA-14701] UI: Fixed issue that triggered an error 500 when accessing a tenant-specific saved search.
- [SA-14423] MTA: Fix issue where results could not be published properly to xcc after a processing timeout.
- [SA-14606] MTA: Silence processing error when analzying excessively large image files.
SA-14660: CVE-2025-49844This patch fixes CVE-2025-49844. It is a vulnerability in the Redis database used on the XCC. There is no immediate risk of exploitation as the Redis access is restricted to authenticated users. Additionally, for on-premise customers, Redis is normally not exposed to an external network. However, we still recommend to update to 9.0.3 as this is a publicly known Redis vulnerability.
Rolled out via xCloud
-
[SA-14425] Rules: Add new high-confidence rule
SPAM_untrusted_non_configured_firebase_sender_not_released(ACTIVEby default) to block spam sent throughfirebaseapp.com. -
[SA-14513] Rules: Add 7 new high confidence rules (all
ACTIVEby default). These rules will improve our general detection in multiple areas:PHISHING_sender_unknown_never_delivered_link_negligible_local_global_reputation_matches_popularPHISHING_untrusted_sender_only_inbound_body_matches_guarded_emailPHISHING_untrusted_sender_domain_only_inbound_matches_document_signature_keywordSPAM_untrusted_sender_domain_only_inbound_matches_popular_service_and_urgencyPHISHING_untrusted_matches_multiple_phishing_keywords_and_urgencyPHISHING_topic_invoice_untrusted_nonreputable_shortened_no_local_reputationPHISHING_untrusted_cracked_office_interaction_keywords
-
[SA-14557] Rules: Add a new high-confidence rule
PHISHING_sender_unknown_never_delivered_subject_and_body_multiple_document_signature_keywords(ACTIVEby default) to improve our detection of document signature phishing. -
[SA-14618] Rules: Fix
ADAPT_phishing_override_based_on_risk_scoresuch that less benign emails from popular senders get blocked. -
[SA-14627] Rules: Add a new high-confidence rule
SPAM_sender_unknown_never_delivered_subject_matches_urgency_and_phishing_replyto_not_from(ACTIVEby default) to address spam mails that are urging the target to claim a large amount of money. -
[SA-14679] Rules: Update the rule
BEC_bcc_only_html_short_link_image_file_body_matches_popular_serviceto block a broader variety of BEC cases.
Available via upgrade
- [SA-14170] MTA: Bugfix problem where password cracking would fail for zip files with unusual names. This could have lead to situations where mails could not be released via Attachment Unlock.
- [SA-14598] XCC: Improve performance of message and quarantine cleanup. Notice that next xcc start may take a bit longer than usual.
- [SA-14609] XCC: Bugfix problem where config was reloaded even tough the authentication service was still starting up.
- [SA-14651] MTA: Bugfix problem where pdf files with excessive numbers of embedded objects would cause delays.
- [SA-14660] XCC: Upgrade redis dependency to mitigate
CVE-2025-49844.
Rolled out via xCloud
-
[SA-14497] Rules: New rules to address various phishing cases (high-confidence and
ACTIVEby default)PHISHING_topic_account_untrusted_displayname_guarded_no_or_suspicious_linkPHISHING_untrusted_displayname_guarded_or_phishy_mostly_image_subject_phishyPHISHING_untrusted_domain_only_inbound_one_cloud_storage_link_from_outbound_addressPHISHING_untrusted_only_inbound_document_subject_phishy_qr_code_keywordsPHISHING_untrusted_only_inbound_non_reputable_only_media_files_phishing_keywords
-
[SA-14497] Rules: Improved rules to address various malware cases (high-confidence and
ACTIVEby default)MALWARE_encrypted_archive: Now enabled in more rule profiles.MALWARE_office_encrypted: Now enabled in more rule profiles.
Low trusted sender addresseslist.
Available via upgrade
- [SA-14566] MTA: Silence error log in case of duplicate DKIM signatures.
- [SA-14590] MTA: Fix bug where attachment unlock would fail for message that were analyzed before upgrading to release 9.0.
- [SA-14577] UI: Fix a bug where the previous query was saved in the history instead of the current one.
- [SA-14600] XCC: Sync major version of PostgreSQL client tools in XCC containers.
Rolled out via xCloud
- [SA-14261] Rules: Add new high-confidence rule
PHISHING_untrusted_sender_only_inbound_displayname_matches_popular_service(ACTIVEby default). This rule will block more phishing where the attacker imitates a popular sender. - [SA-14469] Rules: Add new high-confidence rule
PHISHING_untrusted_body_matches_multiple_document_signature_keywords_subject_matches_guarded_name(ACTIVEby default). This rule will improve our ability to block document signature phishing, where the attacker impersonates a guarded name. - [SA-14484] Rules: Add new high-confidence rule
PHISHING_untrusted_freemail_body_matches_qr_code_keyword_matches_guarded(ACTIVEby default). This new phishing rule blocks QR-code phishing, where the attacker impersonates a guarded name.
Available via upgrade
- [SA-14230] XCC: Fix issue where a released mail could be unlocked and potentially be delivered twice.
- [SA-14464] XCC: When isolating a message on M365, the result is still marked as
ISOLATEDeven if the message has been deleted by the end-user and could not be found in the mailbox any more. - [SA-14517] UI: Revert event click behavior on the message list rows.
- [SA-14521] XCC: Fix issue where errors would be logged due to invalid email addresses.
- [SA-14530] XCC: Fix issue where SQL errors would be logged right after XCC startup.
- [SA-14531] UI: Fix regression where the SSQ list view would show a disabled release-button even tough releasing was not possible.
- [SA-14534] MTA: Fix bug where we would not fully recover from decrypting a corrupted MS Office file.
- [SA-14536] UI: Add search trigger when pressing the Enter key on the numeric pad.
- [SA-14537] XCC: Fix issue where M365 message isolation health check would fail when testing API capabilities for on-premise accounts.
- [SA-14562] MTA: Limit number of postfix log messages being processed to prevent
ag_mtagoing OutOfMemory. - [SA-14564] MTA: Fix problem where results for mails which had their attachments removed were stuck in publishing.
Highlights
- [SA-12649] XCC: New SSQ release feature: End-users can now request the release of quarantined emails directly via their SSQ. The feature can be enabled individually per quarantine.
- [SA-13771] XCC: Hot-reload for authentication settings: Configuration changes to LDAP, SAML, and other authentication integrations no longer require a service restart. Manual restarts also no longer terminate active user sessions.
- [SA-13765] UI: Enhanced message authentication insights: SPF, DKIM, and DMARC alignment results are now summarized in the message detail view. Analysts can also drill down into detailed results for each method. With this release, all DNS-based authentication checks are consistently executed for every email, ensuring complete and reliable visibility.
- [SA-14284] XCC: Improved multi-tenant support: SSQ configuration and data retention settings are now fully multi-tenant capable and can be managed separately for each domain.
UX improvements and fixes
- [SA-6187] UI: Allow the middle mouse button to open links in a new tab.
- [SA-13356] UI: The Open Case Priorities widget in the dashboard now displays cases that do not have a priority assigned.
- [SA-13636] UI: The trends section in the dashboard now displays the threats blocked according to the selected time range.
- [SA-13935] UI: The
Home,End,Page Up, andPage Downkeys no longer interact with the search bar drop down. These keys now always move the cursor. - [SA-14006] UI: The insights section in the dashboard has been revised, with additional items now included in the Graymail breakdown section.
- [SA-14015] UI: The dashboard header items are now clickable and include an explanation of how the value is computed, including the formulas and a breakdown of the computation.
- [SA-14407] UI: Fix the campaign header information alignment, such as Message Action or Resolve Action, in the campaign page.
Multi-Tenancy improvements
- [SA-13920] MTA: A tenant can now have more than one
tenantSelectorconfigured. AtenantSelector’s value can now match based on a regex pattern. See /9.0/guarded_tenants_yml
Detection improvements
This section lists only the detection improvements that require a version upgrade. Most other detection enhancements are rolled out gradually and do not require an update.- [SA-14163] XCC: Update counters also for
ToandCcaddresses. With this change, seeing an address in theTo/Ccposition of an outgoing or internal email counts as having seen & delivered an email to that address. As a result, the next email from that address will not have the#senderfirstcontacttag.
Breaking changes
-
[SA-14037] Rules: The following MTA trust lists were removed:
MTA EHLO trust list for guarded (regex)MTA EHLO trust list for partner (regex)MTA RDNS trust list for guarded (regex)MTA RDNS trust list for partner (regex)
trustedMTAProfilesinactive_guard.yml. See more information here: https://docs.xorlab.com/9.0/trusted-mtas/. Also removed are the following rule templates:sender_is_trusted_ehlo_for_guarded.xml,sender_is_trusted_ehlo_for_partner.xml,sender_is_trusted_reverse_dns_for_guarded.xmlandsender_is_trusted_reverse_dns_for_partner.xml. If any custom rule exists that relies on these templates (e.g., if it uses<template name="sender_is_trusted_ehlo_for_guarded"/>anywhere), the rule will stop working. -
[SA-14284] XCC: All configuration parameters related to data retention were moved from
xcc.ymltoguarded_tenants.yml, see Data Retention. Additionally, all SSQ related configuration parameters were also moved fromxcc.ymltoguarded_tenants.yml, see SSQ. No action is required from your side. -
[SA-14354] MTA: Only consider
TXTDNS records when verifying SPF, ignoreSPFDNS records. Please ensure all your guarded domains have valid SPF entries in theirTXTDNS records.
Deprecations
- [SA-13855] UI: Removed access to the Explore view in the sidebar. The data remain accessible in Kibana via the Insights sidebar menu and under the “Messages Overview” dashboard. The permission
xcc_sidebar_exploreis removed from all roles. - [SA-13855] XCC: Removed the configuration options
elasticSearch.exploreGlobalTimeoutSthat affected the maximum waiting time for the result in the Explore view. This configuration is not necessary because the feature has been removed in this release. - [SA-13855] XCC: Remove the following configuration options
elasticSearch.exportScrollMaxDurationS,elasticSearch.exportGlobalTimeoutS,elasticSearch.exportMaxNumberOfResults,elasticSearch.taggingScrollMaxDurationS, andelasticSearch.taggingGlobalTimeoutSas they were unused. This configuration is not necessary because it was used by previously removed features.
Bugfixes and improvements
- [SA-7483] MTA, XCC: Loki and Promtail configuration is now hot-reloaded.
- [SA-9755] MTA: Fix a bug where subject-rewrites were not applied to quarantine-released messages.
-
[SA-13212] MTA: Fix postfix warning:
support for parameter "smtp_use_tls" will be removed; instead, specify "smtp_tls_security_level". - [SA-13672] MTA: xorlab now performs a reverse DNS lookup locally if the border MTA does not provide this information.
-
[SA-13758] MTA: Refactored
auditmodule ofag_mtato achieve more reliable email delivery status updates. -
[SA-13788] Rules: Rename rule profiles to be consistent and easier to understand:
global_only_spam_rewrites_and_no_user_notifications.properties->default_actions.propertiesprofile_no_subject_rewrite_no_quarantine.properties->no_subject_rewrite_no_quarantine.propertiesprofile_no_auto_feedback.properties->no_auto_feedback.propertiesprofile_default_dana.properties->default_dana.propertiesprofile_default_dana_monitoring.properties->monitoring_dana_offline_only.propertiesprofile_no_dana_except_for_specific_recipients.properties->no_dana_except_for_specific_recipients.propertiesprofile_fp_sensitive.properties->fp_sensitive.properties(this profile will be deprecated and fully replaced withfp_low.propertiesin future releases)profile_fp_low.properties->fp_low.propertiesglobal_initialization.properties->learning_mode.propertiesglobal_bcc_threat_analyst.properties->monitoring_mode.propertiesglobal_default.properties->default.properties
- [SA-13880] MTA: Fix a bug where SMTP envelope information is lost in certain cases when unlocking an attachment.
- [SA-13897] UI: Improved data loading animations in the Self-Serviced Quarantine.
- [SA-13906] MTA: Fix a bug where an email would be marked as erroneous after exceeding the processing time limit.
- [SA-13908] XCC: Remember active user sessions during Auth restarts caused by config changes or manual restarts. User sessions are still terminated during an Auth version upgrade.
- [SA-13921] UI: The root domain information is always shown for URLs in the message detail view.
-
[SA-13966] MTA: Fix a
NullPointerExceptiontriggered in test quarantine digest email notification. -
[SA-14012] XCC: Fix bug where XCC would log
sys.readytwice on startup. -
[SA-14066] XCC: Reverse proxy does not offer the following weak SSL ciphers anymore:
ECDHE-RSA-AES256-GCM-SHA512,DHE-RSA-AES256-GCM-SHA512,ECDHE-RSA-AES256-SHA384. This change follows latest recommendations of Mozilla (https://wiki.mozilla.org/Security/Server_Side_TLS). -
[SA-14106] MTA: Fix an issue where
.pubfiles were mistakenly analyzed for the presence of VBA macros. -
[SA-14146] XCC: Fix problem where an underscore in a custom quarantine would trigger an error. Allowed quarantine names must match this regular expression:
[0-9A-Za-z_-]+. -
[SA-14148] MTA: Move Postfix
client_access_tenantcheck such that mail headerPREPENDactions are only applied once per mail and not once per recipient. - [SA-14168] MTA: Email transformations (like adding a header or a subject rewrite) are now also applied to emails released from quarantine.
- [SA-14238] Monitoring: Grafana update to apply fixes for CVE-2025-6197 and CVE-2025-6023.
- [SA-14336] XCC: Fix problem where release-8 upgrade would fail because of an improper git configuration.
- [SA-14403] XCC: Upgrade PostgreSQL to mitigate CVE-2025-8713, CVE-2025-8714 and CVE-2025-8715.
-
[SA-14433] MTA: Audit log
trace.msg_verdictwill also report mail envelope informationsenderandrecipients. - [SA-12695] XCC: xorlab now collects usage metrics such as guarded domains and number of seats. This data is sent to xCloud.