Release notes

5.1.260917.0
  • An issue that could cause vulnerability rule updates to fail intermittently for self-hosted customers has been resolved.
  • An issue that could cause the Echo scan probes to be saved incorrectly has been resolved.
  • Fingerprint improvements for Kodi.
  • Fingerprint improvements for Cisco Catalyst & IOS.
  • Fingerprint improvements for Paramiko.
  • Fingerprint improvements for Roumen Petrov SSH.
  • Fingerprint improvements for Advantech.
  • Fingerprint improvements for Digi.
5.1.260915.0
  • The runZero API can now suppress and unsuppress vulnerabilities, vulnerability groups, and findings.
  • The scanner’s fragile device detection for assets running IBM OS/400 has improved, lowering the risk of destabilizing target devices.
  • vmatch no longer produces false positives on some HashiCorp products.
  • runZero now reports GCP load balancer and instance attributes correctly.
  • Example custom integrations now appear on multi-node clusters.
  • Fingerprinting from Wiz integration data has improved.
  • Fingerprint improvements for wireless access points.
  • Fingerprint improvements for the AcyMailing Joomla extension.
  • Fingerprint improvements for the AcyMailing WordPress plugin.
  • Fingerprint improvements for weGIA charity admin panel.
  • Fingerprint improvements for sar2html.
  • Fingerprint improvements for IBM.
  • Fingerprint improvements for Sharp.
  • Fingerprint improvements for NETSCOUT.
  • Fingerprint improvements for Delphix.
  • Fingerprint improvements for Navisphere.
  • Fingerprint improvements for Potter Electric.
  • Fingerprint improvements for Wycom.
  • Fingerprint improvements for Keysight.
  • Fingerprint improvements for Knürr.
  • Fingerprint improvements for Primax.
  • Fingerprint improvements for NetScaler version detection.
  • Fingerprint improvements for VMware vCenter Server.
  • Fingerprint improvements for Ubiquiti.
5.1.260910.0
  • runZero now analyzes Microsoft Defender version numbers more accurately.
  • Fingerprint improvements for Siemens.
5.1.260908.1
  • The console web service now returns more appropriate HTTP status codes for conditions like canceled requests and unknown record IDs, using 4xx codes instead of the generic 500.
5.1.260908.0
  • runZero now supports assigning custom roles to API keys, default user roles, group permissions, SSO defaults, and MCP connections.
  • Users can now create API clients with custom permissions capped by their own access rights. Account-level API clients can also use granular authentication scopes in addition to roles.
  • The MCP experience now works smoothly with Claude Desktop and similar tools. Background MCP connections no longer count against API usage.
  • Users can now reprocess tasks directly from the user interface.
  • Account administrators now receive email warnings before SAML certificates expire.
  • Recent assets now include sub-assets identified through protocol gateways, with a few account-level exceptions.
  • Task summaries now indicate when a task involved more than 1,000 asset changes.
  • Hostname discovery no longer falls back to NetBIOS domains. WS-Discovery XAddr endpoints now contribute to asset hostnames.
  • runZero now populates MAC vendor information for legacy MAC prefixes. The asset inventory now displays MAC vendor data more reliably.
  • Cloud imports now better match directly imported cloud assets. AWS, Azure, and GCP imports now include additional asset types. AI Threads reports now better match the active theme.
  • Dragos and Wiz imports now apply more complete fingerprinting and OS CPE matching when available.
  • Out-of-band detection now works reliably under concurrent task load.
  • MAC and link-local IPv6 addresses discovered via WS-Discovery no longer disappear and reappear between recurring scan tasks.
  • The MAC vendor now displays consistently in the asset inventory.
  • Vulnerability data no longer matches partial version ranges.
  • GCP credentials now save properly.
  • The task inspection card now stays open when you click an asset change summary link.
  • Fingerprint improvements for Citrix.
5.1.260905.0
  • Bulk directory group deletion no longer fails.
5.1.260903.0
  • The CrowdStrike integration now correctly populates software installation time and paths.
  • The integration test panel now returns custom integration credentials correctly.
  • The External Asset Report now generates correctly.
  • Weekly recurring tasks no longer skip a week.
  • Fingerprint improvements for Arthrex medical devices.
  • Fingerprint improvements for Microsoft.
  • Fingerprint improvements for Vertiv.
5.1.260901.0
  • Users can now share standard reports through the External Reporting feature.
  • TLS endpoints now display x.509 certificate Issuer and Subject information more consistently.
  • Alert rules now support conditions for Issue lifecycle events.
  • Issue owners now receive an email with a direct link when they are assigned an Issue, unless the Issue is linked to a third-party ticket or the owner lacks a valid email address.
  • The Issues inventory now supports searching Issue comments with the comment: keyword.
  • Invalid report searches now return more descriptive error messages.
  • Users can now sort Findings by name.
  • The Censys integration now processes assets.
  • runZero now stores and displays hostnames with consecutive hyphens correctly.
  • Remediation tracking no longer overcounts remediated instances or incorrectly marks an Issue as Remediated.
  • Users can now close an Issue from the Issue Details page.
  • Fingerprint improvements for Arista.
  • Fingerprint improvements for AVM.
  • Fingerprint improvements for Brocade.
  • Fingerprint improvements for Cisco.
  • Fingerprint improvements for Cohesity.
  • Fingerprint improvements for Control4.
  • Fingerprint improvements for DIRECTV.
  • Fingerprint improvements for Dresden Elektronik.
  • Fingerprint improvements for HPE.
  • Fingerprint improvements for Huawei.
  • Fingerprint improvements for Imeon Energy.
  • Fingerprint improvements for Kaleidescape.
  • Fingerprint improvements for Keenetic.
  • Fingerprint improvements for LaMetric.
  • Fingerprint improvements for Linn.
  • Fingerprint improvements for Logitech.
  • Fingerprint improvements for Microsoft.
  • Fingerprint improvements for NETGEAR.
  • Fingerprint improvements for Provectus.
  • Fingerprint improvements for Raspberry Pi.
  • Fingerprint improvements for Roku.
  • Fingerprint improvements for Sonos.
  • Fingerprint improvements for Sony.
  • Fingerprint improvements for Traefik.
  • Fingerprint improvements for Ubiquiti.
  • Fingerprint improvements for Universal Devices.
  • Fingerprint improvements for WiLight.
5.1.260827.2
  • Generated script resources now carry the embedded AI-generated label on download, and the exported-report label is placed and de-duplicated more reliably.
  • The credential form for the NinjaOne, Miradore, and Tailscale integrations now renders correctly.
5.1.260827.1
  • runZero now labels AI Threads and AI Artifacts as AI-generated, following EU guidance on labelling AI-generated content. The label appears in the console the first time a response or artifact is shown. It is also embedded in exported reports, downloaded files, and generated custom-integration scripts, so it stays with the content when shared.
  • The query library’s “Dashboards” column now shows how many personal dashboards use a saved query, and whether the query is also used on other dashboards.
  • runZero now handles invalid software and inventory search terms more gracefully.
  • The list of default roles selectable in SSO settings now includes the Annotator role.
  • The Censys Platform integration now retries API calls on connection errors and other retryable codes.
  • Scanning member accounts in an AWS Organization with an IAM Role Credential no longer fails prematurely.
  • Explorer packet listeners no longer consume 100% of a CPU core after a scan encounters read errors during network disruptions.
  • Daily API usage counters no longer miss their nightly reset or lock accounts out of the API. Daily API usage is now tracked per UTC calendar day and recovers automatically.
  • Custom integration scripts running on an Explorer can now connect to internal IP addresses.
  • Fingerprint improvements for Brocade.
  • Fingerprint improvements for Ruckus.
  • Fingerprint improvements for APC.
  • Fingerprint improvements for Zebra.
  • Fingerprint improvements for Kyocera.
  • Fingerprint improvements for FUJIFILM.
  • Fingerprint improvements for Brother.
  • Fingerprint improvements for ServerTech.
  • Fingerprint improvements for Enlogic.
  • Fingerprint improvements for Dell.
  • Fingerprint improvements for Lenovo.
  • Fingerprint improvements for NetApp.
  • Fingerprint improvements for Adtran.
  • Fingerprint improvements for Digi.
  • Fingerprint improvements for Gude.
  • Fingerprint improvements for Awind.
  • Fingerprint improvements for ZPE.
  • Fingerprint improvements for Crestron.
  • Fingerprint improvements for IBM.
  • Fingerprint improvements for Philips.
  • Fingerprint improvements for Silex Technologies.
5.1.260826.0
  • Security: runZero fixed a bug in the MCP service that could have allowed a user to access organization data outside their authorized scope. The exposure was limited to Findings summaries and required knowing the target organization’s unique IDs.
  • Security: runZero removed obsolete dependencies from the product during a routine review.
  • This update adds several AI-related features. AI support is still disabled by default and requires a BYOK approach. The MCP server uses no AI of its own, but you can plug it into your workbench of choice to work with the platform.
  • The MCP service and in-product AI Threads now share the same tools.
  • The MCP service now supports OAuth, including using Export Tokens and Organization Keys as OAuth Client Secrets, in addition to API Clients.
  • The AI Threads feature now supports extensive charting and diagrams via Mermaid.
  • The AI Artifacts feature now supports full-page viewing.
  • Custom Integration scripts received another large update. The community repository now covers more than 100 products. This library is available in the console, and you can modify individual scripts or use them to build similar data flows.
  • Scripts are now available to all administrators, even those with narrow access scopes.
  • You can now run scripts in console instances in addition to Explorers and the CLI.
  • You can author and test scripts in-product using your AI model of choice.
  • Scripts now track a maturity mode (alpha, beta, stable) for easy filtering.
  • Scripts can now define detailed credential fields and validation rules.
  • Scripts now support settings shared across protocols like HTTP and TLS.
  • Scripts now support WMI (WinRM, SMB, DCERPC) for deep Windows collection.
  • Scripts now support custom application protocols over TCP, UDP, and Unix streams.
  • You can submit scripts for inclusion as native runZero sources.
  • The Cryptographic bill of materials (CBOM) is available as a new CycloneDX JSON export and detailed report.
  • The Censys integration now supports the Censys Platform (v3 API).
  • runZero optimized MAC merging, so large scan jobs now process faster.
  • The scanner’s fragile device detection now always uses a soft close (FIN), reducing the risk of destabilizing target devices.
  • User-facing messaging throughout the runZero console has improved.
  • Fingerprint improvements.
5.1.260825.0
  • The scan page now has a configuration option to toggle the promiscuous ARP probe.
  • vmatch no longer tries to compare version date strings to semver versions.
  • Editing an Organization Overview report no longer creates a new task.
  • Some Organization Overview report settings no longer save improperly.
  • Fingerprint improvements.
5.1.260821.0
  • The console no longer panics when an OpenAI-compatible AI provider returns an out-of-specification response.
  • The ts field of services no longer contains multiple Unix timestamps.
  • vmatch-suggested updates now match Microsoft Office versions.
  • Performance improvements.
  • Fingerprint improvements.
5.1.260820.1
  • The Organization Overview report now shows total asset counts in the sites summary instead of live asset counts, matching the sites table in the runZero console.
  • The issue edit form now displays a warning when external ticket assignment fails.
  • AI Threads and natural language search no longer fail with GPT-5 models.
  • Azure tasks no longer fail because of expired authorization tokens.
  • Fingerprint improvements.
5.1.260820.0
  • runZero no longer intermittently signs users out immediately after they sign in.
  • Fingerprint improvements.
5.1.260818.1
  • The asset inventory now has an OCSF 1.9.0 export. Assets export as Device Inventory Info events and their observed services as Live Evidence Info events, available as assets.ocsf.jsonl and assets.ocsf.json from the inventory export menu and the Export API. The export keeps fields without an OCSF equivalent under the event’s unmapped object.
  • AWS tasks no longer fail when they are not configured for us-east-1.
  • Query-based widgets now load on large dashboards.
  • An “AG Grid” diagnostic panel no longer appears in some circumstances.
  • Fingerprint improvements.
5.1.260814.1
  • Security: This update builds on Go 1.26.6, which includes fixes for multiple security issues.
  • Asset geolocation now uses location data from additional integration-sourced attributes.
  • The Refingerprint asset action now also re-evaluates service fingerprints for improved accuracy.
  • Device type icons in the inventory tables now match the styling of Findings category icons.
  • The scanner now detects a broader range of IPMI vulnerabilities.
  • runZero now processes directory and device data concurrently, improving task performance.
  • Autonomous discovery no longer creates a separate sub-task per target.
  • Non-secret fields now appear when you edit a custom integration credential.
  • The scanner no longer drops UDP responses at high load.
  • Searches on name no longer return assets that do not match the search term.
  • Variants of excluded hostnames no longer appear on an asset.
  • runZero now matches vulnerabilities to Citrix Workspace versions correctly.
  • The vulnerabilities by asset inventory no longer displays duplicated suppression columns.
  • Findings data grids now update after suppression changes.
  • The “Top findings” widget no longer displays a false no-data message.
  • Fingerprint improvements.
5.1.260813.0
  • The AWS integration now supports AWS Inspector findings for EC2 and Lambda assets.
  • The AWS integration no longer checks linked organizational accounts that are closed.
  • The reports page now displays a paginated list of all analysis task-based reports, and you can search and delete reports from it.
  • Vulnerability exports now run faster.
  • runZero no longer adds NetBIOS domains as asset hostnames.
  • Issues no longer state that merged assets do not exist.
  • runZero now sends Rapid Response alerts in some platform tenants where it previously did not.
  • The “Additional security tests” section of the task configuration form now keeps previously saved settings instead of resetting them to their default values.
  • Fingerprint improvements.
5.1.260811.0
  • Connector tasks now honor the configured attribute and vulnerability expiration thresholds during import.
  • Custom integrations can now continue processing results even if a single device causes errors.
  • Tasks that update directory groups now run faster.
  • Metrics recalculation is now faster in some scenarios.
  • vmatch no longer mistakes Citrix short-form versions for extremely high versions.
  • The integrations landing page no longer shows broken cover images.
  • Asset merges no longer fail.
  • The external assets report no longer fails for large organizations.
  • runZero no longer labels assets discovered solely through passive traffic sampling as identified by active scanning.
  • You can now re-invite an external user who already has access to the account.
  • Fingerprint improvements.
5.1.260806.1
  • runZero fixed a security issue that could allow new account registration in restricted environments.
  • Performance improvements.
  • Fingerprint improvements.
5.1.260804.1
  • The link from relevant integrations to the AI configuration form now works.
5.1.260804.0
  • runZero now clears existing service fingerprints when a task has no fingerprint matches.
  • The Rapid7 InsightVM Cloud integration now formats tags correctly.
  • Fingerprint improvements.
5.1.260731.2
  • Compliance-friendly AI workflows now deliver data insights.
  • Autonomous discovery now automates complete attack surface intelligence.
  • An improved framework speeds up custom integrations and refines merge logic.
  • Remediation handoffs now happen directly inside runZero or through ITSM integration.
  • The improved Dragos integration enriches OT context and eliminates silos.
  • Connected AWS accounts now skip task processing for disabled AWS regions.
  • Fingerprint improvements.
5.0.260730.0
  • Natural language inventory search has improved.
  • Attribute names no longer overlap their values in vulnerability details views.
  • Stale integration data expiration tasks no longer fail.
  • Some CrowdStrike attributes no longer remain after they should have expired.
  • Software version-based vulnerability reporting now suggests updates that match Microsoft Office versions.
  • Fingerprint improvements.
5.0.260728.1
  • Users with organization access can now view site details and subnet definitions on the new site details page.
  • runZero can now sync issue owners with Jira.
  • The Goals widget now includes a Pending metric showing baseline assets that do not match the target query, with a click-through to those assets in inventory.
  • The Tanium integration now supports specifying multiple sensors.
  • The scanner now supports services using the Git Smart Protocol.
  • Windows Server detection is now more accurate.
  • The software inventory now supports the search terms purdue_level and lowest_purdue_level.
  • The vulnerability inventory now supports the search terms purdue_level and lowest_purdue_level.
  • Active and passive data collection for the AMQP protocol now has broader coverage.
  • Platform performance has improved.
  • The AWS integration no longer creates duplicate sites when “Automatically create a new site per account” is enabled.
  • runZero fixed an issue that could crash the Explorer.
  • Fingerprint improvements.
5.0.260723.0
  • runZero now shows Purdue levels for assets sourced by or enriched with information from Dragos.
  • Backported NGINX versions no longer produce false-positive vulnerability matches.
  • Software version-matching for vulnerability reporting no longer misreads source version numbers.
  • Vulnerability scans no longer fail to match to assets.
  • Fingerprint improvements.
5.0.260721.0
  • You can now remove the Bookmarks widget from dashboards.
  • runZero no longer misidentifies Windows assets in corporate environments.
  • Reported vulnerabilities no longer use the wrong lower bound for affected software versions when data sources disagree.
5.0.260717.1
  • Validation errors now display when you update a scheduled or recurring scan.
  • Deleting the user who created an Explorer group no longer deletes the group.
  • Assets no longer retain stale sources after stale attribute expiration removes all relevant attributes.
5.0.260716.0
  • Detection of services advertising over MDNS has improved.
  • The 2D Network Map report now enforces per-hop exclude filters on nodes that share a subnet cluster with non-excluded peers.
  • runZero no longer associates IPv6 addresses with the wrong MAC address, which had led to asset mismerging.
  • Passive tasks now process certain packets that they previously could not.
  • Explorer assets no longer show phantom services in rare configurations.
  • Alert rules no longer return inaccurate query results.
  • Fingerprint improvements.
5.0.260714.0
  • The Dragos integration now includes assets’ crown jewel status and Purdue level.
  • The vulnerability groups inventory now shows a meaningful error message when a search contains unsupported terms, instead of a generic SQL error.
  • External reporting links now use the correct console URL.
  • Fingerprint improvements.
5.0.260709.1
  • The Start time date picker now works when you configure an integration task.
5.0.260709.0
  • The vulnerability inventory table no longer includes the finding name column.
  • You can now export 3D Network Map report results as CSV and JSON.
  • The Dragos integration no longer fails when ingesting all assets.
  • The “View more” link on the Rapid Response widget of the Exposure Management dashboard now responds to clicks.
  • runZero no longer associates IPv6 addresses with the wrong MAC address, which had led to asset mismerging.
  • Fingerprinting from InsightVM Cloud data has improved.
  • Fingerprint improvements.
  • Performance improvements.
5.0.260707.0
  • The stale integration attribute expiration feature now supports stale threshold overrides for individual integration sources, configured in organization and account settings. Integrations without an override continue to use the global setting.
  • The software count column in the asset inventory now links to the software inventory.
  • IPv6 link-local addresses no longer contribute to multi-homed asset detection.
  • Fingerprint improvements.
5.0.260704.0
  • You can now scroll vulnerability tooltips.
  • Performance improvements.
5.0.260702.0
  • The Dragos integration can now match assets with SentinelOne data based on asset serial number, and vice versa.
  • Issue status now treats suppressed vulnerabilities as Resolved.
  • Vulnerability suppression status now persists across imports.
  • Loading task data into a new project no longer fails.
  • Removing SentinelOne data no longer leaves SentinelOne data behind on assets.
  • Fingerprint improvements.
5.0.260630.0
  • The asset inventory now supports searching for assets with a tag that has no value. For example, tag:test= matches assets with tag test but not assets with tag test=example.
  • Detection of invalid assets has improved.
  • runZero no longer creates phantom assets.
  • Fingerprint improvements.
5.0.260625.0
  • The AWS integration can now create assets for VPC Endpoints.
  • You can now share issues externally from the issues datagrid.
  • The “Findings Overview” widget now counts accurately when findings appear in multiple sites.
  • Rapid7 InsightVM Cloud task runs no longer exclude non-critical vulnerabilities.
  • Fingerprint improvements.
5.0.260625.0 - Detect, Prioritize, Remediate, Verify, Report
  • runZero 5.0 connects the exposure lifecycle end to end: detect, prioritize, remediate, verify, and report. This release introduces an exposure-first landing experience, remediation tracking with verified closure, recurring external reporting, and broader vulnerability detection across IT and OT.
  • The Exposure Management dashboard is now the default landing view. It shows prioritized exposures immediately and puts externally exposed issues at the top.
  • The Exposure Snapshot widget pulls live data directly from the underlying queries. It isolates multi-homed network paths and separates OT and IoT into distinct streams.
  • Returning users see what is new, resolved, or worsened since their last session, so they can re-orient quickly and decide where to focus.
  • New widgets track Mean Time to Remediate (MTTR), issue status totals, reopened-issue trends, and vulnerability status trends by severity. A Goals widget shows progress toward targets as a progress bar.
  • Dashboards for organizations with little or no data show a clean no-data state rather than an error.
  • You can create a Remediation Issue directly from an exposure, finding, or vulnerability group in a single click. The issue form fills in the Name, Description, and Remediation fields from shared vulnerability properties.
  • You can push work to Jira as an External Ticket. Credentials map down to the project key and support a custom state-to-state mapping matrix. ServiceNow support will follow.
  • External Ticket status changes flow back to the Remediation Issue, and runZero records them on an immutable timeline. Closing an issue requires an explanation comment, which runZero keeps permanently for audit.
  • runZero preserves a compressed snapshot of the original exposure state on each issue and compares it against live discovery to verify the fix. Verification runs on scheduled discovery iterations rather than as an instant on-demand re-scan.
  • runZero tracks reopened issues automatically. The Issues inventory adds searchable, sortable Recurrences and Last Recurrence columns that increment when an asset returns to an active state.
  • Due-date alert rules fire email or webhook notifications when a Remediation Issue passes a set number of days past due.
  • Stale-vulnerability cleanups archive rather than delete vulnerabilities referenced by active issues, and search supports an explicit archived filter.
  • You can schedule recurring reports, for example weekly or monthly, from supported dashboards and views. Sub-report instance management tracks one-time and recurring runs.
  • Reports compile as interactive, point-in-time HTML snapshots delivered by email. Recipients need no runZero account to search, filter, paginate, and preserve chosen line items.
  • Modernized report views cover Asset Risk, Asset Ownership, Outlier Overview, and Specific Outlier reports. Interactive snapshots are also available for the Vulnerability, Vulnerability Groups, Software, Software Groups, and Issues inventories.
  • External inventory reports include only the line items you selected at creation rather than the entire table.
  • Recipients can export to CSV, JSON Lines, and JSON, and export shared dashboard layouts as high-resolution PNG images.
  • Notification emails include the report name and schedule frequency in the subject and body, along with the sender’s name and a reply address. runZero stores report snapshots compressed in S3 with token expiration.
  • Version-based rollups match each asset’s OS, hardware, and software versions against known advisories and report a single “Missing Patches for [Vendor] [Product]” finding per asset and product, aggregating every affected CVE. This is on by default for new and existing accounts and organizations.
  • Expanding a Missing Patches finding shows the recommended action, the matched rule, the detection location, the source of the version evidence, and a risk assessment with severity, CVE breakdown by criticality, and exploited-in-the-wild signals. When a CVE appears in CISA KEV or VulnCheck KEV, runZero raises its severity to at least High.
  • Out-of-band testing detects blind vulnerability classes using runZero-hosted services in US and EU regions, with no customer-side infrastructure required. Regional availability supports data-residency needs.
  • End-of-life and end-of-support detection covers common network devices, including Cisco, Juniper, and HPE/Aruba. It derives from existing discovery fingerprints and needs no additional scanning or credentials.
  • OT equipment receives the same Missing Patches rollups, matched against vendor advisories published in CSAF format, with no credentialed or agent-based access to OT devices.
  • You can control version-based reporting at the account level and per organization. The organization-level setting is available through the public Account API as vmatch_enabled.
  • Since 4.9 (April 29), 5.0 has touched roughly 1,100 fingerprints across devices and services: 649 added, 469 updated, and 19 removed.
  • Traditional IT and edge devices: this release expands device and service coverage for core enterprise hardware from Cisco, Barracuda, and Ubiquiti, and many, many more.
  • Industrial assets and services: operational environments get a major coverage expansion, with deeper detection for automation platforms from Siemens, Schneider Electric, and Rockwell Automation, among others.
  • Consumer products: runZero now also supports a few consumer-centric IoT items, since these often turn up in enterprise networks thanks to work-from-home realities. This includes the Maytronics pool robot and the Eight Sleep SmartBed Controller.
  • runZero coordinates and verifies remediation. It does not apply patches or configuration changes, and it does not replace your ticketing system.
  • Verified closure compares the preserved exposure snapshot to live discovery on scheduled discovery runs. On-demand re-scan at the moment a fix is applied is a planned fast-follow.
  • End-of-life and OT advisory coverage continues to expand as runZero adds detection content.
5.0.260623.0
  • Fingerprint improvements.
5.0.260622.1
  • Performance improvements.
  • Fingerprint improvements.
5.0.260622.0
  • Vulnerability recurrence tracking now works for the new Issues feature.
  • The MDE integration can now set asset hostnames from the hyperv.host value.
5.0.260621.1
  • Performance improvements.
5.0.260618.0
  • Alert rule queries now have an option to cover all assets instead of just live assets.
  • You can now run an alert rule on demand.
  • The scanner now covers additional default ports for the GE-SRTP protocol.
  • The scanner now captures metadata for ADB STLS service responses.
  • The Rapid7 InsightVM Cloud Integration now includes asset hostnames.
  • Asset correlation now recognizes IPs that are reused extensively (such as by some VPN systems) and no longer uses those IPs as match criteria.
  • Vulnerability archiving is paused while runZero investigates performance.
  • The scanner no longer trips CIP safety controllers during backplane enumeration.
  • Fingerprint improvements.
5.0.260617.0
  • The Issues table now includes the type and external ticket link.
  • The Goals inventory datagrid “Status” column now sorts correctly.
  • Searching the Users table by full name now returns results.
5.0.260616.1
  • Vulnerability queries now run faster.
  • Offline assets no longer report a service count of 0 when services are present in the asset data.
  • runZero no longer ignores MAC addresses without corresponding IP addresses reported by the Tenable integration.
  • API rate limits no longer apply incorrectly to some access tokens.
  • Fingerprint improvements.
5.0.260614.1
  • Vulnerability ingestion now runs faster.
  • Fingerprint improvements.
5.0.260614.0
  • Recurring tasks that reference an inaccessible credential after an ACL change now pause and indicate why.
  • Asset, vulnerability, and certificate queries now run faster.
5.0.260612.0
  • Vulnerability queries now run faster.
  • Fingerprint improvements.
5.0.260611.1
  • runZero now archives or deletes vulnerabilities instead of orphaning them.
  • One-off tasks run on Explorer groups now upload results.
  • Fingerprint added for Crestron CP4N video conferencing device.
5.0.260611.0
  • Operating System and hardware End of Life (EOL) and end of sale information for Cisco Meraki devices has improved.
  • Operating System and hardware End of Life (EOL) information for Lenovo Chromebooks has improved.
  • Fingerprint improvements.
5.0.260610.1
  • The new Exposure Management dashboard provides a high-level overview of internal, external, and cloud attack surfaces.
  • You can now create Issues to track the resolution of findings and vulnerabilities, with optional third-party synchronization to Jira.
  • You can now generate and share externally visible reports for most dashboards and inventory tables.
  • runZero now provides Operating System End of Life (EOL) information for Arista EOS.
  • The Explorer no longer merges with other assets by MAC.
  • The services section of the asset details screen now renders correctly.
  • Fingerprint improvements.
4.9.260609.0
  • You can now export findings, vulnerabilities, and software for a specific asset directly from the asset details screen.
  • runZero fixed an issue with the MODBUS probe that could result in additional network traffic.
  • Fingerprint improvements.
4.9.260604.1
  • This console-only release fixes a bug in hosted external scan scheduling.
4.9.260604.0
  • Stale integration attribute and vulnerability expiration settings now support client-level defaults, which superusers can update.
  • The site-updated event now includes details about what changed on the site.
  • The scanner no longer misidentifies MCP services in rare cases.
  • Tasks no longer fail with an “explorer timeout” message when the initial upload fails.
  • Fingerprint improvements.
4.9.260602.0
  • Custom dashboards now have widgets that show vulnerability counts.
  • The Export dropdown on asset attribute analysis reports is no longer partially obscured.
  • Certain models of Cisco IP phones no longer merge incorrectly.
  • The scanner no longer collects incomplete data from BACnet devices.
  • Windows Explorers no longer crash while taking screenshots.
  • Fingerprint improvements.
4.9.260529.0
  • Findings updates no longer fail.
  • Vulnerability exports for certain queries now run much faster.
  • Fingerprint improvements.
4.9.260528.0
  • The account and organization API endpoints for creating and updating an organization now support a new field, expiration_settings. The fields expiration_integration_attributes, keep_latest_integration_attributes, and expiration_vulnerabilities are being deprecated in favor of the new field.
  • When creating or editing an organization in the runZero console, you can now leave the attribute and vulnerability expiration settings blank to use the default values.
  • The Findings table no longer shows an inaccurate Instances count.
  • Fingerprint improvements.
4.9.260526.0
  • The Shodan integration can now selectively exclude tags from assets.
  • You can now configure which integrations can modify asset OS, hardware, and device type.
  • The CLI scanner no longer returns truncated scan results.
  • Scan results no longer include bogus arp.mac data.
  • Fingerprint improvements.
4.9.260521.2
  • The scanner now skips protocol negotiation by default for TCP ports 9042 and 9160.
4.9.260521.1
  • Windows Explorers no longer crash during high-speed scans.
4.9.260521.0
  • The AWS integration now enriches VPC assets with VPC endpoints data.
  • You can now enroll TOTP tokens.
  • Scan and passive sampling tasks no longer duplicate assets in some circumstances.
  • You can now remove empty sites.
  • The “Set asset comments” and “Set asset tags” buttons are back in the Modify action within the asset inventory.
  • CrowdStrike integration credential verification no longer fails.
  • Windows Explorers no longer crash while taking screenshots.
  • Fingerprint improvements.
4.9.260519.0
  • Users with the User role can now delete individual assets.
  • The AWS integration now processes VPC assets from connected accounts.
  • Asset queries that use the vuln_exploitable keyword now run faster.
  • runZero fixed an issue affecting Time-based One Time Password (TOTP) multi-factor authentication (MFA).
  • Fingerprint improvements.
4.9.260514.0
  • Multi-source AWS ELBs no longer keep old IP addresses.
  • The scanner now scans additional DTLS ports (12346, 12366, 12386, 12406, 12426).
  • The Export dropdown on the Asset Risk Report is no longer partially obscured.
4.9.260512.0
  • The vulnerability inventory now displays details when you hover over a vulnerability group name.
  • The Explorer details page now includes an option to download Explorer system logs.
  • The Overview dashboard now loads in My Organizations view.
  • The task details page no longer displays negative scan and data acquisition durations.
  • Sorting by Explorer Groups on the Explorer list page no longer causes errors.
  • “findings-with-instances” alert rules can now filter by risk.
  • “findings-with-instances” alert rules configured to notify when the vulnerability count decreases no longer notify when it increases instead.
  • The total result count in the asset inventory is now accurate after deleting or merging assets.
  • Fingerprint improvements.
4.9.260511.0
  • The scanner now detects network disruption and automatically lowers its send rate.
  • The NetBox integration now supports a wide range of server versions (4.0 - 4.5).
  • The Query-Assets MCP tool can now export services, attributes, and foreign attributes.
  • Tasks no longer fail to process in low disk space scenarios.
  • Cloud-based integrations can now use configured proxies via Explorers.
  • Custom integration data no longer reports assets after its definition is removed.
  • Assets no longer mismerge when the router proxies IPv6 NA/NS requests.
4.9.260508.1
  • Assets no longer fail to merge because of a race condition that primarily affected passive traffic sampling and IPv6 link-local scans.
4.9.260508.0
  • The Rapid7 InsightVM Cloud integration now handles larger data objects.
  • The single-count custom widget now includes a value delta for the dashboard’s time period.
  • The CLI scanner now warns when run without the appropriate network permissions.
  • The embedded npcap in Windows Explorers is now v1.88.
  • Integrations no longer report a misleading “API unreachable” message for certain errors.
  • The Avaya OS icon now displays within the product.
  • Oracle ILOM devices no longer display with an HP logo within the product.
  • Fingerprint improvements.
4.9.260504.0
  • The AWS integration now reports FSx assets.
  • The CrowdStrike connector now retries more times on transient 401 responses.
  • The Asset Inventory CSV report now includes the VLAN column.
  • Users with Annotator role access can now add asset comments in addition to tags.
  • The Network Maps now treat eol:true as meaning the later of the OS EOL or EOL Extended dates.
  • The scanner no longer reports Siemens S7Comm virtual modules (“Firmware”) as sub-assets.
  • The scanner now randomizes TCP ports to reduce pressure on transparent proxies.
  • The scanner now uses fewer system resources and handles screenshots more reliably.
  • The scanner now reports screenshots for non-NLA RDP (Windows) and no-auth VNC.
  • The scanner now spends less time on network “tar pits” (hundreds of bogus services).
  • The scanner now reports application-layer data for SSL 2.0 wrapped services.
  • The scanner now handshakes PQC hybrid ciphers for SSH services.
  • Single-source AWS ELBs no longer keep old IP addresses.
  • ARP results no longer report mangled IPs.
  • Assets no longer get duplicate GeoIP attribute values.
  • Scans no longer leave stale Chrome processes behind.
  • The scanner no longer reports invalid SNMP versions.
  • Certificates now sort correctly by Subject or Subject Key ID.
  • Fingerprint improvements.
4.9.260430.1
  • Dashboard widgets no longer render with an incorrect chart height.
  • Custom Integration Scripts no longer throw an error when comparing IPAddress values.
  • The Custom Integration Scripts code editor now renders correctly in dark mode.
  • Inventory tables no longer sort by unavailable columns.
  • The scanner worker group size is now independent of the configured scan rate, which improves resource usage.
  • The scanner now completes web screenshots faster on machines with generous memory but low CPU core counts.
  • The scanner now uses fewer resources during the HTTP and vulnerability scan phases.
  • Fingerprint improvements.
4.9.260430.0
  • The runZero 4.9 release is live. This version focuses on OT, attack graphs, and segmentation analysis.
  • The Network Maps (2D/3D) now render unmapped MACs and unscanned traceroute hops by default.
  • SNMP v3 no longer reports a username when none was specified.
  • The scanner now uses significantly fewer resources and completes scans faster.
  • You can now use tags to specify geolocations manually (for example, geo.City=Austin/TX/USA).
  • Assets with geolocation data now link to the World Map from the inventory icon fields.
  • Fingerprint improvements.
4.8.260429.0
  • SCTP no longer exceeds task rate limits in an additional case. The SCTP protocol is now disabled by default as a precaution; you can re-enable it on the scan configuration probes page by marking sctp-tenable as true.
  • The scanner now uses the mtconnect protocol to collect default device information when available.
  • The Ethernet/IP CIP protocol stack now identifies more module types, including CNCs.
4.0.260428.2
  • SNMP sysObjectID normalization no longer prevents asset matching.
  • Scan files are no longer larger than necessary.
  • The scanner now deduplicates the output of DCERPC and EPM protocol enumeration.
  • The S7 source is now part of the existing S7Comm definition.
4.0.260428.1
  • Fingerprint improvements.
4.0.260428.0
  • This release resolves two issues with the new SCTP protocol implementation, both of which could lead to network disruption.
  • The first issue affected environments where the configured scan rate was close to the network limit. The rate limiter was misconfigured to treat SCTP separately from the rest of the scan traffic, which could run scans at 1.5x to 2.0x of the configured rate. SCTP now uses the shared rate limiter as intended.
  • The second issue affected stateful middle-boxes with low session limits and long timeouts for SCTP flows. The SCTP INIT scan did not proactively reset sessions, so session counts could grow quickly and disrupt other flows once the device limit was reached. The scanner now proactively tears down SCTP sessions, similar to how runZero handles TCP SYN scans.
  • Asset inventory links no longer return a not-found error in My Organizations mode.
  • Exports of the software and vulnerabilities table are no longer slow.
  • The scanner now captures DCERPC EPM results completely.
  • LDAP-sourced Active Directory records and CrowdStrike endpoint records now use the objectGUID and objectSid attributes for matching and merging.
  • Fingerprint improvements.
4.0.260426.0
  • runZero updated the Organization Overview report, Network Map, and World Map.
  • Fingerprint improvements.
  • 4.0.260426.0
4.0.260423.0
  • runZero now has a native integration for Rapid7’s InsightVM Cloud.
  • The assets and services inventory searches now support comma-delimited values for the protocols keyword.
  • Fingerprint improvements.
4.0.260421.0
  • Explorer processes on Windows no longer abort in two additional cases.
  • Asset attributes now track the specific fields that contribute to an outlier score.
  • Fingerprint improvements.
4.0.260420.1
  • Task data now includes TCP diagnostics.
4.0.26020.0
  • Explorer processes on Windows no longer abort in two cases.
  • runZero addressed an issue where provider rate limits could prevent email delivery.
  • Unmerge actions now complete.
  • New maps are in preview; find them under the Manage menu of the asset details page.
  • Fingerprint improvements.
4.0.260417.0
  • runZero addressed an issue that could cause Windows Explorers to crash mid-scan, and all binaries are now built with the Go 1.26.2 toolchain. The root cause was a race condition that corrupted the stack in the TCP connection tracking logic.
  • Saved software queries that could error when run as part of a metrics task now succeed.
  • Integration searches now work with capital letters.
  • Self-hosted upgrades no longer show a migration error.
  • Fingerprint improvements.
4.0.260416.0
  • You can now switch the runZero console between three themes: Classic, light, and dark mode.
  • A dashboard configuration can no longer be viewed from outside the authorized organization scope.
  • Production builds have switched back to the Go 1.25 runtime to mitigate an issue that could crash the Windows Explorer service mid-scan, while we continue to investigate.
  • The Shodan integration now runs all queries.
  • runZero fixed a performance issue with the Software inventory.
  • OS reporting now accounts for the “os-release” OID on Linux systems running net-snmp.
  • Fingerprint improvements.
4.0.260414.0
  • The Wiz integration now supports filtering assets by cloud provider.
  • The scan template form now shows the “Additional security tests” options the same way as the standard form.
  • Scans configured from a template now use the template settings for “Additional security tests”.
  • API-created scan tasks no longer store an incorrect start time due to timezone conversion.
  • The Explorer service no longer crashes during scans in additional cases.
  • The vulnerability inventory by asset index no longer shows vulnerabilities that were suppressed by group.
  • Fingerprint improvements.
4.0.260410.0
  • You can now configure the display order of asset host names at the account and organization level.
  • Operating System End of Life (EOL) dates for Microsoft Windows Desktops now default to the Enterprise edition values unless a more specific edition is reported.
  • Operating System End of Life (EOL) information for Microsoft Windows Server has improved.
  • Fingerprint improvements.
4.0.260407.0
  • Asset correlation now handles ARP data better, using only the latest available data when appropriate.
  • The software inventory now provides an organization name for each software group.
  • The scanner now collects SharePoint versions correctly.
  • Explorers without screenshot capabilities now show the correct icon color.
  • NetBox assets no longer merge incorrectly in some cases.
  • Fingerprint improvements.
4.0.260402.0
  • The InsightVM integration now provides more detail in authentication errors.
  • Explorer performance and reliability have improved.
  • Suppressed vulnerabilities no longer reappear with updated scan results.
  • Fingerprint improvements.
4.0.260401.2
  • Self-hosted installations now upgrade correctly.
4.0.260401.0
  • You can now configure overlapping site subnets.
  • Sub-asset enumeration now works for IPv6 OT services.
  • Scan tasks no longer crash during technology detection.
  • The CrowdStrike integration now uses the correct retry timer.
  • The asset grid no longer disappears when you select an asset with a deleted custom integration.
  • The Subnet report no longer double-counts some addresses.
  • Select All now works on the Software By Asset view.
  • The date picker no longer overflows its container.
  • License counts now temporarily exclude assets identified through BACnet, CIP, MODBUS and KNXnet gateways while we improve the configurability of this feature.
4.0.260331.0
  • The software tab on the asset details screen now loads.
  • The services inventory now loads.
  • Software queries now calculate results.
  • Service queries now calculate results.
  • Fingerprint improvements.
4.0.260330.1
  • Fingerprint improvements.
4.0.260330.0
  • runZero now identifies assets through network-reachable BACnet, CIP, MODBUS and KNXnet gateway devices.
  • runZero now automatically places assets into a Category (IT, OT, IoT) and assigns Functions to OT assets.
  • Explorers deployed on Windows hosts no longer log “Failed to write to log” error messages.
  • Explorers running on Windows no longer crash in certain scenarios.
  • Fingerprint improvements.
4.0.260329.0
  • Windows executables no longer download as zero-byte files.
4.0.260327.1
  • Fingerprint improvements.
4.0.260327.0
  • The merge logic no longer incorrectly merges assets with conflicting Intune hardware data.
  • Failed recurring tasks no longer create events with incorrect metadata.
  • The console no longer runs out of memory when serving Explorer or scanner binaries and large content updates.
4.0.260326.0
  • runZero now supports an optional API key IP address allowlist, which you can configure in the Account Settings section of your console.
  • The InsightVM integration can now import asset tags.
  • The Tanium integration now filters additional invalid attribute values.
  • The Active Directory integration now includes Referrals in LDAP search error messages, if available.
  • The Tasks page now loads faster.
  • Cross-site aggregate query metrics now populate.
  • Creating new dashboards now works.
  • Fingerprint improvements.
4.0.260323.0
  • The runZero Risk Management dashboard is now the default view when no other dashboard is selected.
  • The LDAP integration now includes extension attributes in its available data.
  • Images now display in specific sections of the console where they previously did not.
  • The BACnet probe now pulls data from the BACnet Broadcast Management Device (BBMD) and the Foreign Device Table (FDT).
  • User avatars in the team tables now render correctly.
  • runZero addressed an issue where metrics calculations would not return suppressed vulnerabilities when queried.
  • Fingerprint improvements.
4.0.260318.0
  • The asset view now includes Unmerge and Export as task data actions under the Manage menu.
  • The scanner now supports the Atlas Copco Open Protocol for device discovery.
  • The scanner now provides additional detail for the IPMI protocol.
  • The scanner now skips screenshots for TLS versions unsupported by Chrome.
  • The scanner now enumerates the backplane of Ethernet/IP CIP services automatically, reporting any visible assets.
  • runZero updated Operating System End of Life (EOL) data for Microsoft Windows and HP/HPE iLO.
  • The web console minimum supported browser version is now Chrome 123 (March 2024).
  • Low console disk space no longer prevents tasks from rescheduling.
  • Fingerprint improvements.
4.0.260312.0
  • The AWS integration no longer trims the role prefix from the ARN.
  • The self-hosted console no longer returns an error when the AWS_CA_BUNDLE environment variable is set.
  • The self-hosted console no longer removes the systemd service during manual restarts.
  • The self-hosted console no longer prints an error on startup.
  • runZero fixed an issue with empty notification templates being sent.
  • Task processing no longer refreshes software records excessively.
  • Fingerprint improvements.
4.0.260311.0
  • The scanner now covers additional default ports for the BACnet protocol.
  • runZero retired the Known Exploited Vulnerability finding in favor of direct vulnerability inventory queries (kev:true).
  • The self-hosted console now suggests email as an alternative if the fingerprint exceeds the maximum size.
  • The SentinelOne integration now supports a longer timeout for API calls (5 minutes).
  • The Tanium integration now matches assets more accurately.
  • The LDAP integration now imports directory groups much faster.
  • Fingerprint improvements.
4.0.260307.1
  • Integration tasks with significant software records now process faster after an initial sync.
  • Fingerprint improvements.
4.0.260307.0
  • software: searches from the asset inventory now run faster.
  • Ghost asset filtering no longer removes valid SSH endpoints.
  • The NetBox integration now connects to 4.2.x versions that previously failed.
  • Scan configuration no longer accepts excessive domain: keywords.
  • The Shodan integration now resolves scan targets when configured as part of a scan task.
  • Explorers no longer register as a new instance during an upgrade.
  • Fingerprinting via BACnet is now consistent.
  • Fingerprinting for assets imported from Dragos has improved.
4.0.260304.1
  • Performance improvements.
  • Merge logic improvements.
  • Phantom device detection has improved.
  • runZero now logs Shodan integration tasks that find no results, and those tasks do not fail.
  • Navigation items within dropdown menus are now more accessible.
  • Fingerprint improvements.
  • Some inventory searches linked to outliers no longer fail to return the expected results.
4.0.260302.0
  • runZero no longer fails to apply CrowdStrike fingerprinting to assets.
  • Fingerprint improvements.
4.0.260301.0
  • Explorer processes no longer crash during a scan.
  • Fingerprint improvements.
4.0.260222.0
  • The matching engine now uses hostnames from Rapid7 and Tanium sources to break matches.
  • Explorer processes no longer crash during a scan.
  • Large vulnerability processing tasks no longer use excessive memory.
  • IPMI enumeration no longer returns incomplete results.
  • The scanner now skips protocol discovery for the Microsoft SQL Server replication service.
  • The scanner now handles the IDENTD, Daytime, RIP, STUN, and TURN protocols better.
  • Fingerprint improvements.
4.0.260219.0
  • The asset inventory search can now filter results by vulnerability suppression state.
  • Scans now apply the scheduling grace period settings from their scan templates.
  • runZero now properly removes old software records.
  • The platform now supports a larger limit on asset vulnerability records.
  • Fingerprint improvements.
4.0.260218.1
  • The stale integration attribute cleanup task now completes.
4.0.260218.0
  • The AWS integration now supports roles with non-default paths for the IAM Role credential type.
  • The SNMP probe now trims whitespace from v3 credentials to avoid inadvertent misconfigurations.
  • The Layer-2 topology report now uses PAN API probe data.
  • The Explorer details view now performs better.
  • Fingerprint improvements.
  • runZero no longer incorrectly removes addresses from an asset’s Addresses Extra list.
  • Services now use the latest fingerprints when you manually refingerprint assets.
  • The IEC 60870-5-104 probe now operates correctly.
  • Some MDNS data no longer fails to apply to assets.
  • The “Reset security tokens” user action now deletes TOTP MFA tokens.
  • The speedtest results table now renders.
  • Scan tasks no longer report the error scan data is unavailable.
  • LDAP connector scan tasks no longer hang when the service is unreachable.
  • Assets discovered through the MECM integration no longer mismerge with assets discovered in other Microsoft integrations.
4.0.260213.0
  • The scan creation page now loads faster.
  • The subnet import action on the site edit page now provides error messages if the chosen file is malformed or incorrect.
  • The scanner now better detects and filters bogus MSSQL responses from Azure firewalls.
  • The runZero Service Graph Connector’s asset export API now defaults to a page size of 1,000.
  • Fingerprint improvements.
  • Tasks no longer show an inaccurate “Assets ignored” count in the change summary.
4.0.260211.0
  • The import page now sorts site options alphabetically.
  • Fingerprint improvements.
4.0.260210.0
  • A credential can no longer be updated and used for a task from outside the authorized organization scope.
  • Data extraction from LLMNR sources has improved.
  • Fingerprint improvements.
  • The scanner no longer misses CLDAP responses.
4.0.260209.0
  • Fingerprinting and data extraction from CDP sources have improved.
  • The scanner now supports a redact-secrets option for the IPMI probe.
  • Fingerprint improvements.
  • runZero now marks previously scanned assets offline as expected.
  • Metrics calculations no longer return incorrect vulnerability counts.
  • AWS integration tasks running with IAM-console credentials within EC2 can now access AWS GovCloud regions.
  • runZero now skips SNMP-reported interface MACs if the LAA bit is set and other non-LAA MACs are present in the interface list.
  • runZero now categorizes HP iLOs as BMC rather than Server.
4.0.260208.0
  • Explorer groups can no longer be accessed from outside the authorized organization scope.
  • The scanner now reports additional UDP protocols, including echo, daytime, cldap, iec104, llmnr, qotd, stun, time, turn, and zebra.
  • The scanner now reports new IPMI attributes, including cipher zero support, RAKP hash disclosure, and weak passwords found via RAKP.
  • New queries report vulnerabilities associated with the new IPMI service attributes.
  • The scanner now supports a new option for the SNMP probe: debug-scope. When given an IP address or CIDR, it records full diagnostic logs of the SNMP session in the scan task file.
  • runZero now better normalizes hardware values received through the NetBox integration.
  • Fingerprint improvements.
  • runZero now uses custom fingerprints in all situations.
4.0.260206.0
  • The MCP endpoints no longer expose records outside the authorized organization scope.
  • runZero has fully adopted v2 of the AWS Go SDK, which addresses potential risk from the out-of-support v1 library.
  • Fingerprint improvements for Telerik, Cockpit, RustDesk, Home Assistant OS, and Tenable Core.
  • runZero now better normalizes device types for free-form values ingested through integrations.
  • Dashboard vulnerability metrics now match the underlying queries.
  • The scanner now collects Palo Alto Networks TLS thumbprints.
  • Viewing an Explorer with a long web screenshot diagnostic message no longer causes UX issues.
4.0.260205.0
  • runZero no longer exposes task information outside the authorized organization scope.
  • The scanner now identifies and reports detailed version information for exposed MCP servers.
  • The NetBox connector now better normalizes free-form operating system values.
  • Fingerprint improvements.
  • The onboarded status filter for Microsoft Defender connections works again.
  • A matching asset no longer receives only a single subnet tag.
  • The scan configuration page no longer loads slowly.
  • runZero no longer reports SNMP warnings as errors.
  • The bundled npcap driver is now v1.87, which resolves a potential BSoD in NPF_DoTap().
  • The asset inventory now deprioritizes hostnames with the .localdomain and .crestron suffixes.
4.0.260204.2
  • runZero fixed an issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields.
  • Fingerprint improvements.
  • The task inspection card on the task overview now refreshes automatically.
  • Explorer speed test results no longer include speed tests from other Explorers within the organization.
4.0.260204.1
  • The “Software inventory” table now includes a site name column.
4.0.260204.0
  • Scan processing no longer fails with an error.
4.0.260203.0
  • MCP agents can no longer access certificate information from outside their authorized organization scope.
  • Administrators can no longer create and update users outside their authorized organization scope.
  • Automatic page reloading no longer prevents session inactivity timeouts from triggering.
  • A user with access to a credential can no longer view its sensitive fields through an API response.
  • Fingerprint improvements.
  • Metric counts now match live search results in circumstances where they previously did not.
  • Scan tasks that enable web screenshots no longer use excessive memory.
  • Large Explorer-run tasks no longer produce scan data is unavailable errors.
  • Deleting the last organization within an account no longer triggers a console stack trace.
4.0.260202.0
  • You can now request Internet speed tests from any deployed Explorer. You can run these tests on demand or on a recurring schedule.
  • You can now re-fingerprint assets in bulk from the Asset Inventory using the new “Refingerprint assets” action in the “Modify” action menu.
  • MCP agents can no longer access remediation and asset information from outside the authorized organization scope.
  • All-organization administrators can no longer promote accounts to superuser status.
  • Fingerprint improvements.
  • runZero no longer inadvertently clears site subnet tags on an asset.
  • Scans no longer stall for up to fifteen minutes.
  • The scanner no longer stalls during initialization on macOS.
  • Tasks no longer stall while stopping in certain rare cases.
  • Tasks no longer stall at 99% in certain rare situations.
  • Screenshot capture no longer leaks resources.
  • Custom integration tasks now re-import correctly.
  • NetBox imports no longer omit certain assets.
  • Custom integration warnings no longer appear when no integration is specified.
4.0.260129.0
  • Fingerprint improvements.
4.0.260128.0
  • The scanner now supports a new “strategy” probe for adjusting the target order. Setting the “scan-sequential” option switches from randomized target ordering to linear sequential scans. This option can help when assessing large networks with low DHCP lease times.
  • Saved queries containing “OR” operators no longer fail to complete or return incorrect values.
  • Fingerprint improvements.
4.0.260127.1
  • Security: This update resolves an internally identified issue that could have allowed a user to observe an organization’s details from outside the authorized organization scope.
  • Scans no longer take longer than expected in the SYN phase.
  • Large Explorer-run tasks no longer produce scan data is unavailable errors.
  • A browser detection error no longer appears when screenshots are available.
  • Vulnerability links from the asset details page now lead to asset_id queries instead of certificate_id queries.
  • Scans using valid SNMP v3 credentials no longer return incomplete information.
  • Large browser detection warning messages now display correctly.
  • Fingerprint improvements.
4.0.260127.0
  • The asset CSV export format now includes the fp.os.cpe23 attribute.
  • The scanner can now detect and filter bogus MSSQL responses from Azure firewalls.
  • Datagrid pages now re-populate the most recent search query when you return using the browser forward and back controls.
  • runZero no longer over-reports ignored asset counts.
  • The vulnerability count column in the asset inventory now links correctly.
  • Fingerprint improvements.
4.0.260126.0
  • Security: This update resolves an internally identified issue that could have allowed an Explorer within an account to be selected from outside the authorized organization scope.
4.0.260123.3
  • runZero now syncs data from NetBox instances with custom field values.
  • alive inventory queries no longer run slowly.
4.0.260123.2
  • The vulnerability groups inventory no longer performs slowly.
4.0.260123.1
  • Security: This update fixes an SQL injection vulnerability introduced in version 4.0.260123.0 related to saved queries.
4.0.260123.0
  • Explorers now monitor available disk space and terminate tasks early if less than 250MiB remains free.
  • Vulnerability queries limited to risk and source keywords now run faster.
  • File import tasks now import custom integration data correctly.
  • Searching vulnerability groups by CVE no longer omits some vulnerabilities with multiple CVEs.
  • Microsoft SQL Server protocol discovery no longer fails in some cases where encryption is required.
  • You can now sort credentials by ID.
  • Fingerprint improvements.
4.0.260120.2
  • The scanner now identifies and tries to work around network interfaces that don’t apply BPF rules correctly.
  • Match and merge behavior for SNMP devices and Azure database instances has improved.
4.0.260120.1
  • You can now create, update, and import queries that use the organization keyword.
  • Fingerprint improvements.
4.0.260120.0
  • The scanner no longer fails to capture web screenshots.
  • Asset merges no longer fail in some cases.
  • The scanner now ignores bogus FTP service replies from Zscaler systems.
  • The Palo Alto Networks connector now reports additional diagnostic data.
  • Fingerprint improvements.
4.0.260118.1
  • Long-running scan tasks that enable web screenshots no longer leak memory.
  • Asset merges no longer fail in some cases.
  • The scanner now manages memory use better in low-memory conditions.
  • Fingerprint improvements.
4.0.260118.0
  • The Wiz integration now merges similar vulnerability reports within the same system.
  • The NetBox integration now supports versions 4.3.0 and newer.
  • CrowdStrike syncs now complete during a session refresh.
  • runZero Explorers no longer ping the IMDSv2 service outside of AWS.
  • Operating system normalization improvements.
  • Fingerprint improvements.
4.0.260115.0
  • Microsoft MECM connector tasks now include recent user data.
  • Hosted scans no longer use excessive memory when capturing screenshots.
  • Search buttons no longer appear incorrectly for image attributes.
  • Fingerprint improvements.
4.0.260114.0
  • The scanner now uses the Chrome Debug Protocol by default, falling back to the original headless --screenshot command-line method if necessary.
  • The scanner now supports more browsers, including many variants of Chromium, as well as Microsoft Edge when running on Windows.
  • The scanner now supports environment variables for controlling which Chromium version to use, including automatic installation.
  • The scanner now runs the browser with reduced privileges and within a sandbox when possible.
  • The scanner now collects the names of global JavaScript objects from the browser environment.
  • This release also addresses bugs with the previous web screenshot functionality:
  • The scanner now disables the browser sandbox on Linux platforms where user namespaces are disabled and no appropriate AppArmor profile or setuid sandbox helper is present.
  • The scanner now completes a self-test at the start of each task and skips web screenshots if initialization fails, avoiding repeated browser crashes.
  • The scanner now prevents the browser from writing core dumps to disk on crash.
  • The Windows Explorer now captures runtime exceptions into a .err file in the executable directory.
  • Dashboard metrics now account for vulnerability suppressions.
  • LDAP integrations now complete when using trusted TLS certificates.
  • The scanner no longer collects only partial TCP service information.
  • The scanner no longer reports MongoDB on port 27017 erroneously.
  • Fingerprint improvements.
4.0.260110.0
  • Scan tasks no longer report out-of-scope IPv6 addresses.
  • The certificate inventory no longer falls out of sync with services.
  • TCP collection in scans now completes.
  • The individual task size limit is now 100GB, up from 40GB, to handle larger vulnerability exports.
  • Active vulnerability scans for critical vulnerabilities now include non-HTTP services.
  • runZero now shows End-of-Life data for the Solaris operating system.
  • Starlark scripts now support HS256 cryptographic operations.
  • Fingerprint improvements.
4.0.260107.1
  • Windows RDP service enumeration is no longer slow or incomplete.
  • Azure GCC partitions now authenticate correctly.
  • Processing assets with large numbers of MAC addresses is no longer slow.
  • Asset matching no longer fails when the capitalization of a Windows hostname changes.
  • Stale asset removal is no longer excessively slow in large environments.
  • The bundled npcap driver is now v1.86.
  • Fingerprinting improvements.
4.0.260107.0
  • The scanner now detects recent versions of MongoDB’s wire protocol.
  • Fingerprint improvements.
4.0.260106.0
  • IAM role authentication no longer fails.
  • Tasks that process extremely large vulnerability exports now use less disk space.
  • Fingerprint improvements.
4.0.260105.0
  • The hosted scanner no longer ignores assets with internal IPs.
  • The Azure GCC integration now uses the correct endpoint.
  • The scanner now collects detailed statistics for every TCP connection.
  • The AWS integration now collects additional information for failed logins.
  • You can now specify task credentials within scan templates through the API.
  • Fingerprint improvements.
4.0.251231.0
  • Passive sampling tasks no longer over-merge assets.
  • The Google Workspace integration now reports an asset-level serial number attribute.
  • Fingerprint improvements.
4.0.251230.1
  • Task processing now better handles ARP proxies for asset matching on small network segments.
  • SNMP fingerprinting is no longer inconsistent in rare situations.
  • Fingerprint improvements.
4.0.251230.0
  • Scan task processing is now significantly faster and produces fewer ghost assets when specific firewalls are present.
  • Fingerprint improvements.
4.0.251228.0
  • runZero no longer marks out-of-scope assets as offline.
  • Fingerprint improvements.
4.0.251224.0
  • Self-hosted installations now correctly remove old binaries during updates when installed in a non-default location.
  • The Findings view now loads in All Organizations mode.
  • Tasks no longer show greater than 100% completion.
  • The findings-with-instances event rule now saves the Risk filter.
  • The “Assets updated by task” text in task details now reflects that this is the number of observed assets, not the changed count.
  • Fingerprint improvements.
4.0.251222.0
  • Passive sampling tasks no longer clear services from unmatched site assets.
  • Self-hosted customers can now specify a proxy for AWS integrations with the HTTPS_PROXY_AWS setting.
4.0.251221.1
  • Passive sampling tasks no longer mark scanned assets as offline.
4.0.251221.0
  • Large scan and passive sampling tasks now process faster.
  • CrowdStrike tasks no longer abort early when the remote endpoint is slow to respond.
  • Hostname-based matching now handles systems named test correctly.
  • Fingerprint improvements
4.0.251218.1
  • Passive sampling, PCAP import, and reprocessed tasks now handle IP address reassignments more accurately.
  • Merge behavior for long hostnames with truncated NetBIOS responses has improved.
  • Large scan grace periods no longer wrap to negative.
  • Fingerprint improvements
4.0.251218.0
  • Default login tests no longer run unless explicitly enabled.
  • DNS requests no longer include brackets in the hostname.
  • Merge behavior for NetBIOS responses from multi-homed assets has improved.
  • The Findings inventory now loads much faster for large organizations.
  • Fingerprint improvements.
4.0.251217.0
  • The widget library modal search now shows custom widgets.
  • The Huawei iBMC OS now shows the correct icon.
  • Creating, updating, and automatically running saved certificate queries now works.
  • You can now set and export tags whose value is a single double-quote character ".
  • Fingerprint improvements.
4.0.251216.0
  • You can now search services by a related certificate.
  • The asset attribute runZeroLastScanTS no longer contains invalid data.
  • Manual merging and refingerprinting no longer fail to assert OS EOL.
  • Fingerprint improvements.
4.0.251212.0
  • Security: This update fixes two security issues that our external assessment partner identified. The first was a SQL injection vulnerability in the autocomplete backend, and the second was related to improper access control for custom dashboards and widgets.
  • Findings, Vulnerability Groups, and Vulnerabilities now support suppressions.
  • Custom Integration scripts can now read HTTP response headers using the http or requests modules. The headers are available as response.headers["Header-Name"] and return a string array.
  • The CrowdStrike integration now includes the CrowdStrike ExPRT Rating attribute when applicable.
  • End-of-Life tracking has improved for Windows versions where the network response returns incorrect version information.
  • The self-hosted installer now defaults to PostgreSQL 18 (up from 16).
  • You can now configure alert rules for certificate queries using the event type certificate-query-results.
  • Deleting a dashboard no longer creates a blank dashboard.
  • Tenable attributes that previously could fail to process now process properly.
  • Manual merges no longer lead to incorrect asset fingerprinting.
  • runZero now sets the runZeroLastScanTS attribute for imported scan data.
  • Performance improvements.
  • Fingerprint improvements.
4.0.251209.0
  • The Microsoft Intune integration can now optionally retrieve LAPS information for assets.
  • Merge logic for the Wiz integration has improved.
  • The Groups data table no longer has a broken layout.
  • Performance improvements.
  • Fingerprint improvements.
4.0.251208.0
  • Security: This update fixes an open-redirect issue in the next parameter that our external assessment partner identified.
  • Software Counts on assets no longer go stale.
  • The scanner now captures LLDP attributes via SNMP.
  • Fingerprint improvements.
4.0.251206.1
  • The Tenable integration now supports WAS vulnerability imports.
4.0.251206.0
  • Security: This update fixes two open-redirect issues in the next parameter that our external assessment partner identified.
  • Job processing for exceptionally large assets is now faster.
  • User Groups now display correctly.
  • The MCP server now uses organization_id consistently between tools.
  • Fingerprint improvements.
  • This is a console-only update (no new Explorers or CLI).
4.0.251204.0
  • The scanner no longer crashes in rare cases.
  • HTTP X-Powered-By headers now populate.
  • Fingerprint improvements.
4.0.251203.0
  • runZero no longer extracts an invalid domain name from Active Directory integration data.
  • Some assets with integration data no longer merge incorrectly during scan tasks.
  • Performance improvements.
  • Fingerprint improvements.
4.0.251202.0
  • Security: This update builds on Go v1.25.5, which includes security fixes related to TLS validation.
  • Inventory searches of asset attributes now specifically handle version comparison queries.
  • You can now set the user profile notification email correctly.
  • runZero no longer fingerprints TLS stacks incorrectly.
  • Defender vulnerability imports now set Risk correctly.
  • deflate errors no longer corrupt task data.
  • The Wiz integration now works around the 10,000 result limit for assets by switching to the report API.
  • The Prisma integration now more accurately matches and merges assets by host name.
  • Performance improvements across the user interface and processing backend.
  • Fingerprint improvements.
4.0.251201.0
  • Security: This update fixes two security issues found during internal review. Both issues were introduced in the 4.0.251120.0 release and (ironically) involved the upcoming vulnerability suppression feature. The first is a SQL injection vulnerability in the suppressed search keyword. The second could allow vulnerability suppression rules to apply to records outside the authorized organizations if the unique record IDs were known.
4.0.251128.0
  • PCAP imports no longer use excessive CPU and disk.
  • Fingerprint improvements.
4.0.251126.2
  • Security: This update fixes an issue that could allow a user without an all-organization role to view the organization hierarchy.
  • Qualys syncs now retry more often after connection drops and timeouts.
  • TLS fingerprinting now specifically flags services using Go 1.25.0 or newer.
  • Console tasks interrupted by lack of disk space now retry automatically.
  • Fingerprint improvements.
4.0.251126.1
  • Fingerprint improvements.
4.0.251126.0
  • Associating existing TLS certificates with new services no longer causes errors.
4.0.251125.1
  • Recording TLS certificates no longer causes errors.
4.0.251125.0
  • The Explorer now reports an error when trying to use IAM role credentials outside of an AWS environment.
  • The Certificates inventory now supports the risk and ocsp_stapling keywords as well as sorting on risk.
  • Queries with organization keywords now set dashboard metrics.
  • The console no longer uses excessive disk space during processing.
  • Updated TLS findings no longer show a stale risk score.
  • runZero no longer uses a bogus MAC presented by some printer models for matching (Wave7 Optics).
  • Fingerprint improvements.
4.0.251122.1
  • runZero now removes stale software group entries.
  • Fingerprint improvements.
4.0.251121.0
  • The Prisma integration now supports three new asset types: Azure Scale Set VM, Azure SQL VM, and Azure SQL Database.
  • Fingerprint improvements.
4.0.251120.2
  • Performance improvements.
4.0.251120.1
  • A problem that could affect runZero console updates no longer occurs.
4.0.251120.0
  • The certificate inventory now supports the “risk” search keyword.
  • The embedded npcap is now version 1.85.
  • Existing certificates found before v4.0.251118.0 now relate properly to their services.
  • runZero now asserts End of Life correctly for a subset of Windows LTSC versions in Tanium data.
  • Assets fingerprinted from LDAP data now include Windows edition information.
  • Users with the User role can now create integration tasks.
  • runZero now reports clearer errors when AWS IAM Role operations fail outside of an AWS context.
  • The CLI scanner now includes the “Include CIDRs” and “Include Site Names” NetBox integration parameters.
  • Tooltips now show correctly on the certificate details page.
  • Fingerprint improvements.
4.0.251118.0
  • The Tenable integration can now optionally exclude Tenable Agent data.
  • Certificates now track OCSP stapling and name constraints fields along with new search keywords.
  • Certificates now track a risk field that you can override and search, much like asset risk.
  • The scanner no longer crashes abruptly in rare situations.
  • Duplicate Tenable Security Center assets no longer appear in some circumstances.
  • The screen no longer flashes when you download a certificate PEM.
  • Indicator icons now animate correctly.
  • Tooltips no longer show on fully displayed card titles.
  • Fingerprint improvements.
4.0.251114.0
  • The NetBox integration can now override asset information from custom fields.
  • The NetBox integration now includes searchable TS variants of the Date and Date & Time fields.
  • runZero now merges third-party integration data into the most recently seen scanned asset.
  • Metrics calculation no longer fails to complete in some cases.
  • Fingerprint improvements.
4.0.251113.2
  • TLS enumeration no longer aborts early.
4.0.251113.1
  • Searching for certain values in numeric fields no longer produces search errors.
4.0.251113.0
  • The task details page now displays the asset change log in full.
  • Scan exclusions now respect the site:scope keyword when the defaults keyword is also specified.
  • The logic for merging assets by hostname has improved.
  • Processing scan tasks no longer mismerges assets.
  • Scan results no longer fail during processing.
  • Azure Client Secret credentials in the GCC environment no longer produce verification errors.
  • The Qualys integration now retries after a connectivity error.
  • runZero now records task collection logs.
  • Scans no longer freeze in rare cases.
  • Fingerprint improvements.
4.0.251105.0
  • The certificates inventory now includes an associated vulnerabilities field that shows the count of certificate vulnerabilities related to the associated services.
  • Certificates in the Certificates Inventory now include a validity_period attribute that displays the certificate’s lifetime.
  • Baseline goals that use certificate queries no longer fail.
  • Manually merging assets with integration data no longer results in duplicate assets when the integration runs again in certain circumstances.
  • Explorers no longer appear as new after a restart in self-hosted installations.
  • Merge logic for the Tenable Security Center integration has improved.
  • Fingerprint improvements.
  • MCP improvements.
4.0.251103.0
  • The Meraki integration now better handles hostnames with spaces.
  • Processing Active Directory / LDAP data no longer causes a panic.
  • Fingerprint improvements.
4.0.251031.0
  • Selecting hosted zones on the scan page now works.
  • If an asset has duplicate copies of attributes from an integration, task processing for that integration now cleans them up.
  • The CrowdStrike integration no longer skips assets because of an incorrect last seen filter.
  • Certificate details now display when related services have already been removed.
  • Fingerprint improvements.
  • MCP improvements.
4.0.251030.0
  • The linked “Matches” column on the queries list now navigates to the pre-filtered certificate list for certificate queries.
  • Template scan creation no longer fails.
  • Custom integration icons now display in software data grids.
  • The scanner no longer stalls in rare cases.
  • Fingerprint improvements.
4.0.251028.0
  • Organization and account administrators can now modify and reorder the attribute list that determines default asset ownership, per organization or at the account level.
  • The AWS integration can now import from multiple AWS accounts without AWS Organizations, using a new AWS IAM Role credential type.
  • The hamburger menu on the asset details page now includes a “Report incorrectly merged asset” action, so you can contact support faster when you believe an asset was merged incorrectly.
  • A new Certificate and TLS Service Risks finding groups the Certificates and TLS Services queries that contribute to Certificate Risk.
  • You can now search services by all certificates in the certificate chain, using their sha256, sha1, or bk_hash attributes.
  • A certificate’s extended key usage now displays correctly.
  • Fingerprint improvements.
4.0.251023.0
  • Software CSV exports now include ownership information.
  • The runZero MCP service now includes the start_scan tool.
  • Asset processing now includes @tanium.dev.lastLoggedInUser in the list of attributes that determine an asset’s default ownership.
  • Data collection from TLS wrapped services no longer fails in some cases.
  • runZero now asserts Proxmox EOL information.
  • Phantom device detection has improved.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.251021.0
  • Certificates now show associated services, assets, and vulnerabilities, with multiple new search terms and an improved UI.
  • The public scan API endpoint now supports Explorer Groups.
  • The duration of the TLS socket in a ztls handshake is no longer limited.
  • Integrating with Nuclei no longer runs into a performance problem.
  • Changes to dashboard custom widgets now persist without reloading the app in the browser.
  • Discovery no longer misses recent LAPS schema attributes.
  • The subnet sampling parameters for a scan now persist.
  • Fingerprint improvements.
4.0.251017.0
  • Tasks no longer stay in the New state without being scheduled when a runZero Explorer upgrade fails.
  • runZero scans no longer stall in a partially completed state.
  • Fingerprint improvements.
4.0.251016.0
  • The services inventory now supports searching by certificate_id.
  • The certificates inventory now supports shorthand search for attributes of pk_parameters: fields, such as rsa_exponent:65537.
  • The “Refingerprint asset” action is now always available on the asset details page.
  • New customer accounts must request the ability to create new sites within an organization through support. Existing customer accounts can still create sites.
  • Asset records no longer include Meraki IP addresses used for internal purposes.
  • Foreign attribute names on the Asset detail page no longer overflow onto the displayed value.
  • Screenshots and favicon images now display on the asset details page.
  • Analysis tasks no longer run for a new organization with no completed tasks.
  • Some query links in Rapid Response Alert emails no longer work incorrectly.
  • Qualys tasks no longer fail with “unexpected EOF” errors.
  • Fingerprint improvements.
4.0.251015.1
  • Self-hosted installations of the runZero console no longer have problems updating.
4.0.251015.0
  • The task forms for the NetBox, Intune, Meraki, Miradore, Google Workspace, Censys, LDAP, Shodan and AzureAD integrations now share a consistent user experience and let you select Explorer groups to run tasks.
  • SentinelOne integration device attributes now include serial numbers.
  • Passive scans can now run on a network interface without assigned IP addresses.
  • runZero now fingerprints the OS correctly from Qualys data.
  • You can now sort vulnerabilities by finding name when viewing asset details.
  • The echo-filter-spoofed-responses probe option now functions properly.
  • The echo-filter-spoofed-responses probe option is now named echo-ignore-icmp-only-internal-hosts.
  • Fingerprint improvements.
4.0.251008.0
  • Self-hosted instances now have a system configuration option to disable CSRF protection.
  • Asset attribute reports now load.
  • Merging two assets no longer removes some of their vulnerabilities.
  • Fingerprint improvements.
4.0.251007.2
  • The duplicate key errors that some scan tasks hit no longer occur.
4.0.251007.1
  • You can now query certificates by “signature” and “public_key”.
  • The Microsoft Configuration Manager (MECM) integration now supports filtering by device collection ID.
  • The MCP query syntax for wireless now provides the correct keys.
  • Processing Wiz integration data no longer results in incorrect asset software.
  • Vulnerability detection dates now update after an asset is scanned.
  • runZero now removes remediated vulnerabilities after scanning.
  • Unexpected merge behavior no longer occurs during integration tasks.
  • runZero now removes stale AWS assets when the relevant task option is enabled.
  • Fingerprint improvements.
4.0.251007.0
  • Scans no longer stall in certain situations.
4.0.251003.0
  • Custom integration scripts can now use the trust_device_type, trust_os and trust_os_version attributes on the ImportAsset object to set an asset’s fingerprint, even if runZero’s fingerprint engine cannot normalize the custom values.
  • You can now configure AWS IAM credentials with a static external ID at the account level.
  • You can now create baseline goals against the certificates inventory.
  • The connector form now selects the configured Explorer option when you edit recurring connector tasks.
  • You can now edit a recurring connector task to stop running it on an Explorer.
  • Fingerprint improvements.
4.0.251001.0
  • The new Explorer groups feature lets you create logical groupings of Explorers that intelligently schedule tasks among themselves.
  • Azure Government credentials now validate successfully.
  • MECM tasks no longer hang for a long time after being stopped.
  • Fingerprint improvements.
4.0.250930.0
  • The MCP server now includes the list_sites, query_directory_group, and query_wireless tools.
  • The vulnerability inventory by asset now supports searching by certificate attributes, including ID, type, serial, public key, signature, fingerprint, subject, issuer, and key usage.
  • The Qualys integration now collects data with multiple parallel threads when available.
  • runZero now sends Rapid Response alert emails once per organization instead of once per site with results.
  • CSV software exports no longer run slowly.
  • Searching for certificates by the is_ca field now works correctly.
  • The runZero console’s CSP policy no longer blocks custom JavaScript in self-hosted environments.
  • The site configuration page now formats subnet tag key names that contain underscores correctly.
  • Some integrations that were not recognized as active now are.
  • Fingerprint improvements.
4.0.250926.0
  • You can now search assets by certificate attributes, including ID, type, serial, public key, signature, fingerprint, subject, issuer, and key usage.
  • The Prisma integration now supports Azure VMs, GCP VMs, Azure Load Balancers, Azure SQL Server, and Azure Cosmos DB.
  • Hostname matching logic has improved.
  • Custom widgets for the certificate query type now display.
  • runZero no longer misidentifies the MAC vendor from AirPlay devices/services.
  • runZero no longer sends invalid characters during IPv6 DNS requests.
  • Fingerprint improvements.
4.0.250924.1
  • Service cleanup no longer fails when the database is heavily loaded.
4.0.250924.0
  • Certificate queries can now apply a vulnerability record to matching assets.
  • The vulnerability details view no longer shows an empty “References” section.
  • The Findings list page and Findings detail pages no longer load slowly.
  • Some assets no longer fail to merge during integration processing.
  • Invalid SNMP responses no longer result in assets with incorrect hostnames.
  • Copying a Dragos task no longer omits values in the subnet filter input.
  • The Tanium integration now filters bad data during data collection more effectively.
  • Fingerprint improvements.
4.0.250922.1
  • The console service no longer restarts during heavy processing.
4.0.250922.0
  • The site configuration page now includes a CSV import feature for configuring subnets.
  • The MECM integration now imports information about the last software patch applied via MECM in three new attributes: lastSoftwarePatchTitle, lastSoftwarePatchArticleID, and lastSoftwarePatchTime.
  • The Wiz integration now includes a task parameter for choosing which Wiz resource types are imported into runZero.
  • The Wiz integration now adds two attributes, @wiz.dev.resourceType and @wiz.dev.resourceApiType, that correspond to the Wiz resource type.
  • Azure Client Secret credentials can now include or exclude user-specified subscription IDs. Service verification has also improved in other ways.
  • Self-hosted customers can now disable all public API endpoints by setting the RUNZERO_DISABLE_PUBLIC_APIS value to true in /etc/runzero/config.
  • The license expiration warning now displays suggested actions to a superuser.
  • Assets no longer fail to merge when runZero processes Qualys integration tasks.
  • Asset fingerprinting from Tanium data has improved.
  • Fingerprint improvements.
4.0.250918.0
  • The self-hosted installer no longer fails to complete on certain RHEL versions and variants.
4.0.250917.2
  • Some AWS tasks no longer fail to complete.
4.0.250917.1
  • Tenable Nessus scans now complete.
  • Some Qualys tasks no longer fail.
4.0.250917.0
  • The Dragos integration now accepts TLS thumbprints in the credential configuration.
  • Certificate queries no longer have the option to apply a vulnerability record to matching assets.
  • Improved memory management keeps tasks with a large amount of vulnerability data from failing due to memory exhaustion.
  • The scanner’s interaction with certain OT devices has improved.
  • runZero now calculates certificate query matches.
  • Scans no longer fail with an “explorer failed to queue task” error.
  • Assets with Qualys data no longer merge incorrectly in some circumstances.
  • Users with no default role can now create “Email runZero users” alert channels for organizations they have access to.
  • Copying Wiz integration tasks no longer fails.
  • Assets now show correct vulnerability counts.
  • Task tables now display rows.
  • Rapid Response alert emails are now legible in Classic Outlook.
  • The Findings list no longer fails to load with an “array size exceeds the maximum allowed” error.
  • Fingerprint improvements.
4.0.250912.0
  • The MCP server now supports retrieving vulnerabilities.
  • Fingerprint improvements.
4.0.250910.0
  • Separate options to disable importing software and/or vulnerabilities now replace the “Fingerprint Only” integration task option for CrowdStrike, MS365Defender, SentinelOne, Wiz, Tenable, Rapid7 InsightVM, and Qualys.
  • The Dragos integration can now filter asset results by subnets.
  • runZero now subscribes all superuser accounts in trial and platform licensed tenants to automatic email alerts whenever a Rapid Response query’s match count is greater than zero. To turn these alerts off, disable the appropriate rule on the alert rules page; to exclude specific users, add them to the “Excluded users” field of the appropriate alert channel.
  • The Rapid Response MCP tool now functions in offline environments.
  • Manually merging assets no longer produces an error.
  • The Organization overview report no longer limits the number of top metrics to 10 entries.
4.0.250908.0
  • You can now save certificate queries to the query library and search on the fields signature_algorithm_insecure, public_key_insecure, public_key_algorithm, public_key_bits, pk_parameters, signature_algorithm, key_usage, ext_key_usage, version, ocsp_server, crl_distribution_points, and issuing_certificate_url.
  • The Rapid7 InsightVM integration can now filter results by InsightVM site name using regex pattern matching.
  • Custom integrations that run on hosted Explorers no longer have a script size limit.
  • You can no longer copy a user’s invitation link to the clipboard.
  • You can now search assets by a finding_code term on the Assets page and via the assets API.
  • The Qualys integration now supports excluding assets with certain tags during import.
  • Updating Licensed entity details now displays a save confirmation dialog.
  • The MCP server now supports retrieving query findings.
  • Asset export APIs no longer include a finding_count attribute.
  • SSO group access details now display even when the user is not logged in.
  • You can now hide a certificate from view.
  • You can now update the query on a saved query goal or custom widget.
  • Some Wiz serverless assets no longer fail to merge with AWS assets.
  • You can now select all rows in a table.
  • Task processing no longer duplicates an asset in some circumstances.
  • The “Latest Rapid Response” dashboard widget now respects the selected site filter instead of displaying data from all sites.
  • Findings APIs no longer return duplicate findings.
  • Widget history charts now display accurate timestamps.
  • The current organization team table no longer shows confusing contents.
  • Fingerprint improvements.
4.0.250904.0
  • Fingerprint improvements.
4.0.250902.0
  • runZero now integrates with the Dragos platform.
  • Vulnerability details now include additional enrichment and an improved user experience.
  • The Tanium integration now supports skipping software and vulnerabilities.
  • Assets with hostnames of 3 or fewer characters no longer merge unexpectedly.
  • Recurring tasks no longer schedule duplicate sub-tasks.
  • Site CSV import error messages now display.
  • Qualys connections no longer fail when the initial response is slow.
  • The Wiz integration no longer fails to import some types of assets.
  • Some Meraki assets no longer fail to merge.
  • Fingerprint improvements.
  • Merge logic improvements.
4.0.250901.0
  • Fingerprint improvements.
4.0.250828.1
  • Fingerprint improvements.
4.0.250828.0
  • You can now update SNMPv3 credentials with an empty context.
  • You can now view the details page of certificates that lack a subject.
  • Recurring connector tasks running on the console now show their start times.
  • Fingerprint improvements.
4.0.250826.1
  • Unmanaged Meraki assets no longer have malformed asset type fields.
  • The heuristics for choosing between tablet, laptop, and desktop asset types have improved.
4.0.250826.0
  • AWS and Wiz tasks now automatically remove unseen assets.
  • runZero now respects a scan template’s Exclude Hosts configuration option when you change sites.
  • Newly discovered assets with missing addresses no longer keep the “Newly discovered assets” table from showing properly after an integration task.
  • Meraki assets no longer merge incorrectly in some circumstances.
  • Removing a custom integration or source from assets no longer causes a problem.
  • runZero no longer creates duplicate software and vulnerability groups.
  • runZero now enforces permissions when custom integrations are removed from assets across tenants.
  • runZero no longer processes multiple connector tasks at the same time.
  • Scans now include safe checks for many remotely exploitable critical vulnerabilities by default.
  • You can now update Explorer scan concurrency via the runZero Organization API.
  • Fingerprint improvements.
4.0.250820.0
  • Goals, alert rules, alert channels, and alert templates can now have new organizations assigned to them automatically when “Automatically add new organizations” is selected in their options.
  • The Latest Rapid Response widget on the runZero-managed Risk Management dashboard now includes a paginated carousel of the five most recent Rapid Response posts.
  • The Active Directory integration now collects data in large environments.
  • The Switch Topology Report now loads.
  • Integration tasks no longer end prematurely before finishing data ingestion.
  • You can now create an external ID for AWS IAM Role credentials.
  • Certificates no longer fail to show in scan results.
  • Querying inventory via MCP from some models now works correctly.
  • Fingerprint improvements.
4.0.250818.0
  • You can now view shared dashboards in “My organizations” mode.
  • Some inventory searches no longer ignore the organization search keyword.
  • runZero no longer marks tasks as “Failed to queue” incorrectly.
  • The hub messaging system no longer deadlocks.
  • A regression no longer hides tooltips on some table cells in data tables throughout the console.
  • Fingerprint improvements.
  • Beginning shortly after the release of runZero v4.0.250818.0, runZero will enroll a small subset of active customers registered to the US region in automatic Rapid Response Matches alerting as part of a phased roll-out. runZero will enroll customers in other regions, including self-hosted customers, automatically at a later date.
4.0.250814.1
  • Explorers no longer disconnect and reconnect repeatedly.
4.0.250814.0
  • The Switch Topology Report’s performance and user experience have improved.
  • Data tables throughout the product now render faster.
  • The Explorer deploy page now displays the currently active organization in the page header.
  • The documentation now lists updated minimum operating system requirements for the runZero Explorer and CLI tool.
  • The Explorer/Scanner no longer uses excessive memory when scanning HTTP endpoints.
  • The Explorer service now starts when the service is marked interactive.
  • runZero no longer marks tasks as “Failed to queue” incorrectly.
  • Asset searches no longer generate an invalid query.
  • runZero no longer incorrectly limits the number of returned software results.
  • Fingerprint improvements.
4.0.250811.1
  • Tasks no longer freeze while running.
4.0.250811.0
  • The layout of regions in the AWS configuration form has improved.
  • runZero no longer removes the runZeroLastScanTS attribute in some cases.
  • runZero no longer incorrectly initializes an asset’s type as its method of detection in some cases.
  • The runZero Splunk add-on no longer imports all assets regardless of the last sync.
  • runZero fixed an issue that prevented saving event templates with invalid Mustache template syntax.
  • Fingerprint improvements.
4.0.250808.0
  • All users across the platform may now create event rules for the following events:
  • rapid-response-published triggers when one or more Rapid Response queries are published, updated, or removed from the console.
  • rapid-response-with-matches triggers when a Rapid Response query’s results change.
  • findings-with-instances triggers when findings instance counts are updated.
  • The progress bar in the Switch Topology Report now hides when the report finishes loading.
  • Fingerprint improvements.
4.0.250807.0
  • The progress bar in the Switch Topology Report now shows without delay.
  • Inventory search with multiple organizations now works correctly.
  • Performance improvements.
  • Fingerprint improvements.
4.0.250805.0
  • Asset matching now considers hardware information when available.
  • The Qualys integration can now filter assets that have not been scanned for a configurable time period.
  • The AWS integration now supports cross-account AWS roles for authentication.
  • An experimental MCP server is now available. This opt-in extension lets users bring their own LLM to interact with their runZero deployment.
  • Tenable assets with agents now show their agent health property as N/A when an invalid agent health property is received, instead of omitting the property from the asset.
  • Fingerprint improvements.
  • Online Explorers no longer disappear from the Explorers list.
  • Subdomain expansion no longer returns false domains for several domains.
  • Nessus-reported vulnerabilities no longer have stale descriptions.
  • The network bridges report no longer deselects the site when you change the filter.
  • The vulnerability table on the Asset Details page now sorts by finding name.
  • The inventory table no longer crashes with an error message when viewing data that contains invalid country codes.
  • A copied custom integration task no longer shows an error and fails before it can run.
4.0.250801.1
  • Some online Explorers no longer go missing from the Explorer view.
  • Merge logic memory usage has improved.
  • The embedded npcap is now version 1.83.
4.0.250801.0
  • Scan tasks no longer stall in a partially completed state under certain conditions.
  • Fingerprint improvements.
  • Security update: This release includes a minor fix for an internally discovered bug in dashboard and goal permissions, where one user could retrieve the dashboard or goal configuration of another user. This is only theoretically possible if they could guess the v4 random UUID of the entry, which is not visible cross-user in these scenarios. We do not believe this exposes sensitive data in any typical configuration, and we have no evidence of it being exploited.
4.0.250731.1
  • The http_post and Session custom integration script libraries now include the insecure_check_verify option.
  • The Metrics and Query metrics, vulnerabilities, and findings background tasks are now combined into a single task.
  • runZero now removes stale AWS assets that it previously could not.
  • Fingerprint improvements.
4.0.250731.0
  • Some integration tasks no longer freeze and restart during processing.
4.0.250730.0
  • Integrations no longer report duplicate assets.
4.0.250729.1
  • Some tasks no longer fail during processing.
  • Pivoting from the goal creation/edit page to the inventory no longer triggers a search error.
4.0.250729.0
  • Custom integration tasks can now exclude unknown assets from the scan results.
  • When the “delete stale assets” option of an AWS integration task is enabled, runZero now removes only stale assets from the AWS accounts associated with the current task.
  • You can now select external users as targets for “Email runZero users” channels.
  • Users can now specify a “Notification email” address in their profile.
  • runZero uses this alternative address in place of the user’s sign-in email address only when the user is chosen as a recipient for an “Email runZero users” type alert channel. It does not use this address for any account alerts, such as sign-in links or password reset emails.
  • Improved merge behavior reduces incorrect merges or duplicate asset records caused by docking stations.
  • Merge behavior now uses hardware vendor data, when available, to reduce incorrect merges or duplicate asset records.
  • Some findings export API calls no longer fail.
  • Some timestamps from Prisma Cloud assets are no longer incorrect.
  • The software keywords now work in the asset inventory.
  • Software groups no longer become outdated in certain circumstances.
  • You can now save the “Excludes” parameter in scan templates.
  • Fingerprint improvements.
4.0.250724.0
  • Introducing Baseline Goals: you can now scope Goals to specific inventory subsets, so you can set goals against a subset of assets. For more information, see documentation.
  • The updated UX for selecting vulnerability checks now defaults to detecting and reporting exposed web panels.
  • You can now select additional security check categories from the scan configuration page.
  • The scanner now detects and reports exposed web admin panels by default.
  • Query totals are now correct.
  • Fingerprinting of Microsoft SharePoint products and versions has improved.
  • Fingerprint improvements.
4.0.250721.0
  • The software inventory now supports filtering by organization ID or name with the organization: search term, and by site ID or name with the site: search term.
  • The vulnerability inventory now supports filtering by organization ID or name with the organization: search term.
  • Customers importing asset data into Splunk can now specify the $checkpoint:ignore search filter to force Splunk to re-ingest all assets instead of just the assets created/updated since the last sync.
  • Assets discovered by the Tenable.io integration now show agentHealth and lastAgentHealthCheckTS values when an agent is installed on the asset.
  • Vulnerabilities on an asset no longer repeatedly duplicate instances.
  • Normalization of assets with the type “Human-machine interface” has improved.
  • Fingerprint improvements.
  • Performance improvements.
  • Merge logic improvements.
4.0.250717.0
  • The “Email runZero users” alert channel type is now generally available, so users can configure channels that email chosen runZero users.
  • The Sites list view now includes a column displaying each site’s last updated time.
  • Merge logic now detects duplicate names across different domains and avoids incorrect merging.
  • The goal detail page no longer omits counts.
  • Goal progress is now consistent.
  • You can now update goals even when the current organization is not selected for the goal.
  • Task parameters now copy accurately for recurring or copied NetBox tasks.
  • Assets no longer fail to merge correctly based on hostnames in some circumstances.
  • Performance and fingerprint improvements.
4.0.250714.0
  • The outlier count on the Asset Details page no longer contains typographical errors.
  • runZero now removes asset services correctly in certain limited cases where it previously did not.
  • The Microsoft Defender probe no longer filters out all vulnerabilities.
  • Performance and fingerprint improvements.
4.0.250711.0
  • Self-hosted instances using the SMTP authentication method “none” no longer incorrectly return an “unsupported SMTP authentication method” error.
4.0.250710.0
  • The Rapid Response dashboard widget now links to the correct search for software matches.
  • Metrics for queries that return zero results for a site now save with the correct total.
  • Authentication tokens for Palo Alto Networks’ Prisma Cloud integration now refresh.
  • Scanner improvements.
  • Fingerprint improvements.
4.0.250709.1
  • Palo Alto Networks’ Prisma Cloud integration no longer runs into out-of-memory conditions.
4.0.250709.0
  • runZero now reschedules tasks that hit memory exhaustion instead of failing them.
4.0.250708.2
  • Processing Microsoft Defender data no longer causes a panic.
4.0.250708.1
  • The scanner no longer panics.
4.0.250708.0
  • CrowdStrike data collection is now more memory efficient.
  • Connectors now explicitly prefer merging devices into assets with a runZero source.
  • Integration tasks now compress Wiz reports during upload.
  • runZero no longer causes certain error messages in Microsoft SQL Server logs.
  • runZero now fingerprints TLS on Microsoft SQL Server endpoints correctly.
  • Vulnerabilities detected via passive scanning no longer duplicate themselves during data processing.
  • An unrecognized SMTP authentication method no longer causes a panic.
  • Asset risk rank no longer regresses.
  • The “last calculated” timestamp on the dashboards page is now correct.
  • Community Licensed users can now navigate to the Organization Settings page.
  • The group assignment form no longer pre-selects incorrect groups for selected users.
  • Scanner improvements.
  • Fingerprint improvements.
4.0.250701.0
  • Fingerprint improvements.
4.0.250630.0
  • The “delete stale” option description for the AWS and Wiz integrations now clarifies that it deletes all AWS or Wiz assets not seen by the currently running task.
  • Event templates now show last_seen attributes as a date instead of a number.
  • Community users can now create an organization when no organizations exist.
  • runZero no longer schedules metrics analysis tasks repeatedly in a loop.
  • Slow queries no longer show up as errors in task logs.
4.0.250627.1
  • Some metrics tasks no longer contain many “duplicate query in metric data” errors.
4.0.250627.0
  • You can now download the self-hosted version of runZero in the EU region.
  • The metrics calculation process has improved.
  • Discovery of embedded IP-to-serial devices has improved.
  • Fingerprint improvements.
4.0.250626.0
  • Email Alerts now have better support for JSON-formatted attachments.
  • Dashboards with header widgets now load correctly.
  • Asset information no longer fails to appear in the RFC1918 report in some cases.
  • Tenable.io integration tasks no longer import INFO level vulnerabilities when configured to omit all vulnerabilities (i.e. “fingerprint-only”).
  • Phantom device detection has improved.
  • Fingerprint improvements.
4.0.250625.0
  • Projects now correctly analyze vulnerabilities, findings, and query match counts.
4.0.250623.1
  • Some scans no longer fail when scanning certain devices.
4.0.250623.0
  • Microsoft Intune tasks no longer fail to complete in some cases.
  • Certain printers no longer experience problems during a runZero scan.
  • Tasks no longer hang at 99% or fail with the error “task lost to explorer restart” in certain uncommon situations.
  • runZero no longer fails to delete stale vulnerabilities in certain circumstances.
  • Fingerprint and performance improvements.
4.0.250622.0
  • runZero no longer sends agent-offline events repeatedly every four hours. It now sends only one agent-offline event each time an Explorer goes offline.
4.0.250620.0
  • The NetBox integration now supports filtering by site names and CIDRs.
  • The first page of the software, software groups, vulnerability groups, and findings instances tables now loads faster.
  • Some software records no longer get duplicated.
  • Metric and vulnerability tasks no longer error.
  • Invitation emails to new users now send.
  • runZero no longer sends agent-offline events when Explorers have reconnected.
  • runZero no longer applies scan task tags incorrectly in some cases.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.250616.0
  • The redesigned goal details page provides more information on goal progress.
  • The redesigned goal creation workflow UI makes editing and creating goals simpler.
  • Users with an inherited or explicit role of User or above within the selected organization can now manage goals, consistent with the functionality in alert rules, channels and templates.
  • Goals previously configured as “global” now apply to all currently existing organizations and no longer attach to new or future organizations unless explicitly configured to, consistent with the functionality in alert rules, channels and templates.
  • Task statistics now display the total count of software and vulnerability records created.
  • The display name for the default asset ownership type no longer shows as a nil UUID.
  • Invalid device detection improvements.
  • Fingerprint improvements.
4.0.250611.0
  • runZero now provides better Operating System End of Life (EOL) information for Microsoft Windows LTSC.
  • You can now configure data retention per site.
  • Wiz integration tasks now have an option to delete stale Wiz assets after each sync.
  • The Tenable.io integration now has separate options to disable vulnerability import and software import.
  • Asset search now supports filtering by missing ownership_type and missing mac_countries.
  • runZero now launches Chrome with the --disable-breakpad option when taking screenshots.
  • The Meraki integration now sets First Seen and Last Seen correctly.
  • Dashboards now display ownership_type information correctly.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.250610.0
  • Scans no longer stall when using TDS 8.0 to interrogate Microsoft SQL Server.
  • Large connector tasks no longer cause out-of-memory conditions on self-hosted consoles.
  • Fingerprint improvements.
4.0.250606.1
  • Finding generation no longer fails for sites in some situations.
  • Fingerprint improvements.
4.0.250606.0
  • runZero scans can now check for default logins. See our documentation for details.
  • The Prisma integration now supports importing assets from AWS.
  • Vulnerability displays no longer show empty information cards when no further information is available.
  • Certificate inventory searches are now faster, particularly for subject, authority, and SAN DNS names.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.250604.1
  • Security: The password reset process no longer allows an MFA bypass. runZero identified this issue internally, and it did not affect users who authenticate through SSO.
  • The mac_countries keyword now matches correctly.
4.0.250604.0
  • runZero now supports TOTP as an MFA option, in addition to the existing WebAuthn and Passkey options.
  • Scan tasks created from templates now carry over the site:scope keyword from the template.
  • Dashboard widgets now display correctly when no data is available.
  • Screenshot capture no longer fails for some services.
  • Passive sampling tasks interrupted by active scans no longer show as failed.
  • Inventory views no longer show link-local IPv6 and APIPA IPv4 addresses first in the addresses column.
  • runZero no longer resolves MAC addresses with the LAA bit set to OUI vendors when the source is known to use random values.
  • MAC addresses from virtual machine prefixes no longer assert a MAC Country field.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.250530.0
  • The Vulnerabilities Inventory now includes a column for any associated Finding.
  • The confirmation dialog for deleting an Explorer now indicates whether tasks will be affected and links to those tasks.
  • The Asset Inventory now includes a MAC Countries column listing the countries associated with device MAC addresses.
  • Asset attributes now include values for mac.mfgCountries and mac.mfgAddresses.
  • The Asset Inventory now accepts searches by MAC Country using the syntax mac.mfgCountries:US.
  • Integration data that previously did not expire according to organization settings now expires correctly.
  • View-only users no longer see a Share action when that functionality is unavailable to them.
  • Users on outdated browsers now receive a warning during sign-in.
  • Tag values are now fully UTF-8 safe and round-trip correctly via tasks.
  • Fingerprint improvements.
4.0.250529.1
  • The runZero Console’s content security policy header is temporarily relaxed so that Firefox ESR no longer refuses to load icon images.
  • A banner now notifies superusers when the SAML certificate used for single sign-on (SSO) will expire soon.
  • Excluding PII attributes now works when integrations are configured to run on an Explorer.
  • Performance improvements.
  • Fingerprint improvements.
4.0.250529.0
  • Fingerprint improvements.
4.0.250527.0
  • runZero now automatically deletes TLS certificates from your certificate inventory once no service uses them.
  • The progress bar has a new design.
  • Tables on the Risk Management dashboard now sort correctly.
  • The GCP integration now logs warnings instead of errors when some projects don’t have certain features enabled.
  • The certificate inventory now displays country flags correctly.
  • Some Azure integrations no longer fail.
  • runZero now reports the error when scan results fail to upload.
  • Identification of progressive web applications has improved.
  • Phantom device detection has improved.
  • Merge logic improvements.
  • Fingerprint improvements.
4.0.250524.0
  • CrowdStrike tasks no longer fail.
4.0.250521.0
  • Findings are now filtered by asset when you follow a link from the asset details page.
  • The CrowdStrike integration no longer lets auth tokens expire.
  • runZero no longer fails to clean up stale integration attributes according to organization settings.
  • The Prisma integration now uses the correct request methods and has improved logging.
  • Fingerprint improvements.
4.0.250516.0
  • The CrowdStrike integration now normalizes software version information more consistently.
  • Detection of web-interception mechanisms has improved.
  • Integration tasks no longer merge assets incorrectly in some cases.
  • runZero no longer overwrites user-set asset criticality values as “Unset”.
  • Wiz integration tasks run on Explorers no longer fail when importing a large number of assets.
  • Referencing organization.name in event templates now works.
  • Alert rules no longer unexpectedly save the current organization in their scope when you edit a rule.
  • Fingerprint improvements.
4.0.250514.0
  • Custom integration scripts can now use gzip compression and decompression.
  • Table columns no longer use unwanted center justification.
  • Editing alert rules after creation now works.
  • Integration tasks no longer merge assets incorrectly in some cases.
  • Risk levels for “Top findings” in the Risk Management dashboard are no longer intermittently inaccurate.
  • Risk level names are now capitalized on the Risk Management dashboard.
  • Importing AWS assets with the Automatically delete stale AWS assets option enabled no longer recreates assets.
  • Fingerprint improvements.
4.0.250513.0
  • User API endpoints now include information about default, assigned, and effective roles.
  • The Microsoft 365 Defender integration now imports the avMode attribute and only sets the EDR name when avMode is Active.
  • The Qualys integration can now filter assets by Network IDs.
  • Custom integration scripts can now call crypto hashing functions including sha256, sha512, sha1, and md5.
  • Custom integration scripts can now export asset data to a json.gz file for import into a runZero organization.
  • Dashboards now include a footer showing when the dashboard’s data was last updated.
  • The Overview section of the finding details page now shows accurate information when viewing “My organizations”.
  • Recalculating metrics in “My Organizations” mode now works.
  • Risk Management dashboard widgets that failed to display results in “My Organizations” mode now work correctly.
  • Passively scanned assets no longer lose IP addresses when merging with integration assets.
  • Asset CSVs containing spaces in owner values now import correctly.
  • Fingerprint improvements.
4.0.250508.0
  • The custom integration script editor now includes autocomplete hints for Starlark and runZero-provided libraries.
  • Certificate inventory performance has improved.
  • Content updates no longer fail for some self-hosted customers.
  • Integration data no longer fails to update in some circumstances.
  • The SentinelOne integration no longer caps the number of applications it collects.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250506.0
  • Deleting and updating Explorers from the Manage menu in the details view now works.
  • The finding details view now displays related runZero blog references.
  • The vulnerability details view now includes links to runZero Rapid Response posts as well as related references.
  • The network bridges and asset route pathing reports no longer cut off parts of the graph.
  • Merging assets no longer drops some integration attributes.
  • Fingerprint improvements.
4.0.250505.0
  • You can now exclude personally identifiable information (PII) or other attributes from data collection for some integrations. See our excluding integration attributes documentation for details.
  • The SentinelOne integration now collects vulnerabilities faster.
  • Custom integration scripts now treat a None return value as success.
  • Custom integration scripts can now use limited session-like functionality to make HTTP requests.
  • Custom integration scripts can now use base64 encoding and decoding functions.
  • The Explorer details page now lists the npcap version when the Explorer is installed on Windows.
  • The npcap installers are now at version 1.82.
  • Exporting data now returns errors correctly.
  • CVE overlay data (for example, KEV membership) is now reflected accurately.
  • Fingerprint improvements.
4.0.250430.0
  • SentinelOne integration performance has improved.
  • Vulnerability exports now work correctly.
  • Fingerprint improvements.
4.0.250428.0
  • The scan configuration discovery and exclude scope fields now accept two new keywords: site:scope, which expands to the default site scope, and site:exclusions, which expands to the exclusions set in the site configuration.
  • The Tenable integration task form is updated.
  • Event log performance has improved.
  • Phantom device detection improvements.
  • Inventory table preferences now persist.
  • NetBox assets now merge on IP address correctly.
  • Alert channel details no longer fail to load in some situations.
  • Wildcard searches of integration attribute data no longer fail in certain cases.
  • Fingerprint improvements.
4.0.250422.0
  • The event log no longer contains duplicate assets-expired events.
  • Fingerprint improvements.
4.0.250421.0
  • Fingerprinting of CrowdStrike integration data now reports the correct OS version.
  • Asset icons and screenshots are no longer duplicated.
  • Fingerprint improvements.
4.0.250418.0
  • The SentinelOne integration now supports importing vulnerabilities.
  • The “Findings by category” header on the runZero Risk dashboard now renders correctly.
  • Vulnerabilities without categories now display details correctly.
  • Directory users and groups are now linked for Google Workspace, Azure AD, and LDAP.
  • Explorers are no longer marked as inactive after a reinstall.
  • User interface improvements.
  • Fingerprint improvements.
4.0.250415.0
  • CSV exports of certificates are now more compatible with spreadsheet software.
  • The findings export now includes the fields instance_count and risk_rank_value, and no longer includes vulnerability_count and risk_score. The field risk_rank now shows the risk label.
  • The NetBox integration no longer filters assets that are older than the Organization’s stale asset threshold.
  • Minor UX improvement to the Certificate Details page.
  • The “Internet accessible assets” widget on the Risk Management dashboard now displays the correct current count.
  • Fingerprint improvements.
4.0.250414.0
  • Asset inventory software searches now support less-than or greater-than version queries. See the Asset Inventory search keywords documentation for more information.
  • You can now search the certificates inventory by the last_seen, valid_from, and valid_until keywords.
  • The /account/users and /account/users/{user_id} API endpoints now include the names and IDs of the groups each user belongs to.
  • The inventory export APIs now support gzip Content-Encoding compression when requested via the Accept-Encoding header.
  • The “High risk findings” widget on the Risk Management dashboard now displays the correct current count.
  • The Queries list now displays the correct finding codes.
  • runZero no longer writes duplicate assets-expired events to the audit log.
  • runZero no longer misidentifies servers as printers in rare cases.
  • Asset discovery improvements.
  • Fingerprint improvements.
4.0.250410.1
  • Importing vulnerability information from Microsoft Defender no longer fails.
  • Fingerprint improvements.
4.0.250410.0
  • The Microsoft 365 Defender integration now has task options to filter imported vulnerabilities by severity.
  • The Microsoft 365 Defender integration can now optionally skip importing software and vulnerabilities.
  • The Rapid Response dashboard widget now distinguishes assets that are potentially impacted from those actually impacted.
  • Assets with no vulnerabilities or findings now show a risk of None instead of Info.
  • The Microsoft 365 Defender integration no longer fails to pull software without CPEs.
  • Successive Microsoft 365 Defender tasks no longer cause some vulnerabilities to disappear.
  • Certain Wiz assets that failed to import now import correctly.
  • Integration attributes are no longer removed from assets in error.
  • Feedback from our annual security audit led to a low-severity improvement to the runZero Console’s content security policy (CSP).
  • Asset merging improvements.
4.0.250409.0
  • The NetBox integration now handles virtual machines, interfaces, and clusters more consistently.
  • The NetBox integration now uses fuzzy matching for OS and HW mappings.
  • The alert rules page data table now displays columns for channel and template.
  • The alert rule details page now displays the channel and template attributes.
  • Gathering screenshots no longer causes errors.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250407.0
  • Asset Details page performance has improved.
  • Tasks assigned to hosted Explorers are no longer delayed.
4.0.250405.0
  • Fingerprint improvements.
4.0.250404.1
  • Scanning a printer’s IPv6 addresses no longer causes it to print garbage output.
4.0.250404.0
  • The Microsoft 365 Defender integration now supports pulling software and vulnerabilities.
  • New public APIs for the findings and certificates inventories are now available. See the API documentation for more information.
  • The scanner now correctly detects and reports encrypted protocols running on non-standard ports.
  • Navigating to a Certificate Details page no longer triggers a page reload.
  • Searching the Vulnerability Inventory by asset for CVEs now works.
  • Fingerprint improvements.
4.0.250402.0
  • The NetBox integration now supports importing virtual machines and asset criticality, and includes other fixes.
  • An icon on the Certificate Details page now shows correctly.
  • Fingerprint improvements.
4.0.250401.0
  • CSRF protection has improved.
  • User public API endpoints now include an mfa_enabled field indicating whether the user has enabled MFA and must use it to log in.
  • The scanner no longer fails to fingerprint services on sensitive ports.
  • The Risk Management dashboard no longer freezes some browsers.
  • Fingerprint improvements.
4.0.250331.0
  • Risk Management dashboard performance has improved.
  • VMware ESXi OS version information is no longer truncated on some assets.
4.0.250330.0
  • Misconfigured Windows adapters no longer cause excessive logging.
4.0.250329.0
  • Services no longer fail to populate in certain circumstances.
4.0.250328.0
  • Users can now create custom widgets for their dashboards with text of their choosing, rendered as a subset of Markdown/CommonMark.
  • The Google Workspace integration now collects data faster.
  • Vulnerability details now display on their own page with a linkable URL.
  • Integration attributes are no longer removed incorrectly.
  • runZero now tracks a VMware ESXi asset’s full name attribute correctly.
  • The findings page no longer takes a long time to load.
  • Searching for certificates using numeric values no longer causes console errors.
  • Searching directory users and groups by organization ID no longer returns errors.
  • The Findings overview dashboard widget now displays Info-level findings.
  • The Risk Management dashboard now shows correct “What’s Changed” values.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250325.0
  • runZero now detects self-signed certificates more accurately.
  • Google Workspace integration collection performance has improved.
  • Findings are no longer duplicated for a single organization.
  • Fingerprint improvements.
4.0.250324.1
  • Fingerprinting of CrowdStrike integration data now reports the correct source.
  • Scans no longer trigger printer output.
  • Fingerprint improvements.
4.0.250324.0
  • Introducing Risk Findings, a new feature that provides a complete view of risk. Findings group vulnerabilities, misconfigurations, and best practices into a curated list of actionable items so you can prioritize and remediate the most critical risk in your environment. To learn more, see our Risk Findings documentation.
  • Introducing the Risk Management dashboard, a new dashboard showing an overview of risk in your environment.
  • Introducing Certificates Inventory, a new inventory type where you can quickly view and search all of the TLS and SSH certificates in your environment. To learn more, see our Certificate Inventory documentation.
  • The “None” Risk Rank is now called “Info”.
  • The SentinelOne integration now processes hostnames with spaces correctly.
  • Custom integrations now process hostnames with spaces correctly. Multiple hostnames must be separated by a tab character.
  • Some vulnerabilities no longer have duplicate records.
  • Fingerprint improvements.
4.0.250317.0
  • A new dashboard list page shows all dashboards the current user can access.
  • Custom integration scripts can now pass an optional timeout=<seconds> parameter to http.get and http.post requests.
  • Custom integration scripts can now use the HEAD, PATCH, PUT, and DELETE HTTP methods.
  • You can now search Meraki firstSeen and lastSeen attributes as timestamps.
  • New snmp.interfaceAddrsMap, snmp.interfaceAliasesMap, snmp.interfaceNamesMap, and snmp.interfaceMacsMap attributes contain SNMP network data indexed by interface index.
  • Users now see a helpful message if they cannot log in via SSO because of an expired SAML certificate.
  • Dashboard widgets now show the date range they cover.
  • Rapid7 InsightVM vulnerabilities now sync the Exploitable flag correctly.
  • Fingerprint improvements.
4.0.250307.0
  • The user interface has several minor graphical fixes.
  • Filling in additional comments in the query builder feedback menu now works.
  • The AWS integration now imports tags for RDS instances.
  • The Nessus integration now continues processing data from other scans, even if an error occurs while ingesting data from one scan.
  • Performance improvements.
  • Fingerprint improvements.
4.0.250305.0
  • Calculation of the last seen value for Active Directory computers has improved.
  • Dashboard widgets no longer misalign at certain browser sizes.
  • Sorting team user tables by ID now works.
  • Fingerprint improvements.
4.0.250303.1
  • KEV-based vulnerability queries are now faster.
4.0.250303.0
  • Self-hosted deployments from the EU SaaS console now install correctly.
  • Fingerprint improvements.
4.0.250228.0
  • Merge logic for the Tanium integration has improved when multiple environments are present.
  • IP address collection from the Tanium integration has improved.
  • The team datagrid no longer shows most users with a “pending” status.
  • Host name expansion of scan targets now works correctly.
  • Fingerprint improvements.
4.0.250226.0
  • The API now supports setting an organization’s vulnerability expiration parameters.
  • Some stale data expiration settings set via the API no longer fail to take effect.
  • HTTP actions in custom integration scripts no longer have a timeout.
  • Fingerprint improvements.
4.0.250221.0
  • Performance improvements.
  • Fingerprint improvements.
4.0.250219.1
  • Metrics and query counts no longer fail to update.
  • Fingerprint improvements.
4.0.250219.0
  • runZero scans now record the last time they detected an asset in the asset attributes.
  • Performance improvements.
  • Fingerprint improvements.
4.0.250214.0
  • Fingerprint improvements.
4.0.250213.1
  • Self-hosted installations configured with SSO-only logins now automatically redirect to the IdP.
4.0.250213.0
  • Hostname collection no longer produces invalid asset hostnames and merges.
  • Drill-down from dashboards’ most- and least-seen charts now works.
  • The organization API now lets you modify an organization’s stale integration attribute setting.
  • Asset matching for the SentinelOne integration has improved.
  • The type: asset search keyword now performs a fuzzy search by default, similar to other search keywords.
  • Log events for tasks starting and failing are now labeled with the task name.
  • The default HTTP timeout for custom integration script requests is now longer, at 5 minutes.
  • Performance improvements.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250209.0
  • Performance improvements.
  • Fingerprint improvements.
4.0.250208.0
  • Performance improvements.
4.0.250207.3
  • Performance improvements.
4.0.250207.2
  • Creating a new project no longer displays an error for some editions of runZero.
  • Metrics recalculation tasks no longer issue spurious warnings.
  • Fingerprint improvements.
4.0.250207.0
  • Organizations now support setting thresholds to automatically expire stale integration and vulnerability data.
  • Merge logic for the Tenable Security Center integration has improved.
  • Merge logic for Windows assets with multiple interfaces has improved.
  • Errors for query widgets on the dashboard now display more clearly.
  • Filtering of invalid data from the Qualys integration has improved.
  • The scan templates page now shows all available templates.
  • The CrowdStrike integration now uses updated APIs to fetch applications, which improves collection performance.
  • Stale protocols no longer remain on services.
  • The asset details page now displays services from different vhosts on the same IP/port/protocol combination.
  • The asset datagrid now shows the full asset comment.
  • The Steam protocol probe no longer returns invalid responses.
  • Certain SSL-related vulnerabilities no longer produce higher-than-expected asset risk.
  • Fingerprint improvements.
4.0.250203.1
  • Scan processing no longer fails with an error.
  • The Tanium integration no longer fails to retrieve vulnerability data after the paging data limit is exceeded.
  • Fingerprint improvements.
4.0.250203.0
  • The Switch Topology report no longer omits hostname/IP combinations for some assets.
  • runZero no longer reports SMB v2 as available on certain Samba configurations.
  • Hosted zone tasks no longer get stuck in a Scheduled state.
  • Some community users who could not run scans using a hosted zone now can.
  • Task details no longer show a negative task duration in some cases.
  • Fingerprint improvements.
4.0.250130.1
  • Certain organization administrators who could not modify asset tags now can.
  • The quick-bookmark buttons on the reports pages now work.
  • The quick-bookmark buttons on the reports pages no longer indicate whether they’re already bookmarked.
  • Merge avoidance logic for certain integration combinations has improved.
  • Asset merging improvements.
4.0.250130.0
  • Dashboard duplication and creation now work correctly.
  • Filtering in the dashboard share menu now works.
  • Fingerprint improvements.
4.0.250129.0
  • Users can now create multiple dashboards, share them to organizations where they have User privileges or higher, and set a preferred dashboard in their profile settings. Any personal or runZero managed dashboard can be the preferred dashboard.
  • Organization administrators can now set a default dashboard per organization. Any dashboard shared to the organization or any runZero managed dashboard can be the default.
  • Query links on dashboards now respect the “Search live assets” attribute.
  • The change report is now visible on the Task Details page.
  • The scanner no longer fails to collect ARP cache data from Palo Alto Networks devices that use self-signed certificates.
  • Merge logic for assets observed via both Wiz and AWS has improved.
  • Fingerprint improvements.
4.0.250127.0
  • Self-hosted instances now check for updated content and queries every 5 minutes in online mode.
  • You can now set recurring tasks to a multiple of minutes.
  • runZero no longer reports SMB v1 as available on certain Samba configurations.
  • Explorer-run InsightVM tasks no longer fail with certain self-signed certificates.
  • Some integrations no longer fail when a non-standard port number is specified.
  • runZero no longer fails to connect to InsightVM installations that use a TLS certificate with a negative serial number.
  • Certain CrowdStrike vulnerabilities are now associated with an asset.
  • Fingerprint improvements.
4.0.250124.0
  • Newly created scans now target the dynamic “defaults” scope when site subnets are defined.
  • The custom integration script editor is now resizable.
  • Connecting to some versions of InsightVM no longer fails.
  • The Switch Topology Report no longer contains broken links.
  • Merge avoidance logic for certain RDP-related corner cases has improved.
  • Fingerprint improvements.
4.0.250123.0
  • The Meraki integration no longer fails to retry requests.
  • An asset’s extra addresses no longer go missing.
  • Operating System End of Life (EoL) coverage and accuracy have improved.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250122.0
  • runZero now supports the iSCSI protocol for asset discovery.
  • Reporting of Meraki integration errors has improved.
  • Some dashboard widgets no longer fail to update properly.
  • Custom dashboard widgets now display system queries to non-admin users.
  • Palo Alto Networks credentials now appear in the scan configuration.
  • Fingerprint improvements.
  • This release also includes the following fixes for low-severity findings from our annual third-party source code audit and security assessment:
  • runZero now stores new password hashes, login tokens, reset password tokens, and new account invite tokens using the argon2id one-way hashing algorithm. Before this release, hashes used the bcrypt hashing algorithm.
4.0.250120.0
  • Metrics no longer display inaccurately.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.250117.0
  • Operating System End of Life (EoL) coverage and accuracy have improved.
  • Fingerprint improvements.
4.0.250116.0
  • Layer 2 topology calculations have improved.
  • The task details page has improved.
  • The asset details page now includes the date the asset record was created in the runZero database. A new optional column in the asset inventory also shows this date.
  • Intune integration performance has improved.
  • Operating System End of Life (EoL) information is now available for Linux Mint.
  • Credentials can now be reused across multiple recurring tasks. runZero still recommends limiting credentials to a single recurring task in most situations to avoid duplicate asset ingestion.
  • Query metrics on the dashboard no longer display inaccurately.
  • The Meraki integration no longer fails to paginate Meraki resources.
  • Self-hosted consoles now honor the NO_PROXY environment variable.
  • Fingerprint improvements.
  • This release also includes the following fixes for low-severity findings from our annual third-party source code audit and security assessment:
  • Requesters who know an Explorer’s ID can no longer list its information across organizations within the same tenant.
4.0.250113.0
  • Vulnerability reporting from the Inside Out Attack Surface Management feature is now more accurate and adjusts severity based on the type of exposure.
  • runZero now supports fingerprinting devices via the Matter IoT protocol.
  • runZero now supports the Service Location Protocol (SLP) for device probing.
  • The Tenable integration now records MAC addresses even if they don’t have an associated IP address.
  • The Layer2 information section of the asset details page now groups unmapped MACs by interface.
  • Custom integration scripts can now use a flatten_json module with a flatten method.
  • Organization roles are now saved when creating or updating a group via the API.
  • Ingesting some assets from Tanium no longer fails.
  • Some connectors now retry timed-out requests correctly.
  • Tasks no longer retry repeatedly when the task data is improperly formatted.
  • Setting some asset values in custom integration scripts no longer fails.
  • Selecting ’no parent’ when editing a project with a consulting license now works.
  • Fingerprint improvements.
4.0.250106.0
  • Custom integration scripts can now run directly on runZero Explorers, and runZero tasks can trigger them. To learn more, see our custom integration scripts documentation.
  • runZero now creates vulnerability records for potentially exposed internal assets (Inside Out Attack Surface Management) and for misuse of shared encryption keys.
  • AWS integration task configuration forms have a new look and feel.
  • Scans no longer deadlock when using maximum scan durations.
  • Fingerprint improvements.
4.0.241223.0
  • Devices discovered by the Tenable integration now merge properly.
  • The list of Explorers now sorts correctly when configuring alert rules.
  • Fingerprint improvements.
4.0.241219.2
  • The runZero CLI is now available for download on all license tiers. Specific functionality still depends on your license and entitlements.
  • Integrations run through an Explorer now use proxy settings in all cases.
  • Explorer upgrades now strictly validate versions and update URLs.
  • Export APIs for export tasks are now available.
  • Scan tasks created in the console now support an optional scan duration limit.
  • The Getting Started Guide is revamped, with additional content.
  • Intune logging has improved.
  • You can now reorder the data sources list of custom multi-query widgets with drag and drop.
  • Name and email changes now work for users who are not enrolled in SSO when SSO is required.
  • The alert rule inventory query preview button no longer unexpectedly URL-encodes search strings.
  • Fingerprint improvements.
4.0.241217.0
  • Merge avoidance logic for integration data has improved.
  • The software section of the asset screen no longer displays all software for the entire organization.
  • The “Copy as a new scan template” button no longer appears for tasks where that action is unavailable.
  • Stale IP addresses resolved through DNS are now periodically removed.
  • Fingerprint improvements.
4.0.241213.0
  • Exporting software without a filter no longer fails.
  • Uploading an invalid IDP metadata.xml in SSO Settings no longer causes an application error.
  • Fingerprint improvements.
4.0.241212.0
  • Alert rules for inventory query event types now include a button to preview the configured query in the inventory.
  • The loading overlay on data tables throughout the product is now clearer.
  • Scan alert delivery through Slack no longer fails.
  • The alert error tooltip message now renders.
  • The discovery scope field now appears on the task inspection card.
  • The task inspection card no longer takes longer than expected to load in some cases.
  • Wiz connectors now work with Wiz API credentials scoped to specific projects.
  • Fingerprint improvements.
4.0.241210.0
  • Some event rules, channels, and templates are no longer hidden.
  • Alert rules now save the query condition.
  • Removing an organization now also removes its event templates, channels, and rules.
  • Some form “Back” buttons that did not function correctly now work.
  • Fingerprint improvements.
4.0.241209.1
  • The navigation menus have a new, easier-to-use design. User settings and sign out buttons are now in the top right of the application.
  • Alerts, rules, channels, and templates are now scoped to one or more organizations, so organization-level users can edit alert rules. See our alerts documentation for more information.
  • Asset merge avoidance logic for custom integration data has improved.
  • Tenable Security Center data now merges correctly.
  • Fingerprint improvements.
4.0.241206.0
  • Some forms that did not function correctly now work.
4.0.241205.1
  • Some dashboard drill-down pages no longer fail to display.
4.0.241205.0
  • Scans now probe Palo Alto Networks firewalls for ARP cache information.
  • The Wiz integration can no longer be configured without an API URL.
  • Hostname collection no longer produces invalid asset hostnames and merges.
  • Our annual third-party source code audit and security assessment is in progress. This release includes fixes for the following issues:
  • Content-Security-Policy headers are now stricter.
  • An XSS vulnerability was identified in the Asset Ownership form.
  • A few minor weaknesses were identified in the password reset flow.
4.0.241203.0
  • Assets discovered via CIP backplane enumeration now display more clearly.
  • The task inspection card on the task overview page now shows the scan discovery scope.
  • Discoverability of Fortinet appliances using the FortiGate to FortiManager (FGFM) protocol has improved.
  • Detection of bulk responses from Fortinet network filtering and interception products has improved.
  • Sample tasks are no longer delayed from starting once a scan completes.
  • Exporting asset attribute reports for foreign attributes now works.
  • Tenable tasks no longer occasionally ignore their filter settings.
  • The task inspection card on the task overview page no longer shows inconsistent state.
  • Explorers with identical host IDs no longer replace Explorers in another organization.
  • The events page no longer shows invalid events.
  • Assets no longer retain invalid serial numbers from filtered services.
  • Fingerprint improvements.
4.0.241125.0
  • Fingerprint improvements.
4.0.241123.0
  • Low memory conditions no longer cause excessive error reporting.
  • Fingerprint improvements.
4.0.241122.0
  • Assets with more than 128 ports open are no longer excluded from asset lists.
  • Dashboards now load faster when assets have many tags.
  • The Explorers list now loads faster.
  • Tasks no longer report spurious download errors.
  • Assigning rDNS names as an asset name no longer fails.
  • Fingerprint improvements.
4.0.241120.0
  • Refined Tenable merge rules now produce fewer duplicate assets.
  • Connection-related error messages for the Active Directory (LDAP) integration have improved.
  • Fingerprint improvements.
4.0.241118.0
  • Intune data collection is now faster.
  • Qualys integration logging has improved.
  • Unprocessed sample tasks no longer occasionally overload the task queue.
  • Fingerprint improvements.
4.0.241114.0
  • runZero now supports the Hikvision SADP protocol.
  • Microsoft Azure and Intune connections now complete faster.
  • You can now reprocess recent tasks to take advantage of updates to asset merge logic.
  • Shodan devices no longer fail to merge into existing assets.
  • Explorers no longer unregister due to operational issues with runZero’s platform.
  • runZero no longer logs api-export events as api-organization events. The api-export events generated between versions 4.0.241022.0 and 4.0.241114.0 were logged as api-organization events.
  • Fingerprint improvements.
4.0.241109.0
  • Qualys jobs no longer fail to complete in some cases.
  • Fingerprint improvements.
4.0.241106.0
  • Assets no longer have duplicate foreign data attribute sets.
  • The CLI scanner --output-raw option now produces gzipped output and disables output directory creation.
  • The CLI scanner now supports the link4 and link6 scan targets for local network ranges.
  • The CLI scanner help output now omits redundant host-ping/subnet-ping options.
  • Fingerprint improvements.
4.0.241101.2
  • Enumeration of buggy TLS ECDH implementations no longer fails.
  • The scanner now reports SNMP interface aliases in addition to names.
4.0.241101.1
  • Assets scanned over certain VPNs now merge correctly.
4.0.241101.0
  • The event details modal now displays links to source and target objects.
  • The events data grid page now includes an Organization column.
  • The Tanium integration now retrieves endpoints’ Custom Tags when available.
  • The switch topology export options now include the entire graph.
  • IP address ingestion via the CrowdStrike integration has improved.
  • The metrics recalculation actions on the task overview and dashboard have improved.
  • Fingerprint improvements.
4.0.241029.0
  • The GCP integration no longer attempts to retrieve resources from deleted projects.
  • runZero now supports fingerprinting Comtrol IO-Link devices.
  • runZero now supports the FortiGate to FortiManager (FGFM) protocol for asset discovery.
  • Fingerprint improvements.
4.0.241025.0
  • The task details page view for recurring tasks has improved.
  • The console now shows more clearly whether each user is required to use SSO.
  • runZero now processes UTF-8 BOM sequences in CSV files correctly.
  • Links in the Switch Topology report no longer break.
  • The standard query library is now accessible from the EU region.
  • runZero no longer fingerprints assets with stale service data incorrectly.
  • Fingerprint improvements.
4.0.241023.0
  • runZero now supports backplane enumeration of OT devices using CIP over EtherNet/IP.
  • CSV exports can now include Unicode characters.
  • Editing organization settings no longer causes an error.
  • runZero no longer fails to enforce “SSO Required” login restrictions on existing user accounts.
4.0.241022.0
  • You can now create multiple export tokens.
  • New export tokens now show creation information and accept a description.
  • Windows binaries are now signed only with the runZero code signing certificate. runZero has retired the old Rumble code signing certificate.
  • The “Summary” column in the service inventory view is now named “Service response”, which better describes the data.
  • Asset tags now work correctly in alert templates.
  • runZero now parses tags with no value correctly.
  • Tags are no longer dropped from event rule data.
  • The event log now formats tag changes correctly.
  • Very long Explorer names are now fully visible on the Explorer details page.
  • Assets with certain integration sources are now fingerprinted correctly.
  • runZero now collects asset hostnames from integration data correctly.
  • Windows Subsystem for Linux (WSL) guests observed in MS 365 Defender data are no longer merged with their hosts.
  • Merge avoidance logic for integration data has improved.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.241016.0
  • The current organization now stays consistent when you open links in the console.
  • The task card on the Explorer details page no longer shows tasks from other Explorers when multiple Explorers in the organization share the same name.
  • Email invites from users with punctuation characters in their names now work correctly.
  • Exporting vulnerabilities from the UI when filtering by site now works.
  • Viewing recurring task details when no subtasks exist now works.
  • Fingerprint improvements.
4.0.241015.0
  • runZero now integrates with NetBox.
  • The Completed and Recurring task list pages now include duration and average duration columns. You can view and sort tasks by duration.
  • Self-hosted installs now have a quick link to log in with SSO.
  • The dashboard menu now includes an option to recalculate dashboard metrics.
  • You can now refingerprint an individual asset with the latest fingerprint database directly from the asset details page.
  • Users are now redirected to a newly created organization or project after creating one.
  • The “Switch to” button in the organization table now works.
  • Asset links in the organization comparison report are now valid.
  • Fingerprint improvements.
4.0.241010.0
  • Logging in via SSO now works when a first name or last name is missing.
  • Disabled project settings are no longer clickable.
  • Fingerprint improvements.
4.0.241009.0
  • The login page now displays the active console region.
  • Exporting assets to Splunk via the runZero Splunk Add-on now uses less memory (requires v3.1.0 or greater of the add-on).
  • Querying for assets with multiple CVE matches from the vulnerability inventory page now works.
  • Explorers older than v4.0 are now phased out and can no longer connect to the console.
  • Fingerprint improvements.
4.0.241003.0
  • The Software Inventory no longer populates incorrectly in certain limited situations.
  • runZero no longer asserts an incorrect asset Type in limited situations.
  • Fingerprinting of Apple macOS from CrowdStrike data has improved.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.241001.0
  • The NOT and OR operators now work in queries on the site/organization report.
  • Operating System End of Life (EoL) values for Red Hat Enterprise Linux are now correct.
  • Login no longer requires some users to enter their email address twice.
  • The new first_seen_task search keyword finds assets first seen by a particular task.
  • The asset CSV export now includes serial numbers from additional protocols and devices.
  • Fingerprint improvements.
4.0.240927.0
  • You can now configure Explorer TLS settings with the TLS_VERSION_MIN and TLS_VERSION_MAX parameters.
  • You can now save Software and Vulnerability inventory queries to the query library.
  • Vulnerability groups now support searching by site ID or site name.
  • The task status icon and its error/warning logs now update when you select different tasks.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.240926.0
  • runZero scans now include the CUPS (IPP) Browser protocol as a new probe on UDP/631.
  • Matching between Tenable sources no longer produces incorrect results.
  • The console now prominently displays any error messages from the SSO process.
  • Fingerprint improvements.
4.0.240925.0
  • Pivoting from grouped vulnerabilities with multiple CVEs no longer produces a malformed query.
  • runZero no longer sends invalid JSON in some events that reference organization.id or site.id.
  • Wiz connections no longer report that results were not found when the service account credentials are correct.
  • Fingerprint improvements.
4.0.240924.1
  • Short rpcbind replies no longer produce an error message in scan logs.
  • The Site ID and Organization ID fields in event messages are now formatted as strings rather than byte arrays.
4.0.240924.0
  • Single sign-on no longer fails with the error “Email address … is already in use”.
  • The Asset inventory now displays the OS CPE value.
  • runZero now supports the Oracle Solaris Service Tag protocol for asset discovery.
  • Fingerprint improvements.
4.0.240923.0
  • The console has a new login screen.
  • runZero now integrates with Tanium API Gateway.
  • The API can now bulk remove a custom integration source from a list of assets.
  • Windows binaries are now signed with the new runZero, Inc. code signing certificate. runZero is currently dual signing with the old and new certificates.
  • Navigating to subsequent pages in inventory tables is now faster.
  • The Wiz integration’s performance has improved.
  • Event rule errors now display better via the tooltip within the table.
  • Event channels now display in the Channels list even if the user who created them no longer exists.
  • The bundled npcap driver is now v1.80.
  • Wiz vulnerability data no longer fails to process.
  • Event rules now handle UUIDs correctly.
  • The Wiz integration no longer fails to import some assets created more than 180 days ago.
  • Directory user and group membership counts are now correct.
  • The Wiz integration now properly syncs when the Wiz Service Account credential is limited to specific projects.
  • Fingerprint improvements.
4.0.240921.0
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.240919.0
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.240918.0
  • A race condition no longer causes incorrect asset matching.
  • Integration attributes no longer fail to update.
  • Managing alerts now works for all-organization admins.
  • runZero now supports the PCWORX protocol.
  • Fingerprint improvements.
4.0.240917.2
  • CrowdStrike tasks no longer fail and retry.
  • Fingerprint improvements.
4.0.240917.1
  • runZero now integrates with Microsoft Endpoint Configuration Manager (MECM).
  • The self-hosted platform now supports ARM64 (aarch64) on Linux.
  • Imported scan data now reports the correct scan times in the task view.
  • You can now query CrowdStrike device last seen fields as relative timestamps.
  • The CrowdStrike integration’s performance has improved.
  • Self-hosted runZero now installs on newer versions of Alma Linux.
  • The access summary for some users now displays correctly.
  • Querying directory user and group attributes with relative time queries now works.
  • Fingerprint improvements.
4.0.240910.2
  • Login link authentication no longer fails.
  • The Explorer no longer leaves temporary files in its temp directories.
  • My Orgs now works with a large number of organizations.
4.0.240909.0
  • The login process has a new, smoother design.
  • Viewing different organizations in separate browser tabs no longer causes confusing navigation behavior.
  • Asset merging improvements.
  • Fingerprint improvements.
4.0.240907.0
  • Asset correlation has improved for Meraki, ChromeOS, and SentinelOne sources.
  • Fingerprint improvements.
4.0.240904.1
  • Tasks that import software records no longer fail.
4.0.240904.0
  • Modifying a daily recurring task no longer schedules it incorrectly.
  • runZero can now identify assets using the Automatic Tank Gauge protocol.
  • Fingerprinting of Dell iDRAC devices has improved.
  • The RFC1918 scan options are now available from the RFC 1918 reports page.
  • Asset merging logic has improved.
  • The performance of foreign data integrations has improved.
  • Fingerprint improvements.
4.0.240902.0
  • Hardcoded device-side MAC addresses no longer cause incorrect correlation.
  • The scanner now ignores bogus network responses for PPTP and FTP services.
  • Fingerprint improvements.
4.0.240829.0
  • Large numbers of temporary files are no longer created with certain versions of Chrome.
  • runZero no longer sets an incorrect asset Type based on integration data.
  • Recurring tasks no longer create a new subtask when you modify properties other than “Start time” or “Scan frequency”.
  • Time and date values in searches now support relative times in more cases.
  • Integrations now handle API request retries better.
  • JSON alert templates now render arrays and objects as JSON arrays and JSON objects, without needing to loop through fields or values.
  • Fingerprint improvements.
4.0.240826.0
  • Asset merging no longer deletes custom integration attributes.
  • Assets no longer accumulate large numbers of attributes in some situations.
  • The CrowdStrike integration’s performance has improved.
  • Fingerprint improvements.
4.0.240825.1
  • Integration source attributes no longer fail to age out during merges.
4.0.240825.0
  • Scan and passive discovery tasks now complete faster for large sites.
  • CrowdStrike integration tasks now complete faster.
  • Fingerprint improvements.
4.0.240822.0
  • Operating System End of Life (EoL) coverage has improved for Cisco IOS XE, IBM AIX, Juniper Junos OS, and Palo Alto Networks PAN-OS.
  • Integration-source asset processing now avoids matching assets with excessive attribute sets.
  • Self-hosted installations now track performance profiles per task automatically.
  • The asset inventory now supports the foreign_attribute_count keyword.
  • Fingerprint improvements.
4.0.240820.0
  • The query library now includes a system query for assets past OS Extended End of Life.
  • Passive sampling tasks can now identify Avast, Bitdefender, Carbon Black, ESET, Kaspersky, McAfee, SentinelOne, and Trellix AV/EDR products.
  • The Alerts page has a new, easier-to-use design.
  • Asset merging performance has improved.
  • Fingerprint improvements.
4.0.240817.0
  • Blank foreign IDs no longer cause bad matches. Assets that had conflicting source data from blank foreign ID matching will rebuild as part of normal job processing.
4.0.240816.0
  • The self-hosted installer now supports custom installation and temporary directory paths.
  • The self-hosted installer now supports systems with disabled or restricted sudo.
  • The self-hosted console now supports text-format logging via the LOG_FORMAT=text configuration parameter.
  • Asset merging performance has improved.
  • Fingerprint improvements.
4.0.240814.0
  • The Meraki integration now supports filtering the imported assets by organization name and/or ID.
  • The Qualys integration now supports filtering the imported assets by tags.
  • The Asset Inventory view now has improved Operating System icons.
  • The license information page now shows license utilization as a percentage.
  • Directory group CSV exports now include the directory_group_user_count field at the end of the existing column set.
  • The Switch topology report has a new, easier-to-use design.
  • The Switch topology report no longer omits links for multi-homed hosts.
  • Fingerprinting logic now better accounts for certain source combinations.
  • Fingerprint improvements.
4.0.240811.0
  • Software vendor searches by prefix with wildcards now work.
  • Fingerprint improvements.
4.0.240809.0
  • The Alert Templates page has a new, easier-to-use design.
  • Valid JSON event rule templates are no longer rejected.
  • MAC and IP address mapping information is no longer dropped from custom integration device data.
  • Fingerprint improvements.
4.0.240807.0
  • The Alert Rules page has a new, easier-to-use design.
  • Fingerprint improvements.
4.0.240803.0
  • runZero now also stores Azure and GCP subscription IDs in the top-level asset attributes.
  • Fingerprint improvements.
4.0.240802.0
  • The Tenable Security Center integration no longer fails to import data.
  • The dashboard now supports filtering trending widgets by a customizable date range.
  • Invalid service detection has improved.
  • Fingerprint improvements.
4.0.240731.1
  • HTTP service data is no longer ordered incorrectly.
4.0.240731.0
  • runZero fixed an issue that could reduce the performance of large task processing.
  • Fingerprint improvements.
4.0.240730.0
  • Fingerprint improvements.
4.0.240729.1
  • The CrowdStrike integration no longer fails to run from an Explorer.
  • The matching engine for integration-sourced assets is now faster, more accurate, and better at merging related devices.
  • SSH enumeration now produces more consistently named fields.
4.0.240729.0
  • The Meraki integration now supports filtering by VLAN and SSID.
  • Fingerprint improvements.
4.0.240727.0
  • Vulnerability group exports now apply the search filter.
  • SSH enumeration now captures all host keys as well as server extensions.
  • Fingerprint improvements.
4.0.240726.0
  • Checkbox states no longer fail to persist in some cases.
  • Fingerprint improvements.
4.0.240725.0
  • runZero now supports discovery of devices using the TwinCAT ADS protocol.
  • Event templates can now use asset risk, vulnerability, and outlier fields.
  • Temporary directory selection for Explorers has improved.
  • The console now displays integration data fetch durations.
  • Fingerprint improvements.
4.0.240722.0
  • runZero now calculates vulnerabilities even when software entries are not present.
  • Name-based asset matching has improved significantly. It now uses more sources and trusts PTR records less.
  • Fingerprint improvements.
4.0.240719.0
  • The Tenable Security Center integration risk filter now works correctly.
  • Merging of VMware assets has improved.
  • Fingerprint improvements.
4.0.240718.0
  • The Goals Overview dashboard widget now displays data for the selected timeframe rather than an incorrect number of days.
  • Network topology calculation is now faster and runs as part of the metrics analysis task rather than inline with normal task processing.
  • Additional CrowdStrike device data is now available for users with access to CrowdStrike’s Discover API.
  • The CrowdStrike, Intune, Tenable, and Wiz integrations now process large datasets faster.
  • The Asset ID and Organization ID now appear on their respective details pages.
  • Fingerprint improvements.
4.0.240716.0
  • The CLI scanner now correctly supports the --import-pcap option.
  • Hosts with only some of their addresses excluded now match existing assets during merge.
  • Assets sourced from the Meraki connector now report the wired-side MAC for better correlation.
  • Fingerprint improvements.
4.0.240715.1
  • Connectors now use fast-fallback to IPv4 for non-responsive IPv6 endpoints.
  • Topology calculation no longer suffers from a performance regression.
  • The Tenable connector now supports filtering by source and tag.
4.0.240715.0
  • Fingerprint improvements.
4.0.240712.0
  • The CrowdStrike integration’s performance has improved.
  • Inventory table preferences now persist throughout the product.
  • Fingerprint improvements.
4.0.240707.0
  • You can now search for assets and vulnerabilities by VulnCheck KEV membership.
  • The CrowdStrike integration now retrieves more detailed information.
  • Users with community licenses are no longer blocked from initiating hosted scans.
  • VMware guest operating systems are no longer fingerprinted incorrectly.
  • Fingerprint improvements.
4.0.240702.0
  • runZero no longer sets asset type to Desktop incorrectly.
  • Certain virtual machine types now merge properly.
  • runZero now parses certain version comparison queries correctly.
  • Fingerprint improvements.
4.0.240628.0
  • Version fields across the product now sort semantically, and you can filter them with the operators >, >=, <, <=, =.
  • The Meraki integration now supports filtering on specific networks by name or ID.
  • The scanner now supports the Canon BJNP protocol.
  • Fingerprint improvements.
4.0.240627.0
  • You can now search vulnerabilities by EPSS score with the epss_score keyword.
  • The vulnerability information page now shows more information about CISA KEV membership and EPSS scores for vulnerabilities that have relevant information.
  • The Asset Ownership report now supports up to 15,000 owners at a time.
  • Vulnerability search is now much faster.
  • Fingerprint improvements.
4.0.240626.1
  • The Meraki integration now populates the switch topology report.
  • VMware guests now link correctly when observed across different ESXi servers and vCenter endpoints.
  • The Intune integration now supports an optional filter for devices.
  • The search option for the Azure AD integration is now deprecated.
  • Custom widgets no longer drill down into inventory views with an incorrect alive:t filter that overrides the query’s configuration.
  • Fingerprint improvements.
4.0.240622.0
  • MSSQL enumeration no longer returns incomplete results.
  • CrowdStrike records are no longer assigned the wrong IP address.
  • Fingerprint improvements.
4.0.240621.0
  • The Organization Overview report now works correctly and generates faster.
  • The dashboard now supports custom widgets based on queries. Users can create them from the widget library on the dashboard or from the query library.
  • Discovery and data collection from Microsoft SQL Server endpoints have improved.
4.0.240620.0
  • Fingerprint improvements.
4.0.240619.2
  • Logging for CrowdStrike connection errors has improved.
4.0.240619.1
  • CrowdStrike credentials no longer fail to validate.
  • Fingerprint improvements.
4.0.240619.0
  • Creating Azure integrations no longer fails.
  • Fingerprint improvements.
4.0.240618.0
  • Passive traffic sampling now detects syslog clients more accurately.
  • The scanner now accepts scan options from a JSON formatted configuration file.
  • Fingerprint improvements.
4.0.240616.0
  • The Export API endpoints now accept POST requests with application/x-www-form-urlencoded parameters, so larger search queries and field filters can be specified.
  • Fingerprint improvements.
4.0.240614.0
  • Scans no longer stall in some situations.
  • x.509 serial number values in tls.serial now keep their leading zero.
  • Fingerprint improvements.
4.0.240613.0
  • Non-Windows installations of the runZero Explorer no longer fail to restart.
  • Tenable assets no longer accrue stale MAC addresses.
  • CrowdStrike tasks with invalid credentials no longer hit long timeouts.
  • Custom integration attribute links now return results for mixed-case integration names.
  • Fingerprinting for Azure VMs now prefers the Azure HW assertion over other sources.
  • Fingerprint improvements.
4.0.240612.0
  • The Meraki integration no longer fails with an error.
  • The dashboard’s most and least seen widgets no longer display incorrect data when you toggle the view.
  • Fingerprint improvements.
4.0.240610.0
  • Some toggles in the UI no longer appear incorrectly.
  • Intune devices no longer fail to sync.
  • Fingerprint improvements.
4.0.240607.0
  • Discovery and data collection from Microsoft SQL Server endpoints have improved.
  • Fingerprint improvements.
4.0.240606.1
  • The Intune integration no longer skips syncing certain devices.
4.0.240606.0
  • New Explorer installations on Windows no longer omit npcap.
  • Connector tasks no longer get stuck in “stopping” status.
  • Users with no access permissions can no longer view the account’s superusers.
  • runZero now supports organization hierarchies up to four levels deep.
  • Fingerprint improvements.
4.0.240605.0
  • You can now search for assets and vulnerabilities by CISA KEV membership.
  • Performance improvements.
  • Fingerprint improvements.
4.0.240603.0
  • The Defender integration now supports filtering assets that have not been fully onboarded.
  • The Defender integration now supports the Graph API filter parameter when running as a scanner probe.
  • The Events view is no longer limited to the previous 30 days of records.
  • The Explorer now uses consistent file names during the upgrade process.
  • The Defender and Intune configuration now validates when you specify a new Azure credential.
  • Fingerprint improvements.
4.0.240531.0
  • runZero now supports discovery of devices using the XDMCP protocol.
  • OS CPE generation no longer produces incorrect values.
  • OS version information in Fortinet FortiOS CPE values has improved.
  • Operating System End of Life (EoL) information is now available for Fortinet FortiOS.
  • Asset merge logic has improved.
  • Fingerprint improvements.
4.0.240530.0
  • API-submitted import jobs no longer show a “user not found” error.
  • Fingerprint improvements.
4.0.240529.1
  • runZero now integrates with Meraki. This initial support syncs Devices and Clients to your runZero inventory.
  • The self-hosted query library no longer shows an “invalid query” message in error.
  • Punycode-encoded hostnames now display correctly.
  • Cross-VLAN mDNS relays in traffic sampling no longer cause incorrectly assigned MAC addresses.
  • Defender 365 sources no longer produce invalid MAC address attributes.
  • runZero scan results are no longer attached to not-onboarded Defender 365 assets instead of onboarded assets.
  • Assets are no longer marked as Laptops instead of Desktops.
  • Multiple passive sampling tasks are no longer scheduled on the same Explorer.
  • Fingerprint improvements.
4.0.240524.0
  • The dashboard now supports theater/kiosk mode and fullscreen display options.
  • The dashboard widget library now includes a customizable bookmarks widget that jumps to your favorite reports and views in runZero or to external web sites.
  • Users with organization-specific roles are no longer prevented from editing asset tags.
  • Fingerprint improvements.
4.0.240522.0
  • Performance improvements.
  • Fingerprint improvements.
4.0.240519.0
  • The domain: scan target keyword now returns substantially more results for most domains.
  • The scanner now treats in-scope addresses found by SNMP as primary addresses.
  • The scanner no longer adds reflected IP addresses in L2TP hostname responses.
  • The scanner no longer merges specific Netgear switches unintentionally.
  • The AzureAD (EntraID) connector now supports the $search and $filter parameters for the Microsoft Graph API.
  • The LDAP connector now syncs additional fields, including employeeID, ms-Mcs-AdmPwdExpirationTime, and ms-LAPS-PasswordExpirationTime.
  • The CrowdStrike connector now provides better OS fingerprinting during multi-source asset processing.
  • The Qualys connector is now more resilient to transient network and service timeouts.
  • The Qualys connector now prioritizes Agent-based operating system fingerprints.
  • The Custom Integration SDK can now ingest ipAddresses, ipAddressesExtra, and macAddresses fields directly without a NetworkInterface structure.
  • The Tenable connector no longer fails to export data.
  • Passive discovery no longer leaves stale asset attributes.
  • Service summary columns no longer go stale.
  • Fingerprint improvements.
4.0.240516.0
  • Fingerprint improvements.
4.0.240514.0
  • Filtering of bogus responses, particularly from interception features of Fortinet gear, has greatly improved.
  • Logging for the Azure and Intune integrations has improved.
  • Fingerprint improvements.
4.0.240508.0
  • Task logs no longer include unexpected Wiz authentication errors.
4.0.240503.0
  • Creating hosted zone scan tasks via API no longer fails if the site has no non-hosted Explorers.
  • Fingerprint improvements.
4.0.240501.0
  • Fingerprint improvements.
4.0.240429.0
  • The CrowdStrike integration now handles large vulnerability results better.
  • Fingerprint improvements.
4.0.240425.0
  • Fingerprint improvements.
4.0.240424.0
  • Fingerprint improvements.
4.0.240423.0
  • Setting a password now works for SSO users when SSO is disabled at the runZero account level.
  • Operating System End of Life (EoL) information is now available for SUSE Enterprise Linux and Apple tvOS.
  • Fingerprint improvements.
4.0.240419.0
  • Fingerprinting of assets from Microsoft 365 Defender data has improved.
  • Fingerprint improvements.
4.0.240417.0
  • Accessibility improvements.
  • Deleting a site no longer produces errors.
  • Wiz tasks no longer fail with an error.
  • Fingerprint improvements.
4.0.240411.0
  • runZero customers can now sync asset, software, and vulnerability data from Wiz.
  • Fingerprint improvements.
4.0.240410.0
  • The runZero dashboard now responds better to browser window resizing.
  • Fingerprint improvements.
4.0.240408.0
  • Data collection from slow SSH services has improved.
  • Fortinet devices are now less likely to cause duplicate assets when traffic is collected using traffic sampling.
  • The runZero Explorer now silently skips non-ethernet-like utun (tunnel) interfaces on macOS.
  • The “User details” page for external users now loads.
  • Changing an email address no longer produces errors.
  • Deleting a user no longer produces errors.
  • Fingerprint improvements.
4.0.240405.0
  • The profile settings page has a new design.
  • You can now name multi-factor authentication tokens when enrolling them.
4.0.240404.0
  • Fingerprint improvements.
4.0.240403.0
  • The Query Insights dashboard widget now clicks through to the appropriate inventory view.
  • Matching of MAC addresses for Fortinet firewall devices has improved.
  • Fingerprint improvements.
4.0.240402.0
  • Fingerprint improvements.
4.0.240401.0
  • The layout of the runZero dashboard is now fully customizable.
  • The runZero dashboard now supports exporting views as CSV and PNG.
  • Fingerprint improvements.
4.0.240331.0
  • Integration task processing is now much faster for assets with large numbers of MAC addresses.
  • Assets no longer accumulate link-local IPv6 addresses.
  • Fingerprint improvements.
4.0.240329.0
  • The “Contact runZero support” menu has a new design.
  • The services attribute report no longer fails.
  • Hostnames with spaces imported from the AzureAD connector are no longer split into multiple hostnames.
  • Logging for the Intune integration has improved.
  • UI improvements.
  • Fingerprint improvements.
4.0.240327.0
  • Tenable connector data processing is now significantly faster for devices with large numbers of MAC addresses.
  • The self-hosted updater no longer shows a SQL error during startup.
  • Scans running on Windows Explorers no longer accidentally terminate unrelated processes.
  • Fingerprint improvements.
4.0.240326.0
  • The CrowdStrike connector now imports only actively installed software.
  • The CrowdStrike connector now handles large software and vulnerability results reliably.
  • The CrowdStrike connector now better filters system accounts from the lastInteractiveUser attribute.
  • Fingerprint improvements.
4.0.240325.0
  • Fingerprint improvements.
4.0.240320.0
  • Fingerprint improvements.
4.0.240318.0
  • The Task ID now appears when you inspect a task on the task overview page and on the task details page.
  • runZero now calculates mid-scan progress correctly for connector tasks running on Explorers.
  • Upgrading self-hosted runZero instances no longer causes service start issues.
  • Fingerprint improvements.
4.0.240314.0
  • Colors throughout the product are now more accessible, legible, and consistent.
  • You can now configure tables in the product to prefer a mono-spaced variant of the table font.
  • Users can now choose a text casing preference for tables throughout the product via the “Prefs” dropdown.
  • Updates to Directory Users / Groups no longer fail.
  • Editing an Explorer’s settings no longer changes the “concurrency” setting incorrectly.
  • Accessibility improvements.
  • Fingerprint improvements.
4.0.240311.0
  • runZero now handles malformed header data from RTSP responses correctly.
  • The runZero CLI now completes faster for local networks.
  • Self-hosted customers can now unbind SSO from a user account using the runzeroctl user reset command.
  • Self-hosted customers can now change the SSO mode using the runzeroctl sso-mode mode command.
  • Accessibility improvements.
  • Fingerprint improvements.
4.0.240308.0
  • Short keywords now show autocomplete suggestions in the query builder.
  • Long fields in Nmap XML exports of asset data are no longer truncated.
  • The scanner now supports probing devices with EtherNet/IP over UDP.
  • Fingerprint improvements.
4.0.240306.0
  • New self-hosted installations and updates to existing installations no longer fail.
  • Fingerprint improvements.
4.0.240305.1
  • Assets no longer merge incorrectly in certain situations.
  • Analysis is no longer delayed for busy Organizations.
  • Fingerprint improvements.
4.0.240305.0
  • Fingerprint improvements.
4.0.240304.0
  • Fingerprint improvements.
4.0.240301.0
  • The asset CSV export now includes a “serialNumbers” column. This field contains serial numbers observed during scanning, along with the protocol used to discover them.
  • Assets discovered by traffic sampling are no longer assigned an incorrect attack surface.
  • Some task errors and warnings no longer fail to display.
  • Fingerprint improvements.
4.0.240228.0
  • The Google Cloud Platform integration no longer fails to create sites per project.
  • Fingerprint improvements.
4.0.240226.0
  • Operating System End of Life (EoL) assertions for certain versions of Microsoft Windows and Linux distributions are now correct.
4.0.240223.0
  • Organization statistics no longer become out of date in organizations with frequent and concurrent tasks.
  • Operating System End of Life (EoL) information is now available for Apple iOS and iPadOS as well as CentOS Stream.
  • Operating System Extended End of Life (EoL) generation has improved.
  • Fingerprint improvements.
4.0.240221.0
  • The vulnerability inventory is now much faster for large organizations.
  • runZero now supports fingerprinting devices via BGP.
  • Tenable integration performance has improved.
  • The asset and service attribute reports no longer fail.
  • Some credential form fields no longer disappear when you modify an existing credential.
  • Site-filtered insights now use the correct query format.
  • Fingerprint improvements.
4.0.240218.0
  • Software inventory is now calculated as part of metrics, which reduces task processing time.
  • The Organization picker now works on pages where it previously did not.
  • Saved queries in the search suggestions menu are now ordered by when they were last updated.
  • Asset correlation logic for devices with wired and wireless interfaces has improved.
  • OS detection logic has improved when considering multiple data sources.
  • Fingerprint improvements.
4.0.240216.0
  • Correlation behavior for assets with information from NTLMSSP or Qualys has improved.
  • Search query and query builder autocomplete results have improved for shorter input.
  • The parent organization picker now appears on the organization create and edit pages.
  • Fingerprint improvements.
4.0.240214.0
  • Protocol detection during traffic sampling has improved.
  • The alert event type emitted after a client switch is now “client-switched” instead of “login”.
  • The software groups table no longer includes the “Site” column.
  • The software inventory no longer occasionally fails to update after a task.
4.0.240213.0
  • The Software Inventory is now much faster for large organizations.
  • Stale service attributes no longer persist through rescans.
  • The LOG_FORMAT and LOG_MAX_LENGTH configuration values are now named RUNZERO_LOG_FORMAT and RUNZERO_LOG_MAX_LENGTH respectively. The old values still work but are deprecated.
  • The request timeout for the Qualys integration is now shorter.
  • TCP stack based OS fingerprinting has improved.
  • Fingerprint improvements.
4.0.240208.0
  • Adding addresses for Custom Integration assets without MACs now works correctly.
  • The request timeout for the Qualys integration is now longer.
4.0.240207.0
  • The Tasks CSV export now includes additional data points for result count and sent/received data.
  • Site subnet tags on assets now display in the correct format.
4.0.240206.0
  • Performance of the Software inventory table has improved.
  • Query Builder autocomplete now includes additional fields.
  • Site Subnet information now exports with Assets.
  • Data is no longer missing from the default email template for alerts.
4.0.240205.0
  • Filtering of hostnames collected from TLS X.509 certificates has improved.
  • Overlapping subnets no longer apply another Site’s subnet tags.
  • HP iLOs are no longer correlated incorrectly with their servers.
  • Fingerprint improvements.
4.0.240202.0
  • Tenable.io connector tasks now perform better when only a subset of Severity/Risk values is selected.
  • Users with the Administrator role can no longer downgrade their own permissions.
  • runZero no longer fails to fully hydrate Nessus attributes.
  • Fingerprint improvements.
4.0.240131.0
  • Fingerprint improvements.
4.0.240129.0
  • A query builder is now available from most datagrids via the “Query builder” button to the right of the search bar.
  • Assets no longer retain some out-of-date service information.
  • Service information is no longer incorrectly removed from assets that were offline during a scan.
4.0.240126.0
  • runZero now supports discovery of devices using the DNP3 protocol.
  • Operating System End of Life (EoL) information is now available for Oracle Linux.
  • Page break locations in the overview report have improved.
  • Operating System End of Life (EoL) generation for Red Hat Enterprise Linux and CentOS Linux has improved.
  • Assets with no known address are now labeled “Unknown” rather than “Unscanned”.
  • The bundled npcap driver is now version 1.79.
  • Last task details now display correctly on the Sites datatable.
  • Expanding dropdown menu sub-menus with keyboard navigation now works.
  • Certain OS fingerprinting data no longer fails to update.
  • Creating new Azure Credentials via the Azure connector configuration page no longer fails.
  • Tenable.io integration tasks no longer import vulnerability data when no severity or risk levels are selected.
  • Fingerprint improvements.
4.0.240124.0
  • Fields on the SNMP v3 Credentials form are no longer hidden.
  • Fingerprinting of Red Hat Enterprise Linux derivatives has improved when limited data is available.
  • Additional fingerprint improvements.
4.0.240122.0
  • The datagrid search bar now shows recent queries and available queries from the query library.
  • Fingerprinting of Red Hat Enterprise Linux and derivatives from Tenable product data has improved.
4.0.240119.0
  • The “Edit user permissions” modal now works correctly.
  • Fingerprint improvements.
4.0.240117.0
  • Re-importing custom integration task data now works.
  • Nessus imports no longer fail due to Nessus response size.
  • Fingerprinting of Red Hat Enterprise Linux derivatives such as CentOS, Rocky Linux, and Oracle Linux has improved.
  • Fingerprint improvements.
  • Accessibility improvements.
4.0.240112.0
  • All task lists in the task overview now include a Site column.
  • Fingerprint improvements.
4.0.240110.0
  • The Nmap XML export now uses the minimum and maximum asset last_seen timestamps as the start and stop times.
  • Updated Assets no longer retain stale services.
  • Self-hosted customers with transparent huge pages (THP) enabled no longer hit a resource leak.
  • Fingerprint improvements.
4.0.240109.0
  • Tenable Security Center tasks now retrieve only records updated since the previous sync.
  • Fingerprint improvements.
4.0.240105.0
  • The API for creating passive sampling tasks now works as documented.
  • Inventory grids no longer disappear in Firefox when you resize the window below a certain point.
  • Error handling for the Tenable, Tenable Security Center, and CrowdStrike integrations has improved.
  • Fingerprint improvements.
4.0.240103.0
  • Correlation for assets sourced from the Censys and Shodan integrations has improved.
  • Certain task failures are no longer logged incorrectly as ’explorer failed to queue task'.
  • Fingerprint improvements.
Updated