2026

Mondoo Release Highlights July 2026

·By Tim Smith

Back to releases

Introduction

The all-new Mondoo App reached general availability this month at app.mondoo.com, the new home that replaces console.mondoo.com. Rebuilt from the ground up around prioritization, remediation, and progress, it carries hundreds of improvements that no single post could list. The legacy console goes away on August 3, 2026, so now is the time to move your team over.

July went deep everywhere else, too. Every organization running TLS and SSH today is holding cryptography with an expiration date, and the new Post-Quantum Cryptography Readiness policy inventories and assesses quantum-vulnerable cryptography across your hosts, your clouds, and your network devices, all in one place. Your AI workloads are now first-class assets, each model, endpoint, training job, and notebook carrying its own risk score. Three new SaaS platforms, 357 new cloud and SaaS security checks, much deeper Snowflake coverage, and vulnerability coverage for nearly 100 more desktop and server applications round out the month, alongside self-serve Analytics in the App and a new Mondoo MCP server that puts Mondoo in your AI assistant. Let's dive in.

The All-New Mondoo App Is Now GA

The all-new Mondoo App is generally available, and it's the biggest change to Mondoo we've ever shipped. You'll find it at app.mondoo.com, which takes over from console.mondoo.com.

We rebuilt the App from the ground up around the two questions a security team has to answer every week: Are we fixing the risks that matter, and are we getting better? So it leads with prioritization, remediation, and progress instead of a wall of finding counts. Risk Dimensions replace the old opaque score with a rating you can explain in a single sentence. Remediation context sits next to the finding it belongs to, so you know how hard a fix is before you assign it. Dashboards and executive reports are written for the people who actually read them.

The Mondoo App organization overview for Lunalectric, with critical and high vulnerability counts, total assets by severity, risk broken down by space, and CVE and misconfiguration trends over time

A feature list wouldn't do it justice. Hundreds of improvements landed across the App on the way to GA, far more than one post can hold, and much of what follows here is a tour of them: Analytics and the rebuilt content management experience are both App surfaces that shipped this month. For the full walkthrough of the redesign and what it changes about vulnerability management, read our deep dive on the new Mondoo UI. GA wasn't the finish line. Three new features landed in the App this month, in the same weeks it went GA, and they're worth calling out by name.

Historical trends are new this month. Your dashboards now carry historical analytics data, so they show you the trend instead of just this morning's number. Vulnerability and misconfiguration counts render as trend lines with projections, which turns "Are we getting better?" from an argument into a chart you can put in front of your board.

Two dashboard cards, Critical + High CVEs and Critical + High Misconfigurations, each plotting counts over the past month, with a dashed projection line extending past the latest data point

A new organization-level dashboard applies that same history across the whole company rather than one space at a time, with measures built for the questions security leaders actually get asked:

  • How long have our critical vulnerabilities been open, shown as an age distribution
  • Is our open backlog growing or shrinking, tracked weekly by severity
  • How fast do we really remediate, reported as p90 and p95 resolution times rather than an average that hides the tail
  • Are we meeting our SLAs, with resolved-within-SLA attainment over a trailing 90 days
  • How is our patch level and compliance posture trending over time

One navigator for every org, space, and workspace

Switching context used to mean remembering where something lived. The new navigator puts every organization, space, and workspace you can reach behind a single search box, so you type a few characters and land where you meant to go. It marks your current location at the top, so you always know which context you're working in.

The Mondoo App navigator, with a search box spanning organizations, spaces, and workspaces, the current location marked, and the list of spaces below

Export any table on the spot

Getting your data out of Mondoo shouldn't take an API script. Every table in the App now exports straight from its menu in CSV, JSON, or XLSX, so when an auditor asks for the asset list or a team lead wants their own findings, you hand it over in the format they already work in. Copy to clipboard sits right beside it, for when pasting into a ticket is all you need.

The export menu on the Mondoo App assets table, with Copy to clipboard and Export to CSV, JSON, and XLSX options

Post-Quantum Cryptography Readiness

Migrating to post-quantum cryptography starts with an honest inventory. You cannot plan a migration for keys you cannot find, and quantum-vulnerable cryptography hides in more places than most teams expect: SSH host keys, TLS cipher suites, IPsec tunnel proposals, KMS key sizes, certificate signature algorithms, and the crypto settings on network gear nobody has audited in years.

This month we're shipping the Mondoo Post-Quantum Cryptography (PQC) Readiness policy, with 195 checks spanning 26 platforms, alongside a companion PQC Asset Inventory query pack that catalogs what you have before you start judging it.

Coverage reaches across your whole estate:

  • Hosts: Linux, Windows, macOS, and Unix, including SSH key algorithms and sizes, and the Windows Schannel TLS configuration.
  • Clouds: AWS, Azure, Google Cloud, OCI, OpenStack, Proxmox, STACKIT, DigitalOcean, and Hetzner, covering KMS and Key Vault key specs, certificate attributes, Application Gateway and Managed HSM crypto, load balancer TLS policy, and site-to-site VPN tunnel proposals.
  • Managed data services: TLS enforcement and cipher configuration on Azure SQL, PostgreSQL, MySQL, Cosmos DB, Cache for Redis, IoT Hub, Function Apps, and Container Apps, Google Cloud Memorystore and AlloyDB, AWS Redshift, Cognito, and CloudTrail, and the STACKIT OpenSearch, RabbitMQ, Redis, and LogMe instances.
  • Virtualization: VMware ESXi and vSphere, including vSAN data-in-transit and data-at-rest encryption, key provider registration, and VM Secure Boot.
  • Data platforms: MongoDB Atlas cluster minimum TLS version, cipher mode, root CA type, and federated identity signature algorithms.
  • Network devices: PAN-OS, F5 BIG-IP, Junos, Cisco IOS-XE, IOS-XR, and NX-OS, Arista EOS, UniFi, and Cloudflare.

Most of that coverage is scoped per resource rather than per account, so a single weak TLS policy on one managed database surfaces as a finding on that database instead of being averaged into a subscription-wide score.

The policy is built on new MQL fields rather than repackaged checks, so the same data is available to you for custom policy. A new windows.schannel resource, for example, exposes the cipher suites and supported groups configured on a Windows host, and answers the post-quantum question directly.

Similar building blocks landed across the board: SSH key algorithm and size on private keys and authorized keys, IPsec tunnel crypto on Azure, Google Cloud, OCI, and DigitalOcean, KMS key size and firewall TLS inspection settings on OCI and Azure, and parsed X.509 certificate attributes on STACKIT and Hetzner.

The result is a single report that tells you where your quantum-vulnerable cryptography lives, so you can sequence the migration instead of guessing at it.

Three New SaaS Platforms

Three brand-new SaaS platforms you can secure with Mondoo this month. Each one arrives complete: a provider you scan from the command line with cnspec, and an out-of-the-box security policy to harden what it finds.

  • MongoDB Atlas: Assess your Atlas organizations and projects with the new Mondoo MongoDB Atlas Security policy (40 checks), covering custom database roles, identity federation, backup compliance, push-based log export, resource policies, and Atlas Search and Vector Search indexes.
  • Databricks: Bring your Databricks accounts and workspaces under continuous assessment with the new Mondoo Databricks Security policy (25 checks), spanning Unity Catalog storage credentials, external locations and volumes, Delta Sharing, init scripts, instance profiles, customer-managed keys, and model serving endpoints.
  • Vercel: Secure your Vercel teams and projects with the new Mondoo Vercel Security policy (16 checks), covering deployment protection (Vercel Authentication, password protection, and Trusted IPs), Git fork protection, environment variable and secret hygiene, web application firewall configuration, API token lifecycle, and storage, domain, and TLS posture.

All three model typed cross-resource references, so you can traverse from a finding to the related resource in a single query. MongoDB Atlas and Databricks remediation guidance is validated against the live API and CLI, so the fix steps you get are the ones that actually work.

Your AI Workloads Are Now First-Class Assets

AI infrastructure has moved into production, and it carries real attack surface: models that can be shared outside your account, notebooks with broad IAM, inference endpoints reachable from the internet, and training jobs touching sensitive data. Last month we added the resources to inspect that infrastructure. This month it becomes a first-class part of your inventory.

Every AI workload gets its own asset, score, and exceptions

We now discover 13 new AI asset platforms across your clouds, so an individual model or training job is an asset in its own right rather than a detail buried under the account:

  • AWS: SageMaker domains, models, notebook instances, processing jobs, and training jobs.
  • Google Cloud: Vertex AI endpoints, jobs, pipeline jobs, and notebook runtime templates, plus Model Armor templates.
  • Azure: AI Services (Cognitive Services) accounts.
  • OCI: Generative AI endpoints.
  • DigitalOcean: GradientAI agents.

Security checks were retargeted onto these per-resource platforms, which pays off the same way finer-grained cloud discovery does: each AI workload carries its own risk score; you can open a ticket against a single endpoint; and you can set an exception on one training job without silencing an entire AWS account.

New AI security checks

We added 31 new AI-service security checks to the existing cloud policies. Whatever cloud your models run on, they come down to four concerns:

  • Encrypted with your own keys. Customer-managed key encryption on Bedrock agents, flows, and guardrails, on SageMaker training volumes, job output, and endpoint data capture, on Azure AI Services accounts and Machine Learning workspaces, and on Vertex AI jobs, RAG corpora, and notebook runtime templates.
  • Closed to the public internet. VPC isolation on SageMaker domains and notebooks, default-deny network ACLs and outbound restriction on Azure AI Services, public network access on Machine Learning workspaces, private networking and Shielded VM on Vertex AI notebook runtime templates, and private endpoints on OCI Generative AI and Data Science notebooks.
  • Authenticated, with no secrets in the clear. AgentCore gateway authentication and plaintext secrets, SageMaker processing job secrets and role scope, and local authentication versus managed identity on Azure AI Services.
  • Guardrails actually turned on. Bedrock guardrail configuration, Defender for AI on Azure, and prompt injection detection, PII detection, and content moderation on OCI Generative AI endpoints.

They ship inside the cloud policies you already run: 13 checks in AWS, 8 in Azure, 5 in Google Cloud, and 5 in OCI.

We're also mapping AI checks into the new NIST AI 100-1 (AI Risk Management Framework 1.0) framework added this month. That gives you automated evidence against AI RMF controls, so guardrail and model governance findings report against an AI risk framework rather than only a security score.

Deeper AI resource coverage

New resources extend what you can write policy against:

  • AWS: Amazon Personalize, deeper SageMaker domain, model, and endpoint configuration posture, and resource-based policies on shareable Bedrock and SageMaker resources, so you catch a model shared outside your account.
  • Azure: AI Services account posture with Entra RBAC role assignments, and Machine Learning workspace managed-network outbound rules.
  • Google Cloud: Document AI, deeper Vertex AI endpoint, pipeline job, and notebook posture, and IAM policy and public-access predicates on Vertex AI models and notebook runtime templates.
  • Databricks: Model serving endpoints and Unity Catalog registered models.
  • MongoDB Atlas: Atlas Vector Search indexes.
  • Snowflake: Cortex Search services and cross-region inference governance.

Connect Your AI Assistant with the Mondoo MCP Server

Your team already works in an AI assistant, and answering a security question should not mean leaving it. The new hosted Mondoo MCP server connects Claude Desktop, Claude Code, VS Code, and other MCP clients directly to Mondoo Platform: authenticate with a read-only API token and explore your spaces, findings, and policies in plain language.

Alibaba Cloud Security

If you run workloads on Alibaba Cloud, you can now assess them with Mondoo. The new provider models 81 resources spanning RAM identity, OSS object storage, ECS compute, VPC networking, SLB, ALB, and NLB load balancers, RDS, Redis, MongoDB, and PolarDB databases, Container Service for Kubernetes (ACK), Function Compute 3.0, NAS file storage, KMS, ActionTrail, Log Service, Cloud Config, Resource Directory, VPC flow logs, WAF, Cloud Firewall, and Anti-DDoS.

It ships with the new Mondoo Alibaba Cloud Security policy (46 checks) and fine-grained asset discovery for network and security objects, so individual resources land as their own assets. Scan it from the command line with cnspec.

Much Deeper Snowflake Coverage

Your data warehouse holds the data everything else is protecting, and it authenticates its own users, opens its own network paths, and reaches out to its own external services. Snowflake coverage got a major overhaul this month.

Scan with programmatic access tokens. cnspec now authenticates to Snowflake using programmatic access tokens (PATs) in addition to key pair authentication, so you can stand up a scan without provisioning and rotating an RSA key pair.

13 new resources. Schemas, tasks, functions, native applications and application packages, external access integrations, storage and notification integrations, network rules, row access policies, Cortex Search services, connections, and managed accounts. Typed cross-resource accessors were added as well, covering object owners, account defaults, integrations, and the task graph, so you can traverse from a task to the role that owns it in a single query.

An expanded security policy. The Mondoo Snowflake Security policy reaches version 2.0.0 with 19 new checks, concentrated on the ways a warehouse actually gets breached:

  • Authentication: MFA required by authentication policy, no single-factor password authentication, no active MFA bypass, service users without passwords, and no legacy service users.
  • Dormant access: Active users who have never logged in, and active users who have gone dormant.
  • Sessions and SSO: Idle timeout on both session policy and the web interface, and SAML2 integrations that sign their requests.
  • Data exfiltration paths: No unloading to inline URLs, stage creation restricted to storage integrations, external stages without inline credentials, storage integrations restricted to known locations, and API integrations restricted by prefix.
  • External access: Scoped external access integrations and secure external access functions.
  • Network and privilege: Network policies that define allow entries, and tasks not owned by a privileged role.

357 New Cloud and SaaS Security Checks

Your teams keep adopting new services, and the gaps that cause incidents spread into corners that were not being checked yet. This month we added 357 new security checks across your clouds and SaaS platforms:

  • 230 checks added to nine existing policies
  • 127 checks in the four new cloud and SaaS policies above

Here is where the new checks landed in existing policies:

  • AWS Security: 82 new checks
  • Azure Security: 65 new checks
  • GCP Security: 25 new checks
  • Snowflake Security: 19 new checks
  • GitLab Security: 12 new checks
  • OCI Security: 11 new checks
  • DigitalOcean Security: 7 new checks
  • OpenStack Security: 6 new checks
  • Hetzner Security: 3 new checks

The new checks concentrate where real incidents start:

  • Supply chain: 12 new GitLab checks cover push rules, CI/CD configuration, and webhooks, so the pipeline that builds production is held to the same standard as production.
  • Identity and authentication: AWS adds console MFA and inactive user checks, alongside the 19 new Snowflake identity and authentication checks described above.
  • Network isolation: A new Azure Virtual Network Manager check catches missing security admin deny rules, alongside VPC encryption in transit, just-in-time network access, and Privileged Identity Management coverage.
  • Under-covered services: 30 new Azure checks reach 12 platforms that previously had little or no coverage, and DigitalOcean and Hetzner add SSH key, function authentication, storage box, and certificate checks.
  • OpenStack: New object storage, Keystone, VPNaaS, and port security checks, bringing the policy to version 1.5.0.

Nearly 100 More Desktop and Server Applications

The software your developers and staff install is where a surprising share of real exposure lives, and it is the part of the fleet most vulnerability tools ignore. This month we added vulnerability coverage for nearly 100 of the most widely deployed desktop and server applications, so the software on your endpoints is assessed with the same rigor as the operating system underneath it.

New coverage spans the software actually running on your systems: productivity and collaboration suites, developer tools, security and endpoint agents, infrastructure and backup software, virtualization and remote access clients, media and utilities, and endpoint management tooling. The list runs from Microsoft Teams and Git to CrowdStrike Falcon, Veeam Agent, VMware Workstation, VLC, and the Intune Management Extension.

Network Device Vulnerability and End-of-Life Coverage

Network devices sit at the edge of everything and are often the last systems to get patched. This month we extended CVE and end-of-life coverage across the network:

  • Juniper Junos OS: CVE and end-of-life coverage, with remediation guidance telling you which release to move to, and advisories scoped to the hardware families they actually affect, so you stop seeing advisories for platforms you do not run.
  • Arista EOS: CVE and end-of-life coverage, with advisories scoped to the chassis you actually run.
  • F5 BIG-IP: CVE and end-of-life coverage.
  • Cisco IOS-XR and NX-OS: end-of-life coverage.
  • Cumulus Linux: end-of-life coverage, following NVIDIA's support policy.

A New Source of Exploited-in-the-Wild Intelligence

Knowing a vulnerability is exploitable matters far less than knowing it is being exploited right now. We added two new sources of real-world exploitation data this month, VulnCheck KEV and Google Project Zero, joining CISA KEV, Metasploit, and inthewild.io. The source that flagged a CVE as known-exploited is now attributed directly on the CVE, with its logo, so you can see where the signal came from.

New Compliance Frameworks

Two brand-new compliance frameworks this month, both addressing regulation that is landing now:

  • EU Cyber Resilience Act (CRA) 2024/2847: 30 controls, with mappings to CIS Controls 8 and ISO 27001:2022. If you sell products with digital elements into the EU, this is the framework you will be measured against.
  • NIST AI 100-1 (AI Risk Management Framework 1.0): 72 controls across the Govern, Map, Measure, and Manage functions, with the new AI checks mapped in so your AI posture reports against a recognized AI risk framework.

We also added mappings from our policies to MITRE ATT&CK, the OWASP Top 10 2025, and OWASP ASVS 5, so findings line up with the frameworks your teams already work in.

Updated CIS Benchmarks

Staying current with CIS guidance keeps your infrastructure hardened against today's threats. This month brings one brand-new benchmark and three updates:

  • CIS Fortinet FortiGate 7.0.x Benchmark v1.4.0 (new, 23 checks, Level 1 and Level 2)
  • CIS Google Kubernetes Engine (GKE) Benchmark v2.0.0
  • CIS Microsoft Intune for Windows 11 Benchmark v5.0.0
  • CIS Oracle Cloud Infrastructure Foundations Benchmark v3.1.1

The CIS AWS Compute Services Benchmark also gained nine automated checks that previously required manual review.

Out-of-Band Management with Redfish

The management controllers on your servers run their own firmware, their own accounts, and their own network stack, entirely outside the operating system you scan. This month we added a new Redfish provider covering baseboard management controllers, including HPE iLO and Dell iDRAC, and a new Out-of-Band Management group in your inventory. Scan them with cnspec and write custom policy against 14 new resources to bring the layer beneath the operating system under assessment.

Organization-Wide Policy and Content Management

Enabling the same policy space by space does not scale. July introduces hierarchical policy assignment, so you assign a policy once at the organization level and it runs across every space beneath it automatically.

That gives you two layers that work together. The business-level policy you set on the organization flows down to every space and cannot be overridden locally, so the standard you committed to your auditors is the standard that actually runs. On top of it, each team stays free to add the policies their own environment needs. Nobody has to choose between a company standard that holds and letting teams own their security posture.

Custom policy uploads can now be scoped to an organization as well, which means a new space arrives already governed by your standards instead of needing to be configured from scratch.

The Organization Policies page in the Mondoo App, with average policy compliance, policies running, and total exception counts above a list of policies that can be filtered to platform wide, organization wide, or individual spaces

Managing that content got simpler at the same time. Query packs, compliance frameworks, and policies now share one management interface instead of three separate flows, and assigning content takes fewer steps. Query pack results are also viewable fleet-wide in the Mondoo App rather than asset by asset, which turns the inventory packs into a way to answer questions about your whole environment at once.

Finding the right content is easier, too: policies and queries carry summaries, policies show their scoring status and whether they are official Mondoo content, and lists sort by assignment state. New and expanded cloud inventory query packs expose more of your environment, with six new packs covering DigitalOcean, Hetzner, Nutanix, OpenStack, Proxmox, and STACKIT alongside an expanded OCI pack.

Finer-Grained User and Team Management

Large organizations do not manage access from one administrator account, and they do not want to grant permissions one person at a time. Teams are how you stop doing that. Group the people who need the same access, give the team its roles, and everyone in it gets them. Onboarding a new engineer becomes adding them to a team instead of reconstructing someone else's permissions by hand, and you now assign those roles when you create the team rather than configuring them afterward.

The Identity and Access page in the Mondoo App, showing counts of users, teams, and service accounts, tabs for each, and the user table with names, emails, and organization roles

Delegation got the same treatment, so everyday membership work no longer requires broad administrative rights:

  • Team member managers: Delegate membership for a single team. A team member manager adds and removes that team's members without space-wide administrative access, and you assign managers directly in the members table.
  • An Identity and Access experience scoped to your role: Team managers get their own navigation and landing experience showing only the teams they manage, rather than an access page full of controls they cannot use.
  • Roles that explain themselves: Every built-in role now carries a description and a populated permission summary, so you can see what a role actually grants before you assign it.
  • Guardrails against accidental privilege escalation: Team and team member management is no longer part of the Editor role, and adding a user with a role you do not hold yourself now fails loudly instead of silently.

Analytics: Self-Serve Reporting

Dashboards answer the standing questions; Analytics answers the rest, and it reached general availability this month. Open Reporting > Analytics for seven built-in reports rendered live from your security data, with configurable pivot tables, custom report authoring, and PNG and PowerPoint export, so the numbers your stakeholders ask for come from the Mondoo App instead of a spreadsheet.

The Analytics report gallery in the Mondoo App, with a searchable grid of built-in reports including Security Overview, Vulnerability Overview, Asset Inventory and Risk, Security Posture, Compliance Controls, and Package Vulnerabilities, and a New Report button

Better Infrastructure as Code Results

Catching a misconfiguration in the code that builds your infrastructure costs far less than catching it in production. This month strengthens infrastructure as code scanning in two ways.

Terraform variables now resolve to their real values. A check looking at a Terraform argument set to var.bucket_acl used to see an unresolved reference rather than the value it would actually deploy. We now resolve var.* and local.* references to their effective values, applying variable defaults and overriding them with your .tfvars, during HCL scans. Authenticated and server-side scans no longer miss a bad value hidden behind a variable.

Broader infrastructure as code discovery in your repositories. Scanning a GitHub or GitLab repository now discovers CloudFormation, Dockerfile, Bicep, Helm, and Kustomize alongside Terraform, so more of what builds your environment is assessed. We also expanded the Terraform, CloudFormation, and Bicep variants of existing cloud checks and fixed a substantial number of cases where those variants reported incorrectly.

We also added a new HashiCorp Cloud Platform provider with 13 resources for custom policy.

Stronger GitHub and GitLab Security

  • Scan options: Choose whether a GitHub integration runs secret scanning and vulnerability scanning.
  • GitLab depth: New resources cover CI job token scope, protected tags and environments, integrations, personal access tokens, group webhooks and variables, release and user provenance, instance hardening settings, and GitLab Duo AI indicators, backing the 12 new supply chain checks above.

Deeper Azure Security Operations Visibility

Azure gained 72 new resources this month, with a strong focus on the security operations tooling running inside your subscriptions:

  • Microsoft Sentinel: Incidents, watchlists, and automation rules.
  • Defender for Cloud: Sub-assessments for per-finding drill-down, just-in-time network access policies, alert suppression rules, and workspace settings.
  • Defender for APIs: API collections.
  • Azure Monitor: Action groups, metric alerts, and scheduled query rules.
  • Privileged Identity Management: Role eligibility and assignment schedules, and role management policies.
  • Governance: Per-resource policy compliance states, network security perimeters, firewall policy rule collection groups, and Service Bus and Event Hub SAS authorization rules.

You can now write policy asking whether your detection and response tooling is configured the way you believe it is.

Traversing Your Cloud in a Single Query

Understanding real risk means following relationships: which load balancer routes to which instance, which identity holds which role, which route table sends traffic where. This month we added typed cross-resource references throughout the cloud providers so those relationships are traversable directly in MQL.

  • AWS: Route table next hops, the full load balancer listener to backend chain, Route 53 alias records resolving to load balancers and CloudFront, WAF web ACL associations in both directions, and cross-references across ACM, IAM, S3, EFS, FSx, EC2 images and volumes, KMS, subnets, hosted zones, and network interfaces.
  • Azure: Resource identities traversing to their role assignments, private link reachability from endpoint to subnet to virtual network, private endpoint network interfaces, and typed network interface IP configurations.
  • Google Cloud: Typed network edges and instance network interfaces.
  • OCI: Transit networks with traversable route rules, and site-to-site VPN and FastConnect ingress paths.
  • Elsewhere: Typed references across Hetzner, STACKIT, DigitalOcean, Snowflake, Okta, and the three new SaaS providers.

In practice, this makes cross-resource questions much easier to ask. The relationships resolve directly, so you follow them in a single query instead of correlating identifiers by hand.

Which instances sit behind an internet-facing load balancer, following each listener through its target groups to their backends:

MQL
aws.elb.loadBalancers.where(scheme == "internet-facing") {
listeners { forwardTargetGroups { ec2Targets } }
}

And on Azure, the resource-to-privilege leg of an attack path, in one query, is what an internet-reachable VM's identity is authorized to do:

MQL
azure.subscription.compute.vms.where(exposure.internetReachable == true) {
systemAssignedIdentity { roleAssignments { role.name } }
}

Internet exposure is now also attributed to the hosts behind a load balancer, so an exposed backend is flagged even when the load balancer is what holds the public address.

Remediation for More of Your Stack

  • New platforms: Remediation generators now cover Huawei Cloud EulerOS, EulerOS, openEuler, and CentOS, and Python package findings generate PyPI upgrade steps.
  • Junos OS: Junos advisories now carry remediation guidance naming the release to upgrade to.
  • Windows accuracy: A large effort on Microsoft update supersedence means findings for Windows and .NET Framework resolve to the correct cumulative update far more reliably, with superseded preview updates withdrawn automatically and re-issued update chains followed to the right fix. Remediation scripts now also surface the reboot-pending case.

Quality-of-Life Improvements

A number of smaller additions this month that make everyday work smoother:

  • More Okta visibility: 17 new resources cover resource sets and the admin privilege graph, application entitlements and client admin roles, device trust and threat posture, and hooks, log streams, and API service integrations.
  • Audit log detail: Audit log events now record the client IP address the action came from, and exports carry the acting identity's email. Mondoo's own internal events are filtered out, so the log shows what people did rather than what the platform did.
  • Scoring transparency: An asset that is being rescored now shows "scoring in progress" instead of a stale score.
  • Integration states: Integrations report QUEUED and RUNNING states, and the Kubernetes integration supports pause, unpause, and configure.
  • Ticketing: Webhook payloads now include the rendered ticket content, matching what the GitHub and Jira integrations already send.
  • New operating system support: WizOS is detected with its apk packages, and Raspbian is normalized to the Debian ecosystem so it gets full vulnerability coverage.
  • New host inspection: A new PostgreSQL resource inspects on-disk configuration (postgresql.conf, pg_hba.conf, and pg_ident.conf), and the nginx stream block is now readable.
  • Container scanning: Rootless Docker is supported, and Kubernetes discovery gained image filtering options.
  • Kubernetes operator: A new scan cache skips re-scanning container images that have not changed, so the operator stops pulling the same images every cycle. Node scan garbage collection no longer deletes container image assets alongside node assets, and the running cnspec version is now reported in the operator's status.
  • Microsoft 365: New Power BI resources and tenant license seat counts.

And There's Even More

Beyond the highlights above, July brought a long list of smaller improvements throughout the product, too many to call out individually. And we're already hard at work on what's next, so look for more new functionality next month.

On this page