2026

Mondoo Release Highlights September 2026

·By Tim Smith

Back to releases

Introduction

September belongs to Mondoo 14.0. It brings endpoint management across macOS, Windows, and Linux; one command that finds and scans every kind of infrastructure as code in a repository, OpenTofu included; container scanning from the base image up; and cloud scans that make up to 97% fewer API calls. Underneath, MQL gained strict mode, so a check that could not look is no longer a check that passed, and cross-version support, so a newer policy no longer breaks on an agent you have not upgraded yet. The full story lives in Mondoo 14.0 is out!, and it is worth your time.

14.0 is only part of what shipped this month. Vulnerability coverage expanded on every front: Mondoo now identifies 4,000+ more applications, matches vulnerabilities on more platforms and package ecosystems, and flags software its vendor has abandoned. New edr, mdm, and idp resources show whether every workstation is protected, managed, and joined to your identity provider, and 35+ more resources shipped in the week after 14.0. The UK government's Cyber Essentials v3.3 framework arrived with 418 control mappings, the AI platforms your developers build on gained their own security policies, 200+ new security checks landed across AWS, OCI, and the rest of the policy library, and AI remediation now covers vulnerabilities you can fix with configuration. The GitHub integration now scans code, secrets, and dependencies in every repository it reaches, and SecurityScorecard findings now flow into Mondoo.

Finally, September was a big month for software supply chain security. Our new project, xgrep, finds vulnerable code, leaked secrets, and vulnerable dependencies wherever your code lives: in your terminal, in CI, in your editor, and in every repository your GitHub integration reaches. This post introduces xgrep and everything it gained this month. Let's dive in.

Mondoo 14.0 Is Out

Mondoo 14.0 shipped this month, and it touches every part of how you scan. The headlines:

  • Endpoint management. New MDM and EDR resources for macOS, Windows, and Linux.
  • Automatic client updates on Windows. cnspec on Windows now updates itself in place, as it already does on Linux and macOS, so your whole fleet stays current without anyone reinstalling a package. See Update cnspec.
  • Container scanning from the base image up. Hardened and minimal base images are named, and the container hosts beneath them are assessed.
  • Precise detection for 15 more operating systems, with expanded Solaris, FreeBSD, and SUSE 16 support.
  • OpenTofu support. cnspec scans OpenTofu configurations, plans, and state files directly, and reads .tofu files the way OpenTofu does, so your checks move with you when you migrate off Terraform.
  • Unified infrastructure as code scanning. The new iac provider walks a repository, finds every Terraform module, OpenTofu configuration, Helm chart, Kubernetes manifest, Dockerfile, CloudFormation template, Bicep file, and Ansible project in it, and scans them all with one cnspec scan iac command that drops straight into CI.
  • Cloud scans that make up to 97% fewer API calls.
  • OCSF, InSpec (OHDF), and CSV output, so scan results land in the formats your pipeline already reads.
  • MQL strict mode. A typo or a missing key is an error, not a silent pass, so a green result means the check actually looked.

Two feature releases followed within a week: 14.1 on September 25 and 14.2 on September 29. Read the full 14.0 announcement for every detail, including the breaking changes to review before you upgrade.

xgrep: Securing the Code You Ship

Your software supply chain starts long before anything is deployed. It starts in the source code your developers write, the secrets that slip into a commit, and the open source dependencies every project pulls in. Mondoo has always secured the infrastructure you run. xgrep is Mondoo's command line tool for the code you ship, and it is a core part of our larger push into supply chain security.

If you have not met it yet, xgrep is one fast binary that brings three scanners together:

  • Code scanning (SAST) with built-in security rules and taint analysis that follows untrusted input all the way to a dangerous sink. Rules use the Semgrep YAML syntax, so the rules you already have keep working.
  • Secret scanning, on by default, including your full git history and encoded payloads, with validation that tells you whether a leaked credential is still live.
  • Dependency scanning (SCA) that generates an SBOM, finds vulnerable packages, and uses reachability to tell you whether your code actually calls the vulnerable function.

xgrep is built to cut the noise: it focuses on real, exploitable vulnerabilities and verified secrets, so the findings you act on are the ones that matter. It needs no account and no configuration, so you can try it on any repository right now:

Bash
npx @mondoohq/xgrep scan .

Run it from the command line, in CI, in your editor through the Mondoo VS Code extension, or as a guard hook inside Claude Code or OpenAI Codex that blocks leaked secrets and dangerous commands before the agent acts. Sign in and xgrep publishes its findings to Mondoo Platform, where they sit next to your infrastructure risk in one prioritized view. See Getting Started to go from install to first scan.

xgrep ships continuously, and September was a big month for it.

Four New Languages

xgrep now reads four more languages, each with real AST parsing, a dataflow extractor so taint rules work end to end, and a starter rule pack.

  • Cairo, the smart contract language for StarkNet. Taint follows a value out of a function through Cairo's implicit tail expression returns, the way the language actually returns it.
  • Hack, Meta's language derived from PHP.
  • Jsonnet, the configuration language, which ships with a dataflow extractor so taint rules run on it.
  • Salesforce Apex, covering Salesforce classes and triggers.

See supported languages for the full list.

Nearly 150 New Rules Across 23 Languages

The built-in rule library grew by nearly 150 rules, led by Kotlin, PowerShell, Bash, and new secret detectors. The standouts:

  • Supply chain integrity (OWASP A03:2025). New rules flag the dependencies that quietly become a backdoor: npm git dependencies pinned to a mutable ref, npm install hooks that download and run code, Composer dependencies that track a mutable development branch, and Dockerfile base images left untagged, which means latest. A dependency you cannot reproduce is a dependency you cannot trust.
  • Verification that fails open (OWASP A10:2025). A verification path that says "allowed" when it hits an exception is worse than no check at all. New rules catch it in Java, PHP, C++, and Swift.
  • PowerShell, seriously. Twenty new PowerShell rules arrived, including credential handling problems that PSScriptAnalyzer misses, plus correctness and best practice rules for both PowerShell and Bash.
  • Rust transport security. New rules catch cleartext transmission and cookies without the Secure flag, and they know when plaintext to a loopback address is not actually a risk.

Secrets: Broader Coverage, Fewer False Positives

New detectors cover CrowdStrike Falcon API client secrets, OAuth 1.0 tokens and consumer secrets, NTLM authentication material, PASERK keys, private JWK members, signed session cookies, bearer tokens, and hex keys, and a generic secret assignment detector is now on by default. Teams that want it can opt in to a broader password rule.

A dedicated cleanup cut false positives in the test corpus by more than a third, and well-known test card numbers no longer trigger a finding. Secrets found in test code are now marked and ranked below production ones, because a fixture key and a leaked production key should not read as the same emergency.

An Always-Warm Guard Daemon

Guard hooks check every prompt and command an AI coding agent sends or runs, so they have to be fast. The new optional per-user guard daemon keeps them warm: hooks try it first and fall back to a cold start. Guard and the editor integration share one in-memory scan pipeline, so rules load and caches warm once. Register it as a per-user service (launchd on macOS, systemd on Linux) with:

Bash
xgrep guard install --daemon

A Calmer, Faster Scan

  • Calm by default. xgrep scan now leads with a short, readable coverage summary and gathers end-of-scan notes into one actionable section. The full diagnostics moved behind --verbose, so you can tell at a glance whether you need to act.
  • Faster where it counts. The cross-file pass now does its setup once per scan instead of once per rule, and startup does less work up front. Large repositories scan faster without changing a single finding.
  • A version your scripts can read. xgrep version --format json gives scripts and CI a stable shape to parse.
  • Its own code search. xgrep now ships its own code search engine for text search, replacing a third-party indexer. That means fewer dependencies and a search path xgrep can keep improving.

Accuracy First: Reachability and Precision

Fewer findings you have to second-guess:

  • Reachability that does not overwarn. When xgrep cannot read one module's source, it no longer withholds verdicts for the whole project. The gap only affects the build that actually uses that module, so a missing developer tool dependency stops blanking answers for your main code. Modules replaced with a local directory, a common pattern in large monorepos, now resolve from that directory.
  • Sharper taint in C. Taint now follows an identifier aliased through a macro, exactly as the compiler would expand it.
  • No runaway scans. Regular expressions that could stall a scan on hostile input were replaced, keeping analysis time bounded.

Expanded Vulnerability Support

You cannot fix a vulnerability in software you cannot see, cannot name, or do not know is dead. This month Mondoo got better at all three: it identifies thousands more applications, matches vulnerabilities on more platforms and package ecosystems, reads installed software more reliably, and flags the software its vendor has walked away from.

4,000+ More Applications Identified

4,000+ more applications, from common security tools to the productivity and utility apps on your desktops and servers, now resolve to a vendor, a product name, and a product page wherever they are installed.

The same application rarely goes by one name. The Windows build, the macOS app, the package a package manager installs, and the marketing name on the vendor's website can all look different, and they change from release to release. Mondoo recognizes every one of those names and resolves them to the same product, so the CVEs published against an application are reported on every asset that runs it, no matter how or when you installed it.

Know What That Vulnerable App Actually Is

A critical CVE on a product nobody on your team recognizes is a finding that sits in the queue while someone searches the web for what it even is. Every product in the Mondoo catalog now comes with a plain language description of what it does and who uses it, alongside its vendor and product page. When a scan turns up a vulnerable copy of B&R Automation Runtime, Siemens SIMATIC ProSave, or the ShareFile StorageZones Controller, the finding tells you what you are looking at, so you can decide who owns it and how urgent it is without leaving Mondoo.

Vulnerability Matching on More Platforms and Ecosystems

Mondoo now matches vulnerabilities on:

  • Azure Linux, end to end
  • BellSoft Alpaquita Linux and BellSoft Hardened Containers, with advisories straight from BellSoft
  • macOS 12 and 13, so the Macs that cannot take the latest release are still assessed
  • Fedora 30 through 38
  • Debian 8 and 9, the long-lived hosts that never made it to a newer release
  • C and C++ dependencies declared with Conan and vcpkg
  • R and Haskell packages, with advisories straight from each ecosystem's own database

Behind those matches, four new advisory sources landed, Azure Linux, BellSoft, R, and Haskell, taking the Mondoo Vulnerability Database to 66.

Fix Guidance for Every Dependency Ecosystem

Knowing a dependency is vulnerable is half the answer. The other half is what to change in the repository, and every package manager has its own way of doing it. Mondoo's remediation guidance, which already covered npm and PyPI, now covers Java (Maven and Gradle), Go, .NET (NuGet), Rust (Cargo), Ruby (RubyGems), PHP (Packagist), Elixir (Hex), Dart (Pub), Swift, C and C++ (Conan), R (CRAN and Bioconductor), and Haskell (Hackage).

Each finding gives you the ecosystem's own commands for a targeted upgrade, validated against the real toolchains, and lets the package manager regenerate the lockfile rather than asking you to edit it by hand. Because a vulnerable package is often pulled in by something else, the guidance covers both cases: the dependency you declared yourself, and the transitive one you never named. Flatpak apps on Linux get guidance too, including a plain statement when no fixed build exists yet.

End of Life for Abandoned Software

Some of the riskiest software in your environment is software nobody will ever patch again. When a vendor retires a product, the vulnerabilities keep arriving and the fixes stop, and because there is no newer version, a vulnerability scanner has nothing to tell you to upgrade to. Those installs are time bombs.

Nearly 100 more applications now carry end-of-life detection this month, and many of them are products their vendors retired years ago: Adobe Flash Player and AIR, Microsoft Silverlight, Skype, classic Teams, WinPcap, Tera Term 4, the Access Database Engine, Windows Mobile Device Center, and SQL Server Native Client among them. Actively maintained products gained lifecycle tracking too, so an install that has fallen off its support window is flagged: RabbitMQ, Amazon Corretto, Python on Windows, Splunk, Checkmk, Cortex XDR, OpenSSL on Windows, and Ubuntu on WSL.

When a product has been discontinued outright, its remediation says so. Instead of an upgrade path that does not exist, you get the two real choices: uninstall it, or move to the successor that carries it forward, such as the Open-Shell fork of Classic Shell.

Better Package Detection

Vulnerability matching is only as good as the package list it runs against, so we made that list more complete:

  • Windows per-user installs: Software installed for an individual user is now reported from every profile on the host, with its install scope, so the apps your users install without admin rights are no longer invisible.
  • macOS applications: Each app now reports its bundle ID, signer, App Store receipt, architecture, install scope, and install date. Mondoo matches vulnerabilities on the bundle ID as well as the display name, reports Safari and other apps macOS ships outside the usual folders, and finds applications even when Spotlight or the System Profiler application returns nothing.
  • Browser versions on Windows: Apps kept current by Google's updater, such as Chrome, report their true installed version, and duplicate package rows collapse into one.
  • Available updates: The package resource's available field reports the latest version the package manager offers, and outdated tells you whether the installed version is behind it, now on Debian, Ubuntu, and Red Hat family hosts and on Flatcar. Mondoo asks apt or dnf only when a query reads one of those fields, so scans that do not need the answer do not pay for it. packages.where(outdated == true) lists every package with an update waiting.
  • Last update: The os.base resource's lastUpdate, lastUpdateAge, and lastUpdateSource fields report when a host last installed an operating system update and which record that came from: the dnf transaction log, apt history, the apk log, macOS install history, the Windows Update Agent, or NixOS generations. NixOS and Alpine 3.23 and later joined this month. Together with outdated, they catch the host whose patching has quietly stopped: os.base.lastUpdateAge != null && os.base.lastUpdateAge.days < 30.

Endpoint Security You Can Query

Your laptops and desktops are where your people meet the internet, and the controls that protect them are spread across a half dozen consoles: the endpoint agent in one, the MDM in another, the identity provider in a third. Each one answers only for the devices it knows about, and none of them tells you about the laptop that quietly fell out of all three.

This month Mondoo brought those answers together on the device itself, so one policy can hold every workstation to the same bar, whatever mix of vendors you run.

edr reports whether an endpoint agent is actually protecting the device. It finds endpoint security agents on Windows, macOS, and Linux and reports, for each product, whether it is installed, running, enabled, and healthy, what mode it runs in, and how old its signatures are, down to the component that is not running. Since 14.0 shipped, edr also reports each agent's own identity: the CrowdStrike Falcon sensor ID and the Microsoft Defender for Endpoint machine and organization IDs.

MQL
edr.products.where(healthy == false) { name vendor running signatureAge }

mdm reports whether a device is managed, and by whom. It tells you whether a Mac or PC is enrolled, in which MDM (Intune, Jamf, Kandji, Mosyle, Workspace ONE, and more), how it enrolled, and which server it reports to. For Intune, mdm.intune now adds the Intune device ID and tenant ID.

idp reports whether a device belongs to your identity provider. idp.joined tells you whether the device is joined to a directory at all, and idp.entra reports its Microsoft Entra ID device ID, tenant ID, and whether it is Entra joined or hybrid joined, read from the device's own Entra certificate. A laptop joined to the wrong tenant, or to none, stands out immediately.

Together those IDs mean a Mondoo asset lines up with its record in Intune, Entra ID, Defender, and CrowdStrike, so you can follow one device across every tool that claims to protect it.

windows.uac reads the User Account Control policy behind the security options in Windows: whether UAC is on at all, how administrators and standard users are prompted, whether the prompt appears on the secure desktop, whether installers are detected, and whether remote connections by local administrator accounts are filtered. Those are the settings that decide whether malware running as a user gets a free path to administrator.

macOS security settings enforced by your MDM are read where current releases keep them, so firewall and Sharing checks give a clear answer on managed Macs, even when the settings come from a configuration profile.

See endpoint management in 14.0 for the rest of the story.

FreeBSD and Solaris, on Par with Linux

Most security tooling treats Linux as the whole of Unix. The FreeBSD firewalls and storage appliances, and the Solaris systems still running the workloads nobody wants to migrate, get a version check and little else. These systems tend to be the ones that matter most and change least, which is exactly why they need the same scrutiny as everything else.

14.0 started the work with FreeBSD package repositories, FreeBSD listening ports, and Solaris processes. In the weeks since, we brought both platforms up to the same level as Linux, with the same resources answering across the board. Every custom policy you can write for Linux, you can now write for your whole Unix fleet.

FreeBSD

  • Packages report their install date, license, purl, installed files, and available updates.
  • Services, users, and processes: rc.d service status, system accounts, and each process's state and executable.
  • Network: routes, plus listening ports that keep IPv6 zones and dual-stack listeners.
  • Kernel and host: ASLR, machine ID, hypervisor, cloud detection, SMBIOS, pending reboots, and sysctl values read exactly as the kernel reports them.
  • Configuration where FreeBSD keeps it: MySQL, MariaDB, PostgreSQL, logrotate, and snmpd configuration from FreeBSD's package layouts, crontabs from /var/cron/tabs and /usr/local/etc/cron.d, and inetd read the way the daemon reads it.
  • Storage and audit: ZFS pools and datasets on every OpenZFS release, and OpenBSM audit retention settings.

Solaris

  • Network: listening ports, network interfaces, and routes.
  • Kernel and host: kernel information and loaded modules, SMBIOS, hypervisor, CPU clock, and the root certificates the system trusts.
  • Storage: mounts, and ZFS on Oracle Solaris.
  • Configuration and processes: sshd's effective configuration, ntp.conf, and process state.
  • Packages from every publisher, including publishers whose names contain a dot or a hyphen.

New MQL Resources Since 14.0

Mondoo 14.0 brought 500+ new resources. Within a week, 14.1 and 14.2 added 35+ more resources and 250+ new fields. Beyond the endpoint resources above, the highlights:

Operating systems

  • memory reports physical and virtual memory on Windows, Linux, macOS, FreeBSD, NetBSD, and Solaris.
  • windows.disk reports every physical and virtual disk on a Windows host: bus type, partition style, boot and system roles, and health.
  • kernel.livepatch reports the live patches applied to a running Linux kernel, so a host patched without a reboot is no longer mistaken for one that was never patched.
  • auditd.status reports whether kernel auditing is enabled or locked and whether events are being lost, and auditd.rule.watch normalizes file watches written in either auditd syntax, so one check covers both.
  • systemd.coredump reports how core dumps are handled and stored. A core dump holds whatever the process had in memory, credentials included.
  • apt.config reads APT's effective configuration, exactly as APT resolves it.
  • rsyslog.ruleset and snmpd.config.user make logging pipelines and SNMP access rules checkable.

AI agents in the cloud

  • Amazon Bedrock AgentCore payment managers, connectors, and credential providers, for agents that are allowed to spend money, plus VPC configurations for Bedrock knowledge bases.
  • Azure Container Apps sandbox groups and their VNet connections, where untrusted or generated code runs.
  • DigitalOcean hosted agent configs and triggers, and MicroDroplet checkpoints, which hold whatever the instance had in memory when they were taken.
  • GitHub Copilot cloud agent secrets, the credentials Copilot's agent works with inside your repositories.

Cloud and SaaS

  • Cloudflare One CASB posture policies, with their automated remediations and webhooks.
  • Datadog Security Inbox rules, workflows, and Databricks and Snowflake integrations, including which identity each workflow runs as.
  • Tailscale external and organization tailnets, so every tailnet your nodes are shared with is visible.
  • GCP Bigtable automated backup policies and Cloud Tasks HTTP target overrides.
  • Auth0 self-service organization settings for applications.

UK Cyber Essentials v3.3 Compliance Framework

If you do business in the UK, you have almost certainly been asked for a Cyber Essentials certificate. The scheme is backed by the UK government, owned by the National Cyber Security Centre (NCSC), and delivered by the IASME Consortium, and it is a common requirement for public sector contracts and supply chains.

Mondoo now ships Cyber Essentials v3.3, implementing "Cyber Essentials: Requirements for IT Infrastructure v3.3" from April 2026. The framework organizes its requirements under the scheme's five technical controls: Firewalls, Secure Configuration, Security Update Management, User Access Control, and Malware Protection.

418 control mappings tie those requirements to the Mondoo checks you already run, across operating systems, cloud platforms, SaaS, and network devices. The framework also maps to CIS Controls v8, so the evidence you gather for one serves the other. That matters more in v3.3 than ever: cloud services can no longer be excluded from scope, and Mondoo already assesses your AWS accounts, Azure subscriptions, GCP projects, and SaaS platforms alongside your endpoints.

Cyber Essentials brings the number of compliance frameworks in Mondoo to 19. See compliance frameworks to get started.

Security Policies for the AI Platforms Your Teams Build On

Your developers hold API keys to model providers, and those keys reach your data, your prompts, and your spend. Each provider has its own notion of owners, projects, and keys, and until now none of them sat inside your security program.

Four new AI platform policies change that:

  • Mondoo OpenAI Security (7 checks): limit organization owners, keep pending invitations and project service accounts from holding the owner role, rotate project API keys, retire keys in archived projects, give vector stores an expiration policy, and keep organization audit logs accessible. See scanning OpenAI.
  • Mondoo Anthropic Claude Security (7 checks): limit organization admins, clean up stale and admin-granting invitations, give active API keys an expiration date and a known creator, pin workspaces to a default inference region, and keep activity logs accessible. See scanning Claude.
  • Mondoo Hugging Face Security (4 checks): fine-grained access tokens, Enterprise governance controls for organizations, HTTPS webhook delivery, and a check for models Hugging Face has disabled.
  • Mondoo Together AI Security (3 checks): OIDC identity federation for GPU clusters, and a recorded owner for every stored secret and inference endpoint.

Three more platforms gained their first Mondoo policies at the same time:

  • Mondoo Datadog Security (20 checks): SAML single sign-on and strict mode, the email domain allowlist, and external sharing of dashboard widgets.
  • Mondoo Jamf Pro Security (4 checks): single sign-on that cannot be bypassed, plus FileVault disk encryption and the host firewall on every managed Mac.
  • Mondoo Weaviate Security (2 checks): no anonymous access, and role-based access control enforced.

200+ New Security Checks

Beyond the new policies, the ones you already run got deeper. 215 new checks landed this month:

  • Mondoo AWS Security: 36 new checks
  • AWS Operational Best Practices: 34 new checks, including EC2 instance metadata limited to a single network hop, Redshift clusters encrypted at rest with enhanced VPC routing, RDS clusters spread across Availability Zones, and subnets that do not hand out public IP addresses
  • CIS Oracle Cloud Infrastructure Foundations: 30 new checks, covering notifications for IAM, identity provider, and network changes, customer managed keys on block, boot, and file storage volumes, Cloud Guard in the root compartment, Secure Boot and in-transit encryption on compute instances, and VCN flow logs on every subnet
  • Mondoo OCI Security: 16 new checks
  • Mondoo AWS Inventory: 15 new checks that describe how your EC2 instances, EKS clusters, IAM roles, RDS instances, S3 buckets, and security groups are exposed
  • Mondoo UniFi Security: 8 new checks

AI Remediation for Vulnerabilities You Can Fix with Configuration

Not every vulnerability waits on a patch. Plenty of CVEs can be mitigated today by turning off a feature, tightening a setting, or changing how a service is exposed, and that is often the fastest fix you have while the upgrade works its way through change control.

AI remediation for configuration is now generally available. When a vulnerability can be mitigated through configuration, Mondoo generates the configuration fix for each affected platform, right alongside the package upgrade path. There is nothing to turn on: it works wherever AI features are enabled in your organization.

Operational Considerations are generally available too. Each finding's detail page now carries an AI summary of the operational impact across the highest-risk assets the finding affects, so you can weigh what a fix touches before you schedule it.

Hetzner Cloud, Scanned for You

The Hetzner Cloud integration is now available to everyone. Add a Hetzner Cloud API token and Mondoo scans your project for you, with nothing to deploy and nothing to keep running: servers, images and snapshots, networks, firewalls, floating and primary IPs, load balancers, TLS certificates, volumes, Storage Boxes, SSH keys, and managed DNS zones.

The Mondoo Hetzner Security policy holds your project to 19 checks:

  • Firewalls that leave SSH, RDP, database ports, or every port open to the internet, allow unrestricted outbound traffic, or define no rules at all
  • Servers with no firewall applied, outside a private network, reachable from the internet, or running a deprecated OS image
  • Load balancers that serve HTTP without redirecting to HTTPS, lack a TLS certificate, or sit outside a private network
  • TLS certificates that are expired, self-signed, or weakly signed, and SSH keys that use weak algorithms or key sizes
  • Storage Boxes reachable from the public internet, and floating or primary IPs Hetzner has blocked for abuse

A Hetzner inventory query pack rounds it out. Prefer the command line? See scanning Hetzner Cloud with cnspec.

More Ways to Scan GitHub

The GitHub integration now scans exactly what you point it at, and finds more inside every repository it reaches.

  • An organization, a personal account, or a single repository. Pick the integration type that matches what you want covered: every repository in a GitHub organization, the repositories of a personal account, or one repository by its owner and name.
  • Code, secrets, and dependencies in one integration. Three scan options run in each repository Mondoo discovers: static code analysis finds security issues in your source code, secrets detection catches credentials committed to the repo, and dependency vulnerability scanning checks every declared dependency for known vulnerabilities. All three are on by default for a new integration, alongside the existing options to discover Terraform files and Kubernetes manifests.
  • Less to fill in. The integration name is optional. Leave it empty and Mondoo names the integration after the organization or repository you scan.

SecurityScorecard Findings in Mondoo

SecurityScorecard rates your external attack surface by domain, across network security, DNS health, patching cadence, and application security. That view is valuable, and it is even more valuable next to what Mondoo sees from the inside.

The SecurityScorecard integration is now available to everyone. Add an API token and a domain, and Mondoo imports SecurityScorecard findings and combines them with your own scan results, so you get Mondoo's prioritization and ticketing on top of your external posture data. The first import now starts as soon as you create the integration.

Quality-of-Life Improvements

A number of smaller additions this month that make everyday work smoother:

  • 700+ new vendor icons: Software, findings, and policies now carry their vendor's mark, so you recognize what you are looking at before you read a word. Twelve policies gained their vendor icons too.
  • Tables you can sort and export: Ticket details gained column controls, CSV and XLSX export, and sorting across the whole result set. You can export the credentials table and the initiatives list; sort credentials by when they were last checked, registration tokens by when they expire, findings by status, software by version and installation, policy assets by platform and last update, and tickets by progress or creator; and choose how many rows every paged table shows.
  • Share links: Query packs, query results, and tickets each have a Share action.
  • Clearer findings: A check that has passed since its first scan now shows as Passed, and Fixed is reserved for findings that actually went from failing to passing. Checks that errored get their own Errored chip and filter and no longer count as detected. The Security Findings list shows each finding's icon, title, and description.
  • Inventory at a glance: The asset list shows when each asset was last scanned, hosts Mondoo discovered but no Mondoo client scans are marked Unmanaged, and an asset running a Mondoo client older than v12 carries a warning banner.
  • Ticketing: New ticketing integrations close their tickets automatically once the finding is fixed, and you can turn that off during setup. Webhook ticket deliveries are signed and carry an authentication header, so your endpoint can verify they came from Mondoo.
  • AWS: Organization installs walk you through a StackSet wizard, and you pick the serverless scanner release at setup: keep "Latest (rolling)" for automatic updates, or pin a release to hold the stack steady.
  • Policies: Check pages open with the check's summary and put its infrastructure as code variants in tabs, and policy pages show whether a policy is Scored or Preview.
  • Settings and reporting: The organization usage page has a new design, and the executive report's space picker has Select all.

And There's Even More

Beyond the highlights above, September brought a long list of smaller improvements throughout the product, too many to call out individually. And we're already hard at work on what's next, so look for more new functionality next month.

On this page