Release Notes 7.2
Release 7.2.5
Enhancements
DNS Catch-All for Cyolo Connect
Cyolo Connect can now resolve DNS hostnames that are not covered by a specific domain configuration. By setting a site as a DNS catch-all (entering * in the DNS Domains field), unmatched hostnames fall back to that site instead of failing to resolve. This reduces the need to list every internal DNS domain individually. Specific domain matches always take priority over the catch-all.
Connector visibility and alerts
Connectors now display the correct name, hostname, and host address set during installation. Admins also receive notifications and system log entries when a Connector goes offline or comes back online, and an alert is raised when its certificate is about to expire.
Accurate IDAC offline/online system log entries
System log entries for IDAC offline and online events now show the correct Site, IDAC ID, and IDAC Hostname for the IDAC that actually changed state, not the one that reported the event.
API schema validation
API request validation has been strengthened to catch type mismatches and invalid attribute values at submission time. Requests with incorrect values return a clear error immediately, reducing the chance of misconfiguration reaching the system.
Maintenance Release
Stability improvements and bug fixes.
Release 7.2.4
Enhancements
Native RDP File Download
The .rdp file for Native RDP sessions is now generated and served by the server as a standard HTTP file download, instead of being constructed client-side. This ensures compatibility with browser Group Policy Object (GPO) configurations, such as those enforced in Microsoft Edge, that require a real file download to permit the action.
Cyolo Connect Mobile Application
Cyolo Connect version 1.3.2 is available on the Google Play Store and Apple App Store, with compatibility fixes for IDAC v7.2.
Maintenance Release
Stability improvements and bug fixes.
Release 7.2.3
New Features
File Download in RDP Web Sessions
Users can now download files from a remote desktop directly to their local machine during a web RDP session. Files placed in the shared drive on the remote desktop are listed in the session toolbar and can be downloaded with a single click.
Malware Scan Verdict for File Transfers
Users now see the malware scan verdict for every transferred file — via web RDP/SSH, SMB, or Secure File Transfer — directly in the transfer interface. The verdict (OK, Threat Detected, Not scanned) is shown alongside the file's allowed or blocked status with no extra clicks required.
Login Reminder Notifications
The Cyolo agent now displays a login-reminder notification when you are signed out or need to re-authenticate. A single notification is shown per state change, clears automatically on sign-in or network disconnect, and respects a quiet interval to prevent repeated alerts. Restarting the tray application re-evaluates whether a reminder should be shown.
Enhancements
Improved OT Asset Type Detection via NetFlow
Asset type detection now recognizes a broader range of OT device types including PLCs, RTUs, OPC servers, and workstations. Traffic classification is protocol-aware and preserves detection evidence for improved accuracy.
Maintenance Release
Stability improvements and bug fixes.
Release 7.2.2
Maintenance Release
Stability improvements and bug fixes addressing custom access request form management for operational admins, dynamic group membership visibility in the Admin Portal, personal desktop template variable resolution in RDP applications, and scheduled access request notification delivery to approvers.
Release 7.2.1
Highlights and New Features
Attack Surface Management (ASM)
Cyolo 7.2 introduces Attack Surface Manager (ASM), which helps customers detect traffic arriving from untrusted networks into the OT environment. ASM enables preventive actions such as blocking addresses and/or protocols, defining trusted networks, or remediating exposure by routing access through Cyolo to achieve full visibility and control. Assets with external communications outside defined trusted networks are automatically detected and surfaced as exposed assets that require attention. ASM also displays assets that are already protected, giving admins full context before applying new policies.
Cyolo Malware Detection
Cyolo Malware Detection is a Cyolo-managed service that wraps deep file scanning engines, accessible via Cyolo Global or Private Gateways. It enables file scanning for users transferring files during RDP, SSH, Secure File Transfer, and SMB sessions. Offered as a monthly file-based subscription, allowing customers to purchase a set number of files per month.
Session Intelligence
Session Intelligence is offered as a monthly hour-based subscription, allowing customers to purchase a set number of hours per month. It transcribes and summarizes user activity during RDP sessions, accelerating incident response by enabling plant managers, OT engineers, cybersecurity analysts, and auditors to quickly understand what occurred during remote access sessions without replaying lengthy recordings.
Simultaneous Multi-Tenant Operation with Built-in NAT
Cyolo Connect users can now securely connect to multiple tenants at the same time. Built-in NAT resolves connectivity challenges caused by overlapping IP address spaces across sites, ensuring traffic is routed correctly and in tenant isolation. A key machine-to-machine use case is a central platform that collects data from devices sharing identical IP addresses across multiple tenants and sites.
Asset Discovery and Vulnerability Management Integration
Cyolo enriches asset data by integrating with external discovery and vulnerability management systems, including Forescout, Nozomi Networks Guardian, and Armis. Admins can configure asset connectors with a polling interval, enabling automated and accurate asset inventory without manual input.
Cyolo Insights (Beta)
Cyolo Insights is an AI-powered querying tool that allows Super Admins to ask questions and extract insights directly from the platform — including security posture, asset counts, and MFA status — without navigating menus or generating reports manually. This feature is currently available in beta.
Enhancements
Security Key as a Second Factor
Users can authenticate using a hardware security key as a second factor (FIDO2 compliant), providing a phishing-resistant and highly secure authentication option — particularly suited for manufacturing floors where other second factors may not be accessible.
Multiple IdP Assignment per User with Group Synchronization
Users can now be assigned to multiple Identity Providers, with group membership synchronized from each IdP. Access to assets is evaluated based on group membership across all assigned providers, regardless of which IdP was used to authenticate. This is particularly useful in organizations where all users authenticate via a central IdP, while each plant or site maintains a dedicated IdP (e.g., Active Directory) to manage access to local assets.
Platform Branding Customization
Customers and managed service providers can now customize the Admin Portal and Applications Portal look and feel by configuring brand colors and company name. The customization applies across all system pages, messages, and email templates.
Custom Admin Roles
Customers can define custom administrative roles with granular resource-level permissions, enabling organizations to delegate specific management responsibilities while maintaining control over platform access and security. Default system roles can be cloned and customized, and users or groups can be assigned to multiple roles with effective permissions being the union of all assigned roles.
Flexible Traffic Steering and Network Awareness
Cyolo Connect supports a Network Awareness policy that controls agent behavior based on network conditions. Admins can configure an optional network probe to detect whether the user is on a specific network, and define independent behavior for probe success and failure — including connectivity mode (unrestricted or restricted) and traffic steering (whether network application traffic and web traffic are routed through Cyolo).
A new Secure Web Gateway (SWG) policy replaces the identity and condition settings previously configured on the Forward Proxy. The SWG policy determines how web traffic is inspected and routed — either through an external SWG (forward proxy) or the Cyolo built-in SWG.
Asset Risk Level in Condition Policy
A new toggle in the condition policy allows customers to control access based on asset risk level. Risk level can be manually configured per asset or automatically populated from external asset management and threat detection systems, enabling risk-aware access decisions without manual policy updates.
Asset Groups and Segmentation
Assets can now be organized into static or dynamic groups. Dynamic groups use attribute-based filters to automatically include matching assets, simplifying segmentation policy management at scale.
Asset Dashboard — Groups and Vendors
The Admin Console dashboard includes two new asset widgets: Group Types, which shows a breakdown of static vs. dynamic asset groups as a bar chart, and Vendors, which displays assets by MAC address vendor as a donut chart. A new Assets overview card shows the total asset count.
Session Stickiness per Web Application
Admins can enable session stickiness per web application to ensure all requests within an active session are consistently routed to the same IDAC, preventing session expiry errors caused by mid-session rerouting.
Custom RDP File Properties
Admins can now define custom RDP file properties per native RDP application. Non-conflicting properties are appended to the generated .rdp file, while Cyolo-managed properties always take precedence.
Session Recording Statistics Dashboard
The Admin Console dashboard now includes a session recording statistics widget showing total recording hours, session count, and storage used per year for the past three years.
Asset Table Export
The asset table can now be exported to CSV, with options to export all assets or only the current filtered view.
Connections Tab in Asset Details
A new Connections tab in the asset details view shows inbound and outbound network connections per asset, including source/destination IPs, protocols, ports, and last seen time.
IDAC Upgrade Confirmation
Admins are now prompted for confirmation before triggering an IDAC upgrade, preventing accidental upgrades.
Updated Email Templates
All Cyolo system email templates have been updated to reflect the current Admin Console UI and branding.
Configurable Maximum Duration for Scheduled Access Requests
Admins can now configure a maximum allowed duration for scheduled access requests. Users and approvers cannot submit or modify requests that exceed the configured limit.
UI Improvements and Performance (API v2)
This release includes several usability improvements across the Admin Portal: tables now support quick filtering and improved pagination; a new right-side drawer provides contextual details without navigating away from the current view; and the session recording dashboard has been redesigned for clearer visibility into recording activity and storage. In the Applications Portal, the default view is now organized by categories; users can switch to a different view and their preference is saved in the browser. A redesigned Admin Portal API (v2) significantly improves performance and scalability, enabling reliable operation in large-scale user deployments with high-volume operations.
Copy Installation Token
The button on planned IDAC, Connector, and Fabric Controller cards is renamed from "Copy installation command link" to "Copy installation token". Clicking it now copies only the token value (CYOLO_TOKEN=
Updated 1 day ago