Skip to main content
Skip table of contents

AgileSec 3.5.1 Release Notes

APRIL 2026

This release introduces automated data migration and improves deployment flexibility, compatibility, scalability, and operational reliability.

Who Should Upgrade and Why

  • Users upgrading to AgileSec v3.5 while continuing to use pre-3.5 sensors and who want automatic data migration.

  • Users installing a multi-data center stretch cluster.

  • Users exporting CBOM from AgileSec.

New Features and Enhancements

Automated Data Migration Tool for the v3.5 Data Model. A new built-in migration tool automates the transition of cryptographic finding data to the new data model, supporting both one-time bootstraps and continuous scheduled runs to maintain backwards compatibility during phased rollouts.

  • Flexible retention options – Choose to retain original pre-v3.5 documents after migration to preserve backwards compatibility with existing Search API integrations, or delete them post-migration to reduce storage overhead. Behavior is controlled via the MIGRATION_KEEP_SOURCE flag in config_envs/scheduler.

  • Live migration for older sensors – Pre-3.5 sensors (v3 and v2) can continue sending data in the legacy format without interruption. The migration tool automatically detects and converts incoming data to the v3.5 format on a configurable schedule (default: every hour), eliminating the need for a hard cutover.

  • Large volume data migration – For migrating large volumes of historical data, it is recommended to bootstrap the migration using isg_tools before enabling automatic migration. Refer to the Data Migration Guide for details.

CrowdStrike Scripts Included in Unified Sensor. CrowdStrike scripts are now bundled directly with the Unified Sensor, eliminating the need for a separate download. The Unified Sensor can be downloaded from the AgileSec UI.

Bug Fixes

CBOM Export Now Fully Compatible with CycloneDX v1.6. Resolved issues with CBOM export causing incompatibilities with the CycloneDX v1.6 standard. Exported CBOMs now conform to the CycloneDX v1.6 specification.

On-Premise Installer Bug Fixes

  • Fixed an issue where mongosh would silently fail when the home directory lacked sufficient disk space. mongosh now uses <install dir>/temp, and if mongosh fails, the installer halts with a clear error message.

  • Fixed an issue where tune.sh would fail on systems with Git pre-installed. The installer now handles the presence of Git gracefully.

  • Fixed missing explicit coordinator role assignment for 7-node multi-data center stretch cluster installations.

  • Fixed OpenSearch cluster healthcheck and HA parameters to correctly support multiple failover options for stretch clusters.

  • Fixed CBOM Exporter storage handling to prevent export failures due to insufficient storage. CBOM Exporter now cleans up in-progress export on failures.

Fixed: protocol_insecure_kex Policy False Positives on Secure Key Exchange Algorithms. Resolved an issue where PQC hybrid algorithms (X25519MLKEM768) and secure DH groups (group14 and higher) were being incorrectly flagged as insecure. Matching is now scoped to DH/modp context and bounded to groups 1, 2, and 5 only.

Vulnerabilities Status

Component

Critical

High > 60 days

Medium > 90 days

Platform

isg-agilesec-analytics-manager

0

0

0

Both

isg-agilesec-api

0

0

0

Both

isg-agilesec-web

0

3

0

Both

isg-agilesec-fluentd

0

0

0

Both

isg-agilesec-ingestion

0

0

0

Both

isg-agilesec-sandbox

0

0

0

Both

isg-agilesec-scheduler

0

0

0

Both

isg-agilesec-sm-service

0

0

0

Both

isg-indexing-service

0

0

1

Both

isg-opensearch

0

1

0

Both

isg-opensearch-dashboards

0

0

0

Both

Unified Sensor

0

0

0

Both

mongodb-server

0

1

39

Both

mongodb-agent-ubi

0

67*

64

Kubernetes

mongodb-kubernetes-operator

0

0

11

Kubernetes

mongodb-kubernetes-operator-version-upgrade-post-start-hook

0

0

11

Kubernetes

mongodb-kubernetes-readinessprobe

0

0

11

Kubernetes

cp-server

0

0

8

Kubernetes

cp-zookeeper

0

0

1

Kubernetes

confluent-operator

0

1

2

Kubernetes

confluent-init-container*

1

1

26

Kubernetes

isg-ingress-nginx-controller

0

0

6

Kubernetes

isg-kafka-exporter

0

2

4

Kubernetes

isg-node-exporter

0

6

3

Kubernetes

isg-elasticsearch-exporter

0

3

0

Kubernetes

isg-mongodb-exporter

0

3

0

Kubernetes

Kafka

0

5

2

OnPrem

  • mongodb-agent-ubi – No remediations currently available from the vendor.

Release packages can be downloaded from: InfoSec Global Inc.

Access credentials are required for all download links.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.