{
  "summary": "Added Google Drive support to the existing OneDrive/SharePoint sync-provenance and lineage-tagging feature: a file synced by Google Drive for Desktop's Shared Drives is now attributed back to its Shared Drive name the same way OneDrive files are attributed to a SharePoint site, including the ability to tag a specific Shared Drive with a standing DLP sensitivity rule. Strengthened inbound email phishing detection with three additions to the authenticity scoring engine: a fix so newly-registered-domain detection correctly evaluates the sender's actual registered domain rather than a subdomain of it; a new signal for links that serve a full HTML page directly from public cloud storage (Google Cloud Storage, S3, Azure Blob, and similar), a known technique for evading domain-reputation checks; and a new signal for messages whose plain-text part is trivial boilerplate while the real content only exists in the HTML part. Added a warning when a block-action DLP rule is scoped by a field that only resolves asynchronously after a transfer completes, since such a rule can silently never block. Added JA3 as an independently selectable scope condition on firewall and DLP rules, alongside JA4/Mercury/HASSH, and fixed the admin UI so the existing source-IP/CIDR scope condition is actually visible and editable on both the firewall and DLP rule pages."
}
