{
  "summary": "Firewall and DLP rules scoped to a specific process now also match when that process appears anywhere in the connecting process's ancestry - closing a gap where a rule scoped to an application (e.g. an RDP or Citrix client) wouldn't catch a helper process it spawned that made its own network connection independently. The event log now shows the full process chain when a rule fires this way, so it's clear why. Strengthened inbound email phishing detection: a message that declares a non-standard content encoding on its HTML body - a technique seen hiding phishing links inside base64 content that scanners would otherwise skip - is now both decoded for inspection and flagged as suspicious in its own right. Added detection for GitHub and Slack API tokens to the DLP secret-pattern library, alongside the existing AWS and private-key detectors."
}
