{
  "summary": "Firewall and DLP rules can now match on ashfp1, an in-house HTTP request fingerprint that normalizes header order to resist a simple evasion technique - available to every fleet with no license restriction. New: JA3S server-TLS-fingerprint matching against your MISP threat-intel feed - fleets whose MISP instance publishes JA3S indicators can now have connections to known-malicious servers flagged automatically, the same way JA3, JA4, and JARM indicators already are. Inbound email authenticity scoring now also recognizes invisible Unicode characters (zero-width spaces, bidi control characters, and similar) hidden inside a word in the subject or body - a technique phishing campaigns use to defeat keyword and brand-name matching while the message still looks completely normal to the recipient."
}
