{
  "summary": "Suricata rules gain flowbits/flowint support for multi-stage correlation within a single connection - a low-severity signal can mark a flow without alerting on its own, and a later rule can escalate only once that mark is present. A third rule source joins custom rules and the abuse.ch URLhaus feed: Allod's own vendor-curated ruleset, delivered and refreshed through the same license check-in mechanism. The Firewall page's custom-rules card now adds and edits rules one at a time with a small input, mirroring the firewall rules table's UX, instead of a paste/upload-only textarea; bulk replace-all import remains available but API-only. Fixes a bug where disabling IDS/IPS after enabling it never actually stuck in the UI. The dashboard's blocked-countries map no longer lights up a country for a device blocked there by an unrelated rule that had nothing to do with its location. New: detection and active blocking of supply-chain credential theft - a compromised npm/pip/yarn/etc. package's postinstall script spawning a secret scanner (TruffleHog and similar) to read .env files, SSH keys, or cloud credentials is now caught and killed before it can exfiltrate anything, with an admin-configurable exemption for legitimate build tools that genuinely need one of those paths."
}
