Elements Security Center
Elements Portal – new Dashboard and Devices
We have now made the new Dashboard (Advisory Service) and the Devices page the default views, with the older pages still being available for those who wish to use them.
The Dashboard will list following:
· Devices that have a reboot pending
· Devices that have malware protection disabled, malfunction or expired
· Devices that have dangerous exclusions in profiles / local settings
· Devices that have outdated malware definitions
· Devices that have outdated scan results for software updates
· Devices that are missing critical or important software updates
· Devices that have firewall disabled (profile or GPO)
· Devices that have low disk space (less than 5GB)
· Devices that have severe or high EDR incidents
· Elements Connectors that have certificates which are expiring soon
· Device view allows customized set of columns to be shown
· Device view allows custom views to be saved
· Device view allows more flexible filtering capabilities
The toggle to switch between old and new views will remain on the dashboard still a while longer as we migrate final features and iron out any potential issues discovered.
Please note that there might be differences in the data shown in new and old views. New views utilize different services, different data sets and different logic to show information. Old views utilized data that was pre-calculated and updated periodically whereas the new views the data is more real time and better reflect the current status and more accurate information.
New items:
- Dashboard will now also show an issue item for Windows clients which are no longer supported
- "Change subscription" operation is now available also on new device view
New Dashboard view:
New Devices view:
Elements Security Center – Removing pending invitations
If an email invitation to install a client has been sent by mistake, it can be removed from "Manage device invitations" view. After the removal, invitation emails are still in the invitees' mailboxes, but activation links are invalidated.
Elements Endpoint Protection
WMI Provider enabled by default
We made one configuration change which partners and customers need to be aware of. The WMI Provider is now enabled by default. For details please see the online manual.
Elements Agents 22.5
A new version of the endpoint clients is now available. This release makes the Elements Agent version 22.5 available (internal version 4.36.3020).
The endpoints automatically upgrade, without a reboot.
Features:
- Added new automated task to lock workstation and trigger on workstation lock
- Added more events:Report and show in portal if RDP is enabled on device
- Report account lock threshold to portal
- Report changed exclusions to portal
- Report ODS events and excluded URLs to Application Windows Event log
- Report IPv4 and IPv6 addresses separately
- Added remote action to temporarily turn off protection features from portal
- SafeSearch for Bing on Edge uses now built in system functionality
- WithSecure Firewall has a new feature to allow certain rules and groups of rules when "disable all rules" option is selected. It's useful if you want, for instance, to disable all rules except Network Discovery
- WithSecure Firewall now allows to use user environment variables in application names.
- More disk encryption information is sent to portal
GUI changes:
- Software Updater shows flyer with notification about found new updates
- Running scheduled scan is possible to cancel now in event history
- Tray icon shows now red and yellow statuses in case of problems
Elements Endpoint Detection and Response
Feature update – opening incident in new tab
WithSecure Elements EDR feature update has introduced following improvements:
- Broad Context Detection list view supports opening of incidents in a new tab. This option is available by right-clicking while hovering above the Broad Context Detection ID field in the table.
Elements Collaboration Protection
New features and improvements:
- Improvements to the user interface and product functionality
- The filtering of items in the Cloud service Details was improved
- Links in the Support tab were updated and localized
- Improvements to the readability of system events
Elements Collaboration Protection privacy policy update
The Elements Collaboration Protection privacy policy document has been updated to reflect the product evolvement. It covers the statement on how personal data processing is with the introduction of new functionality.
Please take a look and share with end customers where needed.
Go to Corporate business privacy policy and choose WithSecure™ Elements Collaboration Protection on the left hand side menu.
Other items of interest
WithSecure™ Threat Highlights Report - August 2022
Access the monthly Threat Highlights Report PDF – following this link.
- August 2022
- Top malware strains 2021
- Mailchimp and Twilio incidents highlight the supply chain issue
- State-backed actors target Confluence vulnerability
- Microsoft disrupt Callisto Group
- Ransomware: Trends and notable reports
- ENISA’s ransomware threat landscapeA history lesson on Ransomware
- A look at Initial Access Brokers
- Newcomers: SolidBit
- Other notable highlights in brief
- Research highlights: WithSecure™ ransomware threat update
System- Status – status.withsecure.com
As a WithSecure™ partner you should be subscribed to our System Status. Due to recent domain change, you likely have to re-subscribe to all incidents or to selected of your interest.
Subscribe options are: email, phone, Slack, Atom/RSS or by contacting our support about an incident.
On our Service status and DB updates webpage you can also track the latest versions of our database updates.
In case you missed it
Domain changes for accessing WithSecure™ Elements
As F-Secure Business is now WithSecure™, we will shortly be moving the Elements portal and related services so they work under the withsecure.com domain. Once this change is made, the portal will be accessible using the URL https://elements.withsecure.com.
To aid partners and customers during this transition, we will be redirecting access made via https://elements.f-secure.com automatically to the new domain. However, we do advise any partners or customers to ensure that they whitelist this new URL to ensure continued access.
In addition to the main portal access, the authentication URL used for sign-in will also change to one using a withsecure.com address.
Please note: Once the new domains are taken into use, users who are logged in to the portal will need to re-authenticate. This is a one-time action, but is unfortunately unavoidable due to the change. To ease this transition, we will schedule the change so that it occurs during off-peak hours.
API access URLs are not affected by this change, and existing client installations continue to work without any changes being needed to Access Control Lists.
Share your ideas with us
Our purpose is to co-secure the world with you – now as WithSecure™. To co-create the best possible cyber security products and services, we warmly recommend you share your ideas via our Ideas Portal, now accessible directly from WithSecure™ Elements Security Center.
Further information
Changelogs and Release Notes for all parts of WithSecure™ Elements can be found at the Help Center