What's New
New Secure Web Sessions versions are released and announced on a varying cadence. Occasionally, new versions that include only performance, stability and bug fixes, and do not require customer actions, are released without an announcement.
Version 23-9-1
What's new in this release?
Secure Web Sessions is now available from India and Singapore data centers, increasing its overall availability to seven data centers globally. For details, see Region availability.
Released components
Component |
Version |
---|---|
SWS browser extension |
2.1.16103 |
SWS SaaS |
23-9.1 |
CyberArk Mobile app on android |
8.12 |
CyberArk Mobile app on iOS |
8.12 |
Upgrade notes
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
CyberArk Mobile app |
Upgrade the CyberArk Mobile app according to your device and app store settings. |
Behavior changes
Area |
Description |
---|---|
CyberArk Identity SSO URL configuration |
For SWS protected applications from CyberArk Identity SSO, improvements have been made so that the root domain URL is now identified more accurately. |
Cloud console monitoring |
Cloud console applications (Azure, AWS, GCP) are now tracked using both the URL and username. This improves targeting and policy enforcement between parallel cloud console sessions using different accounts. |
Version 23-8.3
Rules can now be created based on steps captured within SWS recorded sessions or any previously audited event. This makes it easier to manage and create Session Control rules for all customers, particularly where the rule-creator might not have access to the particular application themselves. For details, see Create a rule from the session timeline.
SWS visibility and coverage has been significantly enhanced within applications. This update improves recording, audit, and control capabilities at a more granular level than before allowing for more contextual step-recordings and additional page elements for session control.
For details, see What is Step Recording? and What is Session Control?
General performance and security improvements were added.
The API Token Helper is a new tool that aims to simplify the process of generating access tokens for the SWS APIs. The API Token Helper is available in the CyberArk Marketplace.
For details, see Automatically create a token using the API Token Helper.
Component |
Version |
---|---|
SWS browser extension |
2.1.15501 |
SWS SaaS |
23-8.3 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Session recordings |
Fixed and improved keyword and application results. |
Version 23-7.3
Administrators can now block buttons and links within any web application using Session Control rules. This enhances the benefits and coverage Secure Web Sessions is able to provide by enabling you to create restrictions per user/group/role, beyond those built into the web application. For details, see Create Session Control rules .
Component |
Version |
---|---|
SWS browser extension |
2.1.14601 |
SWS SaaS |
23-7.3 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Version 23-7.1
Administrators now have an easier time using the rule creation form for Session Control. The new form improves the ability to create rules based on any triggered action in protected web sessions.
Administrators can now easily delete unnecessary sessions from the session recording page. Each deletion and creation of new sessions is audited in the activities area to maintain a record of actions taken.
Component |
Version |
---|---|
SWS browser extension |
2.1.14301 |
SWS SaaS |
23-7.1 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Version 23-5.5
You can now add security policies to your pre-defined SAML claims.
For details, see Create security policies for SAML claims.
Component |
Version |
---|---|
SWS SaaS |
23-5.5 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Version 23-4.4
Administrators can now define session control rules with an action that automatically flags the triggered event as 'suspicious' when viewed in session recordings. For details, see Create rules.
Administrators can now define a maximum threshold for email notifications to prevent accidental overload of emails. This is measured per rule and per session, ensuring that important notifications arrive, but also that multiple copies of the same notification get aggregated. For details, see Configure Session Control rule notification limit.
Component |
Version |
---|---|
SWS browser extension |
2.1.13801 |
SWS SaaS |
23-4.4 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Version 23-3.4
The product versioning convention for SWS has been updated. The format is now YY-M.<Week#>.
Session Control allows you to define specific actions within your applications and implement restrictions or notifications based on simple if/then rules. For example - restrict entries users can add to specific fields, or trigger email notification every time a specific button is used. Any text field, number field, button, or link, from any any application protected by SWS can be used as the trigger for a rule.
For details, see What is Session Control?
Component |
Version |
---|---|
SWS browser extension |
2.1.13401 |
SWS SaaS |
23-3.4 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Application policies - default policies |
The method for setting a default policy for new members has been moved into the list of overall members. For details, see Set default security layers for new application members |
Application policies |
Configure Security Layers popup has been changed to a split screen experience. This allows more room for working with additional configuration options, like session control rules. |
Area |
Description |
---|---|
SWS browser extension |
Copy to clipboard button was hidden by a tooltip in some cases. |
SWS browser extension |
Enabling verbose logging at the extension wasn't saved |
Session recordings |
Some data fields within protected applications captured extranous data meant to be ignored. |
2023.01.23
CyberArk has received Secure Web Sessions’s official SOC 2 Type II certification. This means that an independent auditing firm has reviewed and examined our control objectives, activities, and tested those controls to ensure that they are operating effectively. In achieving this certification, customers can be assured that data is kept secure through the implementation of standardized controls as defined in the AICPA Trust Service Principles framework.
2023.01.01
Administrators can now full manage their SWS security policies via API's. Today's release includes updatePolicybyID, updatePolicyMemberSecurityLayers, updatePolicyDefaultSecurityLayers, and updatePolicyApplicationConfiguraiton. For details, see API commands.
End user facing pages in SWSverifying security layer, continuous authentication, OS notification, and browser extension screens have been translated into Spanish (Latin America), and Portuguese (Brazil) languages. The language code is determined by user's browser locale.
General performance and security improvements were added.
Component |
Version |
---|---|
SWS browser extension |
2.0.10802 |
SWS SaaS |
2023.01.01 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
SWS portal |
Added support for RTL languages in all fields. |
Application recordings |
New layout for filtering list of recordings. |
Application recordings |
When there are multiple recordings returned as query results, the number of total steps is listed alongside the total number of sessions. |
Area |
Description |
---|---|
CyberArk Identity integration |
Various formatting and text improvements. |
Activities |
Improvements made to Search loader and filter actions. |
Step recording |
Some Recording Started OS notifications were not appearing. |
2022.12.04
Administrators can now apply or exclude SWS security layers by specific URL's within protected applications (wildcard characters are supported).
For details, see Define security layer configurations per application policy.
Component |
Version |
---|---|
SWS browser extension |
2.0.10610 |
SWS SaaS |
2022.12.04 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
APIs |
GetSessionbyID/steps - Fixed an issue where the 'extensionEventId" field for 'File Download' events returned NULL. |
2022.11.21
Administrators can now apply and enforce SWS protections on sensitive applications in Microsoft Edge (chromium) browser. Combined with existing support for Google Chrome browser, Secure Web Sessions is now expanding coverage to additional desktop browsers with this release.
Microsoft Edge (chromium) browser is supported with SWS browser extension version 2.0.10501.
Component |
Version |
---|---|
SWS SaaS |
2022.11.21 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Tenant integration |
Fixed an issue where some fields were not recent when unlinking with Identity SSO. |
SWS menu |
Fixed an issue where in some cases the scroll bar was not present in the SWS navigation menu. |
2022.11.08
Users can now see the security layers protecting the current session via a quick click on the SWS browser extension. For details, see View active security layers for an application session.
Alert messages have been improved to add additional detail and helpful actions. Administrators configuring 3rd-party SSO applications with SWS now have an easier time fixing configuration issues. Additionally, users missing the SWS extension while attempting to access a protected application now have an improved warning message indicating that the SWS extension is required.
Three new API's are now available for use. Get a list of all sessions within a certain time frame (GetSessions), get information on a specific session, such as active security layers or username (GetSessionsByID), and get the specific steps taken within a particular session (GetSessionsById/steps). These have been added in addition to the already released GetRecordings API's in order to align with industry standards. The previous API's will continue to be supported for backwards compatibility, but new improvements will only be made to the GetSessions API's. For details, see API commands.
General performance and security improvements.
Component |
Version |
---|---|
SWS browser extension |
2.0.10501 |
SWS SaaS |
2022.11.08 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Application policies |
Edit and Delete buttons have now been added to the Application policies page for each of the 3rd-party SSO application tiles. |
Application policies |
The applications list now shows the amount of active security layers in the table view. |
Area |
Description |
---|---|
Application settings |
Fixed an issue affecting the display of continuous authentication settings |
Session details |
Fixed an issue where resuming a session from continuous authentication might not have been recorded correctly. |
Session details |
Fixed an issue on session details page where the action-type filter didn't work properly. |
Application setup |
Fixed an issue where the logo of a 3rd-party SSO app couldn't be removed. |
Continuous authentication |
Fixed an issue causing excessive 'Session Locked' notifications in specific scenarios. |
2022.09.18
SWS now provides visibility and auditing for user downloads and clipboard actions taken in any we session secured with Step recording. In addition, SWS session details now include events for any user actions that were blocked by Session protection.
For details on the auditor workflow, see Monitor sessions.
Manifest V3 is a name for the new upcoming browser extension API, essentially a large set of changes that will determine the next generation of the Chrome browser extensions. Beyond changes for new extensions - support for extensions with the current manifest V2 format will no longer run on Chrome as of January 2023. In this release, the Secure Web Sessions browser extension adds support for the new Manifest V3 API, while maintaining all existing functionality. (Previous versions of the SWS extension will continue to work at the previous level of support in order to provide backwards compatibility).
Component |
Version |
---|---|
SWS browser extension |
2.0.10202 |
SWS SaaS |
2022.09.18 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Session recording |
We have updated the view of session details to include information on the security layers assigned to this particular session. |
Area |
Description |
---|---|
SWS portal - User invitation |
Fixed the invite user QR, which in some cases appeared with abnormal artifacts. |
SWS portal - 3rd-party IdP application setup |
Fixed an issue where new applications were deactivated by default. |
SWS portal - 3rd-party IdP application setup |
Fixed an issue where updated application logos were not saving correctly. |
Continuous authentication - User notification |
Fixed an issue where in some cases users received a notification that a session was locked without an overlay. |
2022.08.28
Customers can now apply Secure Web Sessions protections directly on-top of 3rd party identity providers (IdPs) SSO sessions, without requiring CyberArk Identity SSO. This streamlines setup, maintenance, licensing, and provides an easier user experience with less actions.
For details, see Configure SWS policy for third-party IdP apps
Component |
Version |
---|---|
SWS SaaS |
2022.08.28 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
User authentication - Continuous Authentication |
Fixed an issue affecting some SWS users who joined a tenant via link to QR code and weren't redirected after successful login. |
SWS Portal - Tenant lobby |
Fixed the logout button not appearing on tenant selection page. |
SWS Portal - Session Recordings |
Fixed an issue with the TabID# not appearing in some cases. |
SWS Portal - UI |
Added a fix preventing elements from being hidden beyond the screen boundries. |
SWS Portal - Role/Group membership |
Fixed an issue where verification of a user's rights and roles failed in some scenarios due to case sensitivity. |
SWS Continuous Authentication |
Fixed an issue where some vendors from CyberArk Remote Access were blocked from accessing assigned SSO applications where SWS Continuous Authentication was applied. |
2022.08.21
Two new API's are now available that enable SWS customers to GET a list of all recodings within a certain time frame (GET SWS Recordings), and also to GET the specific steps taken in a particular session (GET SWS recordings by ID). These API's allow customers to pull specific session details, and can enable integration with other security tools (such as SIEM).
For details, see API commands.
Component |
Version |
---|---|
SWS SaaS |
2022.08.21 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Session recordings |
Added the ability to remove all flags from all sessions. For details, see Remove all flags from session recordings. |
2022.07.31
Administrators can now enforce an additional layer of protection for sensitive web applications by monitoring footsteps taken by the end user during their sensitive web session. The feature protects against unauthorized access if the authenticated user leaves their computer unattended while the sensitive web session is left open on the endpoint and exposed.
The current release supports Android (in addition to the already supported iOS).
For more details about this solution, see Continuous authentication with the CyberArk Mobile app
For details on how to enforce Continuous Authentication with the pedometer lock, see Configure Continuous Authentication with the CyberArk Mobile app.
Component |
Version |
---|---|
SWS browser extension |
1.71.9602 |
SWS SaaS |
2022.07.31 |
CyberArk Mobile app on iOS |
8.1 |
CyberArk Mobile app on iOS |
8.2 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
CyberArk Mobile app |
Upgrade the CyberArk Mobile app according to your device and app store settings. |
Area |
Description |
---|---|
SWS browser extension |
Improved communication logic between a users mobile device and the SWS SaaS during sessions protected by Continuous Authentication |
2022.06.26
Administrators can now enforce an additional layer of protection for sensitive web applications by monitoring footsteps taken by the end user during their sensitive web session. The feature protects against unauthorized access if the authenticated user leaves their computer unattended while the sensitive web session is left open on the endpoint and exposed.
The current release is available with CyberArk Mobile on iOS only.
For more details about this solution, see Continuous authentication with the CyberArk Mobile app
For details on how to enforce continuous authentication with the pedometer lock, see Configure Continuous Authentication with the CyberArk Mobile app
New users of the CyberArk Mobile app, who are assigned an application that is protected by Continuous Authentication, can now have their trusted mobile device joined to SWS during the first application access QR, requiring no separate onboarding steps or invitations.
SWS now supports EPM integration with EPM tenants that use the new policies management UI.
For details, see Configure Session Protection and EPM integration
Additional actions are now included in the Session Recording details when triggered during protected sessions. The new events are:
-
Session locked by - Pedometer lock
-
Session locked by - Idle Timeout
-
Session resumed by - CyberArk Identity MFA
-
Session resumed by - CyberArk Mobile App
Component |
Version |
---|---|
SWS browser extension |
1.70.9202 |
SWS SaaS |
2022.06.26 |
CyberArk Mobile app on iOS |
8.1 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
CyberArk Mobile app |
Upgrade the CyberArk Mobile app according to your device and app store settings. |
Area |
Description |
---|---|
Continuous authentication with pedometer lock |
Web sessions opened in incognito mode might be unstable. Issues with locking/unlocking web sessions. |
Continuous authentication with pedometer lock |
The continuous authentication lock message might still appear in background, even after session is unlocked by end user. |
Area |
Description |
---|---|
Settings > Session Protection |
Session Protection with EPM integration settings now include two different download policy files; one for VFP (existing) and the other for EPMP (used with the new EPM policies management UI). For details, see Configure Session Protection and EPM integration |
SWS APIs |
Swagger page now opens to the latest API version. |
SWS tenant link |
SWS now fully supports linking with *.id.cyberark.cloud tenants from CyberArk Identity Security Platform. |
Area |
Description |
---|---|
SWS APIs |
Fixed getPolicyByID API 404 and incorrect layer display names. |
Step recording |
Improvements made to recording actions made in some in-app calendar widgets. |
Session recordings |
Fix made to full screen view navigation when handling 'no screenshot' events. |
Activities |
Fix made for Activity Types select field on Activities page not properly showing longer activity names. |
Continuous authentication |
Fix made for scenario where Reauthenticate button became non-responsive after window timed-out. |
2022.05.22
CyberArk Identity Secure Web Sessions can now enter into Business Associate Agreements (BAA) with US based healthcare customers requiring adherence to the Health Insurance Portability and Accountability Act (HIPAA). This confirms that CyberArk meets or exceeds all regulations and US legal requirements regarding the use, disclosure, and safeguarding of individually identifiable health information – that may be recorded, captured or otherwise saved in the Secure Web Sessions service. For more information, see https://www.cyberark.com/trust/hipaa-compliance/
Secure Web Sessions now exposes REST API's, which enables management and visibility of SWS users, application policies, and activities. This allows for integration with external systems for reporting of policies and management console activities. Additional API's are on the way soon. For more information, see Automate with APIs.
Added recommendation to add CyberArk Identity custom application domains to step recording exclude list. For more information, see Configure step recording settings
Component |
Version |
---|---|
SWS browser extension |
1.60.7201 |
SWS SaaS |
2022.05.22 |
CyberArk Mobile app on android |
7.1 |
CyberArk Mobile app on iOS |
7.1 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
CyberArk Mobile app |
Upgrade the CyberArk Mobile app according to your device and app store settings. |
Area |
Description |
---|---|
Step recordings |
Improvements were made to better define when and how the search field is used. |
SWS extension |
Fixed an issue with applying different protection layers between multiple open tabs. |
2022.04.17
Administrators and Auditors now have the ability to flag events or sessions that are of interest to them, and afterward filter their view based on these flags. This allows customers to refer back to interesting or reviewed suspicious events at a later date without needing to search again.
For more information, see Flag session recordings and steps.
Our team is constantly reviewing and taking feedback to improve Secure Web Sessions. This release includes the following minor improvements:
-
Ability to sort recorded sessions by number of steps
-
Timeframe and filters remain visible while scrolling through activities
-
When viewing session details, the username now appears before the start-time in the header
Component |
Version |
---|---|
SWS SaaS |
2022.04.17 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
Recording details |
Fixed an issue where the tabID no longer appeared after the user had scrolled past it. |
Recording details |
Fixed an issue where sometimes the recording details page crashed when filtered by tabID. |
Recordings list |
Fixed an issue affecting the visibility of certain recording list icons. |
Recordings list |
Fixed an issue affecting search abilities when viewing the session list in 'tabular' view. |
Application configuration |
Fixed an issue where selection of the Session Protection security layer sometimes resulted in unnecessary tooltips showing. |
Application configuration |
Fixed an issue where users not assigned with 'Automatically Deploy' permission for an app would not show up in the members list for assignment of a SWS security layer. |
Continuous authentication |
Fixed an issue where a Access Denied message showed when a new tab of the same application was opened. |
2022.04.03
Each week we aim to release new improvements and bug fixes during our set maintenance window (3:30 EST - 6:00 EST (8:30 UTC - 11:00 UTC). When new features are announced, they will be included here.
This weeks release includes bug fixes and minor improvements.
Component |
Version |
---|---|
SWS browser extension |
1.59.7001 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
Continuous authentication |
Better handling of orchestration of multiple application launches. |
2022.03.27
Administrators can now configure and enforce additional protections on their user's web-applications. This release provides the ability to enforce protection against unauthorized application access, allowing organizations to re-authenticate users under special circumstances when using high-risk applications. Continuous Authentication offers protections via integration with CyberArk Identity multi-factor authentication (MFA) or via CyberArk Mobile QR code.
For more information about Continuous Authentication, see What is Continuous Authentication?
For information about configuring Continuous Authentication, see Configure Continuous Authentication with MFA.
Component |
Version |
---|---|
SWS browser extension |
1.57.6702 |
SWS SaaS |
2022.03.27 |
CyberArk Mobile app on android |
7.0.1 |
CyberArk Mobile app on iOS |
7.0 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
CyberArk Mobile app |
Upgrade the CyberArk Mobile app according to your device and app store settings. |
2022.02.06
We have improved the auditor experience for viewing specific session recordings. Higher resolution screenshots, mouse and keyboard directional commands for moving between steps, and better navigation to find and go-to specific steps, all help improve the experience and effectiveness for the SWS Auditor.
Component |
Version |
---|---|
SWS browser extension |
1.51.6101 |
SWS SaaS |
2022.02.06 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
Area |
Description |
---|---|
SWS browser extension |
The SWS browser extension now only captures higher resolution screenshots. This behavior change is effective from the latest version of the browser extension and will only affect new recordings. |
Area |
Description |
---|---|
Step Recordings |
Fixed an issue where in some cases a 'key press' event was shown in the step recording without explicitly mentioning which Tab/Enter key was used. |
Step Recordings |
Fixed an issue where in some cases scrolling up and down in the Step Recordings screen caused unwanted refreshes and wrong count. |
Step Recordings |
Fixed an issue where in some cases, with large recordings, the user would be returned to step 1 before reaching the end. |
Session Recordings |
Fixed an issue where new Session Recordings weren't showing in the Session Recordings page until a new time frame was selected. |
General settings |
Fixed an issue where an error message wouldn't always be displayed in case a logo file was uploaded with an unsupported image file type. |
Application configuration |
Fixed an issue with the SWS-EPM enforcement in an application not accurately reflecting the configuration from tenant settings. |
2022.01.09
Each week we aim to release new improvements and bug fixes during our set maintenance window (3:30 EST - 6:00 EST (8:30 UTC - 11:00 UTC). When new features are announced, they will be included here.
This weeks release includes bug fixes and minor improvements.
Component |
Version |
---|---|
SWS browser extension |
1.49.5901 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
Supportability |
Fixed an issue where 'Enable Verbose Logging' would not keep its configured state. |
Session Protection |
Fixed an issue where 'drag and drop' restrictions were not enforced correctly despite user notification. |
Step Recording |
Fixed an issue where a screenshot was taken while the active tab had changed/closed. |
2022.01.02
SWS administrators can view a history of activities that have been performed in the Secure Web Sessions management portal. For more information, see Monitor activities.
Browser restrictions were optimized with the addition of preventing access to the right-click context menu, as well as multiple improvements.
Component |
Version |
---|---|
SWS SaaS |
2022.01.02 |
SWS browser extension |
1.47.5601 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
Session protection |
The Session Protection browser restrictions were unified into one check box controlling browser level protections together. For more information, see Define security layer configurations per application policy |
Browser extension |
Implemented visual feedback for Clear log operation with 5 second fade out. |
Area |
Description |
---|---|
Step Recording |
Fixed an issue for value changes on searchable drop-down fields. |
Step Recording |
Fixed an issue for step recording screenshot flow to improve issues related to events without screenshots. |
2021.12.23
Each week we aim to release new improvements and bug fixes during our set maintenance window (3:30 EST - 6:00 EST (8:30 UTC - 11:00 UTC). When new features are announced, they will be included here.
This weeks release includes bug fixes and minor improvements.
Component |
Version |
---|---|
SWS browser extension |
1.43.5201 |
Component |
Details |
---|---|
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
Step Recording |
Fixed an issue affecting radio button selection and other user functionality in certain applications. |
Step Recording |
Improved recording details. |
Session Protection |
Fixed issue where Session Protection with 'block downloads' prevented download of SWS extension logs |
2021.12.12
Administrators can now configure and enforce additional protections on their users web-applications. This release provides the ability to enforce restrictions on clipboard / drag&drop as well as restrictions on performing downloads from protected applications. As with SWS Step Recording layer - these protections are only implemented on the protected application tabs for the user leaving clipboard / drag&drop or downloads still fully functional for users in other non-protected applications. Lastly, the user will see an OS notification whenever a user action is prevented by SWS protections letting them know that the block was intended by their Administrator. For more information, see Session protection with SWS browser extension
Integration with CyberArk EPM via SWS Session Protection is now available for client level protections. Customers can now integrate SWS and CyberArk's Endpoint Privilege Manager (EPM). With this integration we are providing a set of chrome browser protection policies which can be imported into EPM and enabled on your client devices. These protection policies also include the ability for the SWS extension and EPM agent to communicate and thereby validate EPM protection during the SWS Security Layer Validation stage of a user login to a protected web-application from CyberArk Identity SSO. For more information, see Session protection with CyberArk EPM integration.
This release of the SWS extension provides the ability to export logs via the SWS extension for better supportability and troubleshooting of both SWS extension browser level actions as well as SWS-EPM integration actions. For more information, see Deploy the browser extension.
Component |
Version |
||
---|---|---|---|
SWS SaaS |
2021.12.12 |
||
SWS browser extension |
1.40.4901 |
||
CyberArk Mobile app on android |
6.5
|
||
CyberArk Mobile app on iOS |
6.5
|
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
2021.11.14
Improvements were made to the performance of search suggestions and filter functionality in the SWS portal.
Component |
Version |
||
---|---|---|---|
SWS SaaS |
2021.11.14 |
||
SWS browser extension |
1.32.4101 |
||
CyberArk Mobile app on android |
6.3
|
||
CyberArk Mobile app on iOS |
6.3 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
CyberArk Mobile app on iOS |
Fixed a issue that caused the app to crash for iOS version 12 and below. |
2021.11.07
Each week we aim to release new improvements and bug fixes during our set maintenance window (3:30 EST - 6:00 EST (8:30 UTC - 11:00 UTC). When new features are announced, they will be included here.
This weeks release includes bug fixes and minor improvements.
Component |
Version |
---|---|
SWS SaaS |
2021.11.07 |
SWS browser extension |
1.30.3901 |
Component |
Details |
---|---|
SWS SaaS |
Customers do not have to take any steps to apply the Secure Web Sessions SaaS upgrade as it is applied by CyberArk during the maintenance window. |
SWS browser extension |
Customers may receive the latest update to the Secure Web Sessions Chrome extension automatically if their browser is configured for this, or can update to the latest version from the Secure Web Sessions Extension page in the Chrome Extension Store. |
Area |
Description |
---|---|
Step recording |
Fixed an issue preventing the OS notification from alerting the user on the start/stop of SWS step recording. (User notification via the SWS loader page and extension icon change were unaffected and function correctly.) |
Step recording |
Fixed an issue where when some of the recordings were viewed, the page title would show in place of the user URL. |
Step recording |
Fixed an issue affecting the display of the domains excluded from step recording. |
2021.10.31
CyberArk IdentitySecure Web Sessions, the newest addition to our Software-as-a-Service (SaaS) portfolio, helps security and compliance teams unmask and address threats quickly by adding extra layers of security to web application sessions.
CyberArk IdentitySecure Web Sessions is a SaaS service that records, monitors and protects end-user activity within designated web applications. The solution uses a browser extension on an end-user’s endpoint to monitor and segregate web apps that are accessed through CyberArk Identity Single Sign-On (SSO) and deemed sensitive by business application owners, enterprise IT and security administrators. Security and compliance professionals can use Secure Web Sessions to efficiently identify anomalous activity, investigate issues and support audits.
Secure Web Sessions can record and monitor screenshots of all actions taken by specific end users within protected web applications. The solution uses a browser extension, installed on the user's endpoint, to monitor and segregate web apps that are accessed through CyberArk Identity Single Sign-On (SSO).
Secure Web Sessions captures only SWS enabled applications, and ignores other tabs opened in the users browser window. End users are notified when a session begins recording, and when it ends. Secure Web Sessions captures all end user actions using a “stepper” approach. Specific actions, like mouse-clicks and “enter” or “tab” keystrokes, trigger a screenshot of the end users’ browser along with relevant metadata.
Screenshots are captured and encrypted at the endpoint by the Secure Web Sessions extension and are then only accessible by authorized Secure Web Sessions administrators and auditors with a customer-controlled encryption key. Encrypted recordings are streamed up to CyberArk SaaS for search and retrieval access by auditor or administrator.
-
Secure Web Sessions is an add-on to CyberArk Identity Single Sign-On. For more information about activation and integration of SWS with your CyberArk Identity SSO tenant, see Activate Secure Web Sessions.
-
Secure Web Sessions Administrators and Auditors will need to install the CyberArk Mobile app. For more information, see Download the CyberArk Mobile app.
-
Users will also need tthe CyberArk Secure Web Sessions browser extension installed in their browsers. For more information, see Deploy the browser extension.
Component |
Version |
---|---|
SWS SaaS |
2021.10.31 |
SWS browser extension |
1.26.3501 |
CyberArk Mobile app on android |
6.2 |
CyberArk Mobile app on iOS |
6.2 |
Area |
Description |
---|---|
Step recording |
Keyboard shortcut user action doesn't trigger a recorded step. For more information on limitations for the Step Recording feature, see Step recording limitations. |
Step recording |
Drag-and-drop isn't recorded as a user action. For more information on limitations for the Step Recording feature, see Step recording limitations. |