Release notes-Cydarm 26.10.0
Updates and release notes for Cydarm version 26.10.0
Cydarm version v26.10.0 is now generally available!
Packed with quality-of-life updates and customer requests, this release introduces a Google Gemini AI connector, enhanced case automations, tighter workflow controls, and reporting refinements.
Enhancements and bug fixes 26.10.0
27 August 2026
New features
Google Gemini AI integration
You can now Ezyconnect Cydarm directly to Google Gemini, using your own API key, to bring generative AI capabilities into your incident response workflows.
Event-driven case automations
Configure automated actions to run directly in response to key case events, streamlining background workflows and response steps. Some examples include:
- Automatically transition a case status (e.g., moving to Analysis or Containment) when specific case events, severity changes, or playbook milestones occur.
- Automatically update case status to Closed when the final remediation playbook step completes successfully.
- Apply a tag when severity changes to a specific value.
- Map and apply multiple tags to a case simultaneously using a single rule powered by a mapping table (such as mapping MITRE ATT&CK to VERIS framework). Config validation rules are also built-in to prevent circular mapping loops and ensure smooth execution.
Enhancements
Dashboards & metrics
-
Introduced a new case transition data type to help teams follow the full lifecycle of a case with metric options including Mean, Median, Total, and Standard Deviation.
-
Case titles in the "Recent Cases" dashboard widget are now direct, clickable hyperlinks.
-
Long-running cases now display durations in human-readable units (such as weeks and days), with exact timestamps.
-
Case re-open rates can now be tracked.
Case management & workflows
-
Enforced conditional closure rules that mandate analysts provide a comment or summary at a specific significance level before cases meeting designated criteria can be closed.
-
Enforced stricter status transition rules with new prerequisite conditions, including "Is set" (must be set) and "Greater Than or Equals" - ensuring key case metadata is populated before moving to the next incident stage.
-
Administrators can now author case automation rules without settings pages failing when encountering unrecognized connector or operation types.
Reporting & evidence
-
All files and attachments added to a case now have an exact SHA-256 checksum calculated and included in generated case reports, giving external recipients cryptographic proof that evidence has not been tampered with since collection.
-
File size reporting for newly uploaded items is now exact.
Playbooks
-
Playbook-triggered actions and case event triggers can now dynamically reference the case assignee's details (such as event.case.assignee.email) in communication templates and filter conditions.
-
When editing a CACAO playbook, the platform now clearly highlights the specific step that failed validation.
Platform & UI usability
-
Settings pages now feature consistent, unified filtering and sorting controls across all configuration tables.
Security
-
Improved authentication checks so that deactivated user accounts are rejected upfront across all sign-in paths before SAML processing begins, optimizing authentication handling and ensuring deactivated users cannot proceed. Reactivating an account restores access seamlessly as before.
Bug fixes
-
Resolved an issue where successful Teams chat notifications were incorrectly flagged with error messages on the case timeline. The platform now properly recognizes provider acknowledgment responses (including HTTP 202 Accepted).
-
Fixed an issue where the case Summary report displayed "No data" for grouped tags (e.g., Detection Source or Category).
-
Fixed generic errors when exporting draft playbooks, as well as an issue where editing a draft could export a previously published version instead. Exports now reflect the exact version currently being viewed.
-
Resolved an error that occurred when publishing a saved draft playbook without making additional edits.
Did you know?
Playbook automation can wire directly into connectors, allowing external platforms to trigger webhooks into Cydarm and enabling Cydarm playbooks to automatically trigger actions back in your other security tools for seamless, bi-directional response!