release notes
What's new in BlackBerry Optics (June 2025)
|
Feature |
Description |
|---|---|
|
Behavioral Detection Engine |
The Behavioral Detection Engine is the new data collection and analysis engine that both powers and significantly enhances the capabilities of the BlackBerry Optics agent on your organization’s devices. Previously, the BlackBerry Optics agent used detection rule sets to detect and respond to potential threats on devices. The Behavioral Detection Engine evolves the BlackBerry Optics threat detection and response mechanisms to make them easier to configure, more intuitive to use, and more expansive in their capabilities. For more information, see Configuring the Aurora Focus Behavioral Detection Engine and Additional resources for BDE. |
|
New BlackBerry OpticsWindows agent |
The BlackBerry Optics Agent for Windows version 3.4.x is now available in the management console.
BlackBerry Optics Agent 3.4 requires Agent 3.3.1001 or later. After a successful upgrade to version 3.4, administrators cannot downgrade the agent using the updater. |
What's new in BlackBerry Optics (December 2024)
|
Feature |
Description |
|---|---|
|
New Windows agent |
The BlackBerry Optics agent for Windows version 3.3.3120 is now available in the management console. For more information about the fixes in this release, see Aurora Focus fixed issues. |
What's new in BlackBerry Optics (September 2024)
|
Feature |
Description |
|---|---|
|
New agents for macOS and Linux |
The following versions of the BlackBerry Optics agent are now available in the management console:
|
|
Support for macOS 15 (Sequoia) |
This release of the agent for macOS adds support for macOS 15 (Sequoia). |
What's new in BlackBerry Optics (August 2024)
|
Feature |
Description |
|---|---|
|
New Windows agents |
The following versions of the BlackBerry Optics agent for Windows are now available in the management console:
注: These releases of the BlackBerry Optics agent address a security vulnerability that is present in the .msi file for previous agent versions. For more information, see KB 139918. If you update the BlackBerry Optics agent to a version listed above using the standard update process available in the Cylance console, note that the .msi file with the security vulnerability will still be present on BlackBerry Optics devices. To update the agent and address the vulnerability, you must do one of the following:
|
What's new in BlackBerry Optics (June 2024)
|
Feature |
Description |
|---|---|
|
New agents for macOS and Linux |
For more information about supported operating systems, see the Cylance Endpoint Security compatibility matrix. |
|
Changes to OS support |
This release adds support for the following operating systems:
|
|
Data collection enhancements for Linux |
This release of the BlackBerry Optics agent adds support for Network Connect events and DNS Request and Response events for Linux operating systems. For more information, see Data structures that Aurora Focus uses to identify threats in the UES Setup content. |
|
Protection features for the BlackBerry Optics agent for macOS |
The following security features that previously were applicable only to the agent are now extended to the BlackBerry Optics agent 3.3 and later for macOS:
These features require the agent version 3.1 or later. |
|
New Windows agents |
The following versions of the BlackBerry Optics agent for Windows are now available in the management console. These versions include the latest stability enhancements:
|
|
Recommendation to disable the optional Cryptojacking Detection sensor |
recommends disabling the optional Cryptojacking Detection sensor, as we are currently investigating stability issues that this sensor can cause with the device OS. |
What's new in BlackBerry Optics (January 2024)
|
Feature |
Description |
|---|---|
|
BlackBerry Optics agent versions |
This release includes the new BlackBerry Optics agent for Windows version 3.3.2311.0. For more information about supported operating systems, see the Cylance Endpoint Security compatibility matrix. |
|
Enhancements to the logic and methods that BlackBerry Optics uses to identify security threats |
BlackBerry Optics 3.3 features significant enhancements to the underlying logic and methods that the BlackBerry Optics cloud services and the BlackBerry Optics agent use to identify security threats. These changes include:
|
|
New sensors |
This release of the BlackBerry Optics agent adds three new optional sensors for Windows devices:
These sensors require the agent version 3.2 or later. For more information, see Aurora Focus optional sensors in the UES Setup content. |
|
Data enrichment for Windows events |
Previously, the BlackBerry Optics agent collected the Provider Name, Class, and Event ID facets for Windows Event artifacts. This release adds significant data collection enhancements for Windows Events, with the agent collecting the data defined in the EventData facet of the artifact (for example, this can include ObjectServer, PrivilegeList, Process ID, Process Name, Service, or other facets). For more information, see Data structures that Aurora Focus uses to identify threats in the UES Setup content. |
What's new in BlackBerry Optics (August 2023)
|
Feature |
Description |
|---|---|
|
Enhancements to advanced query |
This release introduces the following enhancements to the advanced query feature in the management console:
For more information, see Create an advanced query in the UES Administration content. |
Considerations when upgrading from Optics 2.5.x to 3.x
- For configuration requirements for macOS Big Sur (11.x) or later, see the setup instructions in the Cylance Endpoint Security Setup Guide.
- If you do not set up a complete MDM profile for the Optics network extension on devices with macOS Big Sur (11.x) or later, data collection might not occur as expected. Verify that you satisfy the configuration requirements for MDM managed devices in the Cylance Endpoint Security Setup Guide.
- recommends installing the latest available version of the Protect agent. For more information, see the Aurora Focus requirements.
- On macOS devices, after you upgrade the Optics agent you need to restart the device.
- If you upgrade the Optics agent on a CentOS/RHEL 8.0 or 8.1 device, you must restart the device after the upgrade is complete. (EDR-6750)
- Upgrading the Optics agent on Linux from version 2.x to a newer version fails if Security-Enhanced Linux (SELinux) is enabled on the device. (EDR-6264)
Workaround: Disable SELinux on the device before you upgrade the Optics agent and enable it again after the upgrade is complete.
- When upgrading the Optics agent on Windows, to avoid an issue with the Optics shutdown time taking longer than usual, disable the TDT sensor in the device policy and enable it again after the upgrade is complete. This issue does not occur if you upgrade from Optics agent version 2.5.3010 or from Optics agent 3.0 to a later version. (EDR-6058)