Skip to main content
Each entry lists changes to the Kyberis API, MCP server, authentication, and documentation that became available in production on the date shown (UTC). Entries cover only behavior you can observe as a developer.
Action required at the top of an entry marks a change that may require you to update a client, integration, or automation. Filter entries by tag, or subscribe to this page with RSS at /changelog/rss.xml.
APINew
ATT&CK detection traversal on relationships

New

  • Traverse ATT&CK detection knowledge. /v2/relationships now links techniques to tactics, detection strategies, analytics, data components, and data sources. Use relationship_types for the related entity type, predicates for the link meaning, and direction, platform, and include_inactive to narrow results. See Traverse ATT&CK detection knowledge.
  • Existing relationship requests are unchanged. General actor, campaign, malware, IOC, sector, and country pivots keep their default behavior; ATT&CK traversal applies only when you request an ATT&CK predicate or target type. ATT&CK cursors follow their own rules. See ATT&CK relationship responses.
APINew
Enterprise IoC feed

New

  • IoC feed for enterprise accounts. GET /v2/ioc-feed keeps a local indicator dataset in sync: retrieve a paginated snapshot, then poll daily for additions, updates, and removals with the saved next_cursor. Kyberis must enable feed access for your account. See IoC feed.
  • Confidence intervals. Set min_confidence and max_confidence on the first request to limit the feed to an interval of source confidence. See Select a confidence interval.
  • Upsert-based credits. Each page costs 10 credits per 1,000 upserts, rounded up; removals and empty responses are free. Cursors expire with retained feed history after seven days, so poll regularly. See Access and credits.
APINewImprovedBreaking
Structured CVE inventory and exploitation-based confidence
Action required
  • Check applicability before patching from /v2/prioritize. CVE items now use recommended_action_type: validate_exposure with conditional remediation advice, or monitor for a conditional product exclusion. Automation that triggers a patch from recommended_action_type must perform the applicability check first. See CVE inventory applicability.
  • Review CVE confidence thresholds. CVE assessment confidence now represents support for known exploitation, not confidence that your environment is vulnerable, and can be lower than before. If you filter or alert on confidence, read it together with metadata.evidence_support and metadata.conditional_on. See CVE environment applicability.

New

  • Structured inventory for environment assessments. Send environment_context.products to /v2/environment-assessments, and set inventory_complete: true only when the list covers the entire environment. Read metadata.applicability for product-level affected, unaffected, or unknown status. See CVE environment applicability.
  • Product applicability on prioritized CVEs. CVE items from /v2/prioritize include product_match and applicability without debug mode. See CVE inventory applicability.

Improved

  • Consistent product matching. Equivalent inventory and source product names now produce the same product applicability on /v2/prioritize and /v2/environment-assessments. Free-text environment is retained but not interpreted; the response reports metadata.environment_text_evaluated: false. See CVE environment applicability.
APIImproved
Enrichment-aware IoC scoring

Improved

  • IoC scores reflect enrichment context. When Kyberis has indicator intelligence for an IOC, /v2/ioc-assessments adds a bounded enrichment boost, capped at 8 confidence points, for MITRE breadth, malware context, attribution, targeting, and source diversity. IOCs with richer context can now rank above sparser IOCs with similar base confidence. See Enrichment-aware scoring.
  • Inspect the enrichment contribution. Read the total in metadata.ioc_enrichment_boost. With options.include_debug: true and the debug:assessments scope, debug.signal_data.enrichment_boost_breakdown returns the five component values. See Enrichment scoring.
APIMCPAuthenticationNewImprovedBreaking
Direct API-key auth for MCP and stable relationship pages
Action required
  • Pass relationship cursors back unchanged. /v2/relationships pagination now uses opaque snapshot cursors that expire after 10 minutes. Pass next_cursor back unchanged with the same request inputs, and do not build, parse, or modify cursors. See General relationship pagination.

New

  • Direct API-key authentication for MCP. One-command MCP setup now installs Authorization: ApiKey <key_id>:<secret> in your MCP client, so tool calls use your API key directly. To switch a client you set up earlier, reconnect it from API keys. See How MCP access works.

Improved

  • Stable, larger relationship pages. Paged traversal returns the same ordered results regardless of page size within a snapshot of up to 500 ranked results. max_results accepts 1–100. See General relationship pagination.