← Platform Changes

Content packs — August 03, 2026

10 files changed, 4989 insertions, 151 deletionsview the commit on the mirror.

Cyberint 1.5.0 adds four Check Point Exposure Management playbooks and two intelligence commands

  • Cyberint 1.5.0 added four Check Point Exposure Management playbooks — IOC enrichment and triage, credential leak validation and response, vulnerability exploitation monitoring, and phishing takedown — all available from Cortex XSOAR 6.10.0.
  • Two new feed commands: cyberint-cve-enrich returns EPSS, CVSS, CWE, the Cyberint CVE score and active-exploitation evidence, and cyberint-credential-leak-lookup finds leaked credentials for a company domain.
  • Check Point EM Premium Feed was renamed Check Point EM ThreatCloud Intelligence Feed; the integration ID and the TIM service value stay Cyberint Premium Feed, so existing instances and indicator filters keep working.
  • Cyberint alerts now extract indicators through two new incident fields — Cyberint Alert URL and CyberInt CVEs — wired into the incoming mapper, incident type and layout.
  • Vega 1.0.1 added a Recommended Actions field, layout section and mapper support; Tenable Vulnerability Management exposed its assets fetch interval in the Exposure Management module.

Highlights

Changes

10 files listed, 3 written up and shaded below.