Detection Engine Updates Version 2.154
Release Date: December 15, 2025
This release introduces new detectors for Cloudflare R2 and Azure SAS URL, significant improvements to multiple detectors, and a major milestone with 152 detectors now running on the Rust scanner for improved performance.
New Detectors and Checkers
- Cloudflare R2 Token: Added a detector and checker for Cloudflare R2 tokens.
- Azure SAS URL: Added a detector and checker for Azure SAS URLs.
- MySQL Credentials: Added a new MySQL assignment detector that doesn't match ports.
New Checkers
- Tailscale SCIM Key: Added a new checker for Tailscale SCIM keys.
Detector Improvements
- SendGrid Key: Updated regex to make it stricter and updated checker endpoint.
- Dwolla Keys: Updated detector to include more values.
- PubNub Publish and Subscription Keys: Updated detector to use an AggregateMatcher instead of explicitly listing multiple matchers.
- Google OAuth2 Keys: Updated detector to use an AggregateMatcher instead of explicitly listing multiple matchers.
- Azure Cosmos DB Keys: Updated detector to use an AggregateMatcher instead of explicitly listing multiple matchers.
- Generic High Entropy Secret: Upgraded detector to remove false positives due to Google Tag Manager.
- HashiCorp Vault Token: Improved detector to not match one-time URLs anymore.
- Discord Webhook URL: Improved detector by widening the webhook_id length restrictions.
- Alchemy API Key: Updated checker endpoint.
- Fireworks AI API Key: Fixed the checker.
Miscellaneous
- Added support for 378 new secret providers for improved incident prioritization on generic secrets.