<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:apigee-api-security-release-notes</id>
  <title>Apigee Advanced API Security - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/apigee-api-security-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-03-17T00:00:00-07:00</updated>

  <entry>
    <title>March 17, 2026</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#March_17_2026</id>
    <updated>2026-03-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#March_17_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On March 17, 2026 we released an updated version of Advanced API Security
abuse detection</p>
<h3>Feature</h3>
<p><strong>VPC-SC support in abuse detection</strong></p>
<p>This release includes full support in Advanced API Security abuse detection
for VPC-SC customers. This includes support for VPC-SC with the Advanced Anomaly
Detection ML model used for abuse detection, as well as detection exclusion
lists.</p>
<p>For usage information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection">Abuse detection</a> in the
documentation.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 10, 2026</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#March_10_2026</id>
    <updated>2026-03-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#March_10_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On March 10, 2026 we released an updated version of Advanced API Security Abuse Detection</p>
<h3>Feature</h3>
<p><strong>General availability of monitoring conditions in risk assessment v2</strong></p>
<p>Starting with this release, the risk assessment v2 monitoring conditions feature is generally available. </p>
<p>For information on monitoring conditions features and usage see <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#monitoring-conditions">monitoring conditions and alerts</a>. For usage information and a list of all features in Risk Assessment v2, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2 customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 03, 2026</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#February_03_2026</id>
    <updated>2026-02-03T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#February_03_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On February 3, 2026 we released an updated version of Advanced API Security
security actions</p>
<h3>Feature</h3>
<p><strong>Support for configuring two condition types within a single security action</strong>
Announcing the availability of support for two condition types
in a single security action. For example, you can include both IP addresses and
ASN numbers in the same security action.</p>
<p>This feature is available in Apigee and Apigee hybrid 1.16.0 and later.</p>
<p><strong>Note:</strong> This feature is available when configuring the security action
via the API, not the UI, at this time.</p>
<p>For usage information, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-actions-api#configure-multiple-condition-types">Configure multiple condition types</a> in the documentation.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 12, 2026</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#January_12_2026</id>
    <updated>2026-01-12T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#January_12_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On January 12, 2026 we released an updated version of Advanced API Security Abuse Detection</p>
<h3>Feature</h3>
<p><strong>Introduction of Terraform support for managing Advanced API Security abuse detection exclusion lists</strong></p>
<p>You can now use Terraform to manage Advanced API Security abuse detection
exclusion lists. The feedback feature allows you to specify CIDR ranges and IP
addresses to exclude from future incident reports, and is used to exclude
traffic known to be safe, such as requests related to automated testing.</p>
<p><strong>Note:</strong> Exclusion lists are not available for VPC-SC customers at this time.</p>
<p>For usage information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#exclude-traffic-from-abuse-detection">Exclude traffic from abuse detection</a>
and <a href="https://docs.cloud.google.com/apigee/docs/api-platform/get-started/terraform-overview">Use Terraform in Apigee</a>
in the Apigee documentation and the
<a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_security_feedback">
        Terraform abuse detection feedback (exclusion lists) instructions</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 17, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#December_17_2025</id>
    <updated>2025-12-17T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#December_17_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On December 17, 2025 we released an updated version of Advanced API Security
Risk Assessment</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two
business days and may take four or more business days to complete across all
Google Cloud zones. Your instances may not have the feature available until the
rollout is complete.</p>
<h3>Feature</h3>
<p><strong>General availability of Risk Assessment v2 and support for assessments using additional policies</strong></p>
<p>Announcing the
<a href="https://cloud.google.com/products#product-launch-stages">general availability</a>
of Risk Assessment v2 and support for assessments using the VerifyIAM policy and
these three AI policies: SanitizeUserPrompt, SanitizeModelResponse, and
SemanticCacheLookup.</p>
<p><strong>Note:</strong> The Risk Assessment v2 monitoring conditions feature remains in preview.</p>
<p>For usage information, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores">Risk Assessment overview and UI</a> in the documentation.</p>
<h3>Feature</h3>
<p><strong>New risk assessment type field when creating or updating a risk assessment version 2 custom security profile</strong></p>
<p>The API for creating and updating a version 2 risk assessment custom security
profile now includes a <code>risk_assessment_type</code> field to specify
whether the custom security profile applies to an Apigee/Apigee hybrid instance
or to API hub multi-gateway.</p>
<p>This field is optional and defaults to <code>APIGEE</code>; this is not a
breaking change for existing risk assessment users.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apigee/rest/v1/organizations.securityProfilesV2">REST Resource: organizations.securityProfilesV2</a> for information on the new functionality.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 02, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#October_02_2025</id>
    <updated>2025-10-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#October_02_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On October 2, 2025 we released an updated version of Advanced API Security Abuse Detection</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Introduction of exclusion lists for Abuse Detection and incidents</strong></p>
<p>You can now specify CIDR ranges and IP addresses to exclude from future incident reports. Use this feature to exclude traffic known to be safe, such as requests related to automated testing.</p>
<p>The new functionality includes the ability to create and manage multiple "exclusion lists" which define traffic to exclude and the reasons it is excluded.</p>
<p><strong>Note:</strong> Exclusion lists are not available for VPC-SC customers at this time.</p>
<p>For usage information, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#exclude-traffic-from-abuse-detection">Exclude traffic from abuse detection</a> in the documentation.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 19, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#September_19_2025</id>
    <updated>2025-09-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#September_19_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On September 19, 2025 we released an updated version of Advanced API Security</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>New security actions status icons and "expired" note in the security actions UI</strong></p>
<p>This release adds security status icons to the Apigee UI to make it easier to see, at a glance, whether a security action is enabled, disabled, or paused, and an "expired" note when an action is expired.</p>
<p>The status icons display next to the action's status in the security actions list and in the security action details page.</p>
<p>For information on security actions and security action statuses, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-actions">Security Actions customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 18, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#September_18_2025</id>
    <updated>2025-09-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#September_18_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On September 18, 2025 we released an updated version of Advanced API Security</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Improvements to the Abuse Detection incident model</strong></p>
<p>This release includes improvements to the incident model, including lower noise and higher accuracy for abuse detection incidents.</p>
<p><strong>Note: This feature is not currently available to customers with VPC-SC enabled.</strong></p>
<p>For information on abuse detection incidents, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incidents">Abuse Detection customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 25, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#August_25_2025</id>
    <updated>2025-08-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#August_25_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On August 25, 2025 we released an updated version of Advanced API Security</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Additional details and explanations for incidents and traffic identified as anomalous in Abuse Detection Advanced Anomaly Detection</strong></p>
<p>Starting with this release, additional details are available for anomalies detected in incidents and detected traffic, including details on why traffic was flagged as anomalous, the days and times it triggered, time series charts showing anomalous traffic spikes, and direct links to the Google Cloud Logging for events.</p>
<p>See the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#details-view">Abuse detection "Details view"</a> for more information.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 11, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#August_11_2025</id>
    <updated>2025-08-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#August_11_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On August 11, 2025 we released an updated version of Advanced API Security Abuse Detection</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>Improved performance when viewing IP address-specific details for abuse detection incidents</strong></p>
<p>With this release, the IP address detail information for abuse incidents displays more quickly for IP addresses with high traffic volumes, potentially reducing load times from minutes to seconds.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection incident detail documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 06, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#August_06_2025</id>
    <updated>2025-08-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#August_06_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On August 6, 2025 we released an updated version of Advanced API Security</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Availability of Shadow API Discovery for APIs in any Google Cloud project</strong></p>
<p>Using Shadow API Discovery, you can find undocumented/shadow APIs in your existing cloud infrastructure. Shadow APIs pose a security risk to your system, since they might be unsecured, unmonitored, and unmaintained.</p>
<p>With this release, you can configure and run API observation jobs in any Google Cloud project, without needing to provision Apigee in that project. You can also centrally view the results of API observation jobs and compare discovered API endpoints and operations to APIs cataloged in API hub to identify shadow APIs.</p>
<p>See the <a href="https://docs.cloud.google.com/apigee/docs/api-observation/shadow-api-discovery">Shadow API Discovery overview</a> for information on Shadow API Discovery and how to add it to projects.</p>
<aside class="note"><strong>Note:</strong><span> Data residency is not currently supported for Shadow API Discovery. See <a href="https://docs.cloud.google.com/apigee/docs/api-platform/get-started/drz-concepts#data-residency-compatibility">data residency compatibility</a>.</span></aside>
]]>
    </content>
  </entry>

  <entry>
    <title>August 04, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#August_04_2025</id>
    <updated>2025-08-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#August_04_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On August 4, 2025 we announced new functionality in Advanced API Security Abuse Detection.</p>
<h3>Feature</h3>
<p><strong>Terraform support for configuring Advanced API Security</strong></p>
<p>We have expanded our Terraform support for Advanced API Security, enabling you to automate the management of your security posture. You can now use Terraform to manage add-on enablement for <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_addons_config">Subscription</a> and <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_environment_addons_config">PAYG</a> environments, create <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_security_profile_v2">Risk Assessment security profiles</a> and <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_security_monitoring_condition">monitoring conditions</a>, <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_environment#client_ip_resolution_config-1">configure IP address resolution</a>, and <a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/apigee_security_action">create security actions</a>.</p>
<p>For information, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/enable-security#configure-advanced-api-security-using-terraform">Configure Advanced API Security using Terraform</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 14, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#July_14_2025</id>
    <updated>2025-07-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#July_14_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On July 14, 2025 we released an updated version of Advanced API Security </p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Support for editing and deleting security actions</strong></p>
<p>With this release you can edit and delete existing security actions using either the UI or the Apigee Management APIs.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-actions">security actions documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 01, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#July_01_2025</id>
    <updated>2025-07-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#July_01_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On July 1, 2025 we released a new version of Advanced API Security Abuse Detection.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>Support for AppGroups in Abuse Detection attributes</strong></p>
<p>Abuse Detection incidents and detected traffic now show information on AppGroups and AppGroup apps when the AppGroup is part of the request or traffic.</p>
<p><strong>Note:</strong> This functionality is not available in Apigee hybrid at this time.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 16, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#June_16_2025</id>
    <updated>2025-06-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#June_16_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On June 16, 2025 we released a new version of Advanced API Security Abuse Detection.</p>
<h3>Feature</h3>
<p><strong>API address drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents in the detected traffic tab.</strong></p>
<p>This new functionality shows details related to specific API addresses when viewing detected abuse in detected traffic.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection customer documentation</a> for incident details.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 04, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#June_04_2025</id>
    <updated>2025-06-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#June_04_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On June 4, 2025 we released an update to the Anomaly Detection model in Advanced API Security Abuse Detection.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>New model for Abuse Detection's Advanced Anomaly Detection rule</strong></p>
<p>With this release, we introduced a new and improved machine learning model for anomaly detection in Advanced API Security. This new model includes the following improvements:</p>
<ul>
<li><strong>Trained on customer-specific traffic patterns.</strong> The new model is trained exclusively on your organization's historical API traffic data. It continues to learn from your API traffic patterns over time to increase accuracy.</li>
<li><strong>Engineered by Google for anomaly detection.</strong> The new model is a custom Vertex AI-based machine learning model, engineered and also used internally by Google specifically to detect anomalies in traffic patterns.</li>
</ul>
<p>Usage requirements:</p>
<ul>
<li>In order to use this new model, you must explicitly opt in to allow the model to use your traffic and other data to train for anomaly detection. Note that your data is never shared with other customers for training purposes.</li>
<li>The new model is not available for VPC-SC customers at this time.</li>
</ul>
<p>The new anomaly detection model replaces the old model, with no customer-facing changes to the API or UI. Upon opting in for model training, you can expect to start seeing detected anomalies within 6 hours. If you have already opted in to allow the older version of our anomaly detection model to use your traffic data for training, you will not need to opt in again.</p>
<p>For more information on this model and on Abuse Detection, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection">Abuse Detection customer documentation</a>, including <a href="https://docs.cloud.google.com/apigee/docs/api-security/detection-rules">Detection rules</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 27, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#May_27_2025</id>
    <updated>2025-05-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#May_27_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On May 27, 2025 we released an updated version of Apigee Advanced API Security.</p>
<h3>Feature</h3>
<p>With this release, Advanced API Security expands its runtime region support to include <code>africa-south1</code> (Johannesburg).</p>
<p>For a list of supported regions, see <a href="https://docs.cloud.google.com/apigee/docs/locations">Apigee locations</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 20, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#May_20_2025</id>
    <updated>2025-05-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#May_20_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On May 20, 2025 we released a new version of Advanced API Security Abuse Detection.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>Advanced API Security Abuse Detection incident reports now include the ability to view raw data</strong></p>
<p>With this new functionality, you can view raw data underlying an incident report, including client IP address, API proxy, developer app, and other attributes.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 25, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#March_25_2025</id>
    <updated>2025-03-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#March_25_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On March 25, 2025 we released an updated version of Advanced API Security.</p>
<h3>Announcement</h3>
<p><strong>Risk Assessment v2 is now the default Risk Assessment version</strong></p>
<p>Starting with this release, Risk Assessment v2 is the default Risk Assessment version in the UI. You will see the see v2 functionality and interfaces unless you choose to switch back to v1 by clicking <strong>Switch to v1</strong> in the upper right of the UI.</p>
<p><strong>Note:</strong> Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Change</h3>
<p><strong>New Advanced API Security support when using data residency (DRZ) with Apigee hybrid</strong> </p>
<p>Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/latest/using-data-residency-with-apigee-hybrid">Using data residency with Apigee hybrid</a>.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/api-platform/get-started/drz-concepts#data-residency-and-apigee-hybrid">Introduction to data residency</a> for information on DRZ and Advanced API Security support across organization types.</p>
<h3>Feature</h3>
<p><strong>New features added to public preview of Risk Assessment v2</strong></p>
<p>This release introduces new features to the Risk Assessment v2 preview:</p>
<ul>
<li><strong>Security monitoring conditions.</strong> Security monitoring conditions allow you to map resources (proxies or environments) to security profiles. Cloud Monitoring can then use this mapping to alert or create dedicated dashboards so that you can track security scores over time.</li>
<li><strong>Alerts on security monitoring conditions.</strong> Once you've created a monitoring condition, you can set up alerts using Alerting in Cloud Monitoring so that you're notified when the security scores change.</li>
</ul>
<p>For information on monitoring conditions features and usage see <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#monitoring-conditions">monitoring conditions and alerts</a>. For usage information and a list of all features in Risk Assessment v2, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2 customer documentation</a>.</p>
<p><strong>Note:</strong> Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 07, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#March_07_2025</id>
    <updated>2025-03-07T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#March_07_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On March 7, 2025 we released an updated version of Apigee Advanced API Security.</p>
<h3>Feature</h3>
<p><strong>Availability of data obfuscation support with Advanced API Security</strong></p>
<p>With this release, data obfuscation can be used with Advanced API Security. </p>
<p>For usage information, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/analytics/obfuscate-user-data-for-analytics">Obfuscate user data for Apigee API Analytics</a> and <a href="https://docs.cloud.google.com/apigee/docs/api-security#data-obfuscation-with-advanced-api-security">Data obfuscation with Advanced API Security</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 13, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#January_13_2025</id>
    <updated>2025-01-13T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#January_13_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On January 13, 2025 we released an updated version of Apigee's Shadow API Discovery.</p>
<h3>Feature</h3>
<p><strong>Shadow API Discovery latency improvements</strong></p>
<p>This release improves Shadow API Discovery and removes the latency impact on load balancers previously documented as part of Shadow API Discovery enablement.</p>
<p>For more information on Shadow API Discovery, see the <a href="https://docs.cloud.google.com/apigee/docs/api-observation/shadow-api-discovery">Shadow API Discovery customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 07, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#January_07_2025</id>
    <updated>2025-01-07T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#January_07_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On January 7, 2024 we released a new version of Advanced API Security Abuse Detection.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances have begun and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>API key drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents.</strong></p>
<p>This new functionality allows viewing details of detected abuse by the API key used to access the API.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection customer documentation for incident details</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 06, 2025</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#January_06_2025</id>
    <updated>2025-01-06T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#January_06_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On January 6, 2025 we released an updated version of Advanced API Security.</p>
<h3>Feature</h3>
<p><strong>UI support for environment-level client IP address resolution</strong></p>
<p>This release introduces the ability to view the client IP address resolution setting for an environment in the Apigee Console.</p>
<p>For more information and usage instructions, see the <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/client-ip-resolution">Client IP resolution customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 20, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#December_20_2024</id>
    <updated>2024-12-20T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#December_20_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On December 20, 2024 we released an updated version of Apigee.</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>Support for environment-level client IP address resolution</strong></p>
<p>This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the <code>ax_resolved_client_ip</code> Analytics variable and the new <code>client.resolved.ip</code> flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.</p>
<p>This functionality is not available in Apigee hybrid at this time.</p>
<p>For more information and usage instructions, see the <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/client-ip-resolution">Client IP resolution customer documentation</a>, <a href="https://docs.cloud.google.com/apigee/docs/api-platform/analytics/analytics-reference#dimensions">Analytics dimensions</a>, and <a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/variables-reference#client">client flow variable</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>November 14, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#November_14_2024</id>
    <updated>2024-11-14T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#November_14_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On November 14, 2024 we released a new version of Advanced API Security</p>
<h3>Feature</h3>
<p><strong>IP address drill down details are now available in the preview release of Advanced API Security Abuse Detection Incidents.</strong></p>
<p>This new functionality allows viewing details of detected abuse by source IP.</p>
<p>For usage information, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/abuse-detection#incident-details">Abuse Detection customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 08, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#October_08_2024</id>
    <updated>2024-10-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#October_08_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On October 8, 2024 we released an updated version of Advanced API Security.</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<h3>Feature</h3>
<p><strong>New features added to the Risk Assessment v2 preview</strong></p>
<p>This release introduces new features to the Risk Assessment v2 <a href="https://cloud.google.com/products/#product-launch-stages">preview</a>:</p>
<ul>
<li><strong>Support for custom security profiles.</strong> You can create your own security profiles, with unique combinations of risk assessment checks and weights, to use for proxy risk assessment.</li>
<li><strong>New assessment checks.</strong> We've added additional checks you can use when assessing proxy risk.</li>
<li><strong>Assess proxies across multiple profiles.</strong> You can now switch between security profiles to see differences in scoring across profiles.</li>
</ul>
<p>For usage information and a list of all features in Risk Assessment v2, see the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2 customer documentation</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 04, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#October_04_2024</id>
    <updated>2024-10-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#October_04_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><strong>On October 4, 2024 we released an updated version of Advanced API Security.</strong></p>
<h3>Change</h3>
<p><strong>Fixed:</strong> Delay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only</p>
<p>In Risk Assessment v2, which is in <a href="https://cloud.google.com/products/#product-launch-stages">preview</a>, this issue has been resolved: </p>
<p>With VPC-SC-enabled organizations only, when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could have take as much as three hours.</p>
<p>See the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2 customer documentation</a> for information on the functionality.</p>
<h3>Change</h3>
<p>Risk Assessment v2 is now available in the <code>me-central2</code> region. See <a href="https://docs.cloud.google.com/apigee/docs/locations#available-apigee-api-analytics-regions">Available Apigee API Analytics Regions</a> for region information.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 11, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#September_11_2024</id>
    <updated>2024-09-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#September_11_2024"/>
    <content type="html"><![CDATA[<h3>Issue</h3>
<p><strong>Delay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only</strong></p>
<p>This issue impacts Risk Assessment v2 only, which is in <a href="https://cloud.google.com/products/#product-launch-stages">preview</a>.</p>
<p><em>With VPC-SC-enabled organizations only,</em> when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could take as much as three hours.</p>
<p>See the <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2 customer documentation</a> for information on the functionality.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 10, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#September_10_2024</id>
    <updated>2024-09-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#September_10_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On September 10, 2024 we released an updated version of Advanced API Security.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</span></aside>
<h3>Feature</h3>
<p><strong>Proxy-specific security actions</strong></p>
<p>You can now create security actions that apply only to one or more specified proxies.</p>
<p>This new functionality is not available with Apigee hybrid at this time.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-actions">Security actions</a> to learn more about proxy-specific security actions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 13, 2024</title>
    <id>tag:google.com,2016:apigee-api-security-release-notes#August_13_2024</id>
    <updated>2024-08-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/api-security/release-notes#August_13_2024"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>On August 13, 2024 we released an updated version of Advanced API Security.</p>
<p><strong>Note:</strong> Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.</p>
<p><strong>Note:</strong> This functionality is not available in the <code>me-central2</code> region at this time. See <a href="https://docs.cloud.google.com/apigee/docs/locations#available-apigee-api-analytics-regions">Available Apigee API Analytics Regions</a> for region information. We will announce with a release note when that region is supported.</p>
<h3>Feature</h3>
<p><strong>Public preview of Risk Assessment v2</strong></p>
<p>This release introduces Risk Assessment v2 in <a href="https://cloud.google.com/products/#product-launch-stages">preview</a>. Risk Assessment v2 includes these improvements:</p>
<ul>
<li>Improved reliability: Faster score calculations with recent proxy data.</li>
<li>Simplified score display: The new score is a percentage, where 100% means full alignment with the security profile.</li>
</ul>
<p>For usage information and a list of all improvements and changes in v2, see <a href="https://docs.cloud.google.com/apigee/docs/api-security/security-scores#risk-assessment-v2">Risk Assessment v2</a>.</p>
]]>
    </content>
  </entry>

</feed>
