- CIS Docker rules now skip evaluation on Kubernetes nodes using non‑Docker runtimes (e.g., containerd, CRI‑O), eliminating false positives on GKE COS and similar platforms.
- Patched a confused‑deputy vulnerability in the Cluster Agent’s AppSec ingress NGINX admission mutator by enforcing namespace matching and emitting warning events.
- Fixed log‑collection stalls caused by Docker read‑timeout shutdowns, corrected AKS selector handling in the admission controller probe, and disabled incompatible v3 API shadow sampling in the OTel Agent.