Device Security
New Features in December 2025
Table of Contents
Expand All
|
Collapse All
Device Security Docs
New Features in December 2025
Review the new features introduced in Device Security in December 2025.
| Where Can I Use This? | What Do I Need? |
|---|---|
|
One of the following subscriptions:
|
The following new features and enhancements were introduced for Device Security in
December 2025.
|
New Features
| |
|---|---|
|
Vulnerability signatures
|
The Device Security Research team added detections for 645
vulnerabilities this month. Of the 645 vulnerabilities, 80 of them
had a critical CVSS score. You can see a complete list of the CVEs
for which detections have been added at
Vulnerability Signatures in 2025.
|
|
Dictionary file updates
|
There were three dictionary file updates in December 2025. The
following summarizes what was added in each update:
|
Device Security Landing Dashboard
Device Security's new landing dashboard in Strata Cloud Manager
presents a centralized, real-time view of your device landscape and
critical risk factor insights, enabling proactive risk management and
rapid incident response. The landing dashboard unifies discovery,
security posture, risk analysis, and remediation workflows, so you can
get a high-level overview of all devices in your network, see where
risks from vulnerabilities and threats appear, and quickly take action
on insights and recommended policies.
Queries for Time-Based Attributes from Third-Parties
You can now query time-based attributes from third-party integrations.
Time-based attribute querying makes it easier to identify and manage devices
based on their temporal activity in your network. You can query using
predefined time values (e.g. 1 month) or custom values, which can be
explicit date ranges (e.g. January 5, 2026) or
relative time operators (e.g. last 10 days). Querying on time-based attributes
uses the existing process for Query Creation and Management.
NetBox IPAM and DCIM Integration
Device Security supports integrating with NetBox functionalities for
IP Address Management (IPAM) and Data Center Infrastructure Management (DCIM).
By integrating with NetBox, Device Security can learn about endpoints and
IP address use, including static IP addresses and DHCP leases. Device Security
uses that information to enrich the Device Security asset inventory,
including creating new assets for devices learned through the NetBox integration.
Enhancements for the Cisco Meraki Integration
December 2025 enhancement Device Security can now learn network details
when integrating with Cisco Meraki. The network details include information about
subnets, VLANs, static IP addresses, and DHCP leases. Device Security and
Cortex XSOARuse a new playbook,
Import Cisco Meraki Networks to Device Security, to get
the network information. The Cisco Meraki integration instance in
Cortex XSOAR also includes a new field, Networks,
to specify which networks to learn network information for. To pull
the network information from your Cisco Meraki solution to Device Security,
update your Cisco Meraki integration instance and configure a new
Cortex XSOAR job with the new playbook.
Device Security integrates with Cisco Meraki Cloud
through Cortex XSOAR
to enrich your asset inventory with detailed data about devices accessing your
network through Cisco switches and wireless access points. This integration enables
you to import device attributes, such as MAC and IP addresses, VLANs, and OS details,
directly into Device Security. For wired clients, you gain visibility into the
connecting switch, while wireless client data includes the associated access point.
Use this feature to correlate network-layer data with traffic logs from
next-generation firewalls. This integratio helps you maintain visibility of both
online and recently offline devices, so you can base your security policy decisions
on the most current context available.
Enhancement for the Infoblox IPAM Integration
December 2025 enhancement Device Security can now learn about
static IP addresses and DHCP leases when integrating with
Infoblox IPAM.
Integrate Device Security with Infoblox IPAM to retrieve
IP blocks and subnets (called containers and networks by Infoblox)
plus related data about sites, VLANs, and descriptions. For more information, see
Integrate Device Security with Infoblox IPAM.
Enhancements for the Microsoft DHCP Servers Integration
December 2025 enhancement Device Security can now learn about
static IP addresses and DHCP leases when integrating with
Microsoft DHCP Servers.
Device Security supports integrating with Microsoft DHCP Servers to
learn about DHCP clients from the servers. Device Security can retrieve
information such as multi-interface configurations, installed software,
DHCP reserved IP addresses, and BitLocker status, and Device Security uses that
information to enrich its inventories.
FedRAMP High Authorization
December 2025 enhancement Prisma Access attached Device Security
is now authorized for FedRAMP High.
June 2024 enhancement Device Security now uses the PAN-OS
Edge Services to support
policy recommendations and Device-ID based automated Zero Trust Enforcement for all
next-generation firewalls and Prisma Access. The Device Security solution
deployed in a FedRAMP moderate environment works with
next-generation firewalls in either FIPS mode or in a commercial environment.
Device Security is authorized for use in a FedRAMP environment.
To learn more about FedRAMP authorization at Palo Alto Networks, see
Palo Alto Networks and FedRAMP Authorization.