Focus

New Features - Device Security - July 2025


Controller Configuration and Inventory File Support for Device Security

Release Date: September 2025 | Last Updated: May 2026

( September 2025 ) Device Security extended support for parsing device configuration files to include:

  • Mitsubishi MELSOFT Series GX Works2 files (.gxw)

  • Emerson DeltaV Explorer files (.fhx)

( July 2025 ) Device Security extended support for parsing device configuration files to include:

  • Siemens PRONETA files (.xml)

Device Security Integration with AIMS 3

Release Date: July 2025 | Last Updated: May 2026

Device Security supports integrating with AIMS 3 from Phoenix Data Systems to learn about healthcare devices and endpoints from AIMS 3 . Device Security can retrieve device details from AIMS 3 and use that information to enrich device information in the Device Security assets inventory. Device Security also creates new devices in the assets inventory for devices learned through the AIMS 3 integration.

Device Security Integration with Atlassian Jira

Release Date: July 2025 | Last Updated: May 2026

Device Security supports integrating with Jira Cloud to streamline alert management for your network. Through this integration, you can automate sending security alerts and vulnerabilities from Device Security to Jira tickets. By specifying the alert and vulnerability severity levels you want visibility into, you can set up a recurring job to automatically create Jira tickets for new alerts and vulnerabilities that match your criteria. You can also manually create Jira tickets from the Device Details, Vulnerability Details, Alert Details, and Alert Inventory pages in the Device Security web interface.

You can also check if the Jira tickets created through Device Security are resolved and update the status of the corresponding alerts and vulnerabilities in Device Security . By supporting both manual and automated ticket creation, as well as automated risk resolution based on ticket status, the Jira Cloud integration lets you manage security incidents through your existing incident tracking system while maintaining a unified, real-time view of network risks.

Device Security Packet Capture Collection

Release Date: July 2025 | Last Updated: May 2026

You can enable packet capture collection across your tenant to improve device identification and enhance security protections. The Device Security Research Team analyzes pcap files to enhance device and application recognition, which in turn helps accurately identify security alerts and vulnerabilities in your network. We encrypt all pcap files, and any file with personal information or customer identifying information won’t be used. For more information about data security and privacy, see the IoT/OT Security Privacy Datasheet.

Device Utilization Download Enhancement

Release Date: July 2025 | Last Updated: May 2026

For the Device Security Medical vertical, the device utilization download now includes information about the hourly use of the device. This enhancement provides the same hourly utilization information as the web interface in the device download file.

IP-MAC Binding Source for Device Security

Release Date: May 2026 | Last Updated: June 2026

( May 2026 ) Device Security now enforces tiered source priority for IP-to-MAC bindings, ensuring that live traffic always take precedence over conflicting data from third-party integrations. Data sources are ranked by confidence: live network traffic observations (ARP and DHCP) carry the highest confidence, followed by network management tools, then endpoint and vulnerability management integrations, and finally static database entries. Your device inventory maintains accurate IP addresses and subnet assignments even when multiple sources report conflicting bindings.

( July 2025 ) When viewing the Assets Inventory and the Device Details page, you can now see the source for each device's IP-MAC binding. Select IP-MAC Sources in the column selector to display the IP-MAC binding source in the Assets Inventory. This column displays where a device's IP-MAC binding came from, whether from network traffic or a third-party integration.

Network Discovery Plugin 2.2.x and 3.0.x

Release Date: October 2025 | Last Updated: May 2026

( October 2025 ) The Network Discovery plugin version 2.2.3 introduces an enhancement for SNMP crawling to skip IP phones. This helps improve runtime and performance for an SNMP crawl. Version 2.2.3 also includes a number of addressed issues to improve runtime performance and results. See Known Issues in Network Discovery 2.2 for a full list of addressed issues. The Network Discovery plugin version 3.0.1 includes the same functionality as Network Discovery 2.2.3 for firewalls running PAN-OS 12.1.2 and later.

( August 2025 ) The Network Discovery plugin version 2.2.2 includes a number of addressed issues to improve runtime performance and results output. See Known Issues in Network Discovery 2.2 for a full list of addressed issues.

( July 2025 ) The Network Discovery plugin version 2.2.1 includes a number of addressed issues to improve configuration and runtime performance. See Known Issues in Network Discovery 2.2 for a full list of addressed issues.