Every check now leads with what matters
Each analysis on a device's Findings page now opens with a one-sentence verdict, lists what to know worst first, says what it checked and found in order, and ends on one action. Listening ports, backup jobs, drives and sessions are shown as tables. The network check knows when a machine sits behind NAT, and the Security Audit reads like every other check, audited by Lynis.
Every check on a device's Findings page now opens with one sentence saying what it found, lists what you should know worst first, and ends on the one thing to do. It's the largest change to how analyses read since the Findings page was built in August.
Each finding has a level
Until yesterday the model wrote each analysis as one block of text, in an outline its instructions set out: "Unexpected listeners", "Delta vs previous snapshot", "Failing drives". It filled in every heading, including the ones with nothing under them. Across our last 3,000 analyses, a service inventory carried 1.9 bullets on average that said "none" or "no change".
Now it writes four parts, and the page puts each in its place:
- The verdict, one sentence under the check's name.
- Findings, worst first. Each is marked act on this, keep an eye on this or worth knowing, and one the last run didn't have is marked New.
- Checked and in order, a short list of what the check looked at and found fine.
- Recommended action, one, with the command or setting when there is one.
A clean check stays short. Disk Health on a healthy machine is a verdict, five ticks and "No action needed."
The compliance chips moved to the foot of each check. The buttons you press stay at the top.
The data is a table
Some checks used to retell their data before judging it: "10 TCP listeners, 6 IPv4, 4 IPv6. Localhost-only: cupsd on 127.0.0.1:631..." Network Connections, Backup Health, Disk Health and User Sessions now show it as a table under the findings, closed until you open it.
Every listening port with its process and where it listens. Every backup job with its schedule, last success and record. Every drive with its health, wear and temperature. The rows the check is about are highlighted.
The network check knows where a machine sits
A service bound to 0.0.0.0 listens on every interface of its machine. Whether anyone outside can reach it depends on the machine's addresses, and the check didn't have them. On one of our own Linux desktops it called SSH "reachable externally" and scored the check 43.
It now gets the machine's interface addresses and the public address the machine reaches us from. A machine whose own addresses are all private sits behind NAT, so the same SSH now reads as reachable from the local network, and from the internet only if a port is forwarded. That desktop scores 78. We still can't see the firewall, and the check says so.
While we were at it we found that a Docker host's interface list kept every interface its containers had ever had, all marked up: 141 rows for 9 real interfaces on that desktop, and 238 stale rows of 511 across the machines we manage.
An interface the agent stops reporting is now marked down at once and removed after a week.
The Security Audit reads like the rest
Lynis audits Linux and macOS machines and lists what could be hardened. It doesn't weigh its findings: on that desktop it listed a GRUB password, legal banners, /tmp on its own partition and nine SSH settings as 46 equal suggestions.
The Security Audit now carries an Audited by Lynis badge and reads like every other check. When an audit changes, the AI provider your account uses reads it with what it knows about the machine, and writes the verdict, Lynis's warnings, at most three suggestions that matter on that machine, and the first thing to change. When we tried it on one of our servers, it named a Redis instance with no password and web sites served without HTTPS. Lynis had filed both among 45 suggestions.
The score is still Lynis's hardening index. Everything Lynis found is in the table under the findings, each control linked to its page on CISOfy's site. Reading the audit costs no wegcoins, like the audit itself.
What stays the same
The PDF reports, the share page and the device chat read the same analyses as before. An analysis written before this change keeps its old look until its check next runs.