File
Libraesva ESG v5.6.gpg
Version5.6
File Size24 KiB
File MD5ce625a0e19ba504338223a6b0be6ff9c
File SHA256b2bcaf6ef48facba3e72e48d6cf5d1fdec9660e4ae680f6082c0dde0a27090b6
Create DateMay 27, 2026
Last UpdatedMay 28, 2026

LibraCyber ESG 5.6 – Strengthening Security with Intelligent Protection

LibraCyber ESG 5.6 introduces a focused set of enhancements designed to strengthen email security while making protection more visible and intuitive for end-users and administrators alike. By combining AI-driven investigation, automated protection for high-value accounts, adaptive takeover detection, and strengthened infrastructure controls, this release gives your teams greater confidence in every email interaction while reducing the operational burden on IT and SOC teams.

These are the major features of this release.

Adaptive Protection Against Account Takeover

Account takeover attacks often begin with subtle anomalies in user behavior. LibraCyber ESG 5.6 addresses this with an adaptive, self-tuning ATP Automatic Quota Engine. The system continuously analyzes your organization’s historical email patterns to learn normal email activity and dynamically assign appropriate quotas to each user. When behavior deviates from those learned patterns, the system identifies potential compromise earlier and triggers protective actions automatically, minimizing the need for manual rule tuning while maximizing detection accuracy over time.

Administrators have full flexibility with two operational choices: you can manually assign email addresses to specific quota levels, or you can rely on the adaptive algorithm to adjust user quotas automatically based on recent email delivery behavior. All quota levels remain fully customizable, both per level and per domain, to precisely fit your organization's security profile.

Second Sight

Second Sight acts as an AI-assisted virtual security consultant right within the inbox, transforming email security into a collaborative process between end-users and security teams. When an email looks unusual or potentially malicious, users can request a deeper analysis directly within the LibraCyber environment. LibraCyber’s detection engines then perform an expanded inspection using contextual signals, behavioral patterns, and semantic analysis driven by the
Esvalabs AI engine to determine whether the message represents a genuine threat.

Instead of forcing users to immediately escalate every concern to the SOC, Second Sight provides an understandable overview for the end-user and a comprehensive technical breakdown for IT/SOC teams. This capability gives users immediate reassurance when evaluating high-risk communications—such as sensitive data submissions, new invoices, or suspicious supply-chain emails—while significantly reducing unnecessary SOC escalations and investigation workloads.

Administrators retain complete control and can manage access to this feature through granular permissions, ensuring only authorized users request and view security insights.

Enhanced C-Suite Protection Through Automated Discovery

Whaling attacks focus on high-profile executives, representing one of the most dangerous and financially damaging forms of Business Email Compromise (BEC). This update introduces Automatic C-Suite Identification to streamline executive protection by automatically importing high-value targets from directory information within Microsoft 365 and Google
Workspace.

The system automatically recognizes C-level and executive users based on security group membership or job title patterns, removing the administrative burden of manually configuring individual security policies. This ensures all high-risk personas and relevant accounts—including secondary email addresses—are automatically wrapped in enhanced protections, reducing the likelihood that attackers can exploit leadership identities in targeted impersonation attacks.
Configuration stays completely up to date via automatic synchronization.

Integrates IoC in Firewall Protection

Version 5.6 introduces advanced controls to tighten email infrastructure and network security. Every incoming connection to LibraCyber ESG is automatically classified into a firewall zone according to the source IP’s network policy. The new configuration interface lets you easily review and customize the local firewall, check which services and ports are open for each zone, and block malicious networks (IoCs) directly at the firewall level. The LibraCyber security team ensures continuous protection by distributing automated, real-time IoC updates.

Additionally, infrastructure security is strengthened by allowing administrators to restrict SMTP authentication to defined network ranges. This ensures authentication is only allowed from trusted locations, shrinking the attack surface for credential abuse and preventing compromised accounts from being exploited outside authorized environments.

Full release notes

To see the full release notes, visit our documentation page

Minor upgrades for this release, which includes all 5.6.x versions, are automatically updated as soon as they are publicly available. These updates include all security fixes and bug fixes that can be installed without service downtime, and the expected behavior of the appliance remains unchanged.

Alongside key security enhancements, this version includes behind-the-scenes platform performance and reliability upgrades to ensure faster and more responsive dashboards, improved integration capabilities for automated workflows, and greater scalability and long-term platform stability.

Breaking changes

This version introduces some changes that require your attention.

  1. TLS policy. Custom policies based on fingerprint must now use the SHA256 algorithm instead of MD5.
  2. ATP Policy Quota. Custom policy quotas from the previous version cannot be automatically
    upgraded. The automatic policy quota will likely obsolete any outgoing policy, while incoming
    policies can be easily reconfigured after the upgrade.
  3. API v1 has been removed, and all requests will return 410 GONE. Entrypoints /api/v1/,
    /api/v1/version and /api/v1/api-specifications.json are preserved for smoother migration.
  4. MSSP Panel. Dropped support for managing remote appliances at version 4.x or below.
  5. Invalid usernames removal. Username requirements for length and uniqueness introduced in ESG
    5.2 is not strictly enforced. All invalid usernames, especially the one from old imports, must be removed before the upgrade.
NOTE: This upgrade takes up to 15 minutes to complete. The appliance will reboot after the upgrade, there is no expected MTA downtime for clusters, and an expected MTA downtime is approximately 1 minute for single nodes. A Snapshot is always recommended as a best practice!
Enter your Email to download