| File |
|---|
| Libraesva ESG v5.6.gpg |
| Version | 5.6 |
| File Size | 24 KiB |
| File MD5 | ce625a0e19ba504338223a6b0be6ff9c |
| File SHA256 | b2bcaf6ef48facba3e72e48d6cf5d1fdec9660e4ae680f6082c0dde0a27090b6 |
| Create Date | May 27, 2026 |
| Last Updated | May 28, 2026 |
LibraCyber ESG 5.6 – Strengthening Security with Intelligent Protection
LibraCyber ESG 5.6 introduces a focused set of enhancements designed to strengthen email security while making protection more visible and intuitive for end-users and administrators alike. By combining AI-driven investigation, automated protection for high-value accounts, adaptive takeover detection, and strengthened infrastructure controls, this release gives your teams greater confidence in every email interaction while reducing the operational burden on IT and SOC teams.
These are the major features of this release.
Adaptive Protection Against Account Takeover
Account takeover attacks often begin with subtle anomalies in user behavior. LibraCyber ESG 5.6 addresses this with an adaptive, self-tuning ATP Automatic Quota Engine. The system continuously analyzes your organization’s historical email patterns to learn normal email activity and dynamically assign appropriate quotas to each user. When behavior deviates from those learned patterns, the system identifies potential compromise earlier and triggers protective actions automatically, minimizing the need for manual rule tuning while maximizing detection accuracy over time.
Administrators have full flexibility with two operational choices: you can manually assign email addresses to specific quota levels, or you can rely on the adaptive algorithm to adjust user quotas automatically based on recent email delivery behavior. All quota levels remain fully customizable, both per level and per domain, to precisely fit your organization's security profile.
Second Sight
Second Sight acts as an AI-assisted virtual security consultant right within the inbox, transforming email security into a collaborative process between end-users and security teams. When an email looks unusual or potentially malicious, users can request a deeper analysis directly within the LibraCyber environment. LibraCyber’s detection engines then perform an expanded inspection using contextual signals, behavioral patterns, and semantic analysis driven by the
Esvalabs AI engine to determine whether the message represents a genuine threat.
Instead of forcing users to immediately escalate every concern to the SOC, Second Sight provides an understandable overview for the end-user and a comprehensive technical breakdown for IT/SOC teams. This capability gives users immediate reassurance when evaluating high-risk communications—such as sensitive data submissions, new invoices, or suspicious supply-chain emails—while significantly reducing unnecessary SOC escalations and investigation workloads.
Administrators retain complete control and can manage access to this feature through granular permissions, ensuring only authorized users request and view security insights.
Enhanced C-Suite Protection Through Automated Discovery
Whaling attacks focus on high-profile executives, representing one of the most dangerous and financially damaging forms of Business Email Compromise (BEC). This update introduces Automatic C-Suite Identification to streamline executive protection by automatically importing high-value targets from directory information within Microsoft 365 and Google
Workspace.
The system automatically recognizes C-level and executive users based on security group membership or job title patterns, removing the administrative burden of manually configuring individual security policies. This ensures all high-risk personas and relevant accounts—including secondary email addresses—are automatically wrapped in enhanced protections, reducing the likelihood that attackers can exploit leadership identities in targeted impersonation attacks.
Configuration stays completely up to date via automatic synchronization.
Integrates IoC in Firewall Protection
Version 5.6 introduces advanced controls to tighten email infrastructure and network security. Every incoming connection to LibraCyber ESG is automatically classified into a firewall zone according to the source IP’s network policy. The new configuration interface lets you easily review and customize the local firewall, check which services and ports are open for each zone, and block malicious networks (IoCs) directly at the firewall level. The LibraCyber security team ensures continuous protection by distributing automated, real-time IoC updates.
Additionally, infrastructure security is strengthened by allowing administrators to restrict SMTP authentication to defined network ranges. This ensures authentication is only allowed from trusted locations, shrinking the attack surface for credential abuse and preventing compromised accounts from being exploited outside authorized environments.
Full release notes
To see the full release notes, visit our documentation page
Minor upgrades for this release, which includes all 5.6.x versions, are automatically updated as soon as they are publicly available. These updates include all security fixes and bug fixes that can be installed without service downtime, and the expected behavior of the appliance remains unchanged.
Alongside key security enhancements, this version includes behind-the-scenes platform performance and reliability upgrades to ensure faster and more responsive dashboards, improved integration capabilities for automated workflows, and greater scalability and long-term platform stability.
Breaking changes
This version introduces some changes that require your attention.
- TLS policy. Custom policies based on fingerprint must now use the SHA256 algorithm instead of MD5.
- ATP Policy Quota. Custom policy quotas from the previous version cannot be automatically
upgraded. The automatic policy quota will likely obsolete any outgoing policy, while incoming
policies can be easily reconfigured after the upgrade. - API v1 has been removed, and all requests will return
410 GONE. Entrypoints/api/v1/,
/api/v1/versionand/api/v1/api-specifications.jsonare preserved for smoother migration. - MSSP Panel. Dropped support for managing remote appliances at version 4.x or below.
- Invalid usernames removal. Username requirements for length and uniqueness introduced in ESG
5.2 is not strictly enforced. All invalid usernames, especially the one from old imports, must be removed before the upgrade.
|
Enter your Email to download
|