This release adds SSH session monitoring, the full set of Agent Schedule behavior rules, content sharing rules for AI applications and MS Teams Web, HTTP/2 support, and file tracking on network shares - plus security fixes and reliability improvements. Available now via New Downloads and Auto-Update for all cloud deployments.
New: SSH Session Monitoring
The agent now captures interactive SSH terminal sessions - even when no desktop (GUI) session is logged in:
The monitored user appears online; recording starts at the first SSH login and stops at the last logout.
Multiple concurrent SSH sessions are composited into a single recording without duplicates.
SSH terminals are recorded and streamed as video, rendered to match the real terminal - colors, cursor, and scrolling.
Keystrokes in SSH sessions are logged and reported, integrated with per-user activity and productivity statistics.
Behavior rules can trigger on SSH session activity, including keystroke-based rules.
SSH tracking can be disabled at install time (agent configuration option) or by disabling video recording.
New: Agent Schedule Behavior Rules
Ubuntu now supports the complete set of Schedule behavior rules: Daily Work Time, Scheduled Work Time, Starts Early, Ends Early, Ends Late, Arrives Late, Is Absent, Is Late, Works on Day-Off, and Idle.
New: Content Sharing Behavior Rules for AI Applications
Content sharing behavior rules now cover the web-based AI applications the agent monitors: Gemini, ChatGPT, Claude, Copilot, and Google AI - so you can detect and act on sensitive data shared with AI tools.
New: Behavior Rules for MS Teams Web
Behavior rules are now supported for Microsoft Teams on the web. Conditions include message content (including sensitive-data content criteria), message direction, messaging app, and contact name.
HTTP/2 Support
The agent no longer forces websites down to HTTP/1.1 - full HTTP/2 support improves compatibility and performance with modern sites.
File Tracking for Network Shares
File operations (copy, move, rename, delete) on SMB and NFS network shares mounted via GVFS are now tracked and appear in file-transfer reports, covering GIO-native applications such as Nautilus and GNOME Text Editor.
Wayland Screen-Recording Safety Net
A new safety-net mechanism bypasses the user-consent pop-up that notifies about the start of screen recording on Wayland, so recording starts reliably without user interaction.
Security Fixes
This release fixes four issues identified through penetration testing:
Real-time policy channel: the agent did not properly validate the TLS identity of the real-time server endpoint, which could allow policy and configuration messages from an untrusted source, including elevated command execution. TLS validation is now enforced.
IPC socket: the root-level engine's IPC socket was connectable by any local user and accepted shell-command requests. Access is now restricted.
Upload directory: a low-privileged local user could write crafted upload/metadata files later processed by the root service. Directory handling is now hardened.
Cached behavior-rule configuration: the per-user rule cache was writable by the local user and later loaded by a privileged process. Cache integrity is now protected.
We recommend updating all Ubuntu agents as soon as possible.
Fixed
Fixed intermittent agent disconnections from the server when monitoring profiles were updated with a large behavior-rule configuration.
Fixed input devices (keyboard/mouse) connected after agent startup not being tracked - which could previously show the user as idle with no activity recorded.
Fixed screen recording not working for monitors plugged in after agent startup.
Fixed Live View not updating after the agent reconnected.
Fixed content-sharing "upload file" rules for non-plain files (PDF, DOCX, etc.) triggering the alert from Access/Copy rules.
Fixed a non-HTML popup warning appearing alongside the HTML popup for rules configured with "Use HTML Template".
Fixed behavior rules with file-write conditions not triggering.
Fixed captured Gmail attachments having corrupt content.
Fixed the Revealed Agent losing the saved login/password after a failed authentication.
Also in This Release
Keystroke reports now display the Space key as <Space>.
