In Case You Missed It
Last month's product updates can be found in July's communication.
Infoblox Announcement
Kentik is Now Part of Infoblox
Infoblox has completed its acquisition of Kentik, uniting our authoritative view of what is on the network with real-time visibility into how traffic behaves and how services perform. For NetOps and SecOps teams, our goal is straightforward: replace fragmented data and disconnected tools with one place to understand what is configured and what is actually happening. That same combination is how we will deliver the authoritative network data layer that reliable agentic operations depend on. To learn more about how we are closing the gap with network truth, visit our blog.
Infoblox Announcement
Infoblox Exposure Management Now Includes External Attack Surface Management (EASM)
Infoblox Exposure Management now includes External Attack Surface Management (EASM), giving your security team a continuous, outside-in view of your internet-facing assets: the same view an attacker has before launching a campaign. Starting from your domain name alone, EASM discovers assets using passive DNS and certificate transparency logs, with no agents, credentials or active scanning required, and delivers a prioritized exposure view in hours. Findings are scored by business impact and exploit feasibility, with particular focus on DNS hygiene exposures, including dangling CNAMEs, weak SPF and DMARC records, and lame delegations that most tools never surface as findings. To learn more, visit our Exposure Management homepage.
Now Available
- Infoblox Support Portal: AI-Powered Support Chat for Support Tickets
- New IPv6 Subnets: for Infoblox Threat Defense™ and Infoblox Universal DDI™
- Infoblox Universal DDI™ Management:
- Infoblox IQ™
- DHCP Shared Networks
- Access Views For Public Cloud
- Early Access Program: Google Cloud Number Registry IPAM Integration
- NIOS-X as a Service: NTP Anycast Support
- Infoblox Universal Asset Insights™:
- Expanded Discovery Coverage
- New Discovery Configuration Page
- Early Access Program: ServiceNow Graph Connector
- Natural Language Query
- Infoblox Threat Defense:
- Infoblox Endpoint: Version 2.6.1 release
- Infoblox Endpoint: UX/UI Refresh
- Custom Lists and Indicator Expiration
- Early Access Program: Blocking Non-Trusted DNS Resolvers with Infoblox Endpoint
- Exposure Management:
- Slack Connection
- Infostealers Logs for All Users
- Supply Chain Intelligence
- DW Ticket Rules Management
Coming Soon
- Infoblox Universal DDI Management: DTC Centralized Health Check Distribution
- NIOS-X as a Service: Server Rightsizing
- NIOS DDI:
- DNSSEC Root KSK Rollover Support
- vNIOS Support in AWS China Regions
- Infoblox Universal Asset Insights: Expanded Discovery Coverage
- Infoblox Threat Defense:
- Clear DNS Forwarding Proxy (DFP) Cache
- DNS Forwarding Proxy (DFP) Source-Based Query Routing
- Ecosystem:
- SentinelOne EDR Integration
- Fortinet SIEM Integration
- ‘Infoblox IQ for Threat Defense’ Integration Updates
Infoblox Threat Intel
- 2026 Threat Landscape Report
Infoblox Support Portal
Now Available
The Infoblox Support Portal now includes a virtual support assistant to help you get answers faster. This new feature is available now for all customers with portal access. The assistant handles common how-to needs, configuration and troubleshooting, and supports questions through a guided conversation. It’s an additional resource alongside existing support options; your ability to open cases through the normal process is unchanged. To experience this new support mechanism, select the chat widget in the lower right corner of the Support Portal home screen.
Networking
Now Available
Infoblox now provides new IPv6 subnets for the management network used by Threat Defense and Universal DDI’s NIOS-X devices communicating to Infoblox. If you restrict outbound traffic to known Infoblox networks only, add the following subnets to your allow list to avoid any interruption in connectivity:
- 2600:1f18:68e9:d500::/64
- 2600:1f18:68e9:d501::/64
- 2600:1f18:68e9:d502::/64
No action is needed if you do not filter outbound traffic to specific Infoblox networks.
Now Available
Infoblox IQ™ for DDI is now generally available. Your apps, users and devices depend on critical network services to stay connected. When those services slow down or fail, you can face outages, delayed rollouts and longer troubleshooting cycles. Infoblox IQ for DDI helps you spot issues before users notice them and turns investigations that once took hours into recommendations you can review quickly. For more information, visit the Infoblox IQ for DDI Webpage.
Now Available
With DHCP shared networks support, DHCP can now assign IP addresses from multiple subnets on the same physical network, so you can expand capacity without renumbering existing networks. This helps improve address utilization, simplifies network growth and gives your team a more flexible way to scale as network demands change.
Now Available
With access views for public clouds, you can now assign an AWS, Azure or Google Cloud discovery job to a default access view, so your teams only see and manage the cloud-discovered IP address management (IPAM) data that’s relevant to them. When a public cloud IP space is first discovered and created, Universal DDI automatically copies the default access view from the discovery job to help simplify setup and reduce manual access management. That access assignment stays with the IP space even if the discovery job changes later. If needed, you can reassign a specific IP space to a different access view.
Now Available
Google Cloud’s Cloud Number Registry (CNR) is a native, policy-driven IPAM service for hybrid environments. With Universal DDI integration for CNR, you can now automatically discover CNR objects, including custom realms, and show that structure in the Infoblox Portal IPAM Navigation Pane so you can view Google Cloud and on-premises IP resources in one place. This helps centralize visibility, automate discovery of Google Cloud VPC networks, internal ranges and custom realms, and reduce the risk of IP conflicts.
Now Available
Infoblox now supports Network Time Protocol (NTP) Anycast for environments that need it. With this capability you can now maintain NTP service resilience and reduce the risk of time synchronization-related issues.
Now Available
Universal Asset Insights now includes new API integrations for Qualys, Okta and Microsoft Entra. By correlating asset data with DDI, it helps you maintain a reliable asset inventory, improve configuration management database (CMDB) accuracy and quickly identify unmanaged, stale or misconfigured assets.
To try the new integration as part of a free Infoblox Universal Asset Insights trial, register here. For more information, visit the Infoblox Ecosystem Portal.
Now Available
With the new Discovery Configuration page, you can find, configure and manage all your third-party API integrations from one place. The updated layout shows all supported integrations, and improved search and navigation help you find the providers you want to connect to more quickly. For integrations you already set up, the page gives you a cleaner view of each integration and its current status, so you can confirm what is running and address anything that needs attention.
Now Available
Infoblox has now launched early access for the ServiceNow Graph Connector for Universal Asset Insights, which supports bidirectional CMDB synchronization. Universal Asset Insights automatically identifies and updates missing, stale or incomplete configuration items (CIs) using authoritative, multi-source asset intelligence, helping organizations maintain a trusted CMDB.
For customers interested in the ServiceNow Graph Connector Early Access Program, please contact your Infoblox account team or Infoblox partner.
Now Available
Infoblox now includes natural language query in Universal Asset Insights, so you can interact with infrastructure data using plain language. You can ask operational questions, generate reports and access infrastructure insights without specialized query skills or syntax. This helps your teams find answers faster and make decisions with less effort.
Coming Soon
Centralized health check distribution will soon let you designate specific DNS Traffic Control (DTC) nodes to perform health monitoring and share the results across your environment, eliminating redundant checks, reducing network load and alleviating challenges where firewalls block access to health checks in your environment by leveraging DTC. The result will be more efficient, scalable health check operations that help protect application delivery across cloud, on-premises and hybrid environments.
Coming Soon
NIOS-X as a Service will soon automatically adjust capacity based on actual utilization, so your deployment will stay aligned with your demands without requiring manual reconfiguration. This will help you maintain performance as usage grows, start small and scale over time, and reduce management effort.
Coming Soon
ICANN will be rolling over the Domain Name System Security Extensions (DNSSEC) root Key Signing Key (KSK), with a new root key set to begin signing the root zone on October 11, 2026. If you run DNSSEC validation, you will need to trust the new root KSK before that date or DNSSEC validation will fail once the new key takes effect. To help you keep DNSSEC validation and the chain of trust intact, Infoblox delivered NIOS hotfixes in July 2026 that updated the root trust anchor to the new KSK and keep your systems aligned with IANA’s published keys.
To avoid DNS resolution failures during the rollover, you should apply these hotfixes before October 11, 2026. You will also be able to update the trust anchor manually if you prefer.
Coming Soon
Infoblox will soon support the deployment of vNIOS in AWS China Regions, giving global and China-based organizations a supported way to run Infoblox DDI in the cloud in China. This offering will extend customers’ global enterprise-grade DDI foundation across on-premises and other cloud environments to include workloads running on AWS China.
Infoblox DDI in China is primarily delivered on premises, while cloud workloads depend on native DNS/DHCP or separate tools. By running vNIOS on AWS China, you will be able to use Infoblox for those cloud workloads and apply the same DDI policies used elsewhere. This will give you a consistent way to manage DDI across AWS China and the rest of your cloud environment.
Coming Soon
To give you deeper visibility into IP-connected assets across on-premises and hybrid cloud environments, Universal Asset Insights will expand API-based discovery. Upcoming integrations include:
- Cisco ISE
- Fortinet FortiCloud
- Red Hat OpenStack
- Cisco WebEx
- Ping Identity
| - Arista CloudVision
- Arista VelaCloud
- Tanium
- Alibaba
- Claroty
- Neat Pulse
|
|---|
These additional integrations will further strengthen Universal Asset Insights as a reliable source of truth for asset discovery, helping you surface stale or misconfigured assets and manage complex hybrid environments with confidence.
Quick Links for Universal DDI
Quick Links for NIOS DDI
Subscribe to the Infoblox Status page to receive real-time notifications on maintenance upgrades.
Security
Now Available
Infoblox Endpoint version 2.6.1 is a maintenance release that improves endpoint reliability, overall security and day-to-day operations. This release also enhances endpoint protection status reporting and makes endpoint behavior more consistent across environments. It also serves as the prerequisite for the new Endpoint UX/UI Refresh, delivering updates that power its health monitoring. The result is a more predictable endpoint experience, less time spent troubleshooting client-side issues and greater confidence when deploying and managing Endpoint at scale.
Now Available
Infoblox Endpoint now delivers a more modern endpoint management experience in the Infoblox Portal. The refresh includes clearer health monitors, improved detail views, richer status and upgrade logs, and safer bulk/group operations. Together, these updates help you answer day-to-day operational questions faster, reduce risk when making changes across large endpoint groups and spend less time switching between views while troubleshooting.
Now Available
Previously, temporary entries in your custom lists stay in place until you removed them by hand, which is easy to forget and can leave stale indicators influencing policy decisions long after they are needed. Now, you can set an expiration on any individual indicator in your custom lists, including Default Allow and Default Block, so temporary entries clean themselves up automatically.
For each indicator, choose no expiration (the default), a specific date and time, or a relative duration in days, hours or seconds. Expirations display in your local time zone with a remaining countdown. Once an indicator expires, it is removed through the same audit-logged process as a manual delete and immediately excluded from policy decisions.
Now Available
The Block Non-Trusted DNS Resolvers Early Access Program (EAP) helps close a common DNS security gap for roaming users by preventing endpoints from sending DNS traffic to unapproved public or third-party resolvers. Instead, endpoints can use only trusted resolvers such as Infoblox Threat Defense Anycast, network-provided DNS or approved internal and fallback resolvers defined in policy. For customers, this reduces the chance that users or malware can bypass DNS-layer security controls while still allowing phased rollout by endpoint group. For customers interested in the Block Non-Trusted DNS Resolvers EAP, please contact your Infoblox account team or Infoblox partner.
Now Available
New detections can be sent directly to the Slack channels your team already monitors; no need to log in to the platform or build a custom integration to stay current. EASM exposures, Supply Chain Intelligence vendor alerts, brand and dark web detections, and other threat findings can be filtered by asset, vendor or detection type before routing to the appropriate Slack channel. Updates arrive within approximately five minutes of a detection, automatically and without any manual action.
Now Available
Infostealers Logs, part of the platform’s Threat Hunting capabilities, is now available to all Exposure Management users; no early-access prerequisites and no activation required. Customers with valid tokens can access it directly, giving your team immediate visibility into infostealer data to identify credential exposure before it can be weaponized.
Now Available
Supply Chain Intelligence is now available as part of Infoblox Exposure Management, extending the platform's outside-in threat monitoring to your critical third-party vendors. Vendor-related threat intelligence, including new certificates, vulnerabilities, and critical bulletins tied to named vendor assets is delivered automatically through the same channels you already use: pull feeds, webhooks, or Slack. Feed configurations support five structured categories with five configurable top-threat actions per category.
Now Available
Rules that control when Dark Web monitoring tickets are created are now managed through the Filtering Rules interface, the same tool used for Collections and Bots, giving you a consistent, centralized way to manage all monitoring logic in one place. Ticket generation activates automatically when Dark Web monitoring is turned on, and rule management is now consolidated alongside the rest of your filtering configuration.
Coming Soon
When you update, correct or delete a DNS record, the DFP keeps serving the previous cached response until that cached entry expires. This keeps your changes from taking effect right away and can delay troubleshooting. Today, the only workarounds are to wait for the cache to time out or restart the service.
You will soon be able to clear the DFP cache on demand directly from the Infoblox Portal (Service Actions > Clear Cache), with no service restart required. Once the cache is cleared, subsequent queries are forwarded upstream immediately, so your corrections, new records and deletions take effect right away. The results will be faster propagation of DNS changes, quicker issue resolution and immediate enforcement of updates, all without disrupting service or waiting for the cache to expire.
Coming Soon
Not every device behind your DNS Forwarding Proxy needs to be resolved through Infoblox Threat Defense Cloud, such as guest or other non-corporate networks. Source-based query routing gives you control over which devices are resolved through the cloud and which are sent elsewhere, helping you manage your Threat Defense utilization and direct selected devices to the resolvers you choose, all without re-provisioning static DNS settings on those devices.
With this feature, you will soon direct specific subnets behind your DFP to third-party resolvers of your choice, bypassing Threat Defense Cloud resolution for just those devices. For each route entry, you map a source subnet to up to four destination resolvers in priority order; if one resolver becomes unavailable, queries automatically failover to the next. You will also be able to enable encrypted DNS on any destination for added protection. Each DFP supports up to 16 non-overlapping route entries, and internal domain routing always takes precedence over source-based routes, so your existing internal resolution paths stay intact.
Coming Soon
Infoblox will soon be adding Ecosystem support with a new integration of Infoblox Threat Defense and IQ for Threat Defense with SentinelOne EDR. This capability will enable detected threats, such as DNS-based data exfiltration, command-and-control attempts and domain-generated algorithm (DGA) activity, to be automatically sent from Infoblox to SentinelOne. Once received, SentinelOne will be able to instantly quarantine the affected endpoint, stopping threats at both the network and device level. This will also identify the endpoint process responsible for the query, allowing the security team to know when the locked-down browser is being bypassed.
Coming Soon
Infoblox and Fortinet will be partnering to integrate security, DNS and IPAM activity into Fortinet SIEM, streamlining event logging and deepening network visibility. The integration will feed enriched IPAM metadata, DNS telemetry, threat intelligence and contextual insights into Fortinet SIEM for stronger correlation, hunting and investigation. A deployment guide is in development to illustrate how to send syslog output from Infoblox via the Cloud Data Connector (CDC) into the Fortinet SIEM environment. Once available, it will be accessible from the Ecosystem Portal with clear, supported configuration steps.
Coming Soon
Infoblox will be updating more than 20 Threat Defense ecosystem integrations - including SIEM applications, SOAR integrations, playbooks, and other integrations that previously used SOC Insights - to the new ‘IQ for Threat Defense’ Insight format. Newly generated Insights will provide richer, more actionable context for ecosystem integrations, including an overview field that explains the threat, an Indicators field listing all associated IOCs, Assets and Users fields that identify who and what is affected, and a recommendation field that provides clear guidance on the next action to take. These enhancements help security teams investigate faster, prioritize response more effectively, and act with greater confidence. Updates will be released as they are completed over the coming month.
Quick Links for Security
Subscribe to the Infoblox Status page to receive real-time notifications on maintenance upgrades.
Infoblox Threat Intel
New Research Available
Infoblox Threat Intel is a leading creator of original DNS threat intelligence, with deep visibility into internet infrastructure that helps discover and disrupt threat activity others miss. The team uses this visibility to predict, uncover and block threat actors before they strike.
Visit the Infoblox Threat Intel site to access the latest research directly and stay up to date on new findings.
On August 3, Infoblox released its 2026 Threat Landscape Report, offering a data-driven look at the structural shifts reshaping cybercrime. Built on billions of DNS queries, millions of underground messages and original Infoblox Threat Intel research, the report delivers insights that are difficult to obtain from any other source.
Among Its Findings:
- 88 percent of threat-related domains were observed in only a single customer environment, highlighting attackers’ growing reliance on highly targeted, short-lived infrastructure to evade detection.
- Enterprise DNS queries to AI applications increased by 159 percent, underscoring how rapidly AI is expanding the enterprise attack surface.
- 96 percent of Infoblox Threat Defense Cloud customers queried TDS domains, which cybercriminals use to profile victims and redirect them through malicious infrastructure before delivering phishing, malware or scams.
- 65 percent of Infoblox Threat Defense Cloud customers queried domains associated with residential proxy networks, highlighting the widespread use of “infrastructure-for-rent” that enables malicious activity to blend in with legitimate internet traffic.
What You’ll Discover:
- Why cybercrime has become an industrial-scale economy
- How AI is changing the speed and sophistication of phishing, scams and malware campaigns
- Why attackers increasingly abuse trusted internet infrastructure, including DNS, cloud services and residential proxy networks to evade detection
- How organizations have been exposed to specific threats, and how a preemptive security approach can reduce risk before attacks reach users