Changelog
What's new in NYXR
Everything that changed, newest first: what it means for you, and why we did it.
The NYXR Challenge trial goes all the way
- SecurityAn account without two-factor can no longer set it up with its password alone: an administrator opens a 24-hour window from the Users page. Turning two-factor off, changing roles or resetting a password now needs a recent full sign-in.
- AddedNew account security alerts: sign-in from a new address, lockout, two-factor turned off, password or roles changed. Settings › Security also lets you sign out your other sessions, and administrators’ “remember me” sessions now last 24 hours.
- SecurityThe console itself is now protected by NYXR like any of your sites: threat lists, bans, robot detection and the WAF (in detection first) apply to nyxr.app. If NYXR ever blocks you, an SSH tunnel to the server still opens the console.
- SecurityA protected site could be reached without the WAF by naming another site in the connection. That path is closed for every protected site, and checked again every ten minutes.
- SecurityStricter encryption and safer answers: old TLS 1.2 ciphers are refused, origins no longer reveal their software, and a refusal no longer tells the visitor which protection stopped it. HSTS no longer adds your domains to browsers’ preload list without asking.
- SecurityThe server only accepts SSH keys, refuses every other incoming connection by default and runs on an up-to-date system. No component exposed to the Internet can read the other containers’ secrets any more.
- FixedBans are sent to CrowdSec again. A configuration line had silently switched this off since September 26.
- ImprovedBackups can now be restored with a tested script, and nothing is written unencrypted while they are made. They also keep the certificates and the server’s mesh identity.
- ImprovedThe simple mode of Protection rules now covers every tab. Two new sentences set what a refused visitor sees, sensitive files, AI robots and fake robots; everything else (score, scenarios, honeypots, TLS check, learned rules…) shows its state, with a link to its setting.
- FixedThe console no longer loops with « the page isn’t redirecting properly » after signing out or when a session expires. The browser kept the old session, and the sign-in page kept sending you back to it.
- FixedThe NYXR Challenge trial in the console no longer stops halfway with a spinner that never ends. The checks it runs on the browser were refused by the console, so the solve never finished.
- FixedIn dark mode, the challenge preview and the Hardening tab trial no longer show a white band or a white widget. Both now follow the console colours.
- FixedOn the Challenge page your visitors see, the widget now sits right under the title instead of after a large gap. In the simple-mode preview it is also centred in the card.
- FixedIn Services, the NetBird or Manual badge of each row now has the same shape as the other badges of the table. It used to stretch across the whole column.
- ImprovedThe abuse.ch SSLBL list is switched off for good: its publisher stopped it in January 2025. Addresses from a list nobody updates any more no longer block your visitors.
- ImprovedThe console now looks the same on every computer: it brings its own fonts instead of borrowing whatever the system had. Figures in cards and tables line up again.
- ImprovedPeriod pickers, figure cards, charts and tables now take the same shape on every page. Durations are written out (« 7 days », not « 1w »), the figures of a row start on the same line, and the actions of a row are always in the same order.
- ImprovedLearned rules, Challenge statistics and the host resources now speak your language: no more « ua_pattern », « postgres » or « 10.3 GB » on a French page. Top countries and source addresses are shown as one table with named columns.
- FixedThe activity report has a single service filter again, and « All services » really means all of them. It used to have two that could disagree, and the report then stayed on one service.
- FixedOn a phone, the dashboard and the Anti-DDoS tab no longer run off the right edge of the screen. In Quick block the « Allow » and « Challenge » choices show in full, and on Bans the expiry is no longer hidden under the row icons.
What the console promised, the gateway now does
- FixedRate limits and the anti-DDoS shield now really apply. Since 27 September the gateway loaded an empty rule list: rules looked active but slowed nothing down.
- FixedThe adaptive detector can now act on a site under a traffic spike, and it challenges visitors without a session rather than blocking them. The challenge ladder set to « record only » no longer serves real challenges.
- FixedThe NYXR Challenge now completes behind a VPN or Tor: its own request was challenged too, so it disappeared without a word. The page shows a progress ring and the elapsed time, then opens the requested page; the invisible mode and the light or dark theme set in the Widget tab now apply.
- FixedThe NYXR Challenge previews and tests in the console work again instead of looping on « Verifying ». They also follow the Widget settings as soon as you change them.
- FixedThe WAF no longer blocks file uploads over 1 MB, forms with many fields or long text fields: the upload size checked now follows each service's limit (25 MB by default). Real uploads and quiz saves had been refused.
- ImprovedEvery tab of « Règles de protection » opens on its own figures: what it stopped, compared with the previous period, the trend and what it targets most. Figures update on their own everywhere, the « Blocage rapide » page included, which now loads in a few seconds instead of about forty.
- AddedYou can select several rows of a table and act on all of them at once: lift bans, switch lists or rules on and off, delete, copy addresses. Page headers and tabs stay at the top while you scroll, and the services table shows the essentials by default.
- FixedSwitching a threat list on or off now applies within two minutes, not up to six hours later. « Définitivement » for an automatic ban becomes 30 days (it lasted one hour), and a scenario's window is now a real sliding window.
- FixedA configuration backup exported from the console can be restored again. Changing a service's protection level applies that level's antibot settings, and switching off the slow-client protection or a destination's minimum severity now really clears them.
A full security review, and what it changes for you
- SecurityA solved challenge is now valid only on the site that issued it. A bot could solve the easiest challenge of a lightly protected site and present the same cookie to a site in strict or "Under attack" mode; it is now refused there and challenged again.
- SecurityAn automatic ban (honeypot, learned rule, rate limit) now applies only to the site that triggered it, and becomes global only when a second site bans the same address. An automatic ban always ends (one hour by default), and a page on another site can no longer get your visitors banned by making their browser open a honeypot.
- SecurityConsole passwords are now stored with argon2id, today's recommended algorithm, and yours is converted automatically at your next sign-in. A two-factor code works only once, failed attempts are counted per account and not only per address, and turning two-factor on or off signs out your other sessions.
- SecurityTurning two-factor off now asks for the code from your app or a backup code: the password alone is no longer enough. If you lost both, an administrator can still reset it for you.
- SecurityYour visitors' cookies, authorization headers and tokens no longer appear in the event details or the live feed, past events included. A live feed also checks its session every minute, so a revoked session stops receiving events.
- SecurityChanging what the firewall enforces - disabling a rule, writing a custom rule, adding an exception, tuning detection or alerts - now requires the Security Admin role. The rules that turn an anomaly score into a block can no longer be disabled, and a custom rule can no longer read files, run a program or switch the audit log off.
- SecurityA service can no longer point to an internal address of the platform (its database, its API, the console, the server itself): that would have published it on the Internet. Only a Global Admin can still do it, deliberately.
- SecurityAn access rule can no longer ALLOW a client by its TLS fingerprint (ja4:, ja4h:): attack tools copy a browser's fingerprint. Blocking or challenging on a fingerprint still works.
- FixedAfter a gateway restart, a site behind conditional access stays closed until its rules are loaded; it used to be open for a few seconds. A configuration the gateway refuses now keeps the site on its last good version instead of leaving it unprotected.
- ImprovedThe platform's master keys are no longer shared by every component: the gateway, the part exposed to the Internet, no longer holds the console's session key, each component has its own access to the shared datastore, and the daily backups are encrypted. As a result, every console user had to sign in again once.
One tab for what protects a site under load
- ImprovedRate limits and adaptive detection share one tab, "Anti-DDoS and rate limits", instead of sitting in two. They answer the same question - what protects this site when the load rises - and reading them together is what makes a decision. A bookmark on either of the old tabs still lands here.
A detector that watches, and a challenge that gets harder
- AddedA new "Adaptive detection" section shows each service compared with its own usual traffic, right now, and lets you decide what happens when it goes above: nothing, a challenge, or a block. Two thresholds are yours to set - above normal, and far above normal - and a service you name is measured but never touched, for a launch or a live event.
- AddedVisitors who keep failing a check now meet a harder one each time: the self-hosted NYXR Challenge first, then the proof of work, then a refusal. Passing one immediately sends them back to the easiest step, so an ordinary visitor with a bad connection never climbs.
- SecurityBoth ship able to do nothing: the detector has to be switched on and set to "Apply" before it can challenge anyone, and being merely above normal is set to do nothing at all by default. Reaching a refusal always takes several counted failures first, never a single judgement.
Rate limits that hold during an attack
- AddedA new "Rate limits" section sets how fast one visitor may go, counted separately by address, by subnet, by network and by endpoint. Several counts can apply at once, which is what stops a botnet that changes address inside the same subnet every request.
- AddedAn access rule can now name the client's SIGNATURE instead of its address: ja4:, ja4h: or fp:, as an allow, a block or a challenge. A farm that changes address every request keeps the same signature, so one rule stops the whole fleet - and the logs say "fingerprint" rather than pretending an address rule matched.
- AddedA rule can be counted on the visitor's TLS signature (its JA4 fingerprint) - the one identity it cannot change. A farm may rotate a thousand addresses in the same network, but the signature is chosen by its software, not by its configuration, so one rule catches the whole fleet where a per-address rule catches nothing.
- AddedTwelve ready-made models cover the usual targets - login, one-time codes, password reset, sign-up, search, GraphQL, WordPress, administration, uploads. Pick one, adjust it, and the check panel tells you whether it actually reaches the address you tested - including when a fingerprint rule cannot apply because the site's TLS does not terminate here.
- ImprovedCounting now happens inside the gateway instead of in the shared database. A burst no longer depends on that database answering, which is precisely when it is least available - and two limits no longer cost two database calls per request.
- AddedA service can now be served over HTTP/2, one service at a time. It is off everywhere by default and the switch sits in the service's configuration: turn it on for a site you can watch, then widen.
- AddedA service can set its own slow-client limits: how long a pause between two reads is tolerated, how long an idle connection stays open, and the ceilings on one upload and one header block. Raise them for a site that receives big files, tighten them for an API. Left off, nothing changes.
- ImprovedThe platform now compares each site's traffic to what it has learned about that site, and reports the ones that are far above it. It reports only: nothing is challenged or refused on that reading yet, so you can look at the real figures on real traffic before anything acts on them.
- SecurityNothing is refused until you say so: the protection starts off and the first step is "test at blank", which counts and logs everything without turning anyone away. A service left in "detect" only records what the rules would have done.
Proposals in one place, a check that shows
- AddedRecommendations now gathers every proposal in one place: the settings suggested from your real traffic, the exceptions for mistaken blocks, and the blocks the learner proposes. Three tabs, and a period you can send to a colleague.
- FixedOn some sites the verification page arrived incomplete: the visitor saw a spinner that never ended, with no check to solve. The page is now served whole, and "Checking your browser" no longer appears twice.
- FixedThe real-traffic test no longer suggests allowing addresses like /.env or /.git. A probe for a secret file is never legitimate traffic, whatever the response code — and the exception it used to propose would have switched off the rule that caught the scanner.
- ImprovedThe icons on the right of the tables (inspect, explain, act) now keep the same spacing in every table, and the same size. Some rows spaced them unevenly, with one icon sitting twice as far from its neighbour.
- FixedOn Bans, a link shared with a period (?since=) now really applies that period: the selector, the tiles and the table all follow it, and the active button is the one you sent.
- ImprovedThe guided tour was out of date: it now presents Recommendations, Quick block and NYXR Challenge, and it starts when you finish the setup instead of on your first visit.
- ImprovedWhen NYXR’s AI writes an advice, a small star under the text says so — in the console, in the webhooks and in the weekly digest. The rule-based text gets no mark.
Site technologies, WAF rules and a cleaner log
- AddedThe robots page now recognises more than 430 robots, sorted into new groups (feed readers, web archives, advertising checks, vulnerability scanners and more), each with Allow, Challenge or Block.
- ImprovedExplanations rephrased by AI are now on by default, bans get a second opinion from a stronger model, and the request log no longer shows old duplicates.
- AddedChoose the AI behind NYXR in Settings: the model NYXR provides, or your own API key with DeepSeek, Mistral, OpenAI or any OpenAI-compatible service, and a model for each job. Your key is stored encrypted and never shown again.
- ImprovedNYXR now runs on DeepSeek V4.1 Flash by default. On real cases it judges suspicious visitors ten times faster, with no mistaken ban in our test, and its rephrased explanations stay true to the figures.
- SecurityA server rented from Google Cloud, Azure or Yandex Cloud could pass for Googlebot, Bingbot or YandexBot and skip bans and scenarios: those clouds carry the same network name as the search engines. Only the lists the search engines publish now prove who a robot is, and a fake Googlebot on Google Cloud is flagged as a fake robot.
- ImprovedThe word « honeypot » now replaces the former term everywhere in the console, in English and in French.
- AddedTell NYXR what each site runs (WordPress, PrestaShop, Laravel, Java…), in the new Technologies tab of the site or when you add it. Requests aimed at any other technology, such as /wp-login.php on a site that is not WordPress, are then blocked: only scanners send them.
- AddedThe Detect button reads the site’s own traffic to suggest its technologies, and warns you if your choice would block addresses your site really answers. Sites you have not described change nothing.
- ImprovedThe WAF page section is now called « WAF rules »: it lists the OWASP CRS rules and the NYXR rules together. Each NYXR rule now has a real description in your language: what it spots, what attack it stops, and when a legitimate request could trip it.
- FixedThe request log shows each request once. A slow request could appear twice before, and a rule in test à blanc could be filed under the WAF instead of the engine that noted it. Rule badges now say NYXR, CRS or WAF, according to where the rule comes from.
- FixedAutomatic certificates now work without a contact e-mail: the first real sites got their Let’s Encrypt certificate straight from NYXR. The NetBird renewal window no longer briefly lifts the protection of a site in Automatic mode.
Getting started and Quick block
- AddedThe new Quick block page lets you choose in one click what NYXR allows, challenges or blocks: AI crawlers, fake robots, Tor and VPNs, countries, admin pages, bruteforce on your login page, scraping and more. Each card shows how many of your requests it would have concerned over 7 days, and warns you before a choice could lock you out.
- AddedEvery change is listed before you apply it, applied as one batch, and can be undone from the History tab. Settings you tuned by hand are never overwritten: the card says « Custom setting » and links to the detailed page.
- AddedThe new Getting started page sets up your first site in about ten minutes: a few questions, then a summary of exactly what will be created, applied in one click. Nothing is blocked before you apply, and a colleague can pick it up where you left off.
- AddedA site that starts in test mode gets a first-day review the next day, then a recommendation to switch protection on when the test ends. It shows what would have been blocked and how many ordinary visitors that concerns, and you can undo it from the History tab.
- ImprovedProtection levels are now called Relaxed, Balanced and Strict everywhere in the console. Relaxed blocks known attacks with no automatic Challenge; before, it only watched.
- FixedThe request log now shows the real reason for a refusal - sensitive file, honeypot, User-Agent rule - instead of « WAF » when the firewall had logged the same request too. Requests noted in test mode are now stored as such, so their review counts them.
Access rules: Challenge, IPv6 and networks
- FixedHoneypots no longer ban real WordPress administrators: the honeypots NYXR ships now cover only files no site ever serves, such as .env or .git/config. You can switch each honeypot off, add your own, or exclude one on a service, in Protection → Fingerprinting.
- AddedAccess rules can now send a Challenge instead of blocking, target every country except the ones you pick, and target a network by its AS number. A rule can also end at a date you choose, and it stops on time even if the console cannot be reached then.
- FixedCountry and network rules now recognise visitors connecting over IPv6, and IPv6 ranges work in access rules, bans and threat lists. Before, an IPv6 visitor slipped past them.
- FixedA ban limited to one service now applies to that service only; it used to block the address everywhere. Bans by AS number are now enforced too, and a WAF exception with an end date stops on time.
Test mode per protection, and sensitive files blocked
- AddedA service can now keep blocking while chosen protections only record what they would have done: tick them on the Protection page, in advanced mode. The page shows when the test started and the end you planned; nothing switches on by itself, you decide after reviewing the results.
- AddedA new switch refuses requests for secret files (.env, .git, database dumps, keys) before they reach your site. It keeps blocking while the rest of the service is in test mode. Leave it off on a code forge or a file share, which serve such files on purpose.
- ImprovedRequest limits can now target a path and a method, for example 5 POST /wp-login.php every 5 minutes. They count every request whatever the answer, which catches a WordPress login that answers 200 after a wrong password. The WAF score measure, which never fired, is no longer offered.
- ImprovedOn each service you can now pick an action per category (VPN, iCloud Private Relay, hosting), the HTTP methods the firewall accepts - WebDAV included - and the machine-only paths that never get a Challenge. Your limits aimed at a precise path still apply there.
- ImprovedA conditional-access rule can run in test mode first, to check that nobody - you included - would be locked out. Under-Attack mode now shows NYXR Challenge by default, lets you choose its duration and leave out services called by apps.
HTTPS certificates: yours or ours
- AddedEach service now chooses its HTTPS certificate on the new Certificates page. "Automatic": NYXR gets a free certificate and renews it for you, as soon as the domain points to NYXR. "Your certificate": you keep the one you buy from your registrar or authority and upload it; NYXR checks it covers the domain, stores its private key encrypted and serves it.
- AddedTo renew your own certificate, upload the new one: the switch happens without interruption and the previous one stays in the history. A renewal token lets your server send it by itself, and you are warned 30, 14, 7, 3 and 1 days before any certificate expires.
- ImprovedThe Certificates page also checks that your domain points to NYXR and that its CAA record lets NYXR obtain a certificate, and tells you exactly what to change otherwise. Services that already use the NetBird certificate keep it unchanged.
Known robots, AI crawlers and fake robots
- AddedProtection → Antibot now has a Robots section: choose Allow, Challenge or Block for AI training crawlers, AI assistants, AI search engines, SEO tools, link previews, monitors and payment webhooks, for all your sites or one of them. Nothing changes until you decide: everything starts on Allow.
- SecurityNYXR now checks that a robot calling itself Googlebot, GPTBot or Stripe really comes from the addresses that company publishes, and spots scripts that pretend to be a browser. These fake robots start in log-only mode: you see them in the request log, and you can challenge or block them in one click.
- ImprovedUser-Agent rules can now present a Challenge instead of only detecting or blocking. NYXR can also add your choices to your robots.txt, so well-behaved AI crawlers know they are not welcome.
Protection and Challenge in a few sentences
- ImprovedThe Protection and NYXR Challenge pages now open on a simple mode: your whole setup in four sentences, what a change would have done to the last 24 hours of real traffic, and the exact list of what will change before you apply it. Every setting is still there under « Advanced », and old links to a tab still open it.
- AddedThe Challenge page shows the real NYXR Challenge as a visitor sees it, in light and dark, with the effort you are choosing: solve it to measure the wait on your own device. Applying a simple setting never overwrites what you tuned in the advanced mode.
Two-factor authentication for the whole team
- SecurityTwo-factor authentication is now required for every console account, by default. An account that does not use it yet is asked to set it up at its next visit, before it can reach anything else: it takes a minute with an authenticator app. A global administrator can make it optional again in Settings → Security, where the console also shows how many accounts still have to set it up.
The NYXR challenge on your own forms
- AddedYou can now protect your own sign-up, login or contact forms with the NYXR challenge, instead of a third-party captcha. Create a key per service in NYXR Challenge → Your applications: the console gives you the code for your page and your server, then shows what your server accepts and refuses. Nothing is loaded from another company: everything is served from your own domain.
- AddedEach application key now has its own Settings tab, with the same controls and the same live test as the Hardening tab: proof of work, browser checks, refusal of automated browsers. The Integration tab confirms as soon as your server checks its first token with the secret.
- SecuritySigning in to the NYXR console no longer goes through Cloudflare Turnstile: the NYXR challenge checks it, with no box to tick. The login page loads nothing from another company any more.
Four attacks the standard rules miss, now blocked
- SecurityNYXR now blocks forged login tokens: tokens that claim to be unsigned, bring their own key, or hide a file path in their key name. Properly signed tokens are not affected, and unsigned tokens some sites use as plain data are only logged.
- SecurityRequests that try to poison a cache, smuggle a second request past a proxy, or get a logged-in page stored as a public file are now blocked. Before release, these rules were replayed against one million real requests without blocking a single legitimate one.
- SecurityThe AI assistant reads logs written by your visitors, so sometimes by an attacker. Its answers no longer show images, and a link pointing outside the console is shown as plain text instead of being clickable. An instruction hidden inside a request therefore has no way to send your data elsewhere.
- FixedForms and API calls declaring the UTF-8 character set were refused by the attack filter even with no attack in them. They now go through normally; the rest of the filtering is unchanged.
A reference that links the block page to the log, and a European AI
- AddedEvery block, challenge and login page now ends with a reference number. A visitor who was refused can quote it, and you paste it into the request log to land on their exact request.
- SecurityThe block page no longer loads anything from Google or an image host. Until now, every visitor NYXR blocked had their address handed to two companies with no part in the decision. Everything is served from your own server, and the page looks exactly the same.
- ImprovedThe AI that judges borderline visitors now runs on a French model hosted in Europe, instead of a non-European provider. What NYXR sends has not changed - it simply no longer leaves the EU to be judged. The key stays optional: without one, NYXR decides on its own.
- ImprovedVerdicts come back several times faster, and that changes the outcome, not just the wait. The judgement that runs before a ban now finishes in time, instead of giving up and leaving the decision to the raw score.
- SecurityA proposed ban is now reviewed a second time before it applies, and that review can only soften it. This protects the ordinary visitor whose browser trips a few strict rules and looks, at a glance, exactly like a scanner.
- ImprovedThe assistant talks about your protection instead of about itself. It now tells you what is being attacked, what was stopped, what got through, and what to change next.
- SecurityThe assistant can no longer be talked into repeating its own instructions. Text planted in the data it analyses - a URL, a browser name, a log line - is still treated as evidence to report, never as an instruction to follow.
- ImprovedThe assistant answers shorter, and a reply now opens at its first line instead of scrolling you to the end. The message box shows how much room is left and stops at the limit.
- FixedThe credit estimate now uses the new provider’s prices and starts a fresh count, so the balance shown matches the account actually being billed. Re-enter your starting balance on the Alerts page.
NYXR Challenge gets its own page, and an activity report
- AddedNYXR Challenge now has its own page: how many visitors it checks, who passes and from where, which addresses it refuses, and how hard it is to pass. Everything is read through your own login.
- AddedA button on the Hardening tab solves a real challenge with your current settings and reports how long it took. "Difficulty 7" means nothing until you have waited for it - and every human visitor pays that wait.
- AddedNYXR now checks how a visitor connects against the browser it claims to be. A scraper can copy a Chrome browser name perfectly and still be caught the moment its connection is read. Real Chrome and Firefox pass untouched.
- AddedOne Fingerprinting tab replaces the two separate ones, and it opens with what the challenge actually measured. A signature that never passes is not a browser, whatever it claims; one that passes in milliseconds is a solving farm.
- AddedA harder challenge is now served automatically once a visitor’s behaviour score crosses a limit you choose. Protection rules and per-service settings can also pick which check they serve.
- AddedA new Activity report page: traffic handled, threats stopped, coverage and risk over a period, next to the one before. Searchable, filterable and exportable.
- AddedA second connection signature, JA4H, is now recorded alongside the first, so what NYXR sees can be compared against published threat research.
- ImprovedEvery figure in the console now respects the service and the period you selected. A number that silently ignores the filter above it is worse than no number.
- ImprovedThe attack-filtering rules move thirteen releases forward, to OWASP CRS 4.29. The full test suite ran before and after, including a set of legitimate requests, so the stricter rules are known not to start refusing normal traffic.
- ImprovedTables read correctly again: row striping and the hover highlight span the full width instead of stopping at the pinned columns.
- FixedSolving a challenge did not let you through. One real visitor solved 108 challenges in five minutes before we caught it, and every service that challenges was affected.
- FixedThe pass a visitor earns is now tied to their address alone. It also depended on details that legitimately change between the check and the next page load - one visitor showed five of them in a single session.
- FixedTurning bot checks off for a service did nothing at all - visitors were still challenged. It now silences the checks, while bans and traffic limits stay on: those are abuse controls, and "no captchas" does not mean "no protection".
- FixedThe slow-scraper rule challenged anyone above 80 requests a minute, images and scripts included. One shared school connection browsing a normal site peaked at 124. The limit is now 600.
- FixedA visitor whose browser could not reach Turnstile - a VPN, a content blocker, a company proxy - was stuck in an endless loop of challenges. NYXR now falls back to its own check once Turnstile has visibly failed to load.
- FixedA refused challenge answer was read as an outage and quietly downgraded the visitor to the easier check, so anyone could get the easy gate by sending deliberate junk. A refusal is now a refusal.
- FixedConnection signatures were empty on every request - 30,032 in a row - for two separate reasons. Both are fixed, and the signature now matches the reference implementation exactly.
- FixedThe request signature was thrown away entirely on HTTP/2, which is where browsers actually are, and undercounted headers by one on HTTP/1.1.
- FixedThe deploy script announced "all containers healthy" while one was crash-looping. It now checks every container, fails loudly, and prints the logs.
- SecurityThe attack-filtering rules were downloaded without any integrity check, so every build so far compiled an unverified ruleset into the WAF. The download is now pinned to a signed release, and the build fails on a mismatch.
- SecurityA solved challenge can no longer be replayed or handed to someone else: each answer is single-use, and the pass it earns is tied to the visitor who earned it.
Base rules for 15 technologies, and a live scoring simulator
- AddedA base rule set covering 70 sensitive paths across 15 technologies, split between outright secrets and merely sensitive files. Checked against 30 days of real traffic first: of the 101 matching requests that had been allowed through, all 101 were genuine probes.
- AddedA live scoring simulator on the Protection page: move a threshold and see immediately which visitors it would have caught, and which legitimate ones it would have cost. Next to it, a notice names any service that is tuned but not actually blocking.
- ImprovedA visitor hunting for secrets - configuration files, keys, backup archives - now makes its whole group hostile and heads towards a block, instead of being scored one request at a time.
VPN, iCloud Private Relay and hosting detection
- AddedVisitors arriving through a commercial VPN, Apple iCloud Private Relay or a hosting network are now recognised and labelled on every request, allowed traffic included, with a badge and a filter in the request log.
- AddedA card decides what each kind means - label only, challenge or block - with your own lists, exempt paths, an always-allow list, an exemption for search engines, and a lookup naming every list an address is on.
- ImprovedThe country databases behind country rules and the flags you see are kept up to date automatically, for free and within a daily budget, so repeated setup runs no longer exhaust the MaxMind download limit.
Tor detection, and one protection level per service
- AddedVisitors arriving over Tor are now recognised and labelled on every request, allowed traffic included, with a badge and a filter. Exit nodes and relays are tracked separately - only an exit legitimately carries a real person.
- AddedA Tor card decides what detection does - label only, challenge or block - chosen per node kind, with your own node lists, exempt paths, an always-allow list, and a lookup showing exactly what the gateway would decide for an address.
- AddedA private service can now refuse Tor visitors, ask them for a code even when their address is trusted, or exempt them from a country rule that cannot apply to them - a Tor visitor’s country is the exit relay’s, not theirs.
- AddedEach service now carries a single protection level - Off, Basic, Standard or Strict - instead of eight separate switches. It is read back from the real settings, so it says Custom as soon as you tune one and can never claim a protection that is not in force.
- FixedThe protection switch is no longer shown to people who cannot use it, where every attempt ended in a permission error and the control looked broken. It also shows the real saved state after a failed attempt.
- FixedThe dashboard no longer asks for the same figures twice per refresh, and its second panel shows the rule that fired most and the page most aimed at, instead of repeating what the tiles above already say.
- SecurityTor node lists are stripped of private address ranges before use and checked again on every request, so a poisoned list cannot label your internal traffic. A list that fails to refresh keeps its previous addresses rather than silently un-labelling everyone.
Honest threat-list figures, and a configuration you can export
- FixedThreat-list contribution now reports the requests each list actually blocked over the period you chose, credited to the exact address or range that matched. It no longer presents the size of a list as if it were enforcement.
- FixedThe shared AI credit count now records assistant use from every user, not just some, alongside behaviour verdicts and learned labels.
- AddedSettings can export and restore your whole platform configuration as one file, checked before it is applied, with full audit history and a notification when it changes.
- ImprovedLearned rules and signatures now use the same table as the rest of the console: search, per-column filters, selection, CSV export, details and pagination.
- ImprovedBehaviour score sections start collapsed for a clearer overview, and every control now says whether it is on the default value or one you set.
- ImprovedThe language, theme, search and Under Attack controls line up at the same height in the top bar.
- SecurityEvery dependency is updated to its latest compatible release, and the production audit reports no known vulnerability.
Honest enforcement, and complete French
- FixedThe request log now keeps long addresses and provider names inside the card on a phone, and its single paginator is the only navigation control.
- FixedFrench mode now uses 24-hour times on charts, translated country, theme and audit labels, and French explanations for new AI decisions.
- SecurityBehaviour scoring loads its real default weights before you edit or save, so an untouched configuration can no longer be saved as zero protection.
- ImprovedSelecting an access-list entry opens its details, and the person who created it is shown by name and email instead of an internal identifier.
- FixedA request or an AI recommendation is no longer shown as an applied ban when no ban was actually recorded.
- SecurityThe audit log records the real operator address again after a network is recreated, instead of trusting one stale internal range.
- AddedThe security summary now checks that backups completed, that a restore was actually tested, which configuration is live and whether monitoring is running. Anything degraded or missing counts as action required.
- FixedA ban decided by the gateway now carries its exact evidence into a real ban record, gets an immediate explanation in both languages, and is retried after an outage instead of staying invisible.
A task-based console, usable on a phone
- ImprovedThe console is reorganised into five task-based spaces, with a Ctrl/Cmd+K command palette, instant navigation and a single breadcrumb in the header instead of repeated page trails.
- ImprovedThe whole console works on phones and tablets: 44-pixel touch targets, a compact tablet rail, reduced-motion support and no horizontal scrolling.
- ImprovedThe request log becomes cards on a narrow screen and a fixed table on a wide one, with the filters kept in the URL so a view stays shareable.
- AddedA search in the request log can be saved as a private or team view, reopened in one click, and deleted by its owner or an administrator.
- ImprovedThe dashboard service filter and the threat period and country filters are kept in the URL, and now drive every figure, chart and detail below them.
- AddedA read-only security summary, built from your real settings, your environment, two-factor coverage, list health and active sessions.
- FixedThe audit log shows account names and emails instead of internal identifiers, handles deleted accounts explicitly, and hides secrets in the before and after values.
- SecurityTurning on firewall-level blocking now requires typing the exact network interface name, and what you can do follows your real permissions rather than what happens to be hidden.
- FixedFixing a false alarm now opens a real preview backed by the evidence and creates the exception, instead of copying an unusable search snippet.
- AddedThe request log filters on every field it records: service, decision, severity, method, status, path, address, country, rule, reason, provider, browser, scores, period and signature.
- ImprovedRequest details now explain the whole decision: every rule that matched, the scores, the signals that counted, and which threat list named the address.
- SecurityThe real visitor address is taken from the gateway itself rather than re-read from headers anyone can forge. Old rows wrongly attributed to an internal address are repaired.
- FixedThe attack map loads in production again - its dependencies are now included in the console image.
- AddedAn access-list entry can be edited in place. Every change is recorded and applies to the gateway immediately.
- FixedTicking a row to select it no longer opens that row’s details.
- SecurityAsking the AI about a selection now shows a summary card and stores only that summary in history, never the prepared question or the raw data.
- SecurityThe default automatic ban for repeated scanning goes from 24 hours to 7 days.
- AddedAlerts can go to Discord, Slack, Microsoft Teams and Telegram, with encrypted credentials, routing per destination by event, severity and service, and a test message that looks native to each one.
- ImprovedBefore you excuse a rule, the dialog shows the full request, what the rule detects, exactly what matched, and 30 days of history - then the change it will make.
- ImprovedBehaviour scoring is reorganised around a clear path from signal to action, in three guided groups, without losing a single control.
- FixedAn automatic ban shows its latest evidence in the console, and AI recommendations, blocked requests and bans actually in force are now three distinct things instead of one ambiguous verdict.
- FixedThe Protection navigation stays in the page instead of floating in the middle of the screen.
Bulk actions and keyboard shortcuts on the WAF rules
- AddedSelect several WAF rules and turn them all on or off at once. If one fails, the run stops there rather than leaving the table half applied.
- AddedPress / anywhere on the WAF page to jump to the search box, and Esc to clear it.
- AddedEvery rule number links to its source on the OWASP CRS repository, and every category to its directory.
- ImprovedThe traffic-replay panel was rebuilt on one shared, tested helper, so its filters behave the same everywhere.
- ImprovedThe request log keeps its cells and its row menu in step, so an action started in one is reflected in the other.
- SecurityExternal documentation links no longer leak the page you came from, and cannot take over the tab that opened them.
A WAF health score, and false alarms fixed in one click
- AddedA WAF health score out of 100, combining coverage, rules left on, recent blocks and whether the gateway answers, with a breakdown per criterion.
- AddedThe traffic-replay panel gains a period, a service picker and a rule filter, with a reset button and chips so you always know which slice you are looking at.
- AddedEach likely false alarm offers three actions: turn it into a targeted exception, pin the rule for later, or hide it for seven days.
- ImprovedIn the request log, the rule badge and the path are buttons that open the exception dialog pre-filled with what you clicked. The menu adds "See similar requests".
- ImprovedA one-click "Filter by IP" button sits next to the address, instead of hiding in the row menu.
- ImprovedYou can create an exception from a request that was only recorded, not blocked - which is exactly when you want to head off a future block.
- ImprovedThe Services table leads with a coloured badge - Off, Detect or Block, each with its own icon - while the mode picker stays one click away.
- SecurityNo new attack surface: every new screen uses the existing authenticated endpoints, and local preferences are grouped so they can all be cleared at once.
The client fingerprint engine, and deeper investigation views
- SecurityNYXR now scores how coherent a visitor is - the way it connects, the order of its headers, the headers a real browser would send - while staying observe-only by default.
- AddedThe request log shows signature details, what drove the score, how much traffic is covered, and quick filters for a signature, poor coherence or a reputation threshold.
- AddedA signature can now be investigated: timeline, top addresses, top paths, top browsers, frequency, reputation, and your own decision to allow or block it.
- ImprovedProtection adds an explicit fingerprint mode: Observe by default, Block only when you turn it on.
- ImprovedThe nine-step diagram on the public site now follows the real order the gateway runs, not a simplified marketing sequence.
- SecurityThe gateway now uses the compiled reputation data, with observe, challenge or block per service, protection against malformed requests, a fast path for verified search engines, and honeypots baited with plausible fake data.
- AddedReplay and auto-tuning screens show how many past requests a rule would have blocked, and which noisy rules deserve a targeted exception rather than being switched off entirely.
- AddedA request explanation now includes the full decision timeline, from the real address through access, threat lists, bans, bot checks, reputation, learned rules, limits and the WAF.
- AddedBot detection adds a campaign workbench for groups of addresses acting alike, with review controls that act on the whole group.
Fewer pages, clearer navigation
- ImprovedBans and AI decisions are now one page: active bans, the reasoning behind them and the automatic ban rules, in a single view.
- ImprovedBot detection moved into the Protection page as a fourth tab, next to service settings, behaviour scores and automatic rules.
- ImprovedThreat lists now sit below the analysis on the Threats page, and Reports redirects to the request log - eight pages become five.
- ImprovedThe header shows the section and the page name, so you always know where you are.
- FixedThe theme switch no longer crashes the console on first load.
- FixedAuto-deploy rebuilds the images when the code changes. It used to only restart containers, leaving new code unshipped.
Why does this address have this score?
- ImprovedThe whole project moves to current major versions: TypeScript 6, Zod 4, React 19, Astro 7 and more.
- FixedEvery deprecation warning from those upgrades was fixed rather than silenced.
- AddedA "Why does this address have this score?" inspector: which threat lists name it, how much each is trusted, the category, what it triggers, and when it was first and last seen. Turning a list off is now an informed decision.
- ImprovedThe new inspector and the targeted WAF exception dialog are fully bilingual.
Firewall bans work again, and the start of bot learning
- SecurityFirewall-level bans are enforced again. The helper was crashing and silently applying nothing; banned addresses are now dropped before they reach the proxy.
- FixedA threat list naming a private network range was blocking your own infrastructure. Private ranges are now stripped on import, with a second check at the gateway.
- AddedGroundwork for bot learning: a layer that profiles visitors, learns what normal traffic looks like on each service, and proposes detections for you to approve. Shipping in stages.
Uploads work again, plus a guided tour and a health board
- FixedMedia services no longer block legitimate file and audio uploads. Two rules were tripping on browser recordings and large images; they are now relaxed on the upload pages only, so the rest of the service stays fully inspected.
- AddedA guided tour on first sign-in walks you through the console, with a replay button in Settings.
- AddedA health board lists every component with its live status, read through a read-only connection.
- AddedAI credit tracking for the assistant and for behaviour decisions, with an alert when it runs low.
- ImprovedThe whole console and the public site are fully bilingual, with an instant language switch and no page reload.
- ImprovedRicher Discord alerts: a colour per severity, context fields and a direct link back into the console.
A faster assistant, seamless navigation and one alert style
- FixedThe assistant replies in seconds again. It had stopped answering after the anti-injection hardening; the safeguards are intact.
- ImprovedMoving between the public site, the console and this page is instant, with no full reload and no flash.
- ImprovedOne notification style across the console, with a contextual action and a dismiss button.
- ImprovedThis page was rebuilt as a clean release timeline.
Console consolidation and polish
- ImprovedPerformance merged into Health, and Bans into AI decisions, with a redesigned bans view.
- ImprovedBetter contrast in the light theme, and the traffic legend icons now match each curve colour.
- FixedAccessibility fixes across the console, the sign-in page and this one.
Tables, the AI assistant and this page
- AddedOne table toolkit everywhere: search, per-column filters, click-to-sort, multi-select and CSV export.
- Added"Ask AI" on a selection: send a set of requests or decisions to the assistant for analysis, with the data treated as untrusted.
- AddedThis page, reachable from the console and from the public site.
- SecurityThe assistant is hardened against prompt injection: anything you or a tool feeds it is data, never an instruction.
- FixedAssistant conversations replay in order, oldest message first.
- FixedSection tabs sit flush left instead of stretching the full width.
- ImprovedSubtle row striping, and a cleaner selection and export bar.
Detect mode really is observe-only
- FixedA service in detect or off mode no longer challenges or rate-limits anyone. Only block mode acts, so detect and off are genuinely observe-only.
The public NYXR site, and a console home
- AddedA public NYXR site with an animated hero, the nine-step engine diagram and a faithful console preview.
- ImprovedThe public site now lives at /, the console at /dashboard, and sign-in at /login.
Private services
- AddedPut a login in front of any service: a country rule, a code from an authenticator app, a shared password or a trusted address. It cannot be bypassed, and if the check itself fails the door stays shut.
- AddedA limit on failed attempts per policy, with a proper block page on lockout.
- ImprovedAccess lists and private services merged into a single workspace.
- ImprovedBlock, challenge and login pages redesigned in your colours.
Firewall-level bans, and the AI verdict
- AddedConfirmed bans are dropped at the firewall itself - off, log or drop.
- ImprovedAn AI "allow" reaches all the way down to the firewall, lifting an over-eager automatic ban.
- AddedA read-only AI assistant, with conversation history per user.
The gateway
- AddedThe WAF (ModSecurity and OWASP CRS), filtering by address, provider, country and threat list, bot checks, traffic limits and behaviour-based bans.
- AddedA real-time admin console with live logs, dashboards and centralised monitoring.