Release V3.3
Version 3.3 introduces Direct Message Injection for Microsoft 365, a new user lifecycle with Active, Archived, and Deleted states, and a User Import Wizard with workbook support. The Report-a-Phish Button gains configurable routing, extended Outlook and on-premises Exchange support, and new forwarding options. For enterprise environments, this release adds TLS encryption for outbound emails, proxy support, and downloadable system and message logs. The User Portal has been hardened: access via unique links has been removed, so organizations using the portal without SSO need to take action after the update.
Important Changes and Action Required
User Management
Users now have an Active, Archived, or Deleted status, so campaign statistics are preserved even after users leave the organization. Users removed from all Base Groups, manually or via LDAP/Azure sync, are archived automatically instead of being deleted, and restored with their history when re-added. Operators can also restore archived users manually. Deletion is optional: archived users can be deleted manually or automatically after a configurable retention period. On deletion, personal data is replaced by an ID.
Action required: By default, archived users are kept until they are manually deleted. We recommend configuring automatic deletion with a retention period that matches your requirements.
User Portal Hardening
User Portal security has been enhanced so the portal can take a more central role in upcoming releases, such as displaying statistics to stakeholders and users. Access via unique links has been removed. Users must now authenticate via SSO or username and password, and MFA can be enforced.
Action required: If your organization uses the User Portal without SSO, existing Portal users are asked to complete the new authentication process to continue using the portal after the V3.3 update. We recommend resending the User Portal invitations and reviewing your Portal configuration.
New Features
Direct Message Injection for Microsoft 365
Cyberdise now supports Direct Message Injection (DMI) for Microsoft 365, delivering simulated emails directly to users’ inboxes via the Microsoft Graph API. This improves delivery reliability by bypassing SMTP filtering, including spam filters, antivirus, and transport rules, and reduces the need for complex whitelisting configurations.
User Import Wizard with Workbook Support
The new User Import Wizard supports XLSX and ODS files. Operators can select worksheets, map fields, preview data, and choose whether existing records are updated, skipped, or overwritten. Built-in validation and data cleansing identify invalid records, and a downloadable import summary lists imported and rejected users.
Template Import and Export
Templates can now be imported and exported in SCORM and Cyberdise formats, including all components: messages, landing pages, lures, metadata, and all language versions.
System and Message Logs
A new Logs page under Settings allows Tenant Operators to download service logs, including nginx, Postfix, and PostgreSQL, as a compressed archive. Campaign schedules can also display message-specific logs directly on the Schedule page, making it easier to investigate delivery or processing issues.
TLS Encryption for Outbound Emails
Outbound emails are now encrypted via TLS whenever the receiving mail server supports it. Delivery to servers without TLS support remains unaffected.
Proxy Support
On-premises installations now support proxies. Super Admins can configure the proxy URL and no-proxy settings, enabling Cyberdise to run in network environments without a direct outbound route.
Optional DNS Verification for Domains
Operators can now skip DNS A-record verification when adding a domain, so domains don’t have to point to the Cyberdise server. This supports the use of a proxy.
Fancy Background Effect
A new Background Effect option under System Settings > Whitelabel lets operators enable an animated background for the interface and login page.
Improvements
Report-a-Phish Button: Flexible Routing
Administrators can now configure how reported emails are handled. Cyberdise simulated emails can be reported directly to Cyberdise without external forwarding, while other suspicious messages can be routed to external mailboxes. Available for Outlook and Gmail.
Report-a-Phish Button: Extended Outlook Support
Users can now report emails from shared mailboxes, group addresses, and additional external accounts configured in Outlook, not just their primary mailbox.
Report-a-Phish Button: Exchange and On-Premises Support
The button now supports Exchange and on-premises installations via EWS, with no Azure integration required. This includes on-premises Exchange and compatible third-party mail configurations.
Report-a-Phish Button: Improved Message Forwarding (Outlook)
A new HTML email forwarding option preserves reported messages with minimal changes, alongside the existing Picture (Base64) method. Reported emails can also be forwarded as EML attachments to retain the original content and structure for analysis.
Configurable Link Targets in File Templates
Link variables in file templates can now point to different destinations, including login pages, post-login pages, dedicated module pages, trainings, files, and external links. Link openings remain tracked.