Hot on the heels of the slightly earlier update to XProtect, Apple has just released an update to XProtect Remediator security software for Catalina or later, bringing it to version 137.
Apple doesn't release information about what security issues this update might add or change. There are no new scanning modules. Bastion rules see several changes, though. XPR's WaterNet scanner is added to bastion-usual-offenders list, a duplicate removed, and apfsd added. A list of Rule 12 offenders is added, and Rules 6, 7 and 12 are amended. InfoStealer is also added to the list for immediate reporting. If you're following Bastion Rules, these repay careful study.
You can check whether this update has been installed by opening System Information via About This Mac, and selecting the Installations item under Software.
A full listing of security data file versions is given by SilentKnight, LockRattler and SystHist for El Capitan to Sonoma available from their product page. If your Mac has not yet installed these updates, you can force them using SilentKnight, LockRattler, or at the command line.
If you want to install this as a named update in SilentKnight, its label is XProtectPayloads_10_15-137
.
I have updated the reference pages here which are accessed directly from LockRattler 4.2 and later using its Check blog button.
I maintain lists of the current versions of security data files for Sonoma on this page, Ventura on this page, Monterey on this page, Big Sur on this page, Catalina on this page, Mojave on this page, High Sierra on this page, Sierra on this page, and El Capitan on this page.