Combolist Backlog Ingestion
Shared Data Assets
Console
API
Portal
A large backlog of combolists is being ingested and deduplicated.
- Customers may see new unique credential pairs appear in the UI and APIs.
- No email alerts or webhooks are triggered for combolist matches tied to this backlog ingestion.
- Backlog ingests will continue throughout April, May, and June 2026.
Navigation and Workflow Efficiency Improvements
Workforce Threat Protection
Endpoint Threat Protection
Console
Reduced friction navigating from notifications into relevant workflows and destination pages.
- Added shallow link support for Breach Alerts, enabling direct linking into alert context.
- Data export emails now include a direct link to the Exports page.
Records and Investigations Enhancements
Workforce Threat Protection
Console
Improved investigative context, data accuracy, and view persistence in the Records tab.
- Username is now a default column for infected users in the Records tab.
- Phish Time is now available as an optional column.
- Optional column selections persist across sessions — no need to reconfigure on each visit.
- Fixed exposed asset and login credential counts for improved data accuracy.
Data Grid and Table Usability Upgrades
Workforce Threat Protection
Endpoint Threat Protection
Console
A set of stability and usability improvements for data-heavy table views.
- Implemented broader DataGrid persistence across sessions.
- Enabled automatic column pinning during horizontal scrolling.
- Fixed page reset behavior when filters change.
- Corrected watchlist column alignment issues in Workforce Settings.
Endpoint Devices Expanded Coverage
Endpoint Threat Protection
Console
Continued foundational investment in Endpoint Devices to support a more stable and scalable experience.
- Added seeded scenarios and search and filtering support in automated flows.
- Expanded test plan and page object coverage for Endpoint Devices.
Export and Enterprise Behavior Updates
Workforce Threat Protection
Console
Improved consistency and guardrails for export actions and enterprise user permissions.
- Updated export terminology from "Email" to "Domains" for Workforce exports.
- Disabled export from All Records when a date filter is present, preventing unsupported export actions.
- Hid the Delete All option for enterprise users where it is not applicable.
UI Consistency and Cleanup
Workforce Threat Protection
Endpoint Threat Protection
Console
Copy, skeleton, and cleanup fixes to align the interface with current product functionality.
- Shipped copy updates and fixed skeleton loading behavior.
- Resolved a domain dropdown issue.
- Removed remaining email identifier references from latest watchlist events and related areas.
Reliability and Release Confidence
Workforce Threat Protection
Endpoint Threat Protection
Console
Expanded automated coverage and supporting reliability updates to improve product stability across environments.
- Expanded end-to-end and multi-environment test coverage, including password reuse verification flows.
- Supporting reliability updates including timeout adjustments and infrastructure maintenance.
New Data Assets
Shared Data Assets
API
Portal
New breach metadata fields are now available for newly ingested breach records.
- Every new breach record now includes
breach_title and breach_category.
- Where available, records now also include
phone_full and ec_phone_full with country code.
- Applies across supported APIs and Vela v1.