📢 Release Notes

August 2026

August 13, 2026

Introducing Executive Reports for Workforce and Endpoint

Workforce Threat Protection Endpoint Threat Protection Console

Executive Reports generate a boardroom-ready summary of workforce and endpoint exposure straight from the same data your team already investigates, so security leaders can walk into a leadership meeting with a clean, evidence-backed picture of risk instead of building a deck by hand. The report is now generally available, built to handle significantly larger exposure datasets and presented in a more polished, streamlined layout.

  • Generates a leadership-ready summary of exposure across Workforce and Endpoint, sized for a boardroom audience rather than an analyst one.
  • Processes up to 10,000 exposure records in a single run, with a clear, actionable message if a request still needs to be narrowed.
  • Available in one click: generate the report directly from Workforce or Endpoint, with no manual data pulls or deck-building required.
  • Contextual recommendations: cross-references your exposure against SpyCloud Labs research to surface related publications and recommendations tailored to your specific risk profile.
August 12, 2026

ADG 7.5.1 Configuration Migration and Installer Fixes

AD Guardian Installer

AD Guardian 7.5.1 is a patch release fixing two issues in configuration migration and the installer. Previously, importing a configuration exported from an existing ADG installation could silently fail whenever the export included encrypted secrets, leaving remediations, webhooks, and schedules missing and new remediation policies impossible to set. Separately, the installer stripped spaces out of Admin Group and Viewer Group names as they were typed, forcing a workaround of typing the name without spaces and inserting them afterward. Both are fixed in 7.5.1.

  • Config import restored: importing a configuration exported from a previous ADG installation now correctly restores remediations, webhooks, and schedules, even when the export includes encrypted secrets.
  • Installer group name input fixed: Admin Group and Viewer Group fields now accept names containing spaces (for example, "Domain Admins") typed normally, left to right.
August 5, 2026

Identity Guardian Revocation Reliability Improvements

Identity Guardian Console

Identity Guardian revokes exposed users' sessions across a customer's configured Okta and Entra tenants. Previously, exclusion rules could fail silently — wildcard entries were ignored and exact-email entries could throw a save error — so excluded users could still be revoked, and the Retry confirmation showed a misleading count of total ledger entries instead of tenants actually retried.

  • Wildcard exclusions (for example, *@domain.com) now correctly exclude matching users from revocation, and exact email entries save without error.
  • The Retry confirmation now shows the accurate count of IdP tenants being retried instead of total ledger entries.

July 2026

July 22, 2026

New Session Status and Cookie Detail Columns

Workforce Threat Protection Console

Records tables now surface which exposed sessions are still active at a glance. Previously, checking whether a session's cookie was still live meant opening each record individually. The Recent and All Records tables now show a Session Status tag plus cookie domain and expiration detail.

  • Session Status (Active/Expired), Cookie Domain, and an optional Cookie Expiration column let teams prioritize still-live sessions directly from the table.
  • Helps teams spot and remediate active Sev 30 exposures without opening every record.
  • Stay on top of session exposure across your workforce and act before still-live sessions can be abused.
July 22, 2026

Identity Guardian Partial Remediation and Notification Controls

Identity Guardian Console

Identity Guardian now handles mixed Okta and Entra results and lets teams finish the job when only some tenants succeed. Previously, a partial result showed the same "Revoked" status as a full success, with no way to retry failed tenants without leaving the product. A new Retry re-attempts only the tenants that failed.

  • Targeted Retry re-runs only outstanding tenants across Revoked, Failed, and Not In IdP statuses, in manual and automatic modes.
  • Admins can now direct session-revoked email alerts to up to 10 dedicated recipients.
July 22, 2026

Source Type Filter Added to All Records

Workforce Threat Protection Console

Users can now filter the All Records and Recent Records pages by Source Type. Previously, narrowing results to a category like breach or malware meant manually scanning the Source Name column. The new filter works alongside Severity, adds a matching table column, and persists in the URL.

  • Multi-select Source Type filter combines with existing filters and shares via URL.
  • A new Source Type column adds at-a-glance category visibility.
July 22, 2026

Enterprise Admins Can Self-Serve SCIM Setup

Core Platform Console

Enterprise admins can now turn on SCIM provisioning themselves right after enabling SSO. Previously the "Turn On SCIM" button was clickable but a backend permission gap silently blocked it, forcing admins through support. That gap is closed — the flow now completes end to end in the same session.

  • Enable SCIM from Configuration > Settings and get your endpoint URL and token immediately, no support ticket required.
  • Available to enterprise admins with SSO already configured.
July 10, 2026

Removing Searches and Records with Research Agent (Pro Only)

Cybercrime Investigations Console

Analysts can now ask the Research Agent to remove a specific query — and all records tied to it — from an active investigation. Previously there was no way to prune unfruitful queries once executed, so dead ends stayed in the thread. This gives direct control over the context window.

  • Removed records drop from both the result count and the agent's working context, so subsequent reasoning runs only on the relevant set.
  • Keeps investigations minimally noisy by clearing dead ends as you go.

June 2026

June 24, 2026

Research Agent (Pro Only)

Investigations Console

Analysts can now run investigations by describing what they're looking for in plain English. Instead of building manual searches, the Research Agent handles the querying, synthesis, and insight generation automatically — cutting mean time to insight across ATO, fraud, insider threat, and supply chain investigations.

  • Launch from a natural language prompt or a starter template, follow the agent's reasoning in real time, and continue with follow-up questions in chat.
  • Available as an enhancement within the existing Investigations Pro experience.
  • Every type of core investigation is supported, grounded in SpyCloud investigative tradecraft.

April 2026

April 16, 2026

Endpoint Graph View

Endpoint Threat Protection Console

A new Graph tab in Endpoint visualizes device relationships, giving users a more intuitive way to understand connections between devices, domains, and associated users.

  • Graph surfaces domain logos and user details directly within the experience.
  • Reduces reliance on table-only investigation flows for relationship analysis.
April 16, 2026

Shareable Filters and URL-Persistent Navigation

Endpoint Threat Protection Console

Search and status filters on the Devices and Applications views now persist in the URL, enabling shareable links and browser back/forward navigation.

  • Users can save, share, and return to specific filtered views without manually recreating them.
  • Improves collaboration and reduces friction across Endpoint investigation workflows.
April 16, 2026

Devices Tab Error Handling and Watchlist Retry Logic

Endpoint Threat Protection Console

Improved error states, messaging, and retry logic across the Devices tab and workforce watchlist workflows.

  • Enhanced error handling and retry logic for adding workforce watchlists.
  • Clearer failure-state messaging reduces dead ends during investigation and response workflows.
April 16, 2026

UI Clarity and Interaction Refinements

Endpoint Threat Protection Console

Focused UI improvements to reduce visual noise and improve consistency during investigations.

  • Updated glossary drawer descriptions for accuracy.
  • Added row highlighting on selection for Sightings.
  • Loading totals are now hidden until data is fully ready, eliminating loading-state flicker.
April 16, 2026

API Documentation and Test Coverage Improvements

Endpoint Threat Protection Console

Behind-the-scenes investments to improve engineering efficiency, release quality, and API documentation.

  • Expanded end-to-end test coverage for watchlist verification flows.
  • Added Swagger/OpenAPI documentation generation for the API.
  • Improved auto-deploy workflows for test environments.

March 2026

March 31, 2026

Combolist Backlog Ingestion

Shared Data Assets Console API Portal

A large backlog of combolists is being ingested and deduplicated.

  • Customers may see new unique credential pairs appear in the UI and APIs.
  • No email alerts or webhooks are triggered for combolist matches tied to this backlog ingestion.
  • Backlog ingests will continue throughout April, May, and June 2026.
March 18, 2026

Navigation and Workflow Efficiency Improvements

Workforce Threat Protection Endpoint Threat Protection Console

Reduced friction navigating from notifications into relevant workflows and destination pages.

  • Added shallow link support for Breach Alerts, enabling direct linking into alert context.
  • Data export emails now include a direct link to the Exports page.
March 18, 2026

Records and Investigations Enhancements

Workforce Threat Protection Console

Improved investigative context, data accuracy, and view persistence in the Records tab.

  • Username is now a default column for infected users in the Records tab.
  • Phish Time is now available as an optional column.
  • Optional column selections persist across sessions — no need to reconfigure on each visit.
  • Fixed exposed asset and login credential counts for improved data accuracy.
March 18, 2026

Data Grid and Table Usability Upgrades

Workforce Threat Protection Endpoint Threat Protection Console

A set of stability and usability improvements for data-heavy table views.

  • Implemented broader DataGrid persistence across sessions.
  • Enabled automatic column pinning during horizontal scrolling.
  • Fixed page reset behavior when filters change.
  • Corrected watchlist column alignment issues in Workforce Settings.
March 18, 2026

Endpoint Devices Expanded Coverage

Endpoint Threat Protection Console

Continued foundational investment in Endpoint Devices to support a more stable and scalable experience.

  • Added seeded scenarios and search and filtering support in automated flows.
  • Expanded test plan and page object coverage for Endpoint Devices.
March 18, 2026

Export and Enterprise Behavior Updates

Workforce Threat Protection Console

Improved consistency and guardrails for export actions and enterprise user permissions.

  • Updated export terminology from "Email" to "Domains" for Workforce exports.
  • Disabled export from All Records when a date filter is present, preventing unsupported export actions.
  • Hid the Delete All option for enterprise users where it is not applicable.
March 18, 2026

UI Consistency and Cleanup

Workforce Threat Protection Endpoint Threat Protection Console

Copy, skeleton, and cleanup fixes to align the interface with current product functionality.

  • Shipped copy updates and fixed skeleton loading behavior.
  • Resolved a domain dropdown issue.
  • Removed remaining email identifier references from latest watchlist events and related areas.
March 18, 2026

Reliability and Release Confidence

Workforce Threat Protection Endpoint Threat Protection Console

Expanded automated coverage and supporting reliability updates to improve product stability across environments.

  • Expanded end-to-end and multi-environment test coverage, including password reuse verification flows.
  • Supporting reliability updates including timeout adjustments and infrastructure maintenance.
March 5, 2026

New Data Assets

Shared Data Assets API Portal

New breach metadata fields are now available for newly ingested breach records.

  • Every new breach record now includes breach_title and breach_category.
  • Where available, records now also include phone_full and ec_phone_full with country code.
  • Applies across supported APIs and Vela v1.

February 2026

February 18, 2026

Save and Resume Investigations

Cybercrime Investigations Module Console

Investigations now autosave so users can resume work without losing progress.

  • Searches, pivots, graph settings, and record edits are persisted automatically — no manual save required.
  • Graph settings persisted: legend display, layout, orientation, legend per-item visibility, and node X/Y coordinates. Zoom and user-manipulated node placement are not persisted.
  • A new Investigations home view provides a centralized library with a clean table layout; investigations can be renamed from multiple locations.
  • Single left-hand nav item Investigations replaces separate "search" and "investigation" entries.
  • Tab persistence: leaving and returning restores the full investigation context.
  • Inline delete available directly from the home/search page.
  • Note: Using an Incognito node disables saving.
February 18, 2026

API Key Management

Workforce Threat Protection Endpoint Threat Protection Console

API key management is now available directly in the console via a new API Keys section under Settings.

  • API Keys tab: Tabular view of all organization-owned API keys for WF & EP, including key name (last 10 digits), type, quota limit, queries (month to date), and last used. Columns are customizable.
  • Settings tab: Enterprise key details and IP whitelist information.
  • Docs tab: Links to API documentation and data schema.
February 18, 2026

Breach Alerts and Export Notifications

Workforce Threat Protection Endpoint Threat Protection Console

Notification settings for exposure alerts and data exports can now be configured directly in the console.

  • Exposure alert (breach alert) email notifications are enabled by default for all user roles.
  • Data export ready email notifications are available and disabled by default for all user roles.
  • Notifications is the third item in the Settings left-hand panel, beneath Watchlist and API Keys.
  • Workforce and Endpoint share the same Settings page for these controls.