📢 Release Notes

September 2026

September 14, 2026

Expanded IDLink Search Coverage and Faster Query Performance

IDLink API

IDLink now supports direct searches across a broader set of identity attributes, giving investigators and integrations more ways to start with a known identifier and uncover connected breach records. Backend performance improvements also reduce IDLink response times by approximately 75%, helping searches return results significantly faster.

  • 10 new search endpoints: bank number, driver's license, infected machine ID, IP address, log ID, national ID, passport number, password, social security number, and social handle.
  • Expanded direct search coverage: the new endpoints join existing email, phone number, and username searches, bringing IDLink to 13 supported query types.
  • Approximately 75% reduction in response time: performance improvements reduce the time required to process IDLink searches and return results.
  • The new search options are available through the IDLink API using the same authentication and query-depth workflow as existing IDLink searches.

August 2026

August 19, 2026

Research Agent and Search Quality of Life Improvements

Cybercrime Investigations Console

The Research Agent picks up more of what you've already done and cleans up a few rough edges along the way. Previously, anything found through a manual search or pivot wasn't visible to the agent, the Download Records button could stay disabled regardless of results, chat messages could only be reused by manually copying formatted text, and the agent could occasionally mislabel who was doing the targeting in an attack. All four are fixed.

  • Manual searches and pivots are now automatically added to the agent's context, so nothing you've already found falls outside its view.
  • Every chat message — yours or the agent's — now has a one-click copy button, with formatting preserved.
  • Download Records now reliably enables once results are returned.
  • The agent now correctly identifies which party is doing the targeting, including internal IP activity, improving accuracy in threat attribution.
August 19, 2026

Identity Guardian Findings Completeness Improvements

Identity Guardian Console

Identity Guardian's findings pipeline now reliably captures every qualifying credential exposure, including some that were previously missed. A data-ingest timing issue could silently skip exposures — especially backdated or same-day-late records — so they never became findings. Ingest now tracks a reliable, gap-free watermark, and a one-time catch-up pass recovered exposures that were missed under the earlier logic.

  • Reliable ingest tracking: a sequential, gap-free watermark replaces a timestamp that could be skipped.
  • One-time backfill: a recovery pass surfaced previously missed exposures without creating duplicates.
August 13, 2026

Introducing Executive Reports for Workforce and Endpoint

Workforce Threat Protection Endpoint Threat Protection Console

Executive Reports generate a boardroom-ready summary of workforce and endpoint exposure straight from the same data your team already investigates, so security leaders can walk into a leadership meeting with a clean, evidence-backed picture of risk instead of building a deck by hand. The report is now generally available, built to handle significantly larger exposure datasets and presented in a more polished, streamlined layout.

  • Generates a leadership-ready summary of exposure across Workforce and Endpoint, sized for a boardroom audience rather than an analyst one.
  • Processes up to 10,000 exposure records in a single run, with a clear, actionable message if a request still needs to be narrowed.
  • Available in one click: generate the report directly from Workforce or Endpoint, with no manual data pulls or deck-building required.
  • Contextual recommendations: cross-references your exposure against SpyCloud Labs research to surface related publications and recommendations tailored to your specific risk profile.
August 12, 2026

ADG 7.5.1 Configuration Migration and Installer Fixes

AD Guardian Installer

AD Guardian 7.5.1 is a patch release fixing two issues in configuration migration and the installer. Previously, importing a configuration exported from an existing ADG installation could silently fail whenever the export included encrypted secrets, leaving remediations, webhooks, and schedules missing and new remediation policies impossible to set. Separately, the installer stripped spaces out of Admin Group and Viewer Group names as they were typed, forcing a workaround of typing the name without spaces and inserting them afterward. Both are fixed in 7.5.1.

  • Config import restored: importing a configuration exported from a previous ADG installation now correctly restores remediations, webhooks, and schedules, even when the export includes encrypted secrets.
  • Installer group name input fixed: Admin Group and Viewer Group fields now accept names containing spaces (for example, "Domain Admins") typed normally, left to right.
August 5, 2026

Identity Guardian Revocation Reliability Improvements

Identity Guardian Console

Identity Guardian revokes exposed users' sessions across a customer's configured Okta and Entra tenants. Previously, exclusion rules could fail silently — wildcard entries were ignored and exact-email entries could throw a save error — so excluded users could still be revoked, and the Retry confirmation showed a misleading count of total ledger entries instead of tenants actually retried.

  • Wildcard exclusions (for example, *@domain.com) now correctly exclude matching users from revocation, and exact email entries save without error.
  • The Retry confirmation now shows the accurate count of IdP tenants being retried instead of total ledger entries.

July 2026

July 22, 2026

New Session Status and Cookie Detail Columns

Workforce Threat Protection Console

Records tables now surface which exposed sessions are still active at a glance. Previously, checking whether a session's cookie was still live meant opening each record individually. The Recent and All Records tables now show a Session Status tag plus cookie domain and expiration detail.

  • Session Status (Active/Expired), Cookie Domain, and an optional Cookie Expiration column let teams prioritize still-live sessions directly from the table.
  • Helps teams spot and remediate active Sev 30 exposures without opening every record.
  • Stay on top of session exposure across your workforce and act before still-live sessions can be abused.
July 22, 2026

Identity Guardian Partial Remediation and Notification Controls

Identity Guardian Console

Identity Guardian now handles mixed Okta and Entra results and lets teams finish the job when only some tenants succeed. Previously, a partial result showed the same "Revoked" status as a full success, with no way to retry failed tenants without leaving the product. A new Retry re-attempts only the tenants that failed.

  • Targeted Retry re-runs only outstanding tenants across Revoked, Failed, and Not In IdP statuses, in manual and automatic modes.
  • Admins can now direct session-revoked email alerts to up to 10 dedicated recipients.
July 22, 2026

Source Type Filter Added to All Records

Workforce Threat Protection Console

Users can now filter the All Records and Recent Records pages by Source Type. Previously, narrowing results to a category like breach or malware meant manually scanning the Source Name column. The new filter works alongside Severity, adds a matching table column, and persists in the URL.

  • Multi-select Source Type filter combines with existing filters and shares via URL.
  • A new Source Type column adds at-a-glance category visibility.
July 22, 2026

Enterprise Admins Can Self-Serve SCIM Setup

Core Platform Console

Enterprise admins can now turn on SCIM provisioning themselves right after enabling SSO. Previously the "Turn On SCIM" button was clickable but a backend permission gap silently blocked it, forcing admins through support. That gap is closed — the flow now completes end to end in the same session.

  • Enable SCIM from Configuration > Settings and get your endpoint URL and token immediately, no support ticket required.
  • Available to enterprise admins with SSO already configured.
July 10, 2026

Removing Searches and Records with Research Agent (Pro Only)

Cybercrime Investigations Console

Analysts can now ask the Research Agent to remove a specific query — and all records tied to it — from an active investigation. Previously there was no way to prune unfruitful queries once executed, so dead ends stayed in the thread. This gives direct control over the context window.

  • Removed records drop from both the result count and the agent's working context, so subsequent reasoning runs only on the relevant set.
  • Keeps investigations minimally noisy by clearing dead ends as you go.

June 2026

June 24, 2026

Research Agent (Pro Only)

Cybercrime Investigations Console

Analysts can now run investigations by describing what they're looking for in plain English. Instead of building manual searches, the Research Agent handles the querying, synthesis, and insight generation automatically — cutting mean time to insight across ATO, fraud, insider threat, and supply chain investigations.

  • Launch from a natural language prompt or a starter template, follow the agent's reasoning in real time, and continue with follow-up questions in chat.
  • Available as an enhancement within the existing Investigations Pro experience.
  • Every type of core investigation is supported, grounded in SpyCloud investigative tradecraft.

April 2026

April 16, 2026

Endpoint Graph View

Endpoint Threat Protection Console

A new Graph tab in Endpoint visualizes device relationships, giving users a more intuitive way to understand connections between devices, domains, and associated users.

  • Graph surfaces domain logos and user details directly within the experience.
  • Reduces reliance on table-only investigation flows for relationship analysis.
April 16, 2026

Shareable Filters and URL-Persistent Navigation

Endpoint Threat Protection Console

Search and status filters on the Devices and Applications views now persist in the URL, enabling shareable links and browser back/forward navigation.

  • Users can save, share, and return to specific filtered views without manually recreating them.
  • Improves collaboration and reduces friction across Endpoint investigation workflows.
April 16, 2026

Devices Tab Error Handling and Watchlist Retry Logic

Endpoint Threat Protection Console

Improved error states, messaging, and retry logic across the Devices tab and workforce watchlist workflows.

  • Enhanced error handling and retry logic for adding workforce watchlists.
  • Clearer failure-state messaging reduces dead ends during investigation and response workflows.
April 16, 2026

UI Clarity and Interaction Refinements

Endpoint Threat Protection Console

Focused UI improvements to reduce visual noise and improve consistency during investigations.

  • Updated glossary drawer descriptions for accuracy.
  • Added row highlighting on selection for Sightings.
  • Loading totals are now hidden until data is fully ready, eliminating loading-state flicker.

March 2026

March 31, 2026

Combolist Backlog Ingestion

Shared Data Assets Console API Portal

A large backlog of combolists is being ingested and deduplicated.

  • Customers may see new unique credential pairs appear in the UI and APIs.
  • No email alerts or webhooks are triggered for combolist matches tied to this backlog ingestion.
March 18, 2026

Navigation and Workflow Efficiency Improvements

Workforce Threat Protection Endpoint Threat Protection Console

Reduced friction navigating from notifications into relevant workflows and destination pages.

  • Added shallow link support for Breach Alerts, enabling direct linking into alert context.
  • Data export emails now include a direct link to the Exports page.
March 18, 2026

Records and Investigations Enhancements

Workforce Threat Protection Console

Improved investigative context, data accuracy, and view persistence in the Records tab.

  • Username is now a default column for infected users in the Records tab.
  • Phish Time is now available as an optional column.
  • Optional column selections persist across sessions — no need to reconfigure on each visit.
  • Fixed exposed asset and login credential counts for improved data accuracy.
March 18, 2026

Data Grid and Table Usability Upgrades

Workforce Threat Protection Endpoint Threat Protection Console

A set of stability and usability improvements for data-heavy table views.

  • Implemented broader DataGrid persistence across sessions.
  • Enabled automatic column pinning during horizontal scrolling.
  • Fixed page reset behavior when filters change.
  • Corrected watchlist column alignment issues in Workforce Settings.
March 18, 2026

Export and Enterprise Behavior Updates

Workforce Threat Protection Console

Improved consistency and guardrails for export actions and enterprise user permissions.

  • Updated export terminology from "Email" to "Domains" for Workforce exports.
  • Disabled export from All Records when a date filter is present, preventing unsupported export actions.
  • Hid the Delete All option for enterprise users where it is not applicable.
March 18, 2026

UI Consistency and Cleanup

Workforce Threat Protection Endpoint Threat Protection Console

Copy, skeleton, and cleanup fixes to align the interface with current product functionality.

  • Shipped copy updates and fixed skeleton loading behavior.
  • Resolved a domain dropdown issue.
  • Removed remaining email identifier references from latest watchlist events and related areas.
March 5, 2026

New Data Assets

Shared Data Assets API Portal

New breach metadata fields are now available for newly ingested breach records.

  • Every new breach record now includes breach_title and breach_category.
  • Where available, records now also include phone_full and ec_phone_full with country code.
  • Applies across supported APIs and Vela v1.

February 2026

February 18, 2026

Save and Resume Investigations

Cybercrime Investigations Console

Investigations now autosave so users can resume work without losing progress.

  • Searches, pivots, graph settings, and record edits are persisted automatically — no manual save required.
  • Graph settings persisted: legend display, layout, orientation, legend per-item visibility, and node X/Y coordinates. Zoom and user-manipulated node placement are not persisted.
  • A new Investigations home view provides a centralized library with a clean table layout; investigations can be renamed from multiple locations.
  • Single left-hand nav item Investigations replaces separate "search" and "investigation" entries.
  • Tab persistence: leaving and returning restores the full investigation context.
  • Inline delete available directly from the home/search page.
  • Note: Using an Incognito node disables saving.
February 18, 2026

API Key Management

Workforce Threat Protection Endpoint Threat Protection Console

API key management is now available directly in the console via a new API Keys section under Settings.

  • API Keys tab: Tabular view of all organization-owned API keys for WF & EP, including key name (last 10 digits), type, quota limit, queries (month to date), and last used. Columns are customizable.
  • Settings tab: Enterprise key details and IP whitelist information.
  • Docs tab: Links to API documentation and data schema.
February 18, 2026

Breach Alerts and Export Notifications

Workforce Threat Protection Endpoint Threat Protection Console

Notification settings for exposure alerts and data exports can now be configured directly in the console.

  • Exposure alert (breach alert) email notifications are enabled by default for all user roles.
  • Data export ready email notifications are available and disabled by default for all user roles.
  • Notifications is the third item in the Settings left-hand panel, beneath Watchlist and API Keys.
  • Workforce and Endpoint share the same Settings page for these controls.