Changelog

Product updates, reliability work, interface improvements, and release notes for the MagicSword.

Showing 1-10 of 22 releases

August 12, 2026Since v1.1.13

v1.1.14 includes 8 updates since v1.1.13. This release improves Gatekeeper and XProtect triage, clarifies Windows control readiness, and makes password recovery, alerts, telemetry, and high-volume views more reliable.

Highlights

  • Improve Gatekeeper and XProtect attribution: Apple reporting services are now separated from the application or file being assessed. Redacted targets remain clearly identified as redacted instead of being incorrectly attributed to syspolicyd.
  • Strengthen macOS application control: New app_bundle rules resolve applications to the executable macOS actually launches, including Cryptex-backed applications such as Safari.
  • Add macOS CDHash enforcement: The agent can now enforce CDHash rules synchronously and accurately report this capability to the Portal.
  • Close macOS launch enforcement gaps: LaunchServices, Finder, and open launches now reach policy evaluation instead of being hidden by broad Endpoint Security path mutes.
  • Clarify Windows control readiness: Supported but unconfigured Windows controls now show as Control Available instead of requiring attention.

Improvements

  • Use consistent primary-action styling: The Add New Rule and AI Report buttons now use MagicSword green.
  • Preserve macOS trust-event evidence: The agent retains original timestamps, reporter identity, target confidence, signing metadata, and event provenance.
  • Prevent duplicate macOS trust events: Deterministic event IDs make overlapping Gatekeeper and XProtect collection windows idempotent.
  • Improve macOS rule evaluation: Specific deny rules can no longer be hidden by broader allow rules.
  • Refresh macOS authorization state: The agent clears its authorization cache when an application bundle changes.

Fixes

  • Restore protected password recovery: Turnstile verification is now included with password-reset requests.
  • Prevent malformed Unicode from blocking heartbeats: Invalid or PostgreSQL-incompatible Unicode is sanitized before telemetry is queued.
  • Open the correct alert details: Alert panels now remain associated with the selected event and endpoint, even when events share an executable or hash.
  • Finalize agent runs correctly: Completion time, status, knowledge-graph metrics, and errors are now recorded reliably.
  • Improve Gatekeeper classification: Cache updates, housekeeping activity, and observed user overrides are no longer presented as authoritative enforcement events.
  • Improve XProtect classification: The agent emits XProtect observations only for high-confidence detection or remediation activity.

Performance

  • Speed up Overview event paging: More efficient time filtering improves responsiveness for large audited and blocked event collections.
  • Reduce high-volume database pressure: Bounded processing improves heartbeat queues, background workers, and large-portfolio views.
August 10, 2026Since v1.1.12

v1.1.13 includes 10 updates since v1.1.12. This release improves endpoint reporting accuracy, Windows policy readiness, policy editing, and heartbeat reliability while adding stronger WDAC and form protection.

Highlights

  • Endpoint reports now match canonical live endpoint counts, including more accurate stale-device lists and policy assignments.
  • Windows 23H2 devices show clearer WDAC reboot requirements, while 24H2+ is documented as the preferred baseline.
  • Policy editors can switch between Audit and Enforce with the same readiness checks used in the policy manager.
  • Heartbeat processing is more reliable, with fewer retry storms and less duplicate transfer overhead.

Fixes

  • Correct duplicate endpoint counts in reports: You now get accurate Device, Compliance, and Policy report totals, stale-device lists, exports, and compliance rates that match the Fleet page, even after uninstall and re-enrollment events.
  • Classify CodeIntegrity 3004 events as audited evidence: Windows CodeIntegrity 3004 events are now ingested and classified as audited exe_dll evidence by default, giving you more complete visibility into application-control activity.

Improvements

  • Focus Investigate on the last hour by default: Investigate now opens to a focused one-hour time range instead of 24 hours, helping you reach relevant activity faster and reducing the initial amount of data to load.
  • Enable the tray icon by default when deploying agents: New agent install commands now start the tray icon at user logon by default, making endpoint status easier for users to access without additional configuration.
  • Simplify Windows rule creation and support Notepad++ filenames: Windows policy authors now see a clearer new-rule type list and can create version-scoped Filename rules for values such as notepad++.exe and Notepad++.

Security

  • Protect Prevention Lab and enterprise trial forms with Turnstile: You can now submit Prevention Lab and Enterprise Trial forms with CAPTCHA verification, while rejected tokens produce clear form errors instead of blocking valid trial activation.
  • Clarify Windows WDAC and AppLocker support: You now get clearer platform guidance: Windows 11 22H2 uses the limited AppLocker-compatible path, 23H2 is the oldest fully supported WDAC baseline, and 24H2+ is the preferred posture.
  • Add supplemental WDAC and LOLBin bypass intel: You now have broader WDAC coverage for bypass-relevant tools including dbgsrv.exe, TextTransform.exe, WSL container aliases, lli.exe, datacollector.exe, slui.exe, and updated imgmgr.exe guidance.

Features

  • Change policy status directly in the Policy Editor: You can now switch a policy between Audit and Enforce while editing it, with readiness checks and enforcement guidance that match the policy manager experience.

Performance

  • Reduce heartbeat retry storms and transfer overhead: Heartbeat and checkin traffic is now less likely to trigger duplicate retries or 503 responses, improving telemetry delivery reliability and reducing unnecessary endpoint data transfers.
July 31, 2026Since v1.1.11

v1.1.12 includes 1 update since v1.1.11.

Highlights

  • Add Cloudflare Turnstile bot protection to signup, signin, contact, and book-demo forms

Improvements

  • Add Cloudflare Turnstile bot protection to signup, signin, contact, and book-demo forms
July 30, 2026Since v1.1.10

v1.1.11 includes 2 updates since v1.1.10.

Highlights

  • Fix post-release database timeouts, deadlocks, and heartbeat 503s
  • Enable MSSP customer management and profile avatars

Fixes

  • Fix post-release database timeouts, deadlocks, and heartbeat 503s

Improvements

  • Enable MSSP customer management and profile avatars
July 29, 2026Since v1.1.9

Portal v1.1.10

v1.1.10 includes 4 updates since v1.1.9.

Highlights

  • Fix policy deployment leave-site prompt
  • Fix deleting imported agentless endpoints
  • Add MSSP self-service customer provisioning
  • Make tiered heartbeats durable and core-first

Fixes

  • Fix policy deployment leave-site prompt
  • Fix deleting imported agentless endpoints

Features

  • Add MSSP self-service customer provisioning
  • Make tiered heartbeats durable and core-first

Agent updates

  • Today’s agent update includes 5 changes.

Highlights

  • Harden Windows policy deployment and break-glass recovery
  • Make tiered heartbeats durable and core-first across Windows, Linux, and macOS
  • Enhance macOS path rules for scripts and shebang tools
  • Fix non-SCR policy event labeling in Investigate

Fixes

  • Harden Windows policy deployment and break-glass recovery
  • Enforce macOS path rules for scripts and shebang tools
  • Fix non-SCR policy event labeling in Investigate

Features

  • Make tiered heartbeats durable and core-first across Windows, Linux, and macOS
July 27, 2026Since v1.1.8

v1.1.9 includes 2 updates since v1.1.8.

Highlights

  • Replace About Us hero photo with Mux video
  • Add Magic-Atomics to community projects page

Features

  • Replace About Us hero photo with Mux video
  • Add Magic-Atomics to community projects page
July 24, 2026Since v1.1.7

v1.1.8 includes 2 updates since v1.1.7.

Highlights

  • Changelog anchor links, release-count summary
  • Serialize analytics enrichment queue drains

Improvements

  • Changelog anchor links, release-count summary

Fixes

  • Serialize analytics enrichment queue drains
July 23, 2026Since v1.1.6

Investigate is fast and reliable again, even across large, multi-organization datasets.

Highlights

  • Faster initial loading with results appearing before expensive totals finish calculating
  • Smooth, deterministic paging through large volumes of endpoint activity
  • Consistent ordering across organizations and event timestamps

Fixes

  • Resolved query timeouts that could leave Investigate blank or return a 500 error
  • Restored the indexed data path for dramatically faster searches
  • Preserved existing filters, sorting, organization scoping, and backwards compatibility
July 23, 2026Since v1.1.5

v1.1.6 includes 23 updates since v1.1.5.

Highlights

  • Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
  • Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
  • AMSI policy tuning controls are back, so you can adjust protections again
  • Organization rule pages no longer time out for large teams

Improvements

  • Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
  • Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
  • AMSI policy tuning controls are back, so you can adjust protections again
  • Cleaner UI — obsolete preview labels removed
  • Clearer triage — filtered-event counts now match what’s actually loaded
  • Cleaner booking page — free trial badge removed from Book Demo
  • Signer auto-hunt is restored and works with a limited VirusTotal key
  • More visibility into macOS — approval-request eviction telemetry now surfaced
  • Faster intel loading — collector lookups are now batched
  • Detection-rule tables now have sortable columns
  • Investigate stats are compacted to fit laptop screens
  • Intel updates preload so Apply All is smoother and lifecycle-safe
  • Alert details now show which user made an allow request

Fixes

  • Organization-member rule pages no longer time out
  • Superadmin endpoint reporting now shows accurate data
  • Analytics now use the correct last-observed time
  • AMSI pilot plan enforcement now initializes correctly
  • Webhook and syslog notifications deliver more reliably
  • No more duplicate ExtSentry browser-extension rules
  • Detections with unusual (NUL) bytes are no longer dropped
  • Compliance alerts now resolve correctly after device recovery

Performance

  • Preflight UI stays responsive while readiness checks refresh

Features

  • Your Devices sort preference is now remembered between sessions
July 15, 2026Since v1.1.4

This release restores SSO access for provider-bound accounts to ensure seamless portal authentication.

Highlights

  • Restored SSO access for provider-bound accounts.

Fixes

  • SSO portal access: You can now log in to the portal using your provider-bound SSO credentials again, resolving an issue that prevented access for specific account types.
Page 1 of 3 · 22 releases