Changelog

Product updates, reliability work, interface improvements, and release notes for the MagicSword.

Showing 1-10 of 50 releases

September 24, 2026Since v1.1.41

v1.1.42 includes 4 updates since v1.1.41.

Highlights

  • Restore browser extension policy controls and saved settings
  • Add Attacker Tools intel feeds to standard workstation profiles
  • Allow routine macOS updates in default policies
  • Fix email confirmation resend recovery during sign-in

Improvements

  • Restore browser extension policy controls and saved settings
  • Add Attacker Tools intel feeds to standard workstation profiles
  • Allow routine macOS updates in default policies

Fixes

  • Fix email confirmation resend recovery during sign-in
September 24, 2026Since v1.1.40

v1.1.41 includes 2 updates since v1.1.40. The LOTL contributor board now supports browsing historical weeks and verified first-time contributor badges, and the latest weekly edition is published.

Highlights

  • Browse every audited week of 2026 on the LOTL contributor board
  • Verified badges for first-time contributors with links to their first public contribution
  • New weekly edition for September 17โ€“24 with updated leaderboard

Features

  • Browse historical LOTL weeks: You can now navigate backward and forward through every audited week of 2026 on the LOTL contributor board, and jump back to the latest week. Each week keeps its contributor ranks, project filters, counts, and evidence aligned, so you can review past contributions with the same context as the current week.

Improvements

  • Updated LOTL weekly edition: The September 17โ€“24 thank-you edition is now live, recognizing 7 contributors across 3 projects with 23 merged PRs and 5 direct commits, including 3 verified first-time contributors. The leaderboard reflects the latest data.
September 22, 2026Since v1.1.39

v1.1.40 includes 7 updates since v1.1.39.

Highlights

  • ๐Ÿค– Actively Exploited Signers: New Threat(s) Detected
  • Polish private intelligence dialog and center sidebar icons
  • Fix policy clone lineage and preserve large policy contents
  • Add Event Review to superadmin navigation

Improvements

  • ๐Ÿค– Actively Exploited Signers: New Threat(s) Detected
  • Polish private intelligence dialog and center sidebar icons
  • Add Event Review to superadmin navigation
  • Prioritize API keys and separate MSSP settings
  • Add smaller SIEM query batches and batch downloads
  • Add Investigate endpoint pivots and collection guidance

Fixes

  • Fix policy clone lineage and preserve large policy contents
September 17, 2026Since v1.1.38

v1.1.39 includes 1 update since v1.1.38. New actively exploited signer intelligence and the latest Living Off the Land weekly update are now available.

Highlights

  • New actively exploited signer detections
  • Updated Living Off the Land weekly intelligence

Security

  • New actively exploited signer intelligence: You can now detect and block newly discovered actively exploited code signing certificates, helping you stay ahead of threats that abuse stolen or misused signers.
September 14, 2026Since v1.1.37

v1.1.38 includes 4 updates since v1.1.37. This release makes Defender hunt queries more efficient, fixes collector import and invite creation issues, and improves enhancement processing reliability.

Highlights

  • Run 24-hour Defender hunts without exhausting your organization's resource budget.
  • Collector imports now accurately report failures instead of appearing successful.
  • Organization admins can create invites again without 500 errors.
  • Enhancement processing is more reliable with duplicate work prevented.

Performance

  • More efficient Defender hunt queries: Generated Defender hunt queries now use significantly less of your organization's resource allocation, so you can run 24-hour hunts without exhausting your Defender budget. Queries filter candidate events before combining and only use regex and label expansion when necessary.

Fixes

  • More reliable enhancement processing: Fixed a race condition that could cause the same enhancement to be processed twice or results to be lost when multiple workers ran at once. Model timeouts now include response body reads, so jobs no longer hang on slow responses.
  • Accurate collector import failure reporting: Collector imports now report incomplete runs as failures instead of appearing successful, so you know when an import didn't finish. Healthy feeds still persist during partial runs, and zero-feed runs preserve existing data.
  • Restore organization invite creation: Organization admins can now create invites again without receiving a 500 error. The fix also ensures invite recipients can't change authorization-bearing fields.
September 14, 2026Since v1.1.36

v1.1.37 includes 1 update since v1.1.36. Fixed intermittent 500 errors when creating complete policy profiles with the Standard Workstation intelligence selection.

Highlights

  • Complete policy profile creation is now reliable, even for large selections.

Fixes

  • Complete policy profile creation no longer times out: You can now create full policy profiles with the Standard Workstation intelligence selection without intermittent 500 errors. The creation process now has a dedicated 30-second timeout for the database transaction and 60 seconds for the API route, ensuring all selected sources and rules publish atomically even when the profile is large.
September 14, 2026Since v1.1.35

v1.1.36 includes 3 updates since v1.1.35.

Highlights

  • Prevent Security Briefing rule-read timeouts
  • Retry storage retention timeouts with bounded smaller batches
  • Preserve retryable triage provider failures

Security

  • Prevent Security Briefing rule-read timeouts

Improvements

  • Retry storage retention timeouts with bounded smaller batches
  • Preserve retryable triage provider failures
September 11, 2026Since v1.1.34

v1.1.35 includes 11 updates since v1.1.34. Security Briefing becomes the default report with AI summaries and email digests, compliance statuses more accurate instead of false positives, and storage/agent background jobs more reliable.

Highlights

  • Security Briefing is the default report with a generated weekly or monthly email digest.
  • Endpoint compliance no longer marks healthy endpoints as culpant when a policy is simply missing.
  • AMSI detection focuses on actual SAM/SYSTEM/SECURITY hive extraction instead of false positives from normal WDAC policy conversions.

Operations

  • Automatic 30-day telemetry retention: Telemetry older than 30 days is now automatically expired in bounded batches, keeping storage growth under control while preserving recent observations and pending enrichment.

Performance

  • Faster enhancement intel lookups: Queued items no longer bounce back to pending when a global filename/hash intel lookup is slow; indexed intel lookups keep the queue moving.
  • Faster dashboard aggregate loading: Dashboard widgets now load faster by avoiding broad aggregate materialization and repeated row rechecks, while keeping the same eligibility and filter behavior.

Fixes

  • Policy audit events record the real actor: Policy edits now audit under the actual signed-in user who made the change instead of failing or being attributed to the resource owner.
  • AMSI hive extraction false positives fixed: Normal ConvertFrom-CiPolicy conversions no longer trigger the hive extraction alert; detection now focuses on actual reg/reg.exe save and Copy-Item extraction of SAM, SYSTEM, and SECURITY.
  • Compliance no longer conflates missing policies with endpoint problems: Healthy Windows endpoints no longer appear noncompliant because a policy or delivery manifest is missing. Endpoints with no heartbeat or check-in for 48 hours now show Unknown, while tampering and application, inventory, or enforcement-mode failures remain visible across Fleet, reports, and CSV exports.

Improvements

  • Agent jobs complete within time limits and hunter sources are validated: Background agent work is less likely to be lost when it hits a runtime limit, because unfinished groups are resumable. Hunter sources are also matched to your organization before investigation, with a harmless 404 for missing or foreign sources.
  • Dashboard menu expanded by default with a clearer toggle: The dashboard menu now opens expanded on desktop and remembers your collapse/expand choice while navigating. The sword toggle has clear labels, an emerald highlight, keyboard/focus support, and reduced-motion handling.

Security

  • Agent queue operations restricted to service role: Internal agent queue actions can no longer be executed by anonymous or ordinary authenticated users, closing off a path for claiming or mutating cross-organization work.
  • Internal agent operations restricted to service role: Agent data cleanup, configuration access, untriaged analytics queries, and related internal operations now require the service role, so external callers cannot invoke them.

Features

  • Security Briefing is the default report with AI summaries and email delivery: Reports now open directly into Security Briefing, a single dated view of observed blocks, audit findings, enforcement opportunities, alert backlog, coverage, and recommended follow-up. You can opt into a weekly email digest that links back to the exact saved report and export the brief as Markdown or JSON.
September 11, 2026Since v1.1.33

v1.1.34 includes 3 updates since v1.1.33. This release expands actively exploited signer coverage and makes Windows Code Integrity event reporting more accurate by preserving caller context, and distinguishing audited from blocked events.

Highlights

  • Newly discovered actively exploited signers are now covered
  • Windows Code Integrity events keep the full calling process context
  • Audited integrity events are no longer labeled as blocked

Security

  • New actively exploited signers added: You now get coverage for newly discovered code-signing certificates that VirusTotal Intelligence has identified as actively exploited. This lets you act on signers that are already being used in the wild rather than waiting for them to become known threats.

Fixes

  • Code Integrity events keep caller context: You can now see the actual calling process for Windows Code Integrity events, including its name, path, and device path, in Event Review and Triage. That context is preserved separately from parent-process ancestry, so you no longer lose which process attempted the DLL or image load.
September 10, 2026Since v1.1.32

v1.1.33 includes 4 updates since v1.1.32. This release makes enforcement readiness checks reliable for large organizations, clarifies Event Review context, fixes enhancement worker intelligence filtering, and publishes the weekly LOTL contributor edition.

Highlights

  • Readiness checks now handle large organization scopes without request failures.
  • Event Review shows intelligence matches and explains missing rule metadata.
  • Enhancement worker no longer fails on multi-filename intelligence lookups.
  • Weekly LOTL contributor edition is live with a refreshed project inventory.

Fixes

  • Fix readiness checks for large organization scopes: Readiness checks now batch organization IDs and paginate policy results, so large organization scopes no longer fail with request errors or 500s. If a required lookup fails, you get a clear 503 instead of a partial or broken result.
  • Fix intelligence filtering in enhancement worker: Enhancement processing now handles multiple filenames correctly during intelligence lookups, including punctuation and wildcards. If a lookup fails, items return to pending and AI analysis doesn't run with incomplete context.

Improvements

  • Clarify rule and intelligence context in Event Review: Event Review now shows intelligence matches separately from the reported rule source and explains when exact rule metadata is unavailable, so you can see why an event matched without mistaking current policy for the historical trigger. Artifact details appear above policy context, and the source filter is labeled 'All rule sources'.
  • Publish weekly LOTL contributor edition: The September 4โ€“10 contributor edition is now live, with refreshed project inventory and leaderboards.
Page 1 of 5 ยท 50 releases