August 31, 2026
Browser Phishing Protection Optimization
Improvement
Improved reliability and speed when applying exclusions for Browser Phishing Protection, reducing update time and eliminating a brief window during large exclusion list changes when protection could be temporarily incomplete.
Features and Improvements
No additional improvements this release.
Issues Fixed
No issues fixed this release.
August 26, 2026
Export Process Tree
Improvement
Added an Export Tree button on the Process Tree view for suspicious activities. The export contains the complete process hierarchy, including collapsed nodes, with each process name and PID, its command line, and its indicators.
Features and Improvements
Right-click a row in the Suspicious Activity table to open its details in a new browser tab.
Drag the left border of a Suspicious Activity node detail panel to widen or narrow it.
Inventory syncs for Entra ID and Okta manage large directories reliably. They don't overlap, and incomplete syncs don't remove identities.
Managed Services cases are kept for 30 days following your license expiration.
Drive encryption events on the Events page.
Issues Fixed
NDEV-22990: Fixed an issue where the Account page showed the wrong product name and subscription status.
NDEV-23666: Fixed an issue where timestamps in Flight Recorder Search process graphs were shown in UTC while First seen and Last seen used your console timezone.
NDEV-23840: Fixed an issue where the Type selector was unreadable in dark mode on the Email Security Allow list.
NDEV-23777: Fixed an issue where Folder by Path exclusions containing a period were not accepted.
August 18, 2026
Stronger Default Policy settings
Improvement
Updated the default policy settings to provide stronger protection out of the box. The new defaults apply to policies created from any standard template for workstations or servers, and to any policy reset to ThreatDown’s recommended settings. Existing policies are not modified.
Export AI activity
Feature
Export data directly from the AI tools and AI activity tables to CSV so you can analyze AI usage across your organization outside the console or bring it into your own reporting.
Features and Improvements
- Default policy settings updated. Applies only to newly created and reset policies. Existing policies are unchanged.
- Enabled by default:
- Automatic reboot when required: Workstation policies.
- Suspicious top-level domains (Browser Phishing Protection): Workstation and server policies.
- Enhance heuristics detections: Workstation and server policies.
- Enhance Hacktools detections: Workstation and server policies.
- Enhance sandbox detections: Workstation and server policies.
- Suspicious activity monitoring on servers: All Operating systems, workstation and server policies.
- Collect networking events for searching: All Operating systems, workstation and server policies.
- Disabled by default:
- Scan for rootkits (Threat Scan): Workstation and server policies.
- Enabled by default:
- Self-Protection settings moved under Tamper Protection. The Self-Protection options appear under Tamper Protection rather than Additional Protection.
- Clearer setting labels in policy configuration. The following policy settings have been renamed:
- Enable anti-malware scanning interface updated to Enable script scanning.
- Scan compressed folders updated to Scan compressed archives.
- Drill into the AI usage flow chart. Selecting a category in the AI usage flow chart opens the AI tools page filtered to the tools in that category at the governance level you selected. Selecting an individual tool opens the Activity page filtered to endpoints with that tool installed or in use at the same governance level.
- Edit a governance rule from the Governance column. Open and edit the governance rule for a tool directly from the Governance column, without leaving the table.
- Clearer version breakdown. Updated the version breakdown widget layout to make it easier to see which versions are installed across your endpoints.
Issues Fixed
- NDEV-23147: Fixed an issue where the Governance by category widget displayed only five categories.
- NDEV-23442: Fixed an issue where the governance shown for an endpoint reflected only the tool-level governance and did not account for policy overrides.
- NDEV-23260: Fixed an issue where the Policy column filter returned incorrect results.
- NDEV-23719: Fixed an issue where the OS type filter on the Endpoints tab of the AI tools details panel returned incorrect results.
- NDEV-23546: Fixed an issue where the total record count on the AI activity table loaded indefinitely.
- NDEV-23342: Fixed an issue where the tool level of the AI usage flow chart counted only endpoints with recorded activity.
- NDEV-23630: Fixed an issue where opening the Endpoints tab via the Active endpoints link in the AI tools table did not filter to endpoints with activity.
August 17, 2026
ThreatDown AI
Feature
ThreatDown AI is available on Elite accounts. Ask questions about your environment using natural language and quickly uncover insights across endpoints, detections, vulnerabilities, audit logs, and security posture. Receive recommended actions, explore relevant data, and execute selected actions directly from the AI conversation to resolve issues faster.
Features and Improvements
Apply software updates to the endpoints you choose. You can target a software update by application and by endpoint in the same request while leaving others untouched.
Keep typing while suggested actions are on screen. The prompt box stays available when ThreatDown AI presents suggested actions, so you can pick an action or simply ask a follow-up question without dismissing the suggestions.
Answers reflect whether an update is actually available. Questions about vulnerable or outdated software distinguish between applications that have an update ready and those that do not.
Clearer answers about endpoints awaiting a restart. ThreatDown AI reports why a restart is pending on an endpoint.
ThreatDown AI availability setting visibility to Admin and Read-only users. The Account > Configurations > ThreatDown AI setting is visible to Admin and Read-only users, so any user can confirm whether the feature is enabled for the account. Only Super Admins can change the setting.
Clearer messaging for exports that run in the background. When you request an export from ThreatDown AI, the confirmation explains that the export has been initiated and that you will receive an email when the file is ready to download.
Endpoint name included in software asset exports. Exports of software inventory results generated from ThreatDown AI include the endpoint name, making it easier to identify which device each software entry belongs to.
Improved handling of questions that reference multiple endpoints. Questions that name several endpoints at once return results for each endpoint.
Accurate results when asking about detected files. Questions that reference a specific file or file location now match on the detection path, returning more relevant results.
Guidance to documentation for AI Detection and Response questions. Questions about AI usage and AI Detection and Response in your organization point to the relevant knowledge base articles.
Issues Fixed
NDEV-23579: Fixed an issue where asking ThreatDown AI to identify groups without a schedule returned all Nebula groups.
NDEV-23580: Fixed an issue where questions about the Security Advisor Endpoint Status score were interpreted as questions about endpoint state instead of the security posture score.
NDEV-23581: Fixed an issue where ThreatDown AI treated available operating system patches and agent updates as interchangeable.
NDEV-23632: Fixed an issue where questions about .NET updates returned an inaccurate response.
NDEV-23720: Fixed an issue where questions about endpoints requiring a restart were misinterpreted when asked immediately after a question about endpoints requiring an update.
NDEV-23573: Fixed an issue in ThreatDown AI where the background color did not change when hovering over an item.