Release Notes

What's new in Cybereinforce.

Every update to Cybereinforce Threat Enforcement, from the first release to today: the platform your administrators and SOC work with, and the browser extension that protects every device.

Platform
2026.10.2Released 10 October 2026 · 17 releases
Browser extension
1.3.1Released 10 October 2026 · 7 versions
Platform is the cloud service: admin console, threat intelligence, integrations and APIs. It updates for every organisation at once, numbered by year and month (2026.10.2 = second release in October 2026).
Browser extension runs on each device and updates through the Chrome Web Store (Chrome, Edge, Brave), Firefox Add-ons and the App Store. Devices are updated automatically.

October 2026

Platform2026.10.210 October 2026Latest

Warnings for suspicious sites, company-wide deployment, one-click Sentinel export

Warnings and policy enrollment are delivered by extension 1.3.1.

  • NewSuspicious verdict: threat-intelligence entries are either malicious (blocked) or suspicious (users see a warning and may continue at their own risk). Everything is malicious unless an analyst explicitly marks it suspicious.
  • NewBlock or Warn per rule: administrators choose what happens when a rule matches. Microsoft Defender indicators set to Warn are enforced as warnings automatically.
  • NewEnterprise IOC submissions can now also be answered as suspicious, which adds a Warn rule for your organisation.
  • NewCompany deployment: a Windows script for Intune, Group Policy and Defender for Endpoint, and a macOS configuration profile, that install and enroll the extension by itself for every user, profile and browser (Chrome, Edge, Brave, Firefox).
  • NewPrivate windows protected by policy while staying available to users.
  • NewDirect Sentinel Export with a single Azure deployment: pick your workspace from a list, no app registration, no secrets to copy. Test first, then switch it on.
  • NewSentinel incidents for silent failures: devices that stop checking in, outdated extensions, private windows left unprotected, and integrations that stop delivering.
  • NewSentinel analytics rule for users who continue past a warning.
  • NewInsights: new articles on closing the Defender URL gap in every browser, stopping device code phishing, new domain protection, our threat intelligence and real time phishing heuristics.
  • ImprovedWhile Direct Sentinel Export is on, Cybereinforce keeps no per-event data at all, only daily counts. Switching it on moves existing events to your workspace.
  • ImprovedEvents in Sentinel carry the exact time they happened (EventTime) as well as the time they arrived.
  • ImprovedRetention follows your plan: 7 days (Trial), 30 days (SME), 90 days (Corporate), 365 days (Enterprise). Daily block counts are kept for 12 months on every plan.
  • ImprovedDefender integration: your administrators decide whether Defender device groups and domain indicators are imported; filtering happens in your own tenant.
  • ImprovedIntegrations never break: connected Defender and Sentinel integrations keep working when integration tokens are rotated or revoked, and can be disconnected one by one.
  • ImprovedJoin page: the extension installs without leaving the page, and enrollment continues by itself.
  • ImprovedThe Events page always shows the newest events first; token and join-link history is paginated.
  • FixedJoin page on Mac: Chrome, Edge, Brave and Firefox now get their own store and enroll directly, instead of being sent to the Safari app.
  • ImprovedJoin page enrolls by itself: as soon as the extension is installed and ready the device is enrolled, with no click and no refresh. Until then the page keeps trying quietly.
Extension1.3.110 October 2026Latest

Warning page, enrollment by company policy, private-window protection

Browsers: Chrome, Edge, Brave, Firefox

  • NewWarning page for suspicious sites: go back to safety with one click, or continue at your own risk. The site is then not flagged again for an hour, and the decision is recorded.
  • NewEnrollment by company policy: the extension enrolls itself from Intune, Group Policy, Defender for Endpoint or Mac management settings, for every user, profile and browser on a device.
  • NewPrivate windows: when your organisation requires protection there, users are shown how to allow it in one click.
  • NewProtection health reporting: each device reports whether private windows and all websites are covered.
  • ImprovedSelf-healing enrollment: a device whose credentials stop working re-enrolls on its own from the company policy.
  • ImprovedFaster updates: new versions are picked up as soon as they are released.
Platform2026.10.17 October 2026

Day-zero protection and Device Code attack protection for everyone

  • NewNewly registered domains are blocked in the browser across 1,100+ TLDs, so a phishing site that went live minutes ago is stopped before any threat feed knows it.
  • NewDevice Code attack protection on by default: the Microsoft device-code sign-in page is blocked for every organisation, with whitelisting for legitimate use.
  • NewLearning loop: high-confidence automatic blocks are reviewed and added to the shared threat intelligence that protects every customer.
  • NewAutomatic seat management: seats held by long-absent devices are reclaimed, and waiting devices switch on as soon as a seat is free.
  • NewPublic Threat Intelligence & Detections and Device Code Attack pages.
  • ImprovedFaster threat checks, with caching hints so repeat visits need no round trip.
  • ImprovedDaily health checks cover every region with no scheduler to maintain.
  • ImprovedPrivacy policy describes exactly what the extension sends.
Extension1.3.07 October 2026

Blocks on the first visit, faster browsing, status popup

Browsers: Chrome, Edge, Brave, Firefox

  • ImprovedBlocks on the first visit: the threat check is much more patient and resilient, with automatic retries, so a slow connection no longer lets a first visit through.
  • ImprovedMuch faster rule matching, even with thousands of rules.
  • NewLearns as it goes: confirmed threats are blocked instantly on repeat visits, in every tab, even if the service is briefly unreachable.
  • NewStatus popup that shows the protection state in plain language.
  • ImprovedDevices wait their turn: if licences are fully used, a device keeps retrying and switches on as soon as a seat is free.
  • ImprovedClearer enrollment messages: if a token cannot be accepted, the extension says why.
  • SecurityURL fragments, embedded credentials and token-like parameters are never sent in security events.
  • ImprovedOne permission fewer than before.

September 2026

Platform2026.09.230 September 2026

Faster TLD blocking and a cleaner threat feed

  • ImprovedTLD blocking decisions are faster thanks to cached region resolution.
  • ImprovedThreat intelligence feed refreshed and cleaned of false positives.
  • ImprovedThe public status page judges each day against the SLA target.
Platform2026.09.114 September 2026

New browser detections and MSSP partner programme

  • NewWordPress password-reset link abuse is detected and blocked in the browser.
  • NewMachine-generated (DGA) domains on risky hosting are blocked, and suspected device-code lure pages are recognised by their content.
  • NewThe .claim and .support TLDs are blocked by default, following their use by an active extortion group.
  • ImprovedThe TLD coverage catalog was extended with .xyz and 13 more TLDs.
  • ImprovedThe partner programme and portal are now the MSSP programme.
  • SecurityEnrolled devices switch to their own long-lived credential on their first check-in and stay connected for good.
  • SecurityEnrollment links and policies are checked strictly at every use.

August 2026

Platform2026.08.431 August 2026

Self-service account deletion

  • NewOrganisations can delete their account and data themselves; contractual records are kept as required by law.
  • ImprovedYour data region is fixed at sign-up and new regions are provisioned automatically.
  • ImprovedSigning in with Microsoft recognises your organisation by its Microsoft Entra tenant.
Platform2026.08.327 August 2026

Real-time brand-lookalike detection and TLD blocking

  • NewBrand-lookalike and generic-hosting-abuse detection in the browser, in real time.
  • NewSelf-service TLD blocking: block whole top-level domains for your organisation.
  • NewPhishing pages hosted on Google Cloud Storage are blocked by pattern, and a curated list of high-risk TLDs is enforced.
  • ImprovedBlocks name the exact indicator that matched.
Platform2026.08.217 August 2026

Data regions, MITRE ATT&CK tagging and near-real-time Sentinel export

  • NewChoose where your data lives: seven data regions, with your organisation's data kept in its region.
  • NewMITRE ATT&CK tactic tagging for rules; Command & Control rules can never be exempted.
  • NewException categories: manage one set of group and device exemptions for many rules.
  • NewAction-aware Defender sync: Allow indicators become exemptions for the right Defender device groups.
  • NewNear-real-time direct export to Microsoft Sentinel.
  • NewArchitecture Reference for IT, security and SOC teams in the admin console.
Platform2026.08.114 August 2026

MSSP portal, IOC submissions and the public status page

  • NewMSSP portal: partners manage client organisations, threat intelligence and custom block pages, with partner credits and pay-as-you-go.
  • NewEnterprise IOC submissions: send suspected domains and URLs to our analysts; confirmed threats are blocked for you and shared with every customer.
  • NewPublic status page with synthetic end-to-end monitoring against the SLA.
  • NewAvailable on the Microsoft Commercial Marketplace.
  • ImprovedOne-click links and the deployment script name each device after its computer automatically.
  • ImprovedDevices waiting for a seat are activated as soon as one is free.
Extension1.2.29 August 2026

Devices stay enrolled for good

Browsers: Chrome, Edge, Brave

  • ImprovedAfter enrollment, the extension keeps its own long-lived device credential, so it no longer depends on the enrollment token's expiry.
  • ImprovedCredentials renewed by the service are picked up immediately.

July 2026

Platform2026.07.125 July 2026

Threat intelligence expansion

  • ImprovedLarge update of the threat-intelligence corpus, with coverage-gap reporting.

June 2026

Platform2026.06.117 June 2026

Redesigned admin console

  • NewThe admin console is organised into dedicated pages: dashboard, devices, rules, tokens and deployment, events, integrations.
  • ImprovedNew Cybereinforce logo and refreshed branding.

May 2026

Platform2026.05.118 May 2026

Custom block pages

Organisation-branded block pages need extension 1.2.0 or later.

  • NewCustomisable block page: your logo, title, message, help text and support contact.
  • ImprovedEvery event exported to Sentinel uses one consistent format.
Extension1.2.114 May 2026

Token enrollment exchanges for a device credential

Browsers: Chrome, Edge, Brave, Firefox, Safari (iOS, iPadOS, macOS)

  • ImprovedA device enrolled with a token exchanges it for its own device credential on first contact.
Extension1.2.013 May 2026

Organisation-aware block page

Browsers: Chrome, Edge, Brave

  • NewThe block page knows which organisation and device it belongs to, so it can show your own branding.
  • ImprovedMore reliable delivery of block events.

April 2026

Platform2026.04.129 April 2026

ISO/IEC 27001 certification and the Trust Center

  • NewISO/IEC 27001 certified: independent certification of how the service is designed, built and operated.
  • NewTrust Center and published information security policy.
  • NewInsights: articles on browser threats and Microsoft security.
  • ImprovedClearer sign-in flow, and better handling for invited administrators.
  • SecurityHardened administration access.
Extension1.1.11 April 2026

Every block on your own rules is recorded

Browsers: Chrome, Edge, Brave, Firefox

  • NewBlocks by your organisation's own rules are reported as security events, alongside threat-intelligence blocks.
  • ImprovedBrowser and extension pages are never checked or blocked.

March 2026

Platform2026.03.227 March 2026

Safari, multiple administrators and vendor comparison

  • NewSafari support on macOS, iOS and iPadOS.
  • NewSeveral administrators per organisation, with one organisation per company domain.
  • NewPublic vendor comparison and browser extensions pages.
Extension1.1.017 March 2026

Threat intelligence in the browser

Browsers: Chrome, Edge, Brave, Firefox

  • NewLive threat-intelligence checks: each visited address is checked against Cybereinforce Threat Intelligence and blocked if malicious.
  • NewOne-click enrollment from the join page.
  • NewFirefox version, signed by Mozilla.
Platform2026.03.110 March 2026

Cybereinforce Threat Intelligence and plan tiers

  • NewCybereinforce Threat Intelligence: a curated feed of hundreds of thousands of malicious domains and URLs, switched on per organisation.
  • NewPlan tiers from Standard to Enterprise, each with its own capacity and features.
  • NewTerms acceptance and refreshed branding.

February 2026

Platform2026.02.326 February 2026

Defender and Sentinel deployment templates

  • NewOne-click Azure templates for the Defender indicator sync Logic App and the Sentinel data collection resources.
  • NewSentinel analytics rules and a workbook for Cybereinforce events.
  • ImprovedLower ingestion cost for exported events.
Platform2026.02.217 February 2026

Microsoft Defender indicator sync

  • NewMicrosoft Defender for Endpoint indicators are synchronised into browser enforcement through a Logic App in your own tenant.
  • NewSentinel export through a Data Collection Endpoint and Rule in your own subscription.
  • NewPurchase orders and invoicing.
Platform2026.02.18 February 2026

First release

  • NewAdmin console with device inventory, enable/disable and renaming.
  • NewDevice enrollment with enrollment tokens and one-click join links.
  • NewBlock rules for URLs and domains, with validation and bulk import (including Microsoft Defender exports).
  • NewBlock page and security events for every block; audit log of administrative changes.
  • NewSeat licensing: devices beyond your licence wait on hold instead of running unprotected.
  • NewIntegration tokens for Microsoft Sentinel event export.

No release notes match your search.

See it on your own traffic

Start a trial, or talk to us about how Cybereinforce fits your Microsoft Defender environment.

Start Free Trial Get the extension Threat Intelligence Service status