Release Notes
What's new in Cybereinforce.
Every update to Cybereinforce Threat Enforcement, from the first release to today: the platform your
administrators and SOC work with, and the browser extension that protects every device.
Browser extension
1.3.1Released 10 October 2026 · 7 versions
Platform is the cloud service: admin console, threat intelligence, integrations and APIs. It updates for every organisation at once, numbered by year and month (2026.10.2 = second release in October 2026).
Browser extension runs on each device and updates through the Chrome Web Store (Chrome, Edge, Brave), Firefox Add-ons and the App Store. Devices are updated automatically.
October 2026
Warnings for suspicious sites, company-wide deployment, one-click Sentinel export
Warnings and policy enrollment are delivered by extension 1.3.1.
- NewSuspicious verdict: threat-intelligence entries are either malicious (blocked) or suspicious (users see a warning and may continue at their own risk). Everything is malicious unless an analyst explicitly marks it suspicious.
- NewBlock or Warn per rule: administrators choose what happens when a rule matches. Microsoft Defender indicators set to Warn are enforced as warnings automatically.
- NewEnterprise IOC submissions can now also be answered as suspicious, which adds a Warn rule for your organisation.
- NewCompany deployment: a Windows script for Intune, Group Policy and Defender for Endpoint, and a macOS configuration profile, that install and enroll the extension by itself for every user, profile and browser (Chrome, Edge, Brave, Firefox).
- NewPrivate windows protected by policy while staying available to users.
- NewDirect Sentinel Export with a single Azure deployment: pick your workspace from a list, no app registration, no secrets to copy. Test first, then switch it on.
- NewSentinel incidents for silent failures: devices that stop checking in, outdated extensions, private windows left unprotected, and integrations that stop delivering.
- NewSentinel analytics rule for users who continue past a warning.
- NewInsights: new articles on closing the Defender URL gap in every browser, stopping device code phishing, new domain protection, our threat intelligence and real time phishing heuristics.
- ImprovedWhile Direct Sentinel Export is on, Cybereinforce keeps no per-event data at all, only daily counts. Switching it on moves existing events to your workspace.
- ImprovedEvents in Sentinel carry the exact time they happened (EventTime) as well as the time they arrived.
- ImprovedRetention follows your plan: 7 days (Trial), 30 days (SME), 90 days (Corporate), 365 days (Enterprise). Daily block counts are kept for 12 months on every plan.
- ImprovedDefender integration: your administrators decide whether Defender device groups and domain indicators are imported; filtering happens in your own tenant.
- ImprovedIntegrations never break: connected Defender and Sentinel integrations keep working when integration tokens are rotated or revoked, and can be disconnected one by one.
- ImprovedJoin page: the extension installs without leaving the page, and enrollment continues by itself.
- ImprovedThe Events page always shows the newest events first; token and join-link history is paginated.
Extension1.3.110 October 2026Latest
Warning page, enrollment by company policy, private-window protection
Browsers: Chrome, Edge, Brave, Firefox
- NewWarning page for suspicious sites: go back to safety with one click, or continue at your own risk. The site is then not flagged again for an hour, and the decision is recorded.
- NewEnrollment by company policy: the extension enrolls itself from Intune, Group Policy, Defender for Endpoint or Mac management settings, for every user, profile and browser on a device.
- NewPrivate windows: when your organisation requires protection there, users are shown how to allow it in one click.
- NewProtection health reporting: each device reports whether private windows and all websites are covered.
- ImprovedSelf-healing enrollment: a device whose credentials stop working re-enrolls on its own from the company policy.
- ImprovedFaster updates: new versions are picked up as soon as they are released.
Day-zero protection and Device Code attack protection for everyone
- NewNewly registered domains are blocked in the browser across 1,100+ TLDs, so a phishing site that went live minutes ago is stopped before any threat feed knows it.
- NewDevice Code attack protection on by default: the Microsoft device-code sign-in page is blocked for every organisation, with whitelisting for legitimate use.
- NewLearning loop: high-confidence automatic blocks are reviewed and added to the shared threat intelligence that protects every customer.
- NewAutomatic seat management: seats held by long-absent devices are reclaimed, and waiting devices switch on as soon as a seat is free.
- NewPublic Threat Intelligence & Detections and Device Code Attack pages.
- ImprovedFaster threat checks, with caching hints so repeat visits need no round trip.
- ImprovedDaily health checks cover every region with no scheduler to maintain.
- ImprovedPrivacy policy describes exactly what the extension sends.
Extension1.3.07 October 2026
Blocks on the first visit, faster browsing, status popup
Browsers: Chrome, Edge, Brave, Firefox
- ImprovedBlocks on the first visit: the threat check is much more patient and resilient, with automatic retries, so a slow connection no longer lets a first visit through.
- ImprovedMuch faster rule matching, even with thousands of rules.
- NewLearns as it goes: confirmed threats are blocked instantly on repeat visits, in every tab, even if the service is briefly unreachable.
- NewStatus popup that shows the protection state in plain language.
- ImprovedDevices wait their turn: if licences are fully used, a device keeps retrying and switches on as soon as a seat is free.
- ImprovedClearer enrollment messages: if a token cannot be accepted, the extension says why.
- SecurityURL fragments, embedded credentials and token-like parameters are never sent in security events.
- ImprovedOne permission fewer than before.
September 2026
Faster TLD blocking and a cleaner threat feed
- ImprovedTLD blocking decisions are faster thanks to cached region resolution.
- ImprovedThreat intelligence feed refreshed and cleaned of false positives.
- ImprovedThe public status page judges each day against the SLA target.
New browser detections and MSSP partner programme
- NewWordPress password-reset link abuse is detected and blocked in the browser.
- NewMachine-generated (DGA) domains on risky hosting are blocked, and suspected device-code lure pages are recognised by their content.
- NewThe .claim and .support TLDs are blocked by default, following their use by an active extortion group.
- ImprovedThe TLD coverage catalog was extended with .xyz and 13 more TLDs.
- ImprovedThe partner programme and portal are now the MSSP programme.
- SecurityEnrolled devices switch to their own long-lived credential on their first check-in and stay connected for good.
- SecurityEnrollment links and policies are checked strictly at every use.
August 2026
Self-service account deletion
- NewOrganisations can delete their account and data themselves; contractual records are kept as required by law.
- ImprovedYour data region is fixed at sign-up and new regions are provisioned automatically.
- ImprovedSigning in with Microsoft recognises your organisation by its Microsoft Entra tenant.
Real-time brand-lookalike detection and TLD blocking
- NewBrand-lookalike and generic-hosting-abuse detection in the browser, in real time.
- NewSelf-service TLD blocking: block whole top-level domains for your organisation.
- NewPhishing pages hosted on Google Cloud Storage are blocked by pattern, and a curated list of high-risk TLDs is enforced.
- ImprovedBlocks name the exact indicator that matched.
Data regions, MITRE ATT&CK tagging and near-real-time Sentinel export
- NewChoose where your data lives: seven data regions, with your organisation's data kept in its region.
- NewMITRE ATT&CK tactic tagging for rules; Command & Control rules can never be exempted.
- NewException categories: manage one set of group and device exemptions for many rules.
- NewAction-aware Defender sync: Allow indicators become exemptions for the right Defender device groups.
- NewNear-real-time direct export to Microsoft Sentinel.
- NewArchitecture Reference for IT, security and SOC teams in the admin console.
MSSP portal, IOC submissions and the public status page
- NewMSSP portal: partners manage client organisations, threat intelligence and custom block pages, with partner credits and pay-as-you-go.
- NewEnterprise IOC submissions: send suspected domains and URLs to our analysts; confirmed threats are blocked for you and shared with every customer.
- NewPublic status page with synthetic end-to-end monitoring against the SLA.
- NewAvailable on the Microsoft Commercial Marketplace.
- ImprovedOne-click links and the deployment script name each device after its computer automatically.
- ImprovedDevices waiting for a seat are activated as soon as one is free.
Extension1.2.29 August 2026
Devices stay enrolled for good
Browsers: Chrome, Edge, Brave
- ImprovedAfter enrollment, the extension keeps its own long-lived device credential, so it no longer depends on the enrollment token's expiry.
- ImprovedCredentials renewed by the service are picked up immediately.
July 2026
Threat intelligence expansion
- ImprovedLarge update of the threat-intelligence corpus, with coverage-gap reporting.
June 2026
Redesigned admin console
- NewThe admin console is organised into dedicated pages: dashboard, devices, rules, tokens and deployment, events, integrations.
- ImprovedNew Cybereinforce logo and refreshed branding.
May 2026
Custom block pages
Organisation-branded block pages need extension 1.2.0 or later.
- NewCustomisable block page: your logo, title, message, help text and support contact.
- ImprovedEvery event exported to Sentinel uses one consistent format.
Extension1.2.114 May 2026
Token enrollment exchanges for a device credential
Browsers: Chrome, Edge, Brave, Firefox, Safari (iOS, iPadOS, macOS)
- ImprovedA device enrolled with a token exchanges it for its own device credential on first contact.
Extension1.2.013 May 2026
Organisation-aware block page
Browsers: Chrome, Edge, Brave
- NewThe block page knows which organisation and device it belongs to, so it can show your own branding.
- ImprovedMore reliable delivery of block events.
April 2026
ISO/IEC 27001 certification and the Trust Center
- NewISO/IEC 27001 certified: independent certification of how the service is designed, built and operated.
- NewTrust Center and published information security policy.
- NewInsights: articles on browser threats and Microsoft security.
- ImprovedClearer sign-in flow, and better handling for invited administrators.
- SecurityHardened administration access.
Extension1.1.11 April 2026
Every block on your own rules is recorded
Browsers: Chrome, Edge, Brave, Firefox
- NewBlocks by your organisation's own rules are reported as security events, alongside threat-intelligence blocks.
- ImprovedBrowser and extension pages are never checked or blocked.
March 2026
Safari, multiple administrators and vendor comparison
- NewSafari support on macOS, iOS and iPadOS.
- NewSeveral administrators per organisation, with one organisation per company domain.
- NewPublic vendor comparison and browser extensions pages.
Extension1.1.017 March 2026
Threat intelligence in the browser
Browsers: Chrome, Edge, Brave, Firefox
- NewLive threat-intelligence checks: each visited address is checked against Cybereinforce Threat Intelligence and blocked if malicious.
- NewOne-click enrollment from the join page.
- NewFirefox version, signed by Mozilla.
Cybereinforce Threat Intelligence and plan tiers
- NewCybereinforce Threat Intelligence: a curated feed of hundreds of thousands of malicious domains and URLs, switched on per organisation.
- NewPlan tiers from Standard to Enterprise, each with its own capacity and features.
- NewTerms acceptance and refreshed branding.
February 2026
Defender and Sentinel deployment templates
- NewOne-click Azure templates for the Defender indicator sync Logic App and the Sentinel data collection resources.
- NewSentinel analytics rules and a workbook for Cybereinforce events.
- ImprovedLower ingestion cost for exported events.
Microsoft Defender indicator sync
- NewMicrosoft Defender for Endpoint indicators are synchronised into browser enforcement through a Logic App in your own tenant.
- NewSentinel export through a Data Collection Endpoint and Rule in your own subscription.
- NewPurchase orders and invoicing.
First release
- NewAdmin console with device inventory, enable/disable and renaming.
- NewDevice enrollment with enrollment tokens and one-click join links.
- NewBlock rules for URLs and domains, with validation and bulk import (including Microsoft Defender exports).
- NewBlock page and security events for every block; audit log of administrative changes.
- NewSeat licensing: devices beyond your licence wait on hold instead of running unprotected.
- NewIntegration tokens for Microsoft Sentinel event export.
No release notes match your search.