Release Notes

What's new in Cybereinforce.

Every update to Cybereinforce Threat Enforcement, from the first release to today: the platform your administrators and SOC work with, and the browser extension that protects every device.

Platform
2026.10.2Released 10 October 2026 · 17 releases
Browser extension
1.3.1Released 10 October 2026 · 7 versions
Platform is the cloud service: admin console, threat intelligence, integrations and APIs. It updates for every organisation at once, numbered by year and month (2026.10.2 = second release in October 2026).
Browser extension runs on each device and updates through the Chrome Web Store (Chrome, Edge, Brave), Firefox Add-ons and the App Store. Devices are updated automatically.

October 2026

Platform2026.10.210 October 2026Latest

Warnings for suspicious sites, company-wide deployment, one-click Sentinel export

Warnings and policy enrollment are delivered by extension 1.3.1.

  • NewSuspicious verdict: threat-intelligence entries are either malicious (blocked) or suspicious (users see a warning and may continue at their own risk). Everything is malicious unless an analyst explicitly marks it suspicious.
  • NewBlock or Warn per rule: administrators choose what happens when a rule matches. Microsoft Defender indicators set to Warn are enforced as warnings automatically.
  • NewEnterprise IOC submissions can now also be answered as suspicious, which adds a Warn rule for your organisation.
  • NewCompany deployment: a Windows script for Intune, Group Policy and Defender for Endpoint, and a macOS configuration profile, that install and enroll the extension by itself for every user, profile and browser (Chrome, Edge, Brave, Firefox).
  • NewPrivate windows protected by policy while staying available to users.
  • NewDirect Sentinel Export with a single Azure deployment: pick your workspace from a list, no app registration, no secrets to copy. Test first, then switch it on.
  • NewSentinel incidents for silent failures: devices that stop checking in, outdated extensions, private windows left unprotected, and integrations that stop delivering.
  • NewSentinel analytics rule for users who continue past a warning.
  • NewInsights: new articles on closing the Defender URL gap in every browser, stopping device code phishing, new domain protection, our threat intelligence and real time phishing heuristics.
  • ImprovedWhile Direct Sentinel Export is on, Cybereinforce keeps no per-event data at all, only daily counts. Switching it on moves existing events to your workspace.
  • ImprovedEvents in Sentinel carry the exact time they happened (EventTime) as well as the time they arrived.
  • ImprovedRetention follows your plan: 7 days (Trial), 30 days (SME), 90 days (Corporate), 365 days (Enterprise). Daily block counts are kept for 12 months on every plan.
  • ImprovedDefender integration: your administrators decide whether Defender device groups and domain indicators are imported; filtering happens in your own tenant.
  • ImprovedIntegrations never break: connected Defender and Sentinel integrations keep working when integration tokens are rotated or revoked, and can be disconnected one by one.
  • ImprovedJoin page: the extension installs without leaving the page, and enrollment continues by itself.
  • ImprovedThe Events page always shows the newest events first; token and join-link history is paginated.
Extension1.3.110 October 2026Latest

Warning page, enrollment by company policy, private-window protection

Browsers: Chrome, Edge, Brave, Firefox

  • NewWarning page for suspicious sites: go back to safety with one click, or continue at your own risk. The site is then not flagged again for an hour, and the decision is recorded.
  • NewEnrollment by company policy: the extension enrolls itself from Intune, Group Policy, Defender for Endpoint or Mac management settings, for every user, profile and browser on a device.
  • NewPrivate windows: when your organisation requires protection there, users are shown how to allow it in one click.
  • NewProtection health reporting: each device reports whether private windows and all websites are covered.
  • ImprovedSelf-healing enrollment: a device whose credentials stop working re-enrolls on its own from the company policy.
  • ImprovedFaster updates: new versions are picked up as soon as they are released.
Platform2026.10.17 October 2026

Day-zero protection and Device Code attack protection for everyone

  • NewNewly registered domains are blocked in the browser across 1,100+ TLDs, so a phishing site that went live minutes ago is stopped before any threat feed knows it.
  • NewDevice Code attack protection on by default: the Microsoft device-code sign-in page is blocked for every organisation, with whitelisting for legitimate use.
  • NewLearning loop: high-confidence automatic blocks are reviewed and added to the shared threat intelligence that protects every customer.
  • NewAutomatic seat management: seats held by long-absent devices are reclaimed, and waiting devices switch on as soon as a seat is free.
  • NewPublic Threat Intelligence & Detections and Device Code Attack pages.
  • ImprovedFaster threat checks, with caching hints so repeat visits need no round trip.
  • ImprovedDaily health checks cover every region with no scheduler to maintain.
  • ImprovedPrivacy policy describes exactly what the extension sends.
Extension1.3.07 October 2026

Blocks on the first visit, faster browsing, status popup

Browsers: Chrome, Edge, Brave, Firefox

  • ImprovedBlocks on the first visit: the threat check is much more patient and resilient, with automatic retries, so a slow connection no longer lets a first visit through.
  • ImprovedMuch faster rule matching, even with thousands of rules.
  • NewLearns as it goes: confirmed threats are blocked instantly on repeat visits, in every tab, even if the service is briefly unreachable.
  • NewStatus popup that shows the protection state in plain language.
  • ImprovedDevices wait their turn: if licences are fully used, a device keeps retrying and switches on as soon as a seat is free.
  • ImprovedClearer enrollment messages: if a token cannot be accepted, the extension says why.
  • SecurityURL fragments, embedded credentials and token-like parameters are never sent in security events.
  • ImprovedOne permission fewer than before.

September 2026

Platform2026.09.230 September 2026

Faster TLD blocking and a cleaner threat feed

  • ImprovedTLD blocking decisions are faster thanks to cached region resolution.
  • ImprovedThreat intelligence feed refreshed and cleaned of false positives.
  • ImprovedThe public status page judges each day against the SLA target.
Platform2026.09.114 September 2026

New browser detections and MSSP partner programme

  • NewWordPress password-reset link abuse is detected and blocked in the browser.
  • NewMachine-generated (DGA) domains on risky hosting are blocked, and suspected device-code lure pages are recognised by their content.
  • NewThe .claim and .support TLDs are blocked by default, following their use by an active extortion group.
  • ImprovedThe TLD coverage catalog was extended with .xyz and 13 more TLDs.
  • ImprovedThe partner programme and portal are now the MSSP programme.
  • SecurityEnrolled devices switch to their own long-lived credential on their first check-in and stay connected for good.
  • SecurityEnrollment links and policies are checked strictly at every use.

August 2026

Platform2026.08.431 August 2026

Self-service account deletion

  • NewOrganisations can delete their account and data themselves; contractual records are kept as required by law.
  • ImprovedYour data region is fixed at sign-up and new regions are provisioned automatically.
  • ImprovedSigning in with Microsoft recognises your organisation by its Microsoft Entra tenant.
Platform2026.08.327 August 2026

Real-time brand-lookalike detection and TLD blocking

  • NewBrand-lookalike and generic-hosting-abuse detection in the browser, in real time.
  • NewSelf-service TLD blocking: block whole top-level domains for your organisation.
  • NewPhishing pages hosted on Google Cloud Storage are blocked by pattern, and a curated list of high-risk TLDs is enforced.
  • ImprovedBlocks name the exact indicator that matched.
Platform2026.08.217 August 2026

Data regions, MITRE ATT&CK tagging and near-real-time Sentinel export

  • NewChoose where your data lives: seven data regions, with your organisation's data kept in its region.
  • NewMITRE ATT&CK tactic tagging for rules; Command & Control rules can never be exempted.
  • NewException categories: manage one set of group and device exemptions for many rules.
  • NewAction-aware Defender sync: Allow indicators become exemptions for the right Defender device groups.
  • NewNear-real-time direct export to Microsoft Sentinel.
  • NewArchitecture Reference for IT, security and SOC teams in the admin console.
Platform2026.08.114 August 2026

MSSP portal, IOC submissions and the public status page

  • NewMSSP portal: partners manage client organisations, threat intelligence and custom block pages, with partner credits and pay-as-you-go.
  • NewEnterprise IOC submissions: send suspected domains and URLs to our analysts; confirmed threats are blocked for you and shared with every customer.
  • NewPublic status page with synthetic end-to-end monitoring against the SLA.
  • NewAvailable on the Microsoft Commercial Marketplace.
  • ImprovedOne-click links and the deployment script name each device after its computer automatically.
  • ImprovedDevices waiting for a seat are activated as soon as one is free.
Extension1.2.29 August 2026

Devices stay enrolled for good

Browsers: Chrome, Edge, Brave

  • ImprovedAfter enrollment, the extension keeps its own long-lived device credential, so it no longer depends on the enrollment token's expiry.
  • ImprovedCredentials renewed by the service are picked up immediately.

July 2026

Platform2026.07.125 July 2026

Threat intelligence expansion

  • ImprovedLarge update of the threat-intelligence corpus, with coverage-gap reporting.

June 2026

Platform2026.06.117 June 2026

Redesigned admin console

  • NewThe admin console is organised into dedicated pages: dashboard, devices, rules, tokens and deployment, events, integrations.
  • ImprovedNew Cybereinforce logo and refreshed branding.

May 2026

Platform2026.05.118 May 2026

Custom block pages

Organisation-branded block pages need extension 1.2.0 or later.

  • NewCustomisable block page: your logo, title, message, help text and support contact.
  • ImprovedEvery event exported to Sentinel uses one consistent format.
Extension1.2.114 May 2026

Token enrollment exchanges for a device credential

Browsers: Chrome, Edge, Brave, Firefox, Safari (iOS, iPadOS, macOS)

  • ImprovedA device enrolled with a token exchanges it for its own device credential on first contact.
Extension1.2.013 May 2026

Organisation-aware block page

Browsers: Chrome, Edge, Brave

  • NewThe block page knows which organisation and device it belongs to, so it can show your own branding.
  • ImprovedMore reliable delivery of block events.

April 2026

Platform2026.04.129 April 2026

ISO/IEC 27001 certification and the Trust Center

  • NewISO/IEC 27001 certified: independent certification of how the service is designed, built and operated.
  • NewTrust Center and published information security policy.
  • NewInsights: articles on browser threats and Microsoft security.
  • ImprovedClearer sign-in flow, and better handling for invited administrators.
  • SecurityHardened administration access.
Extension1.1.11 April 2026

Every block on your own rules is recorded

Browsers: Chrome, Edge, Brave, Firefox

  • NewBlocks by your organisation's own rules are reported as security events, alongside threat-intelligence blocks.
  • ImprovedBrowser and extension pages are never checked or blocked.

March 2026

Platform2026.03.227 March 2026

Safari, multiple administrators and vendor comparison

  • NewSafari support on macOS, iOS and iPadOS.
  • NewSeveral administrators per organisation, with one organisation per company domain.
  • NewPublic vendor comparison and browser extensions pages.
Extension1.1.017 March 2026

Threat intelligence in the browser

Browsers: Chrome, Edge, Brave, Firefox

  • NewLive threat-intelligence checks: each visited address is checked against Cybereinforce Threat Intelligence and blocked if malicious.
  • NewOne-click enrollment from the join page.
  • NewFirefox version, signed by Mozilla.
Platform2026.03.110 March 2026

Cybereinforce Threat Intelligence and plan tiers

  • NewCybereinforce Threat Intelligence: a curated feed of hundreds of thousands of malicious domains and URLs, switched on per organisation.
  • NewPlan tiers from Standard to Enterprise, each with its own capacity and features.
  • NewTerms acceptance and refreshed branding.

February 2026

Platform2026.02.326 February 2026

Defender and Sentinel deployment templates

  • NewOne-click Azure templates for the Defender indicator sync Logic App and the Sentinel data collection resources.
  • NewSentinel analytics rules and a workbook for Cybereinforce events.
  • ImprovedLower ingestion cost for exported events.
Platform2026.02.217 February 2026

Microsoft Defender indicator sync

  • NewMicrosoft Defender for Endpoint indicators are synchronised into browser enforcement through a Logic App in your own tenant.
  • NewSentinel export through a Data Collection Endpoint and Rule in your own subscription.
  • NewPurchase orders and invoicing.
Platform2026.02.18 February 2026

First release

  • NewAdmin console with device inventory, enable/disable and renaming.
  • NewDevice enrollment with enrollment tokens and one-click join links.
  • NewBlock rules for URLs and domains, with validation and bulk import (including Microsoft Defender exports).
  • NewBlock page and security events for every block; audit log of administrative changes.
  • NewSeat licensing: devices beyond your licence wait on hold instead of running unprotected.
  • NewIntegration tokens for Microsoft Sentinel event export.

No release notes match your search.

See it on your own traffic

Start a trial, or talk to us about how Cybereinforce fits your Microsoft Defender environment.

Start Free Trial Get the extension Threat Intelligence Service status