Release notes
What changed in Edg3, newest first.
2026.10.11
- Changed Changing your password now signs you out of your other sessions; the session you changed it from stays signed in.
- Changed Host isolation no longer offers a "permanent" option. Isolated hosts show the agent's 24-hour limit, and the isolation dialogs explain it.
- Fixed Triage now shows a host as isolated when it was isolated from its agent page or by an emergency isolation.
- Changed When an emergency isolation fails to release, Triage shows the host as still isolated; release it from its agent page with a one-time code.
- Fixed When the console refuses an action on the agent, Triage, Vulnerabilities or Emergency reviews pages, the reason now appears on that page.
- Improved Investigate now shows its progress and elapsed time while it runs, and no longer stops at a "check back shortly" message.
- Fixed The investigation timeline now shows denied and expired approval requests as well as approvals; an expired request reads "expired with no decision".
- Changed Downloading a forensic evidence bundle now requires an approver role, the same roles that approve an isolation.
- Changed Account Settings no longer shows the API tokens and Preferences cards, which had no effect.
- Fixed The vulnerability report upload page now states the actual 1 GB file limit and refuses larger files before uploading.
- Fixed The MFA enrolment screen now names your account, and the account line no longer breaks in the middle of a word.
2026.10.09
- Changed The Vulnerabilities page now prepares its triage once per sync cycle instead of on every page load, so it opens faster. Vulnerability ages (days since detection) refresh every sync cycle; during a sync stall they stop advancing.
2026.10.07
- Changed AI narratives, case summaries and dark web briefings now use an upgraded AI model hosted inside the platform; your security data never leaves it.
- Fixed AI narratives and dark web briefings that had stopped on some consoles are restored.
2026.09.30
- Added Emergency isolation lets an enrolled responder isolate one host in a single step with a fresh sign-in code; a named reviewer is emailed the full record and reviews it.
- Changed Isolation requests now need a second Admin or Analyst to approve them. Tenants with only one approver should add a second one or enrol emergency isolation first.
- Changed Emergency isolations now stay in place beyond 24 hours: the console renews the hold on the endpoint agent every 6 hours, and the agent page and Emergency reviews show when the hold was last renewed and when the agent would release the host if renewals stopped. Hosts need the latest endpoint agent; an older agent shows "Hold unsupported" and still releases the host after 24 hours.
2026.09.28
- Maintenance Platform and delivery updates with no change to what you see or do in the console.
2026.09.26
- Fixed Signals no longer repeats rows or inflates its totals when you change the level filters; totals now come from a 24-hour count.
- Fixed Top Triggered Rules on Signals lists each rule once, with its real severity instead of level 0.
- Changed Signals level filters are proper buttons, the time-window chips that did nothing are gone, and raw log views no longer show detection totals.
- Fixed Dark Web shows "No exposure detected" and LIVE only once the collector has successfully checked the source, not merely run.
- Fixed An agent's vulnerability badge shows the full count, and hosts whose operating system was not assessed say so instead of "No vulnerabilities found".
- Fixed Redux now reads your current data, includes agent detections, and shows when a sync fails instead of an outdated last-sync time.
- Fixed Cases opened by containment workflows now include the incident and the contained host, and list evidence collections that are still pending.
- Fixed "Next actions" on an isolation opens the isolated host's investigation, including for isolations an agent made on its own.
- Changed Opening an incident with no matching runbook no longer drafts a suggestion on every visit; it is drafted once and reused.
- Fixed Signing in right after an update no longer occasionally fails with a temporary error.
2026.09.25
- Added Two-factor sign-in: accounts with an authenticator app now enter a six-digit code, or a one-time recovery code, at every sign-in.
- Added When your console requires two-factor sign-in, users without it set it up at their next sign-in or when activating their account.
- Added Users receive an email whenever two-factor sign-in is set up on their account, and the Users page shows who has it.
- Changed Exchanging a password for a console API token is turned off, and existing tokens stop working; sign in through the console instead.
- Changed When your provider installs your updates, the update card says so instead of offering an Update now button that could not start.
- Fixed The dashboard detection tiles and top rules chart now count matched detections; they read zero before.
- Fixed Active agent and device counts no longer count a host twice or include the built-in AI service.
- Changed Device risk scores now match across the Agents, Entities and Tactical pages.
- Changed Agent search matches names, hostnames and operating systems; the IP option is gone because agents do not report an IP address.
2026.09.24
- Fixed The Executive Summary security alerts figure now counts matched detections instead of every collected event.
- Fixed The Respond page isolated count now shows the hosts that are currently isolated.
- Changed Repeated failed sign-ins now temporarily slow further attempts on that account.
- Changed Agent download links on the Agent Packages page are now private and expire after one hour; copy fresh commands from the console for each install.
2026.09.23
- Fixed Linux agent install commands in the console now install the packages the agent needs, so installs succeed on minimal hosts.
- Fixed macOS endpoints are now labelled macOS in the console instead of Windows.
- Fixed The MITRE technique summary and agent risk queries in the Query Builder now honour the selected time window.
2026.09.17
- Fixed Cloud and Windows detections that could never match now evaluate correctly, so coverage that was silently inactive is live.
- Added Microsoft Entra ID sign-in activity is now evaluated against the cloud detection-as-code (DaC) pack.
- Changed Threat intelligence indicators marked as not for detection no longer raise alerts, removing noise from advisory-only entries.
- Added Tenant encryption and multi-factor key material is now backed up to encrypted object storage.
2026.09.14
- Maintenance Platform and delivery updates with no change to what you see or do in the console.
2026.09.11
- Fixed The console's navigation logo shows the Edg3 mark; on new deployments it was a missing image.
- Changed Sign-up and sales pages are served only from edg3.io; the older copies on the console address have been retired.
2026.09.10
- Fixed The console's browser icon shows the Edg3 mark instead of a broken image reference.
2026.09.09
- Fixed A host isolation is now shown as active only after the endpoint agent has confirmed it. Previously a request could read as active while the host was still online.
- Added An automatic ransomware containment can now be lifted by an analyst from the console. Until now only analyst-approved isolations had a release path.
- Fixed The post-containment forensic collection reports its real status (awaiting the endpoint, not acknowledged) instead of reporting success the moment it was dispatched.
- Changed The isolation runbook page now resolves the affected host and its techniques, so it shows the matching playbook instead of a generic one.
2026.09.07
- Fixed Scheduled and on-demand PDF reports carry the letterhead, confidentiality marking, customer name and page numbers on every page, with the Edg3 logo. Counts print as whole numbers and the executive narrative is formatted rather than raw markup.
- Changed Reports say plainly that detection metrics cover the platform's rolling 24-hour window when a longer period is requested. The incident report groups detection-as-code (DaC) matches by rule and device instead of listing every event, and a data source that is unavailable is named on the report rather than rendered as an empty section.
- Fixed The Tactical Geo dark basemap renders without a watermark, and its attribution sits with the rest of the HUD.
- Fixed Usernames shaped like injection payloads are filtered out of user identities, logons and user-risk scoring.
- Fixed The SOAR tab loads on a fresh deployment before any workflow has run.
- Changed Syslog sources keep their original ports, and appliance events are qualified by their source.
2026.09.06
- Added Windows patch visibility: each device now shows its last scan, last patch and installed-update count on the Vulnerabilities by-host view, and patch-gap analysis runs against that inventory.
- Added Detection coverage for Active Directory object access and computer-account lifecycle events (Windows Security 4662, 4741, 4742).
- Changed The System Update card shows “What’s new” before the update decision, not after it.
- Added Optional cloud object storage for the hot data tier (opt-in, off by default).
2026.09.04
- Changed The investigation agent now recommends host isolation for analyst approval instead of isolating on its own. Automatic ransomware containment is unchanged.
- Fixed Report history now shows how long each report took to generate.