August 2026
17 min
extended lookalike domain monitoring release date august 26, 2026 extended lookalike domain monitoring expands how lookalike domains are detected, tracked, and acted on lookalike domains browser a new per domain view of the lookalike domains detected for your organization browse, sort, filter, and search every detected lookalike domain, open a consolidated domain intelligence profile, and act by viewing a site in the sandbox or submitting a takedown request learn more docid\ juorfpuo86x2fd80cgmkw update events in the events feed update events now appear in your events feed when a change is detected on a known lookalike domain, surfacing how a domain evolves over time rather than only its initial detection because each change generates its own event, you can configure alerts on lookalike domain changes and apply severity rules to them learn more docid\ acmt78djtn8vkuzelrmfw extended coverage and enrichment coverage is extended with domain intelligence through datapulse and visual similarity detection through urlscan, which surfaces sites resembling your own even when the domain name is not similar as a result, you may see an increase in lookalike domain events in your events feed as this broader coverage takes effect detected domains carry greater enrichment, including mx records, whois data, ssl certificates, dns records, epp status, and registrar and registrant information learn more docid 5a9wixcgd5blfi9kdz6ii identity identifier deletion release date august 26, 2026 identity identifiers synced from an idp integration are now automatically removed under the following circumstances user deleted from the idp if a user is removed from your idp, the corresponding identity identifier in flare is deleted after two weeks integration downtime if your idp integration goes down, all identity identifiers synced from that integration are deleted after two weeks restore a broken integration as soon as possible to avoid unintended deletion of identity identifiers tenant admins receive in app notifications of a broken idp integration through the notifications center docid\ ccn4axsjkunh7huil7hzg learn more about okta integration docid\ gvu3v0xvtlo ej0kylebb | learn more about entra id integration docid\ zf pmmjlvgkgdka9bihxj confidence score in the intelligence browser release date august 24, 2026 each intelligence object in the intelligence browser now carries a confidence score reflecting how strongly the intelligence is supported by evidence add confidence as a column in the intelligence browser to see each object's score at a glance use filters to narrow results to objects at or above a chosen score, making it easier to focus on high confidence indicators confidence scores are also available via the api for automated workflows learn more docid 05uqcn5rinzdxddsrktmy domain matching policy for past events release date august 21, 2026 domain matching policies can now be applied to past events an apply to past events checkbox is available when creating a policy, giving you more control over how it behaves selecting it applies the policy to events already in your feed, not just events that arrive after the policy is created learn more docid\ tpncfd8yrm1ea8nu6jql8 new emerging data source release date august 21, 2026 indexed document collections is a new emerging data source that holds documents recovered from breaches carrying sensitive material, such as large volumes of live credentials the first collection comes from the litellm supply chain breach https //thehackernews com/2026/08/malicious litellm releases tied to html , in which malicious pypi releases harvested secrets from affected environments select this data source category when creating or editing identifiers to see relevant events learn more docid\ oc9qrltimxbohtzxbvskj in app notifications in the notification center release date august 19, 2026 in app notifications are automated messages that appear in the top navigation bar each notification points to an operational activity that needs attention and is displayed only for the users who need to act on it initial coverage includes tenant events are rate limited identifier events are rate limited idp integration is broken alert channel is broken sandbox submission report is ready a flare report is ready more use cases will be added over time learn more docid\ ccn4axsjkunh7huil7hzg improved lookalike domain events release date august 18, 2026 ahead of the upcoming extended lookalike domain monitoring docid 4ix vdvxlopuuwhz5q3br , we’ve expanded our certstream coverage of lookalike detection certstream monitors certificate transparency logs in real time, surfacing domains as soon as new tls certificates are issued for them by extending the performance and coverage of this source, we can surface new events in the events feed that identify newly registered lookalike domains sooner and widen the set of domains we catch, so more potential threats are surfaced earlier and with fewer gaps in coverage as a result, you may see an increase in lookalike domain events in your events feed as this broader coverage takes effect these improvements lay the groundwork for the broader lookalike updates coming soon docid 4ix vdvxlopuuwhz5q3br , including the new lookalike domains browser and richer enrichment such as mx records and whois data tenant portfolio release date august 12 2026 the tenant portfolio provides a single view of all your tenants, whether they are clients or your own segmented business units consolidated tenants view every tenant you have access to appears in a paginated view, with leaked credentials, infected devices, chat messages, fired alerts, and last activity date/user shown on each row tenant detail view select any tenant to view its key metrics, a preview of its most recent events, and supporting graphs assigned tenants organization admins can switch between viewing every tenant in the organization or only the tenants assigned to them members see only the tenants assigned to them search and filtering easily search or filter the tenant list by status, severity, or date range learn more docid\ lbqfkeueqklnrcfj7thxd dashboard enhancements release date august 12 2026 the flare dashboard has a fresh new look key metrics now include trend visualizations, making it easier to scan and interpret events this is a visual update only, and all your existing features and data work exactly as before trend visualization each metric card for unresolved events by severity and unresolved events by category now includes an inline trend sparkline, showing how your unresolved events are trending over the selected date range without opening a report compact card layout cards use a more compact layout, fitting more of your metrics on screen at once learn more docid\ ochk6lm5zvkdyoapatm o sandbox enhancements release date august 11 2026 the following updates have been made to enhance the user experience for the sandbox improved analysis richer analysis details are now displayed in app, including threat indicators, artifacts, mitre techniques, and screenshots, alongside the pdf report api driven file uploads api support is being introduced for the sandbox, making it possible to upload files programmatically as part of existing workflows files uploaded through the api appear in the uploads tab, from where they can be submitted manually through the flare ui to begin analysis custom sample names submissions can be assigned a custom name for easier identification and tracking support for password protected documents password protected files can now be submitted for analysis learn more docid\ cjhwrdu1mtyfw kaeo1vq new splunk app release date august 7, 2026 a new flare splunk app is now available in splunkbase https //splunkbase splunk com/apps?page=1\&keyword=flare , offering significant improvements to stability and observability this release introduces prebuilt dashboards, an improved configuration interface, a dedicated tab for reviewing application logs, and support for proxied requests and tls verification note for existing users the new app is distributed separately and is not backwards compatible with the legacy flare splunk app the legacy app remains functional, but migrating to the new app is strongly recommended in order to take advantage of the new features and improvements avoid running both apps at the same time, as this will result in duplicate events in splunk follow the migration guidelines docid ii57usyafzyhtoqb05j3 to transition to the new app learn more docid ii57usyafzyhtoqb05j3 severity rules release date august 3, 2026 severity rules determine how severity is assigned to events in your tenant each rule pairs a query with a severity level, and when an event matches a rule, it contributes to the event's final severity two types of rules are available flare rules these are maintained centrally by flare and are available on all tenants out of the box flare rules can be enabled or disabled per tenant, and their severity level can be adjusted to reflect your organization's priorities custom rules these are created and maintained by individual organizations at the tenant level, allowing severity to be set for specific event types so your feed reflects your organization's actual threat priorities rather than a generic baseline severity rules can also be configured as override rules, which force a specific severity over any other matching rules, giving you precise control when needed mcp tooling to manage severity rules is also included learn more docid\ ltsdxtp9ncx7 fohtdsmk