---
title: August 2026
slug: releases/august-2026
docTags: 
createdAt: 2026-08-03T21:52:15.623Z
---

## Extended Lookalike Domain Monitoring

**Release date:&#x20;**&#x41;ugust 26, 2026

Extended Lookalike Domain Monitoring expands how lookalike domains are detected, tracked, and acted on.

- **Lookalike Domains Browser:** A new per-domain view of the lookalike domains detected for your organization. Browse, sort, filter, and search every detected lookalike domain, open a consolidated Domain Intelligence profile, and act by viewing a site in the Sandbox or submitting a Takedown Request.&#x20;
  [Learn more](docId\:JuORfpuO86X2FD80CgmKw)

- **Update Events in the Events feed:** Update Events now appear in your Events feed when a change is detected on a known lookalike domain, surfacing how a domain evolves over time rather than only its initial detection. Because each change generates its own Event, you can configure Alerts on lookalike domain changes and apply Severity Rules to them.
  [Learn more](docId\:acMt78DjtN8vkUzeLRMFW)

- **Extended coverage and enrichment:** Coverage is extended with domain intelligence through DataPulse and visual similarity detection through URLScan, which surfaces sites resembling your own even when the domain name is not similar. As a result, you may see an increase in lookalike domain events in your Events feed as this broader coverage takes effect. Detected domains carry greater enrichment, including MX records, WHOIS data, SSL certificates, DNS records, EPP status, and registrar and registrant information.&#x20;
  [Learn more](docId:5A9wiXcgd5bLfI9KDZ6ii)

:::Iframe{iframeHeight="0" code="<script async src=&#x22;https://js.storylane.io/js/v2/storylane.js&#x22; data-verify-origin=&#x22;&#x22;></script>&#xA;  <div class=&#x22;sl-embed&#x22; style=&#x22;position:relative;padding-bottom:calc(53.05% + 25px);width:100%;height:0;transform:scale(1)&#x22;>&#xA;    <iframe loading=&#x22;lazy&#x22; class=&#x22;sl-demo&#x22; src=&#x22;https://app.storylane.io/demo/uqsghxmol0l1?embed=inline&#x22; name=&#x22;sl-embed&#x22; allow=&#x22;fullscreen&#x22; allowfullscreen style=&#x22;position:absolute;top:0;left:0;width:100%!important;height:100%!important;border:1px solid rgba(63,95,172,0.35);box-shadow: 0px 0px 18px rgba(26, 19, 72, 0.15);border-radius:10px;box-sizing:border-box;&#x22;></iframe>&#xA;  </div>"}

:::



***

## Identity Identifier Deletion

**Release date:** August 26, 2026

Identity Identifiers synced from an IdP integration are now automatically removed under the following circumstances:

- **User deleted from the IdP:** If a user is removed from your IdP, the corresponding Identity Identifier in Flare is deleted after two weeks.
- **Integration downtime:** If your IdP integration goes down, all Identity Identifiers synced from that integration are deleted after two weeks.

Restore a broken integration as soon as possible to avoid unintended deletion of Identity Identifiers. Tenant Admins receive in-app notifications of a broken IdP integration through the [Notifications Center](docId\:CCN4aXsjkunh7HUiL7hzG).

[Learn more about Okta integration](docId\:gVu3V0Xvtlo_eJ0KYlEBB) | [Learn more about Entra ID integration](docId\:zf_pmMjlvgKgdka9bihxj)

***

## Confidence Score in the Intelligence Browser&#x20;

**Release date:** August 24, 2026

Each Intelligence Object in the Intelligence Browser now carries a Confidence Score reflecting how strongly the intelligence is supported by evidence.

- Add Confidence as a column in the Intelligence Browser to see each object's score at a glance.
- Use Filters to narrow results to objects at or above a chosen score, making it easier to focus on high-confidence indicators.
- Confidence Scores are also available via the API for automated workflows.

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/mgNDd0L3Cg6Ugjp51jOj__image.png)

[Learn more](docId:05UQcn5rINZDxddSrktMY)

***

## Domain Matching Policy for Past Events

**Release date:&#x20;**&#x41;ugust 21, 2026
Domain Matching Policies can now be applied to past Events. An **Apply to Past Events&#x20;**&#x63;heckbox is available when creating a policy, giving you more control over how it behaves. Selecting it applies the policy to Events already in your feed, not just Events that arrive after the policy is created.

[Learn more](docId\:TpNCFD8YRM1Ea8nu6Jql8)

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/TtFj4URTDWHZBm_le_GU6_image.png" size="90" isUploading="false" width="1210" height="1118" darkWidth="1210" darkHeight="1118" position="flex-start" showCaption="false"}

***

## New Emerging Data Source&#x20;

**Release date**: August 21, 2026

**Indexed Document Collections** is a new emerging data source that holds documents recovered from breaches carrying sensitive material, such as large volumes of live credentials. The first collection comes from the [LiteLLM supply-chain breach](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html), in which malicious PyPI releases harvested secrets from affected environments. Select this data source category when creating or editing Identifiers to see relevant events.

[Learn more](docId\:OC9qrlTIMXbOHtzxBvSkj)

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/-mpQf-D7a_okdIqtelAxf_image.png" size="70" isUploading="false" width="1094" height="666" darkWidth="1094" darkHeight="666" position="flex-start" showCaption="false"}

***

## In-App Notifications in the Notification Center

**Release date:** August 19, 2026

In-App Notifications are automated messages that appear in the top navigation bar. Each notification points to an operational activity that needs attention and is displayed only for the users who need to act on it. Initial coverage includes:

- Tenant Events are rate-limited
- Identifier Events are rate-limited
- IdP integration is broken
- Alert Channel is broken
- Sandbox submission report is ready
- A Flare Report is ready

More use cases will be added over time.

[Learn more](docId\:CCN4aXsjkunh7HUiL7hzG)

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/A-N5U9qvvsevOGIVxmfWJ_image.png" size="70" isUploading="false" width="1390" height="1332" darkWidth="1390" darkHeight="1332" position="flex-start" showCaption="false"}

***

## Improved Lookalike Domain Events

**Release date:** August 18, 2026

Ahead of the upcoming [Extended Lookalike Domain Monitoring](docId:4ix_VdVxLOPuuWHZ5q3br), we’ve expanded our Certstream coverage of lookalike detection.

Certstream monitors Certificate Transparency logs in real time, surfacing domains as soon as new TLS certificates are issued for them. By extending the performance and coverage of this source, we can surface new events in the Events feed that identify newly registered lookalike domains sooner and widen the set of domains we catch, so more potential threats are surfaced earlier and with fewer gaps in coverage.

As a result, you may see an increase in lookalike domain events in your Events feed as this broader coverage takes effect. These improvements lay the groundwork for the broader [lookalike updates coming soon](docId:4ix_VdVxLOPuuWHZ5q3br), including the new Lookalike Domains browser and richer enrichment such as MX records and WHOIS data.

***

## Tenant Portfolio

**Release date:** August 12. 2026

The Tenant Portfolio provides a single view of all your Tenants, whether they are clients or your own segmented business units.&#x20;

- **Consolidated Tenants View:** Every Tenant you have access to appears in a paginated view, with Leaked Credentials, Infected Devices, Chat Messages, Fired Alerts, and Last Activity Date/User shown on each row.
- **Tenant Detail View:** Select any Tenant to view its key metrics, a preview of its most recent Events, and supporting graphs.
- **Assigned Tenants:** Organization Admins can switch between viewing every Tenant in the organization or only the Tenants assigned to them. Members see only the Tenants assigned to them.
- **Search and Filtering:** Easily search or filter the Tenant list by status, severity, or date range.

[Learn more](docId\:lBQFKEuEQKlNRCfj7tHxD)

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/j7lHS-Zng5qifNfyoe8RG_tenant-portfolio.png)

***

## Dashboard Enhancements

**Release date:** August 12. 2026

The Flare Dashboard has a fresh new look. Key metrics now include trend visualizations, making it easier to scan and interpret Events. This is a visual update only, and all your existing features and data work exactly as before.

- **Trend Visualization:** Each metric card for Unresolved Events by Severity and Unresolved Events by Category now includes an inline trend sparkline, showing how your unresolved Events are trending over the selected date range without opening a report.
- **Compact Card Layout:** Cards use a more compact layout, fitting more of your metrics on screen at once.

[Learn more](docId\:ochk6LM5ZvkdYoApATM-o)

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/tsoBpAGORGHhNn9MZujar_the-dashboard.png)

***

## Sandbox Enhancements

**Release date:** August 11. 2026

The following updates have been made to enhance the user experience for the Sandbox:

- **Improved Analysis:** Richer analysis details are now displayed in-app, including Threat Indicators, Artifacts, MITRE techniques, and Screenshots, alongside the PDF report.
- **API Driven File Uploads:&#x20;**&#x41;PI support is being introduced for the Sandbox, making it possible to upload files programmatically as part of existing workflows. Files uploaded through the API appear in the Uploads tab, from where they can be submitted manually through the Flare UI to begin analysis.
- **Custom Sample Names:** Submissions can be assigned a custom name for easier identification and tracking.
- **Support for Password Protected Documents:** Password protected files can now be submitted for analysis.

[Learn more](docId\:CJhWrdu1MtYfW_Kaeo1vQ)

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/GAIb_XuiYLNQFiZhozzXo_image.png)

***

## New Splunk App

**Release date:** August 7, 2026

A new Flare Splunk App is now available in [Splunkbase](https://splunkbase.splunk.com/apps?page=1\&keyword=flare), offering significant improvements to stability and observability. This release introduces prebuilt dashboards, an improved configuration interface, a dedicated tab for reviewing application logs, and support for proxied requests and TLS verification.

***Note for existing users:*** The new app is distributed separately and is not backwards compatible with the legacy Flare Splunk App. The legacy app remains functional, but migrating to the new app is strongly recommended in order to take advantage of the new features and improvements. Avoid running both apps at the same time, as this will result in duplicate Events in Splunk. Follow the [migration guidelines](docId:-II57uSYaFZYHtOqB05j3) to transition to the new app.

[Learn more](docId:-II57uSYaFZYHtOqB05j3)

::Image[]{src="https://images.archbee.com/wtmLmyh6YG71yn5qVtkMM/WpSQaxhfS2VxDbENfvAhi_image.png?format=webp" size="80" width="800" height="577" isUploading="false" darkWidth="800" darkHeight="577" position="flex-start" showCaption="false"}

***

## Severity Rules

**Release date:** August 3, 2026

Severity Rules determine how severity is assigned to Events in your Tenant. Each rule pairs a query with a severity level, and when an Event matches a rule, it contributes to the Event's final severity.

Two types of rules are available:

- **Flare Rules:** These are maintained centrally by Flare and are available on all Tenants out of the box. Flare Rules can be enabled or disabled per Tenant, and their severity level can be adjusted to reflect your organization's priorities.
- **Custom Rules:** These are created and maintained by individual organizations at the Tenant level, allowing severity to be set for specific Event types so your feed reflects your organization's actual threat priorities rather than a generic baseline.

Severity Rules can also be configured as override rules, which force a specific severity over any other matching rules, giving you precise control when needed. MCP tooling to manage Severity Rules is also included.

[Learn more](docId\:LtSDxTP9nCx7-FOhtDSMK)

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/Faz4g_0NeziYhgUdWD9Io_image.png)

