July 2026
Rate-limiting for New Identifier Creation
Release date: July 30, 2026
When an Identifier is created or its parameters are modified, past events are evaluated and matching events are added to the Events feed. A new per-Tenant limit of 250k events per hour now caps the total volume of past events matched across all new Identifiers in a Tenant within a given hour. This protects the Tenant from being overloaded when many Identifiers are created or imported in a short span. The limit resets every hour.
This is in addition to the previously in place per-Identifier limit of 50k events per data source Category. Together, these limits ensure the volume of past events remains manageable when new Identifiers are created.
Learn moreLearn more
Leaked Credential Event Categories
Release date: July 23, 2026
Leaked Credential Events in the Tenant feed now include four distinct categories, giving you greater granularity into the validation status of credentials affecting your organization:
- All Credentials: All credentials discovered by Flare.
- Valid Credentials: Credentials confirmed to have a correct leaked password, helping you identify and prioritize active exposures.
- Invalid Credentials: Credentials confirmed to have an incorrect leaked password, helping you quickly rule out inactive exposures.
- Mitigated Credentials: Credentials confirmed to have a correct password, but where mitigation actions have since been taken.
Learn moreLearn more

Flare MCP Server (Beta)
Release date: July 22, 2026 The Flare MCP (Model Context Protocol) server provides AI agents access to Flare's Tenant/Global Search and Platform APIs, allowing them to query Flare's threat intelligence dataset and inspect Tenant Events without writing code using the REST API.
The following tools are available:
- Global Search: Executes a query against the entire Flare threat intelligence dataset.
- Tenant Search: Executes a query scoped to events matching your monitored identifiers.
- Event lookup: Returns the full event payload for a single event by UID.
- Event type reference: Returns documentation and searchable fields for a given event type. Learn more
- Profile: Returns the current user's profile, including tenants, permissions, and feature flags.
See the API documentation for setup instructions and supported MCP clients. Please note that this is a beta release and is subject to change.
Password Attributes for Leaked Credential Events
Release date: July 8, 2026
Leaked credential Events can now be filtered by a set of password attributes that describe the leaked password, including its length and the counts of lowercase, uppercase, numeric, and special characters. These attributes are available when searching for Events in the Events feed or Global Search and in Identifier Matching Policies.
Learn moreLearn more

Identifier Discovery Policies
Release date: July 6, 2026
Identifier Discovery Policies are now enabled by default for all users. These policies control which subdomains are automatically discovered and created as Identifiers, helping you focus monitoring on the subdomains that matter and filter out noise.
With Identifier Discovery Policies, you can:
- Define ignore patterns to exclude specific subdomains from automatic discovery.
- Reduce noise in your Events feed by preventing irrelevant Identifiers from being created automatically.
Learn moreLearn more

ASTP API Updates
Release date: July 6, 2026
Two new updates have been made to the ASTP Public API:
- credentials/_search endpoint: This endpoint now supports including URLs as part of the response, giving you richer context alongside credential results. Learn more
- URLs by credential hash endpoint: A new endpoint that allows you to query which URLs a particular credential hash is valid for, making it easier to assess the scope of a compromised credential. Learn more