August 2026 Release Notes
The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.
Last updated: August 3, 2026
What’s New
Learn about new features across the Command Platform. These features were released over the past month and are available now:
- Risk: Cloud Security (InsightCloudSec), Exposure Command
- Threat: SIEM (InsightIDR), Command Platform
Risk
Risk is the potential for loss or damage to your assets, operations, or reputation, due to vulnerabilities being exploited by a bad actor. Security teams must assess the risk level by evaluating the likelihood of a threat occurring and the impact that it would have if realized.
- Simplify compliance mapping with custom rules and a unified workflow
- Investigate runtime alerts faster with AI-generated root cause analysis
Simplify compliance mapping with custom rules and a unified workflow
In Cloud Security (InsightCloudSec) and Exposure Command, a new Map to Compliance Pack action in the Insights Library consolidates pack membership and compliance rule mapping into a single step, replacing the separate Edit Metadata and Add to Custom Pack actions. Custom packs now support user-defined compliance rules, for example, Custom Control 1.3 or Internal Policy 2.1, and can inherit read-only rules from base packs for scalable, consistent governance.
With these updates in Controls & Compliance > Insights, you can:
- Map individual or bulk-selected Insights to a compliance pack and its rules in one step using the Map to Compliance Pack row or bulk action.
- Define, rename, and delete custom compliance rules from the Compliance Rules tab on a custom pack’s detail page, without losing existing Insight mappings.
- Inherit rules from base packs and filter compliance rules by source.
- Automate compliance rule and mapping management programmatically using new API endpoints.
Investigate runtime alerts faster with AI-generated root cause analysis
When you review a runtime alert in Cloud Security (InsightCloudSec) and Exposure Command, an AI correlation engine can now assemble the pre-existing posture context that explains why it happened. The AI automatically filters out posture, identity, and vulnerability findings unlikely to be relevant to the runtime event, removing noise and leaving only the signals that support your investigation — no manual tool pivoting required. Relevant findings across vulnerabilities, IAM, public exposure, and compliance controls are then ranked, correlated, and surfaced as a Root Cause Analysis tab in the detection findings details view.
With AI-powered root cause analysis in Findings > Detection Findings, you can:
- View a plain-language AI-generated summary explaining how the workload was likely compromised and the chain of posture gaps that contributed.
- Review a prevention timeline showing how long the oldest contributing posture gap existed before the alert fired.
- Prioritize investigation using a ranked list of contributing factors with causal confidence scores.
- Review an overview of the affected asset as it existed at the time of the alert, providing context for how the incident occurred.
Threat
A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.
- Get a quick overview of your environment with the AI Summary Card
- Search events using event time (phased rollout)
- Improved AI-powered query generation
Get a quick overview of your environment with the AI Summary Card
In SIEM (InsightIDR) and the Command Platform, the Detection & Response Dashboard now includes an AI Summary Card for MDR customers. The card provides an AI-generated summary of the most significant detections, trends, and changes in your environment since your last dashboard visit, helping you understand what’s changed without reviewing every widget.
With this enhancement to the Detection & Response Dashboard from Command Home, you can:
- Review the most significant activity in your environment with a synthesized headline.
- Quickly understand key detections and trends through 3 AI-generated insights based on live dashboard data.
- Verify each insight using links to the source dashboard widgets for greater transparency.
- Spend less time reviewing dashboard data and more time investigating the activity that matters most.
Search events using event time (phased rollout)
In SIEM (InsightIDR), we’re beginning a phased rollout of default event time support in Log Search. You can now search events based on when the activity occurred according to the source data, not just when the event was ingested into SIEM (InsightIDR). This makes it easier to reconstruct timelines and understand the sequence of events during an investigation. If an event time isn’t provided by the log source, Log Search continues to use the ingestion time.
This capability is being released in phases and will become available to customers over time.
With this capability in Log Search, you can:
- Search for events based on when they occurred instead of when they were ingested.
- Investigate delayed or historical log data, including logs uploaded after an incident or received from cloud and SaaS integrations with ingestion delays.
- Build more accurate timelines by searching activity in the order it occurred.
Improved AI-powered query generation
In SIEM (InsightIDR), we’ve enhanced AI-powered query generation in Log Search to better interpret natural language prompts and reduce the manual effort required to build searches.
AI-powered query generation can now:
- Automatically interpret natural language time expressions — such as “yesterday” or “last 24 hours” — and apply the appropriate time range to the search.
- Suggest relevant log sources and event source types based on the intent of your prompt.
- Provide a more detailed AI Query Explanation that includes the selected time range and log sources, making it easier to understand how your prompt was translated into a search query.
These improvements help you create more accurate searches faster while providing greater transparency into how AI interprets your requests.
Improvements and Fixes
Keep track of improvements and fixes to core technology.
Application Security (InsightAppSec) and AppSpider
Version 7.5.028
Software release date: July 31, 2026 | Release notes published: July 31, 2026
New Features:
- Out-of-Band Host Header Injection (DNS Redirect) - Added a dedicated OOB attack module to detect DNS Redirect vulnerabilities by injecting callback domains into
Host,X-Forwarded-Host,X-Host,X-Forwarded-Server, and RFC 7239Forwardedheaders. Features raw socket delivery to bypass WinInet constraints and direct Host header replacement. Findings based on DNS-only evidence are assigned Medium confidence. - AI Vulnerability Validator:
- SQL Injection - Integrated automated LLM verification using AWS Bedrock to automatically assess and validate SQL Injection findings, filtering out false positives and reducing manual triage effort.
- Remote File Inclusion - Added AWS Bedrock AI validation to the Remote File Inclusion module to confirm successful exploitation prior to reporting, eliminating false positives from unexploited payload reflections.
- Windows Implicit Authentication Support - Added NTLM, Kerberos, and Negotiate authentication support for Chromium-based scans accessing internal target hosts using default Windows credentials.
Improved:
-
Application Security Scan Engine
- Session Fixation Module - Remediated false positives involving claims-based ASP.NET Core cookies, corrected a bug where cookie value modification was not properly tested, and enhanced finding reporting to explicitly isolate vulnerable cookies when multiple exist in a single request.
- Dynamic Memory Management - Implemented dynamic memory caching controls within the Scan Engine to optimize resource allocation and prevent scan failures caused by insufficient memory.
- Header Sanitization - Injected HTTP request headers are now automatically sanitized to strip leading and trailing whitespace characters.
- Binary Content-Type Blocking - Fixed wildcard matching for binary content-types without file extensions to ensure they are consistently blocked during scans.
- LLM Shadow DOM Analysis - Upgraded response extraction routines to capture Shadow DOM content during LLM security evaluations.
- Runtime Maintenance - Upgraded the installed .NET runtime dependency from version 8.0.19 to 8.0.29 with subcomponent verification checks.
- Attack Data Defs - Updated analyze profiles to include detection for recent Drupal platform releases.
-
R7 Crawler
- Service Worker Coverage - Enhanced
loggedInHeaderRegexevaluation logic to inspect service worker network traffic. - Storage State Conversion - Improved conversion and persistence mechanisms for
localStorage,sessionStorage, andindexedDBbrowser state values. - Cookie Error Handling - Invalid cookies encountered during crawling are now flagged in R7Crawler logs and safely ignored rather than triggering execution errors.
- Service Worker Coverage - Enhanced
Fixed:
- R7 Crawler
- Client Certificate Authentication - Fixed an issue where PFX client certificates were not consistently applied during login macro execution sequences.
Attack Surface Management (Surface Command)
No updates released at this time.
Cloud Security (InsightCloudSec)
No updates released at this time.
Mimics Infrastructure as Code (IaC) Scanning Tool
No updates released at this time.
SIEM (InsightIDR)
No updates released at this time.
Vulnerability Management (InsightVM)
No updates released at this time.
Nexpose
No updates released at this time.
Digital Risk Protection (Threat Command)
No updates released at this time.
Rapid7 Agent (Insight Agent)
No updates released at this time.
Next-Generation Antivirus
No updates released at this time.
Ransomware Prevention
No updates released at this time.
Velociraptor
No updates released at this time.
Automation (InsightConnect)
No updates released at this time.
Insight Network Sensor (Network Traffic Analysis)
No updates released at this time.