Changelog

Release notes

What shipped, when. Material changes to features, pricing, data sources, and how we score risk are announced here as well as in the notification channels for paying customers.

Full changelog

2026-08-22 feature

Playbook changes are easier to review and undo

Custom response playbooks now keep a version history with a short explanation of what changed, who saved it, and when. An authorized team member can restore an earlier saved version without preparing or running anything on a case. Playbooks that existed before this update begin with a clearly labeled imported baseline; earlier changes and authorship are not inferred.

cases response playbooks audit
2026-08-22 feature

Past responses keep the playbook that prepared them

Every response prepared from a playbook now keeps the playbook name, version, and exact steps used at the time. If someone edits or archives that playbook later, the case and Response queue still show the original version so the audit history remains accurate.

cases response playbooks audit
2026-08-22 feature

See what a playbook will use before preparing it

The case playbook picker now shows every action it will prepare, the evidence available for that action, and whether a delivery choice or additional evidence is still needed. Indicator exports show how many observables and analyst verdicts are present, integration handoffs show the available destinations, and takedown steps show the number of eligible findings. A playbook with missing evidence or setup stays visible for context but cannot be prepared until the gap is resolved.

cases response playbooks
2026-08-22 feature

Cases now suggest a playbook when there is a clear fit

Each open next step can now show the playbook that best fits the case type and the evidence already on the case. The suggestion explains what it matched, such as available observables, an eligible takedown finding, or an urgent case with a configured handoff. It does not prepare or run anything on its own; an analyst still chooses the playbook and reviews every resulting draft.

cases response playbooks
2026-08-22 feature

Start with a built-in playbook, then make it yours

Built-in response playbooks can now be copied into a team workspace and adjusted without changing the original. The playbook manager also shows how often each playbook has prepared a response, how many cases used it, and the most recent use. Reopening a playbook when all of its responses are already waiting for review does not increase those numbers.

cases response playbooks
2026-08-22 feature

Teams can build their own response playbooks

The Response queue now has a playbook manager where teams can bundle the response steps they use together most often. Custom playbooks can prepare checklist work, an indicator file, an integration handoff, or eligible takedown drafts. Built-in playbooks stay available as read-only starting points, and custom playbooks can be edited, archived, and restored without changing past case history. Applying one still creates drafts only; every response needs its own review.

cases response playbooks
2026-08-22 feature

Playbooks can prepare a response without running it

Cases now include reusable playbooks for an investigation handoff, a brand abuse response, and a team escalation. Choose a recommended next step and SecurityAlert prepares the matching checklist task, indicator file, integration handoff, or eligible takedown drafts. Each action stays separate in the case and Response queue, where you can review, run, or dismiss it on its own.

cases response playbooks
2026-08-22 feature

Response work now has one queue

The old Pending actions page is now the Response queue. It brings prepared case responses, takedown drafts, delivery problems, and assigned response tasks into one place, with filters for the brand, owner, action, and status. Anything that sends data or files a report still needs its own confirmation, and you can open the supporting case before making that call.

response cases takedowns integrations
2026-08-22 feature

Case recommendations can now become response work

Open a recommended next step and you can add it to the case checklist, prepare a downloadable indicator file, hand an eligible brand finding to the Response queue, or send the case through a configured integration. SecurityAlert creates a draft first so you can see what will happen. Nothing is sent, filed, or added to another system until you review and confirm it, and the result stays in the case timeline.

cases response integrations
2026-08-20 feature

Security News now brings reporting and research together

The Security News hub now brings collected headlines from BleepingComputer, The Hacker News, Dark Reading, and SecurityWeek together with SecurityAlert research in one continuous page. Our latest research appears first, followed by current publisher reporting that you can filter by source or topic and search by product, actor, or CVE. Every collected item links back to the publisher, and both reporting and SecurityAlert research remain available by RSS.

threat-intel security-reporting rss
2026-08-20 feature

Microsoft and Citrix advisories now join the product watch

SecurityAlert now reads Microsoft security updates and Citrix security bulletins directly from their official sources. Microsoft updates are kept at the CVE level, while Citrix bulletins retain the vendor's affected products, fixed versions, severity, CVSS score, dates, and available guidance. The new sources feed the public advisory catalog and the same product-matching checks used by technology watches.

vendor-advisories technology-watch cve
2026-08-20 feature

See exactly how each watched product is covered

The Technologies tab now shows the matching paths available for every product you watch. You can see whether the product appears in the NVD catalog, whether an exact CPE is available, how many CISA KEV and EPSS records match, which official vendor sources are connected, when those sources were last checked, and which recent advisories mention the product. SecurityAlert also calls out delayed data, missing coverage, and products seen on public assets that are not being watched yet. The new freshness check caught a broken EPSS refresh, which has been repaired. Product and advisory matches remain investigation leads, not proof that software is installed or vulnerable.

technology-watch vendor-advisories cve
2026-08-20 feature

You can add your technology stack in one review

Technology watches no longer need to be created one at a time. You can search the vulnerability product catalog, review products SecurityAlert has seen on your public assets, or import a CSV, CycloneDX JSON, or SPDX JSON inventory. The review list lets you correct names and versions and remove products before anything is saved. Only the products you confirm are sent to SecurityAlert, and all of the resulting watches use the alert destinations you choose.

technology-watch sbom cve
2026-08-20 design

Product alerts are easier to set up

Technology watches now guide you through vendor, product, and version choices drawn from the vulnerability data SecurityAlert already collects. Choosing a known version fills the CPE match automatically. Products that are not in the catalog can still be entered by hand, and the CPE field remains available under Advanced options when you need more control.

technology-watch cve threat-intel
2026-08-19 feature

Vendor advisories are easier to follow

Every advisory now has a permanent page where you can review the vendor's timeline, severity, affected products, fixed versions, CVEs, guidance, and related bulletins without losing the link to the original source. The catalog shows whether each source is current, labels dates as published or updated, and keeps a field-level record when a vendor later changes a bulletin. CVE pages show the official vendor bulletins that name that vulnerability. Every search has an RSS feed, and supported products can be carried into a prefilled alert setup. You still review the details and choose where alerts should go before a watch is saved.

vendor-advisories rss technology-watch
2026-08-19 feature

Vendor advisories are now easier to search

A new public advisory catalog brings official security bulletins from Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS into one searchable view. Filter by vendor or severity, search for a product, CVE, or advisory ID, and compare affected products, fixed versions, dates, CVSS, and available fix guidance before opening the original vendor bulletin.

vendor-advisories threat-intel cve
2026-08-19 design

It is easier to see where SecurityAlert connects

The integrations directory now groups connections by the job they do: sending alerts, sharing intelligence, bringing in identity and SIEM evidence, supporting automation, and managing access. Recognizable product logos replace the old letter badges, while open standards and SecurityAlert capabilities use clear interface icons. Every card says how the connection works, which plan includes it, and whether it is available now. Jira, PagerDuty, Opsgenie, Google Chat, Discord, and SMS remain in a separate coming-next section until they can be configured in the product.

integrations api automation
2026-08-19 feature

Vendor security advisories now match the products you watch

SecurityAlert now reads official advisories from Palo Alto Networks, Cisco, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep the vendor advisory ID, severity, CVSS score, affected products, CVEs, publication and update dates, and available fix guidance. New advisories are matched to your technology watches and appear in Pulse with a link back to the vendor.

vendor-advisories pulse technology-watch
2026-08-19 feature

New advisories and security research now flow into Pulse

SecurityAlert now checks 21 approved publisher feeds throughout the day, including government advisories, vendor security bulletins, established research teams, security news, and clearly labeled community discussion. New reporting keeps its source and publication time, is ranked for signals such as active exploitation and zero-day activity, and is matched against watched technologies, CVEs, and industry context before it appears in Pulse.

pulse advisories research
2026-08-19 feature

Campaign research, smarter monitors, and reviewed briefings

A new public campaign catalog brings each campaign's timeline, attributed actors, targets, and sources together on one page. Business workspaces can now add organization context, watch campaigns and other intelligence with precise conditions, save evidence as they investigate, add analyst conclusions, and deliver a briefing only after review.

threat-intel monitors briefings
2026-08-18 feature

Host CVEs now appear on asset pages

Open a monitored host and its active CVEs now appear next to exposed paths. You can see severity, KEV status, known ransomware use, EPSS, affected software, last seen, and related ATT&CK techniques. The riskiest items come first, and shared CDN infrastructure is left out.

assets cve exposure
2026-08-18 fix

Posture alerts wait for a material change

Small day-to-day swings in SLA backlog and modeled loss no longer trigger an email. A change now needs to be large enough in both raw numbers and percentage terms. The same type of event will not alert the same user more than once in seven days, but a different material change can still get through right away.

alerts posture notifications
2026-08-16 feature

Actor tracking watches subdomains and new lookalikes

Actor tracking now watches both sides of an operator's infrastructure: new subdomains appearing under a watched domain and newly observed domains that closely resemble it. Alerts stay tied to the watch that produced them and keep the observation history available for review.

actor-tracking subdomains lookalikes
2026-08-16 feature

WHOIS results now open directly into investigations

WHOIS results now summarize domain age and time to expiry, open the domain directly in SecurityAlert reputation and nameserver investigations, copy a stable report link, and export the complete normalized record as JSON.

whois investigation export
2026-08-16 feature

WHOIS adds authoritative registry and registrar detail

Public WHOIS results now combine registry and sponsoring-registrar RDAP into one structured view. Domain IDs, exact lifecycle dates, EPP status, DNSSEC, registrar IANA and abuse details, nameservers, redaction, contact geography, contact routes, and authoritative record links appear alongside SecurityAlert zone evidence, infrastructure context, and observed history.

whois rdap investigation
2026-08-16 design

Threat actor profiles now lead with SecurityAlert assessments

Threat actor pages retain their complete dossiers, indicators, mappings, relationships, campaigns, victims, and material confidence distinctions while removing repeated publisher names, citation links, provenance identities, routine Reviewed badges, the public evidence-freshness card, and report-only timeline entries. Internal provenance and freshness monitoring remain available to analysts.

threat-actors threat-intel
2026-08-16 feature

SecurityAlert News adds source-backed defensive reporting

A new public newsroom covers attacks, vulnerabilities, threat actors, ransomware, attack vectors, breaches, research, and security trends. Every published article separates verified facts from SecurityAlert analysis, lists practical defensive actions, and links the original source ledger. Category archives, search, pagination, related coverage, RSS, article metadata, and an admin review workflow support ongoing publication.

news research threat-intel
2026-08-16 fix

Intelligence alerts are consistent and more actionable

Technology, identity, actionable vendor degradation, and collection digests now use the same Outlook-safe card, typography, severity styling, action button, footer, and domain-first subject pattern as other SecurityAlert operational emails. Vendor concentration changes remain available in Relevant Threats but no longer generate email or webhook digests.

notifications email intelligence
2026-08-15 feature

App monitoring gains individual review workflows

Every app-store finding now opens in a dedicated review dialog with store metadata, similarity evidence, description, observation dates, and append-only analyst notes. Findings can be investigated, escalated, resolved, dismissed, reopened, marked as owned, or returned from owned status. The app table adds review-state filters and 10, 25, or 50 row pagination while keeping actions permission-gated.

brand-monitor app-store workflow
2026-08-15 design

Operational sections gain evidence-scoped visual summaries

Overview, Pulse, Attack Surface, Relevant Threats, Automation, Threat Actors, and Trending CVEs now pair their evidence with consistent distribution, concentration, coverage, activity, and workflow views. Authenticated evidence tables also gain a visual summary of the currently visible records when their columns support it. Every chart states its scope, updates with filters, includes an accessible tabular equivalent, and remains empty when no records support it. Vendor dependencies now use a contained table with filter-aware pagination and selectable page sizes. Evidence and individual risk decisions open in a dedicated review dialog so table rows stay compact without nested scrolling.

dashboard visualization accessibility
2026-08-15 feature

Customer-owned identity sources add real account context

Relevant Threats can now correlate account-level evidence with read-only directory snapshots from Entra ID, Google Workspace, Okta, and other customer directories. Normalized risk events from Entra ID Protection, Microsoft Sentinel, Defender, Splunk, Elastic, and generic customer sources create cases only when a username or email address is present. Aggregate domain counts remain visible as context but are no longer actionable cases. A tenant-scoped ingestion API supports automation without storing provider credentials, raw logs, passwords, cookies, tokens, or session data.

identity integrations threat-intel
2026-08-15 feature

Identity cases now show account-level evidence

Relevant Threats now separates identified account cases from aggregate host signals. Account records show the username or email address, affected service, breach or stealer context, source, record ID, and evidence dates. Verified workspaces can collect Have I Been Pwned domain results or import an authorized CSV, while sensitive credential and session fields are rejected. Sources that provide only a hostname and count are labeled as unattributed and no longer imply that an affected user was identified.

identity threat-intel evidence
2026-08-15 feature

Connected exposure graph links assets, repositories, cloud, vulnerabilities, and controls

A new Exposure graph workspace turns first-party asset evidence, read-only provider inventory, static CI/CD checks, normalized scanner findings, passive web and API inventory, and ATT&CK control evidence into source-backed paths. Each path can be investigated, accepted, resolved, dismissed, validated, and retested individually. Changed evidence reopens closed paths. Saved graph filters retain the matched records and support daily or weekly email and webhook reports.

exposure-management attack-surface cicd attack
2026-08-15 design

Overview and Attack Surface become operational workspaces

The signed-in Overview now leads with six portfolio metrics, ranked priority work, compact posture, capability health, and the latest first-party findings. Generic sector actor activity no longer appears as if it were customer-relevant. Attack Surface now groups its summary into decision metrics, verified first-party exposure priorities, visible asset inventory, and collection coverage. It uses the same normalized asset CVE observations as Relevant Threats and excludes shared CDN edges. Vendor monitors remain in Vendor Risk and do not inflate first-party asset or vulnerability counts.

dashboard attack-surface operations
2026-08-15 feature

Relevant threats becomes an operational intelligence workspace

A new authenticated workspace ranks threats with visible evidence from verified first-party assets, actor CVE and IOC links, KEV, EPSS, ransomware use, and recency. Typosquats, impersonation infrastructure, brand findings, and sector-only similarity are deliberately excluded from Relevant threats. The workspace also adds technology watches, metadata-only identity response cases, vendor concentration, daily-diff collections with CSV, STIX, and TAXII export, review-gated detection packs, scheduled email and webhook digests, and a read-only analyst available in the dashboard and MCP.

threat-intel operations taxii mcp
2026-08-15 feature

New threat research now enters a review-gated discovery queue

SecurityAlert now monitors six allowlisted primary research publishers for new threat actor reporting. Exact, high-confidence actor matches enter the existing pending report queue with the source and match rationale attached. Weak, ambiguous, and duplicate matches remain private. Code examples are excluded from network-indicator extraction, and discovered network or tool indicators require explicit reviewer selection before publication.

threat-intel actor-dossiers
2026-08-15 feature

Threat actor profiles gain evidence freshness and a unified activity timeline

Actor profiles now show a transparent evidence-freshness score and one dated ledger combining reviewed reporting, actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Every date states what it represents, and changed sources or revoked mappings go to analyst review instead of changing public intelligence automatically.

threat-intel actor-dossiers
2026-08-15 feature

Six high-impact threat actors receive full reviewed dossiers

Qilin, Akira, Clop, Play, INC Ransom, and The Gentlemen now publish source-backed names, tracking identifiers, operational behavior, targeting context, ATT&CK techniques, indicators, associated software, defensive guidance, and cited reporting. Relationship confidence keeps operator, affiliate, overlap, and possible-lineage claims separate from exact aliases, while INC Ransom now reaches its live victim evidence.

threat-intel actor-dossiers
2026-08-14 feature

Threat actor dossiers gain complete catalog coverage and cited evidence

The actor catalog now reaches active, dormant, and historical records; normalizes sector filters; exposes ATT&CK techniques; distinguishes claimed victim dates from first-observed listings; links supporting evidence; and publishes actor profiles in the sitemap. Actor tracking now waits reliably for authentication and creates nameserver-pair watches instead of treating one shared DNS host as actor attribution.

threat-intel actor-tracking
2026-08-09 feature

SecurityAlert is available through MCP

Connect an MCP client to SecurityAlert to look up indicators, review asset exposure, pivot on registrant data, and work with findings without leaving the client. Access is available on Business plans and keeps the same tenant boundaries, permissions, rate limits, and audit logs as the rest of SecurityAlert.

mcp api automation
2026-08-09 data

Ransomware coverage now reaches further back

The ransomware tracker now uses RansomLook alongside our existing source and reaches back through each group's available victim history. We merge duplicate group and victim records and keep observed dates separate from dates claimed by an operator.

ransomware victims history
2026-07-03 fix

Public site aligned with the current DRP platform

Removed stale standalone URL-scanner and YARA-era promises from pricing, API docs, and the featured changelog copy after the sandbox infrastructure was decommissioned. The REST API now documents the supported resources only: brand findings and universal indicator lookup.

docs api
2026-05-02 feature

Customer YARA rules now apply during live URL scans

The YARA editor at /yara-rules ships into production. Every URL scan submitted by an authenticated user pulls their active custom rules, the GCP sandbox compiles them alongside our 32 public-source rules on the same scan, and any matches are tagged with a "YOUR RULE" badge in the Detected by Yara table. Up to 50 active rules per user. Rules can be disabled (kept for later) or deleted; status changes take effect on the next scan.

yara differentiator
2026-05-02 feature

Release notes RSS feed at /changelog.rss

Subscribe to release announcements with any feed reader. Same content as /changelog, structured as RSS 2.0. Featured rocks emit as separate items so each headline shows up. Auto-discovery link on the changelog page picks up automatically in modern readers.

rss
2026-05-02 feature

Custom YARA rules per customer (editor + API)

Paying customers can now upload their own YARA rules via the public REST API or the new /yara-rules editor. Rules are validated against the local YARA 4.5 binary on save, with size + safe-import restrictions. CRUD endpoints under /api/yara-rules. No DRP competitor in our research lets customers ship their own detection rules into the pipeline.

yara differentiator
2026-05-02 feature

Estimated annualized loss exposure on every brand scorecard

Every public scorecard (the URL you share with prospects, auditors, or insurers) now carries a single dollar-figure: the Open FAIR ALE = SLE x ARO derived from the brand's active findings, calibrated per severity from IBM Cost of a Data Breach 2024. Per-severity caps prevent a long tail of low findings from inflating the headline. Pairs with the ATT&CK heat-map dollar overlay shipped earlier today.

scorecard fair
2026-05-02 design

Public RBAC reference at /security/rbac

A public, RFP-ready reference page that documents the 11 product categories and 5 built-in role presets (Owner, Editor, Certificate Manager, Brand Manager, Auditor) used to scope every customer-facing action. Renders directly from the runtime authorization model so it can never drift from what the server actually enforces. Quote it on SOC 2, ISO 27001, SIG/CAIQ, or vendor-risk questionnaire access-control rows.

rbac compliance
2026-05-02 feature

New pricing tier: Solo at $79/month

A new tier between Pro ($29) and Business ($249) for agencies and small SaaS teams that outgrew Pro. 5 brand monitors, GitHub leaked-secrets scanning, brand-asset visual matching, malvertising detection on Meta Ads Library, VIP / executive watchlist (3 execs), one quarterly executive PDF report. Add-on: +5 brand monitors at $49/month. The 14-day trial on every paid tier no longer asks for a credit card.

pricing
2026-05-02 feature

Public REST API v1 + OpenAPI 3.1

A documented REST API at /api/v1 for SIEM connectors, MSSP integrations, and your own automation. Three resources at launch: brand findings, public URL-scan results, and the universal indicator lookup. Bearer-token auth, 120 requests / minute / key, Business or Enterprise plan. Mint a key from /settings#api-keys; full Swagger UI at /api/docs; spec at /api/openapi.json (or .yaml).

api
2026-05-02 feature

Brand-asset visual matching

You can now upload your logo, hero image, or marketing masthead per brand monitor. Every typosquat finding is compared against each uploaded asset, so impersonation pages whose chrome differs from your main site (different layout, but lifted your logo) get caught. Comparisons happen automatically on every scan and are cached for fast re-reads.

brand-monitor visual-similarity
2026-05-02 feature

Malvertising detection on Meta Ads Library

Modern phishing increasingly skips the typosquat domain step and just buys ads on the brand name, routing the click to a kit on a lookalike host. Brand monitor now queries the Meta Ads Library every scan for active Facebook and Instagram ads matching your brand keywords, surfaces ads from advertisers other than yours, and auto-elevates risk when the landing host matches an existing typosquat finding. Google Ads Transparency Center coverage on the same surface ships next sprint.

brand-monitor malvertising
2026-05-02 feature

Per-signal rule citation on URL-scan results

Every line in the Analysis breakdown now ends with a "matched: <rule>" chip naming the detection source. Public threat feeds (URLhaus, ThreatFox, Google Safe Browsing, FeodoTracker, SSL Blacklist) link out to the source so an analyst can pivot to ground truth in one click. Most DRP vendors hide their detection logic; we show ours.

url-scan explainable
2026-05-02 feature

Annualized loss exposure on the ATT&CK heat map

Every technique on /attack-heatmap now carries a dollar figure for estimated annualized loss exposure, and the stats bar shows a sector-level total. Calibrated per ATT&CK tactic from IBM Cost of a Data Breach 2024 (Initial Access $4.88M, Credential Access $4.81M, Exfiltration $4.45M, Impact $7.5M) and the Open FAIR ALE = SLE x ARO model. Numbers round to the nearest $50k to avoid spurious precision.

threat-intel fair
2026-05-01 feature

Universal indicator search at /lookup, expanded

The Cmd+K universal lookup surfaces every place a token appears across your brand findings, ransomware leak sites, threat-intel feeds, and the CVE catalog, alongside the type-to-jump destination.

threat-intel
2026-05-01 data

Three new threat-intel data sources live in scans

Every URL scan now consults Google Safe Browsing v4, abuse.ch FeodoTracker (botnet C2 IPs), and abuse.ch SSL Blacklist (malware certificate fingerprints). A hit on any of them locks the verdict to malware regardless of page contents. These feeds carry far fewer false positives than open IOC catalogs.

threat-intel
2026-05-01 feature

Sharper typosquat detection

The brand monitor now catches dormant-registration squats: domains registered to look like yours but parked, waiting to weaponize on demand. We also added three more variant patterns (character omissions, neighbouring-key swaps, hyphen insertions) that real-world attackers actually use against major brands.

brand-monitor
2026-05-01 feature

YARA on the captured DOM

Every URL scan is now matched against 32 YARA rules curated from public sources (Volexity, Tenable, ditekshen) plus our own SecurityAlert.ai rules, with full author attribution per match. Our first production rule (sa_kit_punchvideo_stripe_lure) fires on a Stripe-themed credential lure we observed in the wild. A rule match is treated as a strong verdict signal, not a soft one.

yara detection
2026-05-01 feature

Drill-down filters on dashboard findings

Click any chip on the dashboard findings panel (severity, source, brand, or status) to filter the list inline. The active filter set is reflected in the URL so you can share a deep-link to a specific cut of findings (for example, all High typosquat findings on a given brand).

dashboard
2026-05-01 feature

Industry sector and Settings on every brand page

A new sector picker at the top of each brand-detail page sets the comparison cohort for industry benchmarks. The Insurance sector was added to the dropdown, and the dropdown is now alphabetical. A Settings drawer collects all the per-brand toggles (notifications, monitor cadence, sharable scorecard) in one place instead of scattered across the page.

brand-monitor
2026-05-01 fix

False-positive hardening

Closed off three classes of false positive in the URL-scan verdict logic: (1) ThreatFox uncorroborated matches no longer auto-force a malware verdict; (2) shared third-party analytics, ad-tech, and chatbot hosts (Marketo, Drift, Qualified, Google reCAPTCHA, marketing redirect chains) no longer drive beaconing or credential-post signals on legit complex sites; (3) GitHub social mentions no longer fire critical on every code-search hit unless we actually detect a real secret pattern.

verdict
2026-04-27 feature

Vendor risk monitoring

A new Vendor risk view at /vendors lets you track your third-party vendors the same way you track your own brands. Add the domains of vendors you depend on (your SSO provider, your cloud, your payroll system) and we run the full scanner against each one: dark-web mentions, exposed services, leaked credentials, certificate posture. Comes with Business and Enterprise plans, capped at 25 and 250 vendors respectively.

vendor-risk
2026-04-27 feature

Stealer-log enrichment on credential exposure

The free credential exposure tool now shows the top hostnames where your credentials were stolen, broken down by employee versus customer sessions. Hostnames only, never paths, so no live session tokens are exposed. You get a concrete reset list instead of a single aggregate count.

credentials stealer-logs
2026-04-27 feature

Wider dark-web coverage: malware feeds + Telegram

Brand monitor scans now pull from abuse.ch URLhaus and ThreatFox (malware-distribution URLs and threat indicators tagged to your domain) plus a curated set of public threat-intel Telegram channels. The brand-detail dark-web tab gets new filter chips for URLhaus, ThreatFox, and Telegram so you can drill into each source. URLhaus and ThreatFox require a free abuse.ch API key.

dark-web threat-intel
2026-04-26 feature

Faster signup and an industry-tailored dashboard

New signups now go through a one-screen setup that asks for your domain and industry, then kicks off the first scan automatically. Your dashboard panel for actors targeting your sector filters to groups known to go after your industry, instead of showing a generic global list. A live progress banner shows whenever a scan is running, so you always know results are on the way.

onboarding
2026-04-26 feature

GitHub leaked-secrets monitoring

We now scan public GitHub every day for code that mentions your monitored brands and flag any exposed credentials: AWS keys, GitHub tokens, Slack tokens, API keys, private keys, JWTs, basic-auth URLs, and more. Findings are sorted by severity, with sensitive files like .env, .yml, and .pem surfaced first. Any matched credential is redacted before it lands in our database, so we never store a live secret.

github code-leaks
2026-04-26 feature

Universal lookup with Cmd+K

Paste any threat indicator and we route you to the right intelligence card automatically: CVE id, IP, hostname, file hash, email, threat actor name, or ransomware group. Cmd+K opens the lookup from anywhere on the site.

threat-intel
2026-04-26 feature

Attack-surface auto-discovery

A new review queue surfaces domains we think belong to you but that you haven't told us about yet. We find them by cross-referencing shared TLS certificates, WHOIS registrant info, resolved IPs, and brand mentions in public GitHub code. One click promotes a candidate into a tracked brand and kicks off its first scan. Stale candidates auto-archive after 60 days if the signal disappears.

discovery
2026-04-26 feature

Searchable certificate history

Search every TLS certificate ever logged for your monitored brands. Filter by hostname, organization, or issuer. Pivot from any result to find sibling certificates: the same cert reused across multiple hosts, or everything a given issuer has signed for you in the last 30 days.

certs
2026-04-26 feature

ATT&CK technique heat map

A public heat map of the techniques attackers actually use, mapped to MITRE ATT&CK across 172 tracked threat actors and 14 tactics. Filter by industry to see what is hitting your sector: financial services skews toward valid-account abuse, government toward phishing, energy toward exposed remote-access services. Click any technique to drill into the actors using it.

threat-intel mitre
2026-04-25 launch

Public launch

SecurityAlert.ai is live as a standalone Digital Risk Protection product. Brand monitor, threat actor catalog, ransomware tracker, CVE intelligence, and three free public tools (SSL grader, phishing checker, credential exposure lookup) all ship at launch. The free tier starts at one brand monitor with no credit card.

pricing
2026-04-25 data

Threat intel catalog ready to browse

172 threat actor profiles, 1,583 CISA Known Exploited Vulnerabilities, and 333 ransomware groups are loaded and ready to browse on day one. Ransomware leak sites are monitored continuously. CVE-to-actor attribution refreshes daily.

threat-intel
2026-04-25 tools

Free SSL grader

The SSL grader runs the full SSL Labs methodology: TLS 1.0 to 1.3 protocol coverage, cipher enumeration, key-exchange analysis, vulnerability checks (BEAST, POODLE, FREAK, LOGJAM, CRIME, BREACH), certificate chain validation, and HTTP security header grading. Letter grade A+ through F. Free, no signup, results cached for 30 days.