Release notes

Brand impersonation detection across mobile app stores

Mark Barber September 9, 2026

Mobile app stores are a favorite venue for brand abuse. A convincing lookalike app can sit in a public storefront, carry an organization’s name and branding, and reach its customers directly, without touching any of its infrastructure. Threat Monitoring now scans the Apple App Store and Google Play Store for apps that reference a monitored domain or brand term. Scanning covers the app name, developer name, description, and listing metadata. The AI Analyst automatically dismisses listings it identifies as official. Security teams review only the listings it flags as potential brand impersonation.

Threat Monitoring filtering by event, detection, or alert date

Threat Monitoring users can now choose which date the filter applies to. A toggle above the date range dropdown switches between event date, detection date, and alert date. The selection carries through the rest of the view: chart grouping and the date label on each threat result card both update to match, and the chosen date field is used in exports.

NIST SP 800-171 Rev. 3 in the Security Profile

Vendor Risk users can now select NIST SP 800-171 Rev. 3 in the Security Profile to assess vendors against. Our control library maps directly to all 97 requirements, so assessing against NIST SP 800-171 runs on the same core checks used across all other frameworks in the Security Profile. This framework sets the security requirements for protecting Controlled Unclassified Information (CUI) across US federal and defense supply chains.

Browser extension branding for User Risk

User Risk admins can now customize the User Risk browser extension to reflect their organization. Admins can set a theme, a company logo, an accent color, and a display name so users see extension nudges, blocks, and other messages branded to their organization instead of UpGuard’s default.

Other improvements

  • Vendor Risk users can now select multiple additional evidence documents and archive, delete, or download them in a single action.
  • Trust Exchange now captures the countersigner’s name when an NDA is countersigned and writes it into the signed NDA document.
  • UpGuard now detects Gitea and its version on scanned sites, so vulnerabilities affecting a specific Gitea release appear in risk findings.
  • UpGuard now detects two critical Gitea vulnerabilities on scanned hosts: CVE-2026-27771, an authentication bypass where the built-in container registry accepts an anonymous bearer token regardless of repository visibility, allowing unauthenticated attackers to enumerate and pull private container images; and CVE-2026-59774, an improper input validation vulnerability in the Org-mode markup renderer that allows unauthenticated attackers to read arbitrary files on the server.
View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more

Updated application usage policy controls

Mark Barber June 17, 2026
Read more

New threat signal: Published MCP server definitions

Mark Barber June 3, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950