Release notes

Threat Posture: an executive view of external threat activity

Mark Barber September 22, 2026

Threat Monitoring no longer stops at the individual threat. When a scan and analysis completes, the Security Advisor reads across every triaged signal in Threat Monitoring and produces a Threat Posture brief: a short, executive-ready read on what the activity around an organization adds up to.

The Threat Analyst works signal by signal. The Security Advisor works one level up, surfacing the patterns behind the noise. Each insight follows the same structure: the pattern observed, why it matters, what it implies about the organization’s controls, and what leadership should prioritize. Recommendations are pitched at leadership priorities rather than individual remediation tasks.

The Threat Posture brief appears on the Threat Monitoring feed page and refreshes weekly. Insights are filterable, and each traces back to its underlying threats, so every statement presented to executives links to the evidence behind it.

Faster threat closure in Threat Monitoring

Every threat card and threat details page now has a Manage threat button with the same options in the same order, replacing the three-dot menu. Two options have clearer names: No action needed replaces Risk Accepted for threats that do not warrant work, with an optional note, and False match replaces False positive for findings incorrectly attributed to the organization. Exposed credential threats close with a single quick action, and the confirmation message includes an undo option.

Sanctions and geopolitical risks now affect security ratings

UpGuard’s Sanctions and Geopolitical Risks have had their provisional status removed, meaning they now contribute to both Breach Risk and Vendor Risk customers’ security rating. For more information see Geopolitical Risks.

Vendor search matches any part of the name or domains

Vendor Risk users can now search both monitored and unmonitored vendors by any part of a vendor’s name or domain. For example searching ‘soft’ will bring up ‘Microsoft’.

Attack surface check timeline in the Security Profile

Attack surface checks will now show a timeline of user actions that affect the check such as remediation requests and waiving risks. The timeline for both attack surface and evidence checks also show when notes are added or deleted and when documents are selected or deselected.

Adding applications to User Risk before browser detection

User Risk administrators can now add an application to their app list and set a usage policy for it before the browser extension detects it. For more information see User Risk: Adding Apps Manually.

View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Brand impersonation detection across mobile app stores

Mark Barber September 9, 2026
Read more

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more

Updated application usage policy controls

Mark Barber June 17, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950