{"id":22977,"date":"2026-09-03T09:11:42","date_gmt":"2026-09-03T09:11:42","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=22977"},"modified":"2026-09-03T09:30:36","modified_gmt":"2026-09-03T09:30:36","slug":"release-notes-august-2026","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/","title":{"rendered":"Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a>\u2019s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The release brings a more connected <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Product Updates <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This month\u2019s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">New Connections Block in TI Lookup for Faster Threat Investigation <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Domains, IPs, and URLs<\/strong> tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"586\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-1024x586.png\" alt=\"TI Lookup Connections\" class=\"wp-image-22984\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-1024x586.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-300x172.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-768x439.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-1536x879.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-2048x1172.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-370x212.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-270x154.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-Connections-740x423.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>TI Lookup Connections bringing related observables into one investigation view<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Analysts can also export filtered results in <strong>JSON<\/strong>, so selected observables can be reused for retrohunting, checked against SIEM\/NDR data, added to blocking workflows, or passed to Detection Engineering for further action. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of stopping at a verdict or a list of indicators, analysts can now use TI Lookup to: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>pivot faster between URLs, domains, and IPs; <\/li>\n\n\n\n<li>focus on malicious and unknown relationships with less noise; <\/li>\n\n\n\n<li>uncover related infrastructure and build a clearer investigation picture; <\/li>\n\n\n\n<li>prepare a relevant set of observables for retrohunting and further analysis;<\/li>\n\n\n\n<li>move findings into blocking and detection workflows without rebuilding the dataset manually. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For SOC and security leaders, the value goes beyond saving analysts a few clicks. Connections shortens the path from a suspicious indicator to an actionable set of findings, reducing manual correlation and helping teams move faster into retrohunting, blocking, and detection updates. That supports <strong>lower time per case, higher analyst throughput, faster Time-to-IOC and Time-to-Block, lower MTTD and MTTR, and stronger detection coverage.<\/strong><\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Reduce the time between detection and response.<\/span> \n<br>\nSupport lower MTTD and MTTR across the SOC.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=release-notes-august-2026&#038;utm_term=030926&#038;utm_content=linktoenterprise#contact-sales \" rel=\"noopener\" target=\"_blank\">\nImprove SOC Performance <\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Threat Coverage Updates <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Detection got a major boost this month, with <strong>81 new behavior signatures, 16 YARA rules, and 559 Suricata rules <\/strong>added across ANY.RUN. Together, they strengthen coverage from malware execution and file analysis to phishing, network activity, and command-and-control traffic. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">New Behavior Signatures <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The latest signature additions focus on malware families analysts are likely to encounter across real-world investigations, from loaders and stealers to RATs, ransomware, and mobile threats. Coverage now extends across Windows, Linux, macOS, and Android, giving analysts more context directly from observed behavior during analysis. <\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid\">\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/b7f1eecb-fbf9-4228-87cf-ca17206f032b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">TonLoader<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/6025e649-0397-42da-8609-5abb4ea4f077?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ShardLoader<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/fcea6463-598a-4106-8329-d07c0c30fdf8\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Ramnit<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/4ab62fd0-36db-43c8-ab15-77a81e84e4a3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SalatStealer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/985e874d-33a1-4714-aa6f-8052a43c89d3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">LKR<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/aadb90cb-e3e2-4fbf-a873-3013be0b22ea?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">BlackSee<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/360afc21-261b-412f-b281-5d98e3c286c8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ValleyRAT<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/bc2ccfc6-cf6c-4f5f-a7fe-647d0314d169?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Phantom<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/810c6f62-1568-4cff-8935-5242e7449df4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">PureLogs<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/47112753-3136-4841-b470-29002e601152?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">DeviceManager<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/9a7aab38-a006-4f5f-ac67-500af1423b4c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">AnimateClipper<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/381ae6fc-2f85-4d49-93e5-869018696672?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">NWHStealer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/388a6647-7f02-45c7-a26c-dc7f9ce60251?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">OverLord<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/73a836bc-d189-441c-ac02-695da7bbc9b4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">IraHook<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/ec02db21-d258-4ad5-a0aa-dcf8d7141f47?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Vidar<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/13a47e0d-35ff-4b6a-8181-baadbec27d1c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Rulftfl<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/474be3ee-cf3a-4877-bacc-75e2ff53c42a?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">RanEnc<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/7f776f87-4257-4916-9bfe-0759f39f1912?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">NeptuneRAT<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/4c3bd52f-613a-4974-a5b2-944be29093d2?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SysTex<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/bc043cca-ff7e-4c48-aa02-db6423e35db4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">StormSer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/9cca89b2-6434-4eed-b9cb-4af2b7b1a138?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">XLoader<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/8477e3b5-4bf9-4dec-9631-6acd3f871668?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Kutaki<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/f0f026b2-88c3-424d-b612-5619e1a382ec?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">DarkSideRAT<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/965d582a-35cf-42c7-a00e-c1f3585b6582?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">DarkCore<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/b3defee7-cc9d-48cc-836c-ab0ab41cbaf8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SynkLoader<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/0feedc64-2b73-423f-9fa7-af1220f40c9e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">PlikanLocker<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/521a274b-ef0d-4bd1-b2ae-3929e496896d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Celestium<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/25963b79-4b25-4630-8548-57b9f0972f4c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Projextor<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/8c15ef1c-d9c4-48e0-a20f-1687fd37325c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Evooo1Bot<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/bdb01790-61d1-41d6-9e8d-a91541b6bdb0?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Kynx<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/e88c3a34-eb2d-478d-86d9-ac69dda81001?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">FudRAT<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/4965e311-f4a5-4dd2-a5a9-2175ee240685?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ChocoShell<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/073564ad-1cf6-4ef5-9384-32535c8fbe80?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">OxideStealer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/1bf2b1a2-64ac-4006-a0c6-cf5d6f294df1?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">GhostDesk<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/613d58d6-d7ad-45d5-95c6-1581b4f14215?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SpecterStealer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/098ce199-9786-4969-ae42-ed7d5fd5e47d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Golsta<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/8e936655-2788-4421-9891-8e04cc795204?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ChainDrop<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/04c5f83d-44b2-4e84-af51-2a73e1b3bf12?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Aeternum<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/340a9d58-0171-4029-b82a-285713b6076d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Abyssos<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/ea9e3824-b4c6-4cdb-a89c-77ef8666e8b3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ToxNetV2<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/aaa28cb0-54ac-4fe0-a7c8-726754b9c45d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">QtRouter<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/bdbe27fb-be07-4863-985d-02188a61bb25?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Nul1Dropper<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/c6ce0966-1139-4d22-8bbc-72c6e8ec515d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">BotKing<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/164f07d0-f781-4a3e-9fb0-8baf44789671?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">XScreen<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/64989bd5-1308-4922-99da-c06b140d0688?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Amnesia<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/91eadad1-8245-4f0a-a687-d8b8cee6f8b7?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ToxicPanda<\/a> <\/li>\n<\/ul>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">New Suricata Rules <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Network visibility also got a substantial update, with <strong>559 new Suricata rules<\/strong> added to detect suspicious traffic patterns tied to phishing, malware delivery, and command-and-control activity. The new rules help surface malicious behavior directly from network traffic and give analysts more context around how threats communicate and spread. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Highlights include: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/26a25650-98b8-4a3e-aa72-ccf44aaf3667\/\" target=\"_blank\" rel=\"noreferrer noopener\">Phish to RMM campaign related URL pattern<\/a> <em>(SID: 85008225):<\/em> Detects webpage lures disguised as Adobe Reader installer pages that lead to infection with RMM software. <\/li>\n\n\n\n<li><a href=\"https:\/\/app.any.run\/tasks\/f21ff2a6-fd29-43e2-9cd7-13c8bc854074\/\" target=\"_blank\" rel=\"noreferrer noopener\">FlowerStorm HTTP activity observed<\/a> <em>(SID: 84004196):<\/em> Identifies HTTP activity associated with the FlowerStorm phishing-as-a-service platform. <\/li>\n\n\n\n<li><a href=\"https:\/\/app.any.run\/tasks\/856203af-6d6c-46aa-ac2f-b6eea229b121\/\" target=\"_blank\" rel=\"noreferrer noopener\">OnyxC2 HTTP activity observed<\/a> <em>(SID<\/em><em>: 84004406): <\/em>Detects command-and-control check-in attempts linked to OnyxC2 malware-as-a-service activity. <\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">New Threat Intelligence Reports <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN published three new <a href=\"https:\/\/intelligence.any.run\/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktottireports\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Reports<\/a>, covering active phishing operations, remote-access abuse, and newly observed malware. Available to <a href=\"https:\/\/intelligence.any.run\/plans?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotiplans\" target=\"_blank\" rel=\"noreferrer noopener\">TI Lookup Premium<\/a> subscribers, the reports combine technical analysis with IOCs, hunting queries, infrastructure context, and MITRE ATT&amp;CK mapping to help analysts investigate and act on threats faster. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"581\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-1024x581.png\" alt=\"Threat Intelligence Reports available for deeper analysis\" class=\"wp-image-22983\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-1024x581.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-300x170.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-768x436.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-1536x872.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-2048x1162.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-370x210.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-270x153.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-reports-740x420.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Threat Intelligence Reports available for deeper analysis<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">1. US-First RMM Phishing Campaign <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/intelligence.any.run\/reports\/08-24-2026-cra-t4-rmm\" target=\"_blank\" rel=\"noreferrer noopener\">US-First RMM Phishing Campaign report<\/a> uncovers a fake-document campaign that tricks victims into installing legitimate RMM software for remote access. What first looked like a Canada-focused tax lure turned out to be part of a broader operation spanning <strong>46 countries<\/strong>, with <strong>45% of observed activity associated with the United States<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report traces the campaign\u2019s reusable phishing kit, rotating infrastructure, password-protected delivery chain, and abuse of tools such as GoTo Resolve, LogMeIn Rescue, ScreenConnect, and ConnectWise. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Mirage2FA: A Phishing Service That Steals Microsoft 365 Sessions in Real Time <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/intelligence.any.run\/reports\/08-17-2026-mirage2fa\" target=\"_blank\" rel=\"noreferrer noopener\">Mirage2FA report<\/a> analyzes an active phishing-as-a-service operation targeting Microsoft 365 accounts through AiTM techniques. ANY.RUN researchers examined <strong>1,249 sandbox sessions<\/strong> and linked the campaign to <strong>9,332 potential compromise events across 4,532 potential victims<\/strong>, with <strong>63.7% of identified victims located in the United States<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report explores Mirage2FA\u2019s browser-based stagers, recurring \/xls\/ loader pattern, WebSocket-based authentication relay, and session-cookie theft, as well as the infrastructure and recurring LINX markers that connect the operation to <strong>LinX Coders<\/strong>. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. OVERLORD RAT, CRPX0, and TRIBACK Loader <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/intelligence.any.run\/reports\/2026-08-07-threat-brief-overlordrat-crpx0-triback\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Threat Brief<\/a> covers three distinct threats with very different capabilities: a cross-platform RAT, a modular stealer-ransomware framework, and an in-memory Windows loader. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The brief highlights <strong>OVERLORD RAT\u2019s<\/strong> encrypted WebSocket C2 and IDE task abuse, <strong>CRPX0\u2019s<\/strong> credential theft, crypto-stealing, and ransomware capabilities, and <strong>TRIBACK Loader\u2019s<\/strong> DLL sideloading and memory-resident execution. It also includes hunting queries, IOCs, and MITRE ATT&amp;CK mappings for each threat. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Get more capacity from the SOC you already have.<\/span> \n<br>\nReduce analyst effort and improve operational efficiency.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoenterprise#contact-sales \" rel=\"noopener\" target=\"_blank\">\nIncrease SOC Capacity <\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations and 700,000 security professionals worldwide. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> helps SOC teams, MSSPs, and enterprise security teams safely analyze suspicious files, URLs, phishing pages, and malware while observing the attack chain in real time. Analysts can inspect processes, browser activity, network traffic, persistence, credential access, and other behaviors to understand what a threat is doing and respond faster. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> turns data from real-world sandbox investigations into actionable context for threat hunting, detection, and incident response. Teams can pivot across indicators, uncover related infrastructure, connect individual findings to wider campaigns, and bring fresh threat data into existing security controls. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN is <a href=\"https:\/\/any.run\/compliance\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktocompliance\" target=\"_blank\" rel=\"noreferrer noopener\">SOC 2 Type II attested<\/a>, reflecting its commitment to strong security controls and customer data protection. By combining behavioral analysis with current threat intelligence, ANY.RUN helps security teams investigate threats faster, improve detection coverage, and contain malicious activity before it causes wider impact. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Integrate ANY.RUN into your SOC workflow \u2192<\/strong><\/a><strong><\/strong> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY.RUN\u2019s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity. The release brings a more connected Threat Intelligence Lookup experience, broader threat [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":21861,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[57,10,56],"class_list":["post-22977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-service-updates","tag-anyrun","tag-cybersecurity","tag-update"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Release Notes: Faster TI Investigations &amp; 650+ Threat Updates<\/title>\n<meta name=\"description\" content=\"Explore ANY.RUN\u2019s August 2026 updates: faster investigations with TI Lookup Connections, 656+ threat coverage updates, and new TI Reports.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates\",\"datePublished\":\"2026-09-03T09:11:42+00:00\",\"dateModified\":\"2026-09-03T09:30:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/\"},\"wordCount\":1162,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Release-notes-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"update\"],\"articleSection\":[\"Service Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/\",\"name\":\"Release Notes: Faster TI Investigations & 650+ Threat Updates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Release-notes-scaled.png\",\"datePublished\":\"2026-09-03T09:11:42+00:00\",\"dateModified\":\"2026-09-03T09:30:36+00:00\",\"description\":\"Explore ANY.RUN\u2019s August 2026 updates: faster investigations with TI Lookup Connections, 656+ threat coverage updates, and new TI Reports.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Release-notes-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Release-notes-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Release Notes August 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/release-notes-august-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Service Updates\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/service-updates\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Release Notes: Faster TI Investigations & 650+ Threat Updates","description":"Explore ANY.RUN\u2019s August 2026 updates: faster investigations with TI Lookup Connections, 656+ threat coverage updates, and new TI Reports.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates","datePublished":"2026-09-03T09:11:42+00:00","dateModified":"2026-09-03T09:30:36+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/"},"wordCount":1162,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Release-notes-scaled.png","keywords":["ANYRUN","cybersecurity","update"],"articleSection":["Service Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/","url":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/","name":"Release Notes: Faster TI Investigations & 650+ Threat Updates","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Release-notes-scaled.png","datePublished":"2026-09-03T09:11:42+00:00","dateModified":"2026-09-03T09:30:36+00:00","description":"Explore ANY.RUN\u2019s August 2026 updates: faster investigations with TI Lookup Connections, 656+ threat coverage updates, and new TI Reports.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Release-notes-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Release-notes-scaled.png","width":2560,"height":1243,"caption":"Release Notes August 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/release-notes-august-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Service Updates","item":"https:\/\/any.run\/cybersecurity-blog\/category\/service-updates\/"},{"@type":"ListItem","position":3,"name":"Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=22977"}],"version-history":[{"count":7,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22977\/revisions"}],"predecessor-version":[{"id":22988,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22977\/revisions\/22988"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/21861"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=22977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=22977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=22977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}