September 1, 2026

    August 2026 Release Notes

    It's back to school season!! But sadly we're all adults living the corporate life so no cool trapper keepers, now you get excited about another release note blog post. August's releases include one new global detection for Webroot endpoint file verdicts, so a confirmed-bad file surfaces as a Blumira finding instead of sitting in the Webroot console. We also tuned three existing rules, two of them Windows noise problems worth calling out: Esentutl File Copy Operation had started firing on a Dell telemetry change, and Potential Application Shimming via Sdbinst was matching standard Windows application-compatibility activity, in some cases isolating endpoints that had done nothing wrong. JumpCloud: Admin Login Without MFA now confirms the login actually succeeded, clearing up findings that contradicted their own evidence. On the platform side, Kindling case collaboration is live for all customers with comments, assignees, and tags, plus case resolution that cascades to the associated findings and two new webhook events to match. Detection Filters picked up every field from the evidence table, including logger. 

    Detection Updates

    Log Type Details
    Webroot
    NEW - Webroot: Endpoint File Detection with Bad Verdict

    This new detection identifies files that Webroot Endpoint Protection has flagged with a Bad verdict on a managed endpoint. A file caught by the local antivirus engine is still evidence of an attempt that landed, whether that was a malicious attachment a user opened, a dropper that got partway in, or a payload staged for a second attempt. Previously that verdict lived only in the Webroot console, so surfacing it depended on someone going to look.

    Default state: Disabled
    Windows
    UPDATE - Esentutl File Copy Operation

    We refined this detection to exclude Dell SRUDBData telemetry activity, which began generating P1 findings, frequently overnight, following a Dell application change in late July. Genuine use of esentutl to copy files still alerts.
    Windows
    UPDATE - Potential Application Shimming via Sdbinst

    We updated this detection globally to exclude legitimate Windows application-compatibility activity. An influx of findings had begun matching standard Windows apppatch shim database operations, in some cases isolating endpoints that were behaving normally.
    JumpCloud
    UPDATE - JumpCloud: Admin Login Without MFA

    We improved this detection to confirm the login actually succeeded before firing. JumpCloud records the credential submission step of some MFA-enforced sign-in flows as its own event without an MFA flag, so an admin who did complete MFA could still generate a finding whose analysis contradicted its own evidence.

    Bug Fixes and Improvements

    Bug Fixes 

    • Report Builder - AWS CloudTrail Account Attribution: We fixed AWS account attribution on CloudTrail logs, where the account ID could be taken from a resource referenced in the event rather than the account the event occurred in. Grouping or filtering by AWS account returned the wrong rows, particularly for cross-account and AWS Organizations API calls. The account ID now comes from the event's own account and is selectable as a column in Report Builder.

    Improvements 

    • Detection Filters - Evidence Fields Now Filterable: All real-time detections have been updated so that every field shown in a finding's evidence table is available when building a detection filter, including logger. Filtering on logger ID rather than device name means filters keep working after a device is renamed.
    • Kindling - Case Collaboration: Comments, assignees, and tags are now live on Kindling cases. Responders can leave context for whoever picks the case up next, hand a case off, and tag it for follow-up without leaving the case.
    • Kindling - Case Resolution Cascades to Findings: Resolving a case in Kindling now resolves its associated findings in the Blumira application. Resolution flows one direction only, case to findings, so closing an individual finding will not change case state.
    • Kindling - Finding Comments on Cases: Comments left on a finding in the Blumira application now appear on the related Kindling case as read-only, so the case carries the full conversation.
    • Kindling - Simplified Case Assignment: Case assignees are now a single responder type, and Managers are excluded from the responder pool, making it clearer who owns a case.
    • Webhooks - Case Collaboration Events: Two new webhook events cover Kindling case comment and assignment activity, allowing external tooling to react to case collaboration as it happens.

    July 2026 Release Notes

    In case you missed the July updates, you can find and review those notes here.

    Amanda Berlin

    Amanda Berlin is the Senior Product Manager of Cybersecurity at Blumira, bringing nearly two decades of experience to her position. At Blumira she leads a team of incident detection engineers who are responsible for creating new detections based on threat intelligence and research for the Blumira platform. An...

    More from the blog

    View All Posts