SPR{K3DEFENDrelease notes
Product improvements · newest first
1.0.15June 29, 2026LATEST
Trusted-app precision
- Made the trusted-app check more resilient. When a legitimately notarized app (such as a container runtime) performs a sensitive action, Defend now remembers its verified good standing and retries if the system signature check is briefly slow — so a real, signed app is no longer stopped just because that check timed out. Genuinely dangerous behavior is still never spared.
1.0.14June 28, 2026
Implant convergence & AI-agent skill defense
- Added detection for a recently-disclosed family of targeted macOS malware. Defend recognizes when several individually-ordinary actions — reading the login keychain, staging a hidden interpreter or archive in a temp folder, installing a startup item, and blocking sleep — converge on one machine in a short window, and raises a critical alert. Watch-and-alert only; nothing you are doing is interrupted and no files are touched.
- Added protection for AI-agent "skills." Defend inspects the skills your AI coding agents install and safely isolates poisoned ones that would make an agent fetch and run code from an attacker-controlled address. You decide what happens through a new menu-bar review item — restore it or keep it removed. Isolation is fully reversible; nothing is deleted.
1.0.13June 27, 2026
Detection precision & dashboard
- Removed a false alarm in the software-registry credential workflow — Defend now flags it only when the same process both reads the credential and publishes.
- The dashboard's "Recent Detections" list is now collapsible.
- Lower-priority, already-suppressed detections are de-emphasized so genuine signal stands out.
1.0.12June 27, 2026
Trusted-app allowlist fixes
- The trusted-app allowlist now matches regardless of capitalization.
- Added a one-click "allow all" for trusted apps.
1.0.11June 27, 2026
Trusted-app protection gate
- Defend no longer interrupts Apple-notarized applications you installed (in /Applications) for the detection types most prone to false alarms — legitimate signed software won't be acted on by mistake.
- Sparing a trusted app is scoped to the specific detection types prone to false alarms; genuine attack chains are still acted on.
1.0.10June 25, 2026
Detection accuracy & stability
- Eliminated false alarms that could occur during routine software updates and downloads — Defend now recognizes application self-updates and similar trusted activity instead of flagging them.
- Improved how Defend separates unrelated background activity from a genuine attack sequence, sharply reducing false positives.
- Protective actions now require stronger corroboration before they trigger, so benign processes are never interrupted.
- Faster, cleaner event reporting and general reliability improvements.
1.0.9June 24, 2026
Catastrophic-command protection
- Added optional blocking of catastrophic, destructive commands for endpoints armed at the highest protection level.
- More accurate "ready to protect" status, so the dashboard reflects an endpoint's true protection state.
1.0.8June 21, 2026
Converged service build
- Defend now runs as a system service — protection continues across logout and fast user switching.
- All communication with the SPR{K3 service uses an authenticated, encrypted connection.
- Added safety controls, including a kill switch and an allowlist.
- Redesigned the "What Defend learned" page to match the product.
- Automatic log-file rotation.
- Fixed the post-install confirmation message.
1.0.7.1June 21, 2026
Beta fixes
- Corrected the dashboard version label and post-install text.
1.0.6June 19, 2026
First public beta
- Background endpoint agent with live fleet reporting to the SPR{K3 dashboard.