Fortra Product Updates

August and September 2026

Explore the latest enhancements for our Fortra cybersecurity products. You can also catch the highlights in our recent webinar.

Text

Adversary Emulation

Red Team Suite

  • New tools in the Red Team Suite include the Red Team Infrastructure builder and new initial access techniques in the OST toolkit.   

  • Continued R&D on new evasion techniques and novel tradecraft.  

  • Coming Q4 2026: Continuous penetration testing in the Fortra platform will enable continuous threat emulation and identity testing to showcase potential attack paths.  

  • New AI assistant for Cobalt Strike will help you with context and next steps during operations (timing TBD).

Learn more about our Adversary Emulation solutions

Brand Protection

Fortra Brand Protection 

  • Threat Trace for Cred Theft customers helps organizations understand their threat landscape and monitor known threat actors. 

  • New UX improvements for a more seamless customer experience as we updated our Fortra platform UX to make it easier to search incidents and view multiple incidents in new tabs, as well as consolidated our incident APIs making it easier to pull incident data. 

  • Automated pivots expanding detections: We turn the detection of one phishing site into an expanding web of additional malicious site detections, to proactively protect your users. 

  • Significantly improved automatic mitigation with new Offline Case Check Tool which has been used to reduce closure times on ~8000 cases since launch. 

  • Crawler improvements help us get around CAPTCHAs and emulate IP addresses more easily, so we can find and take down malicious sites faster. These improvements mean detection for reactivations is now 25% faster! 

  • With Fortra Threat Brain and new data feeds fueling detections, more intelligence and data sources means better detection of threat actor activity.  

  • New ML/AI-based webpage classification helps detect parked domains, CAPTCHAs, and no content webpages faster. 

  • Significant improvements to automatic mitigation include new tools and processes, including a Cloudflare block page and new SOC closure tool, so incidents impacting your brand are mitigated faster. 

  • Better tracking for browser blocking means you have full visibility into incident mitigation metrics, from the time access was blocked to the time a site was taken down. 

  • Consolidating several Incident APIs eases the operational burden of integrating incident data into SIEM and SOAR solutions.  

Not yet a brand protection customer?

For global brands being actively targeted online, in email, and on social media, we offer industry-leading detection and rapid takedown capabilities. Organizations can request a complimentary report of threats targeting your brand, verified by Fortra experts, including details on active threats, and guidance on mitigation. We can also perform courtesy takedowns. Request report here.

Data Security

Fortra DSPM 

  • Fortra DSPM for Databricks provides continuous visibility, automated data classification, and access governance across the entire data environment. Organizations can automatically discover sensitive data, identify exposure risks and over-privileged users, map findings to compliance frameworks like HIPAA and PCI DSS, and quickly prioritize remediation of unprotected data assets. 

  • DSPM for Fileshares and Databases extends data discovery and classification across file shares and databases in hybrid environments, including on-premises infrastructure, AWS, Azure, GCP, and SaaS applications. This broader coverage helps organizations uncover sensitive data that may otherwise remain outside the scope of cloud-focused discovery. By bringing these environments into DSPM, security teams gain a more complete view of where sensitive data lives and can better identify and address data risks.  

Fortra Data Classification

  • DCS One activities are now reported directly within ARC, giving customers their first centralized reporting capability for DCS One. This provides a more complete view of data security activity by bringing events from across the Fortra Data Security portfolio into a single reporting and analytics experience, helping security teams investigate, monitor, and respond more efficiently. 

  • Fortra DCS uses AI-powered classifiers to more precisely identify sensitive and business-critical information, including tax forms, source code, bank statements, network configuration files, budget reports, and names and addresses. This helps organizations classify data more consistently and accurately while reducing reliance on manual identification. More precise classification also provides better context for applying appropriate security and compliance policies. 

  • Fortra DCS labels can now drive Endpoint DLP controls, connecting data classification directly to data protection. This allows organizations to identify and classify sensitive information and then apply appropriate controls based on the context of the data. By bringing classification and protection together, organizations can enforce more consistent, context-aware policies across endpoint activity and better protect sensitive information wherever it is used. 

Learn more about our Data Security solutions.

Tripwire

  • Allowlists control “What’s allowed” per node, including open ports, users, services, and software. Allowlisting is critical for NERC compliance because it enables customers to establish a known-good configuration and monitor for unauthorized configuration drift. By fully integrating this functionality into Tripwire, customers have a single place to manage their workflows with the familiar look and feel they already know.

Learn more about Tripwire.

Email Security

AI/ML Models:  

  • Financial Scam Detector: This model is designed to detect suspicious emails with financial subject lines and no prior communication history between the sender and recipient.  

Fortra Cloud Email Protection: 

  • Fortra Cloud Email Protection is now hosted in the EU. This allows new and existing customers to augment their email security with a cloud-hosted solution deployed in Germany with strong data residency considerations.  

  • New message details interface now explains how the Email Body Content AI model impacts message scoring, informing users if a message is malicious or suspicious. 

  • A new configurable overview page can be customized with the widgets you want to see, for better dashboard visibility of your email environment. 

Fortra Suspicious Email Analysis AI Model

  • As threat actors produce new ways to attack, new approaches are needed to defend against them. The new model increases automation and reduces manual analyst evaluation effort of benign (“No Threat Detected” or NTD) messages. 

  • Expanded incident search capabilities in the Fortra Platform now allow users to do text-based searching across message and indicator fields, such as; Subject, Email Addresses, URLs, Attachment Names, and Phone Numbers. 

Learn more about our Email Security solutions.

Fortra Security Awareness Training

  • Courses and quizzes now have built-in scheduling to streamline the workflow for SAT admins to schedule courses, saving time and simplifying the overall process. 

  • A new comprehensive launch tab now provides a centralized view of all campaign settings providing a summary of key details and configurations of campaigns in a single place.

Learn more about our Security Awareness Training solutions.

Exposure Management

  • Continuous Threat Exposure Management (CTEM) will combine asset visibility, risk-based vulnerability management, threat intelligence, continuous penetration testing powered by Core Impact, and adversarial exposure validation—helping teams prioritize the exposures that can actually be exploited and focus remediation where it matters most. 

Fortra Vulnerability Management 

  • The latest Fortra VM release expands support for on-premises environments, with Fortra Appliance deployment, network- and agent-based scanning, Threat Landscape Mode, new Swagger API documentation, and easier bulk agent management. 

Previous Months

Adversary Emulation

Red Team Suite

  • New tools in the Red Team Suite include the Red Team Infrastructure builder and new initial access techniques in the OST toolkit.   

  • Continued R&D on new evasion techniques and novel tradecraft.  

  • Coming Sept 2026: New AI assistant for Cobalt Strike will help you with context and next steps during operations. 

  • Coming Q4 2026: Continuous penetration testing in the Fortra platform will enable continuous threat emulation and identity testing to showcase potential attack paths.  

Learn more about our Adversary Emulation solutions

Brand Protection

Fortra Brand Protection 

  • Threat Trace for Cred Theft customers helps organizations understand their threat landscape and monitor known threat actors. 

  • New UX improvements for a more seamless customer experience as we updated our Fortra platform UX to make it easier to search incidents and view multiple incidents in new tabs, as well as consolidated our incident APIs making it easier to pull incident data. 

  • Automated pivots expanding detections: We turn the detection of one phishing site into an expanding web of additional malicious site detections, to proactively protect your users. 

  • Significantly improved automatic mitigation with new Offline Case Check Tool which has been used to reduce closure times on ~8000 cases since launch. 

  • Crawler improvements help us get around CAPTCHAs and emulate IP addresses more easily, so we can find and take down malicious sites faster. These improvements mean detection for reactivations is now 25% faster! 

  • With Fortra Threat Brain and new data feeds fueling detections, more intelligence and data sources means better detection of threat actor activity.  

  • New ML/AI-based webpage classification helps detect parked domains, CAPTCHAs, and no content webpages faster. 

  • Significant improvements to automatic mitigation include new tools and processes, including a Cloudflare block page and new SOC closure tool, so incidents impacting your brand are mitigated faster. 

  • Better tracking for browser blocking means you have full visibility into incident mitigation metrics, from the time access was blocked to the time a site was taken down. 

  • Consolidating several Incident APIs eases the operational burden of integrating incident data into SIEM and SOAR solutions.  

Not yet a brand protection customer?

For global brands being actively targeted online, in email, and on social media, we offer industry-leading detection and rapid takedown capabilities. Organizations can request a complimentary report of threats targeting your brand, verified by Fortra experts, including details on active threats, and guidance on mitigation. We can also perform courtesy takedowns. Request report here.

Data Security

Fortra DSPM 

  • Fortra DSPM for Databricks provides continuous visibility, automated data classification, and access governance across the entire data environment. Organizations can automatically discover sensitive data, identify exposure risks and over-privileged users, map findings to compliance frameworks like HIPAA and PCI DSS, and quickly prioritize remediation of unprotected data assets. 

  • Our DSPM capabilities now extend beyond active data to include historical data scanning across SaaS and cloud environments, helping organizations uncover, classify, and secure legacy and dormant data that often goes overlooked. With native support for platforms like OneDrive, SharePoint, Google Drive, Box, Salesforce, and AWS S3, organizations gain comprehensive visibility into sensitive data, exposure risks, and governance gaps across their entire data landscape. 

Fortra DCS

  • DCS One activities are now reported directly within ARC, giving customers their first centralized reporting capability for DCS One. This provides a more complete view of data security activity by bringing events from across the Fortra Data Security portfolio into a single reporting and analytics experience, helping security teams investigate, monitor, and respond more efficiently. 

  • DCS One now supports classification of calendar events, bringing consistency with the capabilities already available in DCS for Windows. This helps organizations apply the same classification policies and governance standards across emails, documents, and calendar content, ensuring more comprehensive protection of sensitive information. 

Fortra DLP 

  • DG Agent for macOS now supports interception of file transfer operations performed through the Messages application. Supported methods include copy/paste actions, drag-and-drop, Finder based sharing, and the Conversation > Send File option. 

  • The DG Agent for macOS supports the Sample Match feature for Adaptive Content Inspection. When enabled, the DG Agent captures both match counts and sample matching content from inspected files and email events. This feature helps analysts review events more effectively in DGMC and ARC forensic reports. 

Learn more about our Data Security solutions.

Fortra File Integrity Monitoring 

  • Product Naming Update: 

    • Tripwire Enterprise and Fortra Integrity and Compliance Monitoring have been rebranded as Fortra File Integrity Monitoring. 

  • Fortra File Integrity Monitoring 9.4 Release 

    • The latest major release of Fortra File Integrity Monitoring, formerly known as Tripwire Enterprise, is live. This release includes integrated allowlist capabilities, new REST API support for token-based authentication, security updates, performance improvements, and important fixes.  

    • Release Highlight: New Integrated Allowlisting capabilities 

      • Manage and validate allowed open ports, services, software, and users directly in the console.  

      • Import allowed items from TSA JSON, WLP CSV, or XML. 

Learn more about our FIM solutions.

Email Security

AI/ML Models:  

  • Financial Scam Detector: This model is designed to detect suspicious emails with financial subject lines and no prior communication history between the sender and recipient.  

Fortra Cloud Email Protection: 

  • New message details interface now explains how the Email Body Content AI model impacts message scoring, informing users if a message is malicious or suspicious. 

  • A new configurable overview page can be customized with the widgets you want to see, for better dashboard visibility of your email environment. 

  • Improved on-demand policy performance makes time to first action and time to complete all actions much faster. 

  • For new customers, Historical Message Ingest via Graph API provides accelerated onboarding and tuning/model training to deliver faster time to value. 

Fortra Suspicious Email Analysis AI Model

  • As threat actors produce new ways to attack, new approaches are needed to defend against them. The new model increases automation and reduces manual analyst evaluation effort of benign (“No Threat Detected” or NTD) messages. 

  • Expanded incident search capabilities in the Fortra Platform now allow users to do text-based searching across message and indicator fields, such as; Subject, Email Addresses, URLs, Attachment Names, and Phone Numbers.

Learn more about our Email Security solutions.

Exposure Management

Fortra Security Awareness Training

  • Courses and quizzes now have built-in scheduling to streamline the workflow for SAT admins to schedule courses, saving time and simplifying the overall process. 

  • A new comprehensive launch tab now provides a centralized view of all campaign settings providing a summary of key details and configurations of campaigns in a single place.

Learn more about our Security Awareness Training solutions.

Adversary Emulation

Red Team Suite

  • New tools in the Red Team Suite include the Red Team Infrastructure builder and new initial access techniques in the OST toolkit.  
  • Cobalt Strike Research Labs gives customers exclusive access to sophisticated evasion techniques, emerging attack methodologies, a comprehensive knowledge base, training resources, and an exclusive Slack community for collaboration.
  • Continued R&D on new evasion techniques and novel tradecraft. 

Learn more about our Adversary Emulation solutions

Brand Protection

Fortra Brand Protection 

  • Crawler improvements help us get around CAPTCHAs and emulate IP addresses more easily, so we can find and take down malicious sites faster. These improvements mean detection for reactivations is now 25% faster! 

  • With Fortra Threat Brain and new data feeds fueling detections, more intelligence and data sources means better detection of threat actor activity.  

  • New ML/AI-based webpage classification helps detect parked domains, CAPTCHAs, and no content webpages faster. 

  • Significant improvements to automatic mitigation include new tools and processes, including a Cloudflare block page and new SOC closure tool, so incidents impacting your brand are mitigated faster. 

  • Better tracking for browser blocking means you have full visibility into incident mitigation metrics, from the time access was blocked to the time a site was taken down. 

  • Consolidating several Incident APIs eases the operational burden of integrating incident data into SIEM and SOAR solutions. 

Not yet a brand protection customer?

For global brands being actively targeted online, in email, and on social media, we offer industry-leading detection and rapid takedown capabilities. Organizations can request a complimentary report of threats targeting your brand, verified by Fortra experts, including details on active threats, and guidance on mitigation. We can also perform courtesy takedowns. Request report here.

Data Security

Fortra DSPM 

  • DSPM for file shares allows for discovery and classification of data in file shares across hybrid environments.  

  • Now customers can access DSPM right within the Fortra platform. 

Fortra DLP 

  • With a new Endpoint DLP+DCS integration, Fortra eDLP will now natively read DCS labels, enabling the use of DCS labels to enforce DLP controls. Existing DCS customers can benefit from adding Fortra DLP to extend data security protections. 

  • New simplified control policy manager makes creating policies easier.  

  • New DLP capabilities for generative AI applications allow customers to discover and block unsanctioned GenAI app usage, as well as inspect and protect sensitive data provided to GenAI apps. 

Learn more about our Data Security solutions.

Fortra File Integrity Monitoring 

  • Added SMTP OAuth Support in v 9.3.2 before Microsoft’s initial March 1, 2026 deadline to ensure customers receive communications from their FIM deployment.  

  • Includes native Allowlist functionality replacing WLP (Whitelist Profiler) and TSA (Tripwire State Analyzer) to simplify and seamlessly monitor systems against predefined allowlists and profiles without leaving the FIM console. 

Learn more about our FIM solutions.

Email Security

Fortra Cloud Email Protection 

  • New message details interface now explains how the Email Body Content AI model impacts message scoring, informing users if a message is malicious or suspicious. 

  • A new configurable overview page can be customized with the widgets you want to see, for better dashboard visibility of your email environment. 

  • Improved on-demand policy performance makes time to first action and time to complete all actions much faster. 

  • For new customers, Historical Message Ingest via Graph API provides accelerated onboarding and tuning/model training to deliver faster time to value. 

AI/ML Models 

New AI/ML models are available in both Fortra Cloud Email Protection and Fortra Suspicious Email Analysis  

  • Email Body Content: A more powerful model adds classification capabilities and support future attack classifications for improved reporting and policy decisions. 

  • ML Social Graph Infrastructure: This model analyzes communication patterns between recipients and senders leading to improved detections and fewer false positives.  

  • Homoglyphs detection: This model analyzes the subject and sender of an email message to detect the presence of homoglyphs and identify potential threats. 

Fortra Suspicious Email Analysis

  • New Email Risk Scoring model enriches and speeds up analyst classification using machine learning 

  • New ability to capture and structure phone number-based IOCs from emails, which helps with vishing analysis and prevention 

Fortra Secure Email Gateway (SEG) 

  • Authenticated Receive Chain (ARC) support is new in the 6.3 release. ARC improves deliverability by preserving the SPF, DKIM and DMARC checks performed by the Fortra SEG before delivering to the intended mail system.  

  • Better identification and sanitization for malicious SVG files 

  • Integration with Fortra Threat Brain reputation and intelligence data for improved detection.  

  • Enhanced security hardening and package optimizations provide greater security coverage while reducing deployment package size, making updates faster and easier to implement. 

Learn more about our Email Security solutions.

Exposure Management

Fortra Security Awareness Training

  • Increases accessibility and usability of Learning Zone by aligning to Web Content Accessibility Guidelines (WCAG) 2.2AA standards.  

  • The solution has several new courses as well as revamped courses with updates that focus on interactivity, modern relatable scenarios, and broader pool of quiz questions.  

  • New micro-learnings and nano-videos have been added along with additional phishing templates to enhance security awareness training programs.  

Learn more about our Security Awareness Training solutions.

Questions? Please get in touch.

Customers: Please contact your customer success manager or account executive, or email us here

Partners: Please contact your channel account manager about trial opportunities for your customers. 

LEARN MORE ABOUT OUR RELEASES