Straight answer

This note covers public announcements from March to September 2026 by the six vendors on this site and by the MITRE ATT&CK and Sigma projects. Most of them widen the data a tool can reach without copying it, shorten the route from intelligence to a tested rule, or change the frameworks detections are written against. None changes a score on its own; scores follow the vendors' product pages.

What this recap covers

This note covers announcements made between March and September 2026. Each item comes from the vendor's own blog or newsroom, a press release, or the MITRE and SigmaHQ project pages, and each is also listed with its source on our news page. We have grouped them by what they mean for the buyer question on this site: Which tool turns new threat intelligence into hunts and detections across the data you already have, without building a new ingestion pipeline?

An announcement is a claim about a product, not a change to our scores. The matrix scores come from product pages and documentation reviewed in September 2026. Where an announcement adds something a buyer should check, we say what to ask.

More data reached where it already sits

The largest group of announcements widens the data a tool can query without copying it first.

  • On 28 July 2026 Anvilogic made Blueprints workflow automation and a Federated Search experience, powered by Anvilogic Compute, generally available. Two days later, on 30 July, Anvilogic 8.0 covered onboarding, search, detection and investigation, added Elastic, CrowdStrike LogScale and Dynatrace to federated search, and added case management.
  • On 29 July 2026 Nebulock introduced Helix, which lets its agents query vulnerability management and security tools when needed instead of ingesting that data ahead of time.
  • On 21 September 2026 Vega said it had brought Wiz exposure, privilege and sensitive data attributes into its detection and investigation workflows. Vega's public connectors page does not name platforms, so this is one of the few named integrations a buyer can point to.
  • On 4 June 2026 Artemis Security added Claude Enterprise Compliance API events, normalized to OCSF, alongside the cloud, identity and SaaS telemetry it already handles.

What to ask: for each named platform, whether it is queried in place or ingested, and which platform's compute runs the query. Reading a vendor connector page has the full checklist.

A shorter route from intelligence to a tested rule

  • On 18 March 2026 Nebulock published a post introducing Vespyr, which it describes as an autonomous hunter. Its platform page says Vespyr turns a threat intel report into a deployable detection in minutes.
  • On 8 September 2026 Mars Security released Real-Time Intel-Based Detection. According to the press release, it converts advisories into ATT&CK-mapped rules, backtests each rule against 30 days of the customer's own data before it goes live, and is available to all Mars customers at no additional cost.
  • On 16 September 2026 Mars Security published a post introducing MARS playbooks, framed around attacks that fail a hypothesis rather than fire an alert.

What to ask: take one advisory from this week and watch it become a rule. Note which steps are automatic, how the rule is tested and against how much of your data. The intel-to-detection row on the matrix shows what each vendor publishes about this today.

Agents, models and open formats

  • On 13 April 2026 Cotool published research benchmarking frontier models on a real macOS infostealer intrusion across response, hunting and detection tasks.
  • On 29 July 2026 Cotool launched Router, which adds fallback across model providers, access to open-weight models and model choice based on evaluations.
  • On 4 August 2026 Vega released Detection Skills, an open specification built on the Agent Skills format, with a library of more than 50 skills.

What to ask: how model choice affects the consistency of results, and whether detection logic can be exported in an open format. Our note on Sigma and open rule formats goes further.

Funding

  • On 5 March 2026 Cotool announced a $7.4 million seed round led by Andreessen Horowitz.
  • On 15 April 2026 Artemis Security came out of stealth with $70 million in combined seed and Series A funding, with the Series A led by Felicis.
  • On 25 June 2026 Nebulock announced a $25 million Series A led by FirstMark, alongside insider risk features, correlation rules and a Command Center view.

Funding says nothing about fit. It can matter to a buyer's procurement team, which may ask about a vendor's size and runway; ask the vendor directly.

Frameworks that detections are written against

  • On 14 April 2026 MITRE created the Defense Impairment tactic, TA0112. ATT&CK v19, released on 28 April, replaced the Enterprise Defense Evasion tactic with Stealth and Defense Impairment and lists 15 Enterprise tactics and 222 techniques.
  • MITRE's updates page dates v19.2, its first smaller agile release, to 6 August 2026. It adds groups including ShinyHunters and TeamPCP and related supply chain software.
  • The SigmaHQ project published three rule releases in 2026: r2026-01-01 on 29 January with 33 new rules, r2026-04-01 on 28 April with 54 new rules and more than 60 improved, and r2026-07-01 on 9 July with 20 new rules and more than 80 updated.

What to ask: which ATT&CK version a vendor's coverage view uses, and how quickly a new release reaches it. See What an ATT&CK coverage claim should show.

What did not change

None of the six vendors published a license price during these six months, and our scores still rest on the product pages reviewed in September 2026. When a vendor's public pages change in a way that supports a different score, we change the score and date the update.