Skip to content

v3.8.5 July 20, 2026

Version 3.8.5 includes:

New features

This section describes the new features added in version 3.8.5.

1 - Coro console

The following features have been added to the Coro console:

1.1 - MSP admin users can now archive channel workspaces

Coro now enables admin users to archive dormant channel and subchannel workspaces where they no longer include active child workspaces.

For more information, see Archiving an inactive workspace.

1.2 - Portuguese (Brazil) language support

The Coro console now includes support for Portuguese (Brazil).

For more information, see Profile settings and password.

2 - Cloud Security

The following features have been added to the Cloud Security module:

2.1 - IP address-based restrictions policy for access to cloud applications

This release adds a new Cloud Security Access Permissions policy type, Restricted locations, that identifies sign-in events from defined IP addresses or CIDR ranges. If a sign-in violates a Restricted Location policy, Coro raises a Blocked IP login ticket for admin user review. Admin users can review tickets for restricted sign-ins and choose to contact or suspend the user.

For more information, see Cloud Security policies

2.2 - MFA enrollment detection for Slack users

Coro now detects and displays multi-factor authentication (MFA) enrollment status for protected users in connected Slack applications.

Admin users now see MFA enabled or MFA not enabled labels for each protected user connected from Slack, and can filter the users list by MFA status.

For more information, see Protected users.

3 - Data governance

The following features have been added to the User Data Governance and Endpoint Data Governance modules:

3.1 - Consolidated Cloud Share Containing Sensitive Data tickets

If a protected user shares a folder containing multiple files with sensitive data, Coro now generates a single, consolidated Cloud Share Containing Sensitive Data ticket for all detected files. This reduces excess ticket creation and improves visibility into connected events.

For more information, see Ticket types for User Data Governance.

4 - Email Security

The following features have been added to the Email Security module:

4.1 - Country-based email geoblocking

Admin users can now add entries to the Email Security blocklist based on country. This blocks all emails that Coro detected as having originated from an IP address in the specified country.

Items in the allowlist retain priority over blocklisted countries, meaning that emails from allowed senders, domains, or IP addresses are still allowed even if they originate from a blocked country.

For more information, see Allow or block email senders

5 - Endpoint Security and EDR

The following features have been added to Endpoint Security and EDR:

5.1 - EDR telemetry data exports

This release introduces the ability to export EDR telemetry data to a downloadable comma-separated value (CSV) file for incident investigation or offline analysis. CSV data exports are triggered from the Reports section of the console, include all data available on the EDR Telemetry page, and are limited to a search period of two weeks.

For more information, see Telemetry.

6 - Network and SWG

The following features have been added to the Network and SWG modules:

6.1 - Device labels in SWG allow-only mode

This release adds device label selection to the Allowlist-only filtering feature, enabling admin users to block all internet traffic except for specifically allowed domains on specified devices.

For more information, see DNS filtering.

6.2 - Subnet selection

Important

This feature requires endpoint devices running Coro Agent v3.8.1 and later.

This release extends Virtual Office functionality by enabling admin users to select a subnet range for VPN connections during initial Network service activation, or when editing the region.

For more information, see Activating the Network service.

6.3 - Virtual Office region updates

The Edit Region feature has been extended to enable admin users to recreate a Virtual Office network within the same region, optionally preserving the existing public IP address.

For more information, see Editing the Network service region.

7 - Security awareness training (SAT)

The following features have been added to SAT:

7.1 - New Coro allowlisting app

As part of the SAT activation flow, Coro now includes a downloadable allowlisting app that system administrators can use to automate the process of configuring their email services with all required SAT addresses and domains.

For more information, see Configuring Security Awareness Training.

7.2 - Portuguese language support

Security Awareness Training simulations and training courses now support Portuguese (Brazil) as a localization option.

Enhancements

Version 3.8.5 introduces the following additional changes:

1 - Coro console enhancements

1.1 - MSP global view improvements

In this release, Coro has made improvements to the following Global View functionality:

  • In workspace hierarchy view on the Global View > Workspaces page, when you select a channel workspace, Coro now shows aggregated information in the right-hand pane for all descendant workspaces. Previously, the details shown were only for the workspace itself. For example, if you select a channel workspace, the number of open tickets now reflects the cumulative total across all child and subchannel workspaces.
  • In workspace hierarchy view on the Global View > Workspaces page, when you select a channel workspace, Coro now includes a panel showing a breakdown of subscribed bundles across all descendant workspaces.

1.3 - Improved page filter layout

This release further improves the layout and appearance of page filters in the console. Major filters and switches remain visible on the page, but supplementary filters are now grouped together under a single Filters dropdown control.

2 - Cloud Security

2.1 - Aggregated malware-sharing event tickets

Coro now consolidates all detected sharing events involving a malicious file into a single Malware in cloud drive ticket.

Previously, a separate ticket was generated for each recipient of the shared file. This release reduces the quantity of generated tickets and improves visibility into related events by listing all recipients within a single ticket.

2.2 - User Management page improvements

The User Management page has been updated to show clearer and more useful information:

  • Added via replaces Protected via, showing how the user was added.
  • Member of replaces Connected apps, showing the cloud apps and services in which the user account is protected.

For more information, see User Management.

3 - Email Security

3.1 - Prevent blocking of internal IP addresses

Coro now prevents admin users from adding the following private and internal IP addresses to the Email Security blocklist:

  • Private IP address ranges
  • Loopback IP addresses
  • Non-routable and internal infrastructure IP addresses

3.2 - IPv6 support

Coro's API-based Email Security protection now supports emails from IPv6 addresses.

4 - Endpoint Security and EDR

4.1 - Remote shell session audit log with viewable XML transcript

This release improves the remote shell session feature by adding a viewable XML transcript of the session log. This helps admin users to monitor activity in remote sessions and provides an audit trail of commands executed on the remote device.

5 - Connectors

5.1 - Public API endpoint for updating workspace details

Coro’s public API now includes an additional endpoint for updating editable workspace details:

PATCH /v1/workspaces

Through this endpoint, you can modify the company name, display name, notifications level, and user and device limits.

For more information, see Coro's Public API.

Agent updates

This section describes the following additional Agent updates that we are releasing with version 3.8.5.

Prerequisites

The Coro Agent software must be updated on your device before changes take effect. The features described may not function until the updated macOS and Windows Agents are installed. Coro commences roll-out of Agent updates after the release.

1 - macOS and Windows Agent 3.8.5

macOS and Windows Agent 3.8.5 include the following:

1.1 - Agent app interface enhancements

The Coro Agent app now provides an enhanced visual indication of protection and connectivity status based on your workspace subscription and configuration.

The Agent now shows:

  • An app footer status message of You are protected when one or more endpoint protection modules (Endpoint Security, EDR, or Endpoint Data Governance) are enabled.
  • A status message in the app Network tab shows the network connection status and type, depending on whether the Network or SWG modules are enabled (as well as an indicator of the Virtual Office network type). This message can also appear in the app footer if all endpoint protection modules are disabled.

The agent adds additional entries to the Notifications tab to indicate the protection and connectivity status.

For more information, see Introducing the Coro Agent.

1.2 - Block process communications to blocklisted IP addresses

The Coro Agent can now prevent background process communications with known malicious IP addresses. The Agent compares process activity with an internal threat list that is frequently synchronized from open-source threat intelligence databases.

When a process attempts to communicate with a malicious IP address, Coro blocks the connection and creates a Malicious process communication ticket for admin review.