Skip to content

v3.8.6 August 31, 2026

Version 3.8.6 includes:

New features

This section describes the new features added in version 3.8.6.

1 - Coro console

The following features have been added to the Coro console:

1.1 - Alphabetical activity log filters

The Activity Log Types filter list is now alphabetized.

For more information, see Activity Log.

2 - Connectors

The following features have been added to Connectors:

2.1 - ConnectWise PSA integration bidirectional ticket status updates

For customers with a configured ConnectWise PSA connector, when a Coro-originated ticket is set to “closed” status in ConnectWise, Coro now automatically closes the related ticket in the Coro ticket log.

For more information, see Integrating with ConnectWise PSA.

3 - Cloud Backup module improvements

The following features have been added to Cloud Backup:

3.1 - New screens for end-customer workspaces

This release introduces a new set of views for end customers of Managed Service Providers who are subscribed to the Cloud Backup module. These new views show a record of backup and restore tasks performed, as well as the health of connected cloud apps.

For more information, see Cloud Backups.

Enhancements

Version 3.8.6 introduces the following additional changes:

1 - Coro console enhancements

1.1 - Console security improvements

Coro console security has been improved in the following ways:

  • Admin user password strength increased
  • Console inactivity timeout reduced
  • Increased audit logging of console events

1.2 - MSP Global View enhancements

The MSP Global View pages have been improved in the following ways:

  • Bundle breakdown panel improved with new pie chart visualizer.

For more information, see MSP workspaces overview.

2 - Connectors

2.1 - Azure Sentinel connector changes

Because of an external process change, customers using Coro's Azure Sentinel SIEM connector must re-establish their connections to continue using the service.

For more information, see Configuring and managing SIEM connectors.

3 - Data Governance

3.1 - Consolidated device data scan findings

Previously, each endpoint device scan might have resulted in Coro raising a new ticket, even if the findings were identical; Coro now consolidates findings from repeated scans of the same device into a persistent Endpoint Drive Containing Sensitive Data ticket.

Subsequent scans update the existing open ticket rather than creating a new one. Newly discovered files (since the last scan) surface at the top of the ticket, each annotated with a "last seen" timestamp.

For more information, see Ticket types for Endpoint Data Governance.

4 - Endpoint Security and EDR

4.1 - Disabled devices page filter

Coro now includes a dedicated filter on the Devices page to show only Protection-disabled devices. This new filter lets you quickly re-enable protection for these devices.

For more information, see Devices.

4.2 - Unencrypted Endpoint Drive ticket notifications

This release improves the processing rules for Unencrypted Endpoint Drive tickets to ensure admin users receive the correct number and frequency of notifications. Improvements include:

  • Open and unresolved Unencrypted Endpoint Drive tickets close automatically after 10 days.
  • If a ticket is marked closed, Coro does not add new detected events of the same type to it. Instead, Coro creates a new ticket for the event, which means it raises a new notification for admin users.
  • When Coro detects that the drive has been re-encrypted (the issue is resolved), it automatically marks the open ticket as resolved and closes it. Coro does not add further detected events of the same type to the resolved ticket, even if an admin user manually reopens it.
  • If the admin user allows no encryption, Coro closes the corresponding ticket.

For more information, see Unencrypted Endpoint Drive.

4.3 - EDR telemetry process ancestry information

This release adds ancestry context to EDR telemetry data, so users can now view parent process IDs (PPIDs) for all listed processes.

For more information, see Telemetry.

5 - Email Security

5.1 - Seven-day grace period after email proxy gateway disconnection

To avoid the risk of lost email due to misconfigured mail settings, Coro now provides a seven-day grace period after a customer disconnects from the Inbound or Outbound Gateway. During this period, Coro will continue to deliver any emails received via either gateway.

5.2 - TLD-based email blocking/allowing

Admin users can now add entries to the Email Security blocklist or allowlist based on TLD (Top-Level Domain).

For more information, see Allow or block email senders.

5.3 - Wildcard subdomain email blocking

Admin users can now add Email Security blocklist entries based on wildcarded subdomains. For example, *.domain.com to block all subdomains (and any nested subdomains) identified at domain.com. The base domain continues to be allowed.

For more information, see Allow or block email senders.

5.4 - Merged Blocklisted IP and Blocklisted Sender tickets

Blocklisted IP tickets are now deprecated; from this release, detections are raised as Blocklisted Sender tickets.

For more information, see Ticket types for Email Security.

6 - Security Awareness Training

6.1 - User search in reports

In the Security Training and Phishing Summary reports, searching for a specific user record now searches all users and not just those shown in the report.

6.2 - Predefined date ranges in reports

Coro now provides improved predefined date ranges in the Date range selector for Security Training and Phishing Summary reports to better fit typical usage.