Releases

What shipped, and when.

Generated from the repository’s changelog at build time, so this page cannot describe a release the changelog does not record. The most recent 6 entries are shown; the console carries the full history.

2.58.6 2026-08-25

The version was set to 2.58.6 on 25 August 2026 because that is the authoritative product version. This file records 2.53.2 immediately before it and nothing between: no release notes exist for 2.54 through 2.58 and none have been written, because inventing them would put fabricated release history on a public page. Everything listed under this heading is work that actually shipped in it.

๐Ÿ”ข Version pipeline

  • Screenshots can no longer claim a release they never saw. The site stamps
  • A build assertion compares the published site against shared/product.json.
  • Structured data's softwareVersion is checked against the same source, since

๐Ÿ”Œ Integration truth

  • Six status pills were typed into the markup by hand and could not follow a
  • The integrations page opens with a board generated from the registry. Building
  • GA, Beta and not-built are now visually distinct, because a grid of identical

๐Ÿ›ก๏ธ Trust and status

  • The status page no longer advertises the controls it lacks. It reported
  • Incident notes state what is posted rather than what has never been published.
  • A neutral contact section: report an issue, and security review.
  • Dependency-advisory detail moved out of marketing copy and into the security

๐Ÿ“ฎ Contact form

  • The spam trap was off-screen, not hidden. Its input was 185x21 pixels with
  • A browser test now covers the marketing site: nearly four thousand existing

2.53.2 2026-08-25

โœจ Added

  • Start Here (/start-here) โ€” six ordered onboarding steps whose state is
  • Dashboard prompt pointing at it while the required steps are incomplete.
  • Start Here tab in the console documentation.
  • scripts/make_walkthrough.sh โ€” records, synthesises the music bed and
  • docs/ONBOARDING.md and docs/MARKETING_ASSETS.md.

๐Ÿ› Fixed

  • Screenshots were annotated twice. Seven tour screens carried both the
  • Two screens numbered their callouts against the wrong notes. fix-first
  • bump_version.py did not know about shared/product.json. product.json
  • bump_version.py refused to reconcile when the version was unchanged. It
  • **The four legacy *.version settings rows went stale at every release.**
  • The console documentation advertised "Latest Features (v2.1.0)" while the

๐Ÿ” Security

  • **seed.py held the live SUPERADMIN password as a literal and reset the
  • Added scripts/rotate_admin_password.py. Rotation is now a deliberate
  • run-local.sh and init.sh fail early when ADMIN_PASSWORD is unset.
  • The admin account is now admin@exploithound.com (was
  • SESSION_SUMMARY.md published a SUPERADMIN password too. It listed
  • Both affected accounts rotated (25 August 2026). Auditing every account

๐Ÿงน Cleaned

  • The 14 permanent pytest collection errors are gone. Three scripts named
  • One of the three, test_scan.py, had no __main__ guard and did its work at

๐Ÿงช Tests

  • 15 new tests for onboarding, weighted towards the downward direction: anyone
  • test_site.py now runs ffprobe against the built walkthrough and fails if

๐Ÿ” Regenerated

  • All 16 screenshots and the walkthrough video, against the current console at

๐Ÿ“‹ Process

  • CLAUDE.md now requires a version bump and a consistency check as part of

2.21.1 2026-08-16

๐Ÿ› Fixed

  • A refused portfolio report returned 500 instead of 403. The authorisation
  • Cross-tenant lookups answered 400 where 404 is honest. A well-formed

๐Ÿงช Tests

  • 13 new tests (618 โ†’ 631) driving the real routers through the real dependency
  • Covered: cross-tenant reads and writes on RMM, Entra, Azure connections;

๐Ÿ“‹ Notes

  • The live probe ran 32 checks against the running API as seeded users in two
  • This is internal testing. It is not an independent penetration test and is

2.21.0 2026-08-15

๐ŸŽ‰ Features

  • Which actions remove the most paths to critical assets ยท Why is this customer
  • Five new evidence slices behind them: tier-zero paths, RMM-actionable
  • Each question names the slices it needs. A prompt carrying the whole tenant
  • RMM-actionable lists only findings on assets the remediation service would
  • Verified reduction counts only actions that were re-checked. Including
  • Known exploited is resolved from the vulnerability corpus before the

๐Ÿ”’ Guardrail

  • The analyst may propose, group, explain, draft and simulate. It cannot patch,
  • An answer phrased as though work has already been done is flagged, even though

๐Ÿงช Tests

  • 18 new tests (600 โ†’ 618), including that no slice reaches another tenant โ€”

2.20.1 2026-08-15

๐ŸŽ‰ Website

  • Numbered callouts burned onto eleven product-tour screenshots, matching the
  • Callouts anchor to text, not coordinates, so a layout change moves the
  • The capture refuses to publish a shot whose callout could not find its
  • The RMM screen appeared twice in the tour under two different sets of notes;

๐Ÿ› Fixed

  • Callouts were blue, and so is Fix First's own ranked list. On that page an
  • Badges sat on top of the words they pointed at. They sit outside the target's
  • Two tour notes described something the callout no longer pointed at, so the

2.20.0 2026-08-15

๐ŸŽ‰ Features

  • Built from execution records rather than intent. Work submitted but not yet
  • Each action carries its PSA ticket, per-device outcome, and what is left:
  • Ranks customers on known-exploited vulnerabilities and routes to critical
  • Every customer appears even when clean; a customer missing from the list reads
  • The only report that spans tenants, so it is restricted to platform operators.
  • Identity, web and cloud exposure counted separately. "142 open findings" tells

๐ŸŽฌ Walkthrough video

  • 44 seconds โ†’ 3 minutes 28. Forty-four seconds could not show what this
  • Captioned on screen, twelve stages: multi-customer view, discovery,
  • Background music, synthesised from sine tones by a committed script rather
  • The capture script is in the repo this time. The previous video was made by

๐Ÿ“‹ Notes

  • The recording carries the same leak guard as the screenshots: it refuses to
  • 600 backend tests, 172 site checks.

Want the detail behind any of these?

Security-relevant changes are covered in a security review, and the console carries the complete changelog for anyone with an account.

Ask us Security review

v2.58.6 Exploit Hound 2.58.6 · Continuous Threat Exposure Management