← Back to feed
Threat Actors & CampaignsEmerging2 sourcesSep 3, 2026 · 09:11via ANY.RUN Blog

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

Brief

Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.

The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.

Product Updates

This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.

Read more on ANY.RUN Blog

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

ANY.RUN BlogPrimary··trust 1.24

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.

The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.

Product Updates

This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.

New Connections Block in TI Lookup for Faster Threat Investigation

Threat Intelligence Lookup now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work.

The Domains, IPs, and URLs tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results.

TI Lookup Connections bringing related observables into one investigation view

Analysts can also export filtered results in JSON , so selected observables can be reused for retrohunting, checked against SIEM/NDR data, added to blocking workflows, or passed to Detection Engineering for further action.

Read more →
Malware.news··trust 0.88

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.

The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.

Product Updates

This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.

New Connections Block in TI Lookup for Faster Threat Investigation

Threat Intelligence Lookup now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work.

The Domains, IPs, and URLs tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results.

Read more →