Highlights
This release focuses on compliance and security, on the transition to the new support portal and on data accuracy.
Privacy Policy and Cookie Policy links are now available on the login page and in the platform footer, as required by GDPR, and Keycloak, the platform's authentication service, has been upgraded to close a critical vulnerability. All support references across the platform now point to the new support portal, the only channel for support requests since August 18.
A set of fixes on user language handling brings back users who were missing or stale in reports, corrects content delivered in the wrong language to LDAP-synchronized companies and unblocks Awareness licenses stuck in pending after CSV imports.
On the phishing side, templates and landing pages are now checked for references to public CDNs that corporate networks block, the XML export respects the active filters and newly created companies get correct sending days. Access control has been tightened in the Download Area, now also available to team leaders, and Spanish (Mexico) joins the platform languages.
New features
- Spanish (Mexico) language — Added Spanish (Mexico) as a new platform language.
- External data via API — External_data is now exposed as read-only in the external APIs, enabling user matching (e.g. Codice Fiscale) with the customer's LMS.
Improvements
- Privacy and Cookie Policy links — Privacy Policy and Cookie Policy links are now shown on the login page and in the platform footer, so the notice is reachable before authentication as required by GDPR (Art. 12–13).
- Keycloak security upgrade — Keycloak, the platform's authentication service, has been upgraded to fix a critical security vulnerability. The upgrade is transparent to users and no action is required.
- New support portal — Support contact details updated across the platform: the Help section, notification emails and the Knowledge Base link now point to the new support portal https://support.libracyber.com, the only support channel from August 18, 2026.
- CDN check on phishing content — Phishing templates and landing pages are now checked on save and import for references to shared public CDNs that corporate networks often block: critical ones are rejected, others raise a warning. This prevents publishing content that would silently break for targets behind strict network filtering.
- Download Area access control — The Download Area now enforces the caller's organization/tag scope: users only see and can download files within their permitted scope, and out-of-scope direct downloads are rejected. Team leaders now have access to the Download Area.
- Email Log report visibility — The Email Log report is now shown only to roles holding the corresponding permission, consistently with the rules already enforced on the download itself.
- Additional content languages — Content can again be created in 11 additional languages (including Afrikaans, Welsh, Irish, Hindi and Norwegian) that had disappeared from the language selectors.
- CSV import validation — Improved CSV import validation to validate languages and countries against supported ISO values and reject invalid timezones.
Resolved bugs
- Fixed an issue where reactivating an expired phishing license restored targets in the UI but left their data anonymized. Reactivating a license now correctly restores the original target details (name, email, phone).
- Fixed the bulk download of company certificates, which could fail or stay "in progress" indefinitely. Failed downloads are now correctly reported as errors.
- The {{Point}} placeholder in certificate templates is now replaced with the points earned by the user instead of being printed literally.
- Fixed an error in the Remediation report that left the target details table empty and showed a "Data fetch error" message.
- Fixed an error that prevented removing a training path from a user who had already obtained a certificate for it.
- Fixed an intermittent error ("Failed to retrieve OAuth configuration") that could prevent users from logging in.
- Fixed the Sent Attacks widget in the Phishing Report, which showed twice the real value after changing filters.
- Fixed phishing scheduling defaults for newly created companies and prevented saving configurations with no sending days selected.
- Fixed student-caring notifications to ensure emails are sent only to students with an active or grace Awareness or Channel license.
- Fixed phishing template XML export to respect UI filters, preventing unnecessary large exports and 504 Gateway Timeout errors.
- Fixed CSV bulk imports to preserve and correctly default account language, country, and timezone, preventing Awareness licenses from getting stuck in pending status.
- Fixed company status transitions so assigning path-based licenses, such as Awareness, correctly moves companies from Setup to Go Live.
- Fixed a bug for which users without a preferred language were missing from reports or shown with a stale status.
- Fixed a bug for which, in companies synchronized via LDAP, the users' language was never imported and was cleared at every nightly sync, so content could be delivered in the wrong language.
- Fixed a bug for which some completed training modules were invisible to reports, rankings and certificates because the content had been unlocked without a release date.