Newsletter - August 2026

August was the month a couple of long-running betas finished, and the month we started publishing the research that sits behind the product. Here's everything we shipped.

Connection Allowlist is out of beta 🔌

Chrome 152 went stable on 25th August with Connection Allowlists shipped to desktop, Android and WebView, ending the origin trial - so we've taken our support out of beta and switched it on for everyone. A Connection Allowlist governs every connection a page opens, not just the ones connect-src covers, and refusals now flow into Data Watch alongside the rest of your egress destinations. There's a feature page and a setup guide to get you started. One thing worth knowing: we've been ingesting these reports since June, so if your site already sends the header you'll now see reports that were previously collected quietly in the background. New reports of this type default to a 10% sample rate, the same as CSP Integrity, because an incomplete allowlist can refuse a very large number of connections at once.

DBSC is now protecting every login 🔐

Device Bound Session Credentials bind your Report URI session to the device it was created on, so a stolen session cookie is useless anywhere else. We started the rollout at 1% of logins and stepped it up through August - 10%, 25%, 50% - and it's now running on 100% of logins, on every account, at no cost. Nothing to enable and nothing to configure; if your browser supports it, your session is already bound.

New free tool: HSTS checker and staged generator 🔒

Our eighth free tool is an HSTS checker. Point it at a site and it reads the Strict-Transport-Security header being sent, checks the things that have to be true before HSTS is safe there, and tells you the next safe step of a rollout rather than handing you a finished header to paste and hope. When you're ready for the preload list, it'll tell you whether you're actually ready. It reads no account and no session - free and anonymous, like the rest of the free tools.

We're publishing our threat intelligence research 🛰️

Until now, the reasoning behind every host on our threat intelligence lists lived in our commit history, which is no use at all if you're staring at a hostname in your own reports trying to work out whether it matters. So we've published it: ten campaign write-ups covering 88 hosts, plus a page explaining how a host gets classified in the first place and how to dispute a classification you disagree with. August's additions include the ClickFix / EtherHiding campaign hosts and two co-located browser-extension C2 clusters. Watch findings also record more of what we saw - the path that was blocked, what the browser was fetching, what pulled it in, and whether the request was actually stopped or only observed - so triage starts from more than a hostname and a directive.

Ten years of scanning the web's top million sites 📊

There's a new research section on the site, opening with a decade of crawl data on how the web's biggest sites actually deploy security headers - published as pages and as a PDF you can hand to someone. Alongside it are evidence pages showing how Google, Dropbox, GitHub, Twitter, GOV.UK and login.gov run CSP in production - useful if you're the one who has to make the case for CSP internally.

New case studies, and easier to find 📁

We've added the Newegg, CosmicSting and Claire's Magecart incidents to the case studies, along with new Supply Chain and XSS categories and the named incidents that sit behind each. The filters are now deep-linkable, so you can send someone straight to the set that makes your point instead of telling them which button to press.

A site you can actually navigate 🧭

We've reorganised the marketing site around what each section is for. The free tools now live under /tools and the product features under /features, both named after what they do rather than when we built them, and the menus have been regrouped to match. Script Vault has moved to where it belongs, and there's a new client-side security guide for AppSec engineers to go with the CISO, compliance and security engineer ones. Every old URL redirects, so your bookmarks and links still work.

Polish in the account area 🧹

We keep chipping away at the small things in the dashboard - the ones that never make a headline but make the place nicer to spend time in. August brought another round of them, in dark mode especially. If something in the account area irritates you, tell us; that's usually how these end up on the list.

Behind the scenes 🛠️

A good chunk of August went on work you'll never see: a lighter, faster front end, some tightening of our own defences, and more resilience in the report pipeline that sits behind everything else. Nothing for you to do, as always - just a quicker and sturdier Report URI underneath.

That's August - a new report type for everyone, DBSC finishing its rollout, another free tool and a lot of research that had been sitting in our heads finally written down. There's more coming on the client-side security side through the autumn. As always, if you have any ideas or feedback, please do let me know.

Scott Helme,
Founder.

Read more