generated: '2026-08-04' method: searched source: https://support.threatdown.com/hc/en-us/categories/4413798473491-Nebula summary: >- ThreatDown publishes dated, monthly product release notes for Nebula (and separately for OneView) as articles in the support portal. The series is continuous from 2022 through 2026. These are PRODUCT release notes covering console and endpoint-agent capability — they are not an API changelog: added, changed or removed API operations are not enumerated, and the OpenAPI definitions carry a static info.version of 1.0.0 that does not move with a release. changelog: published: true type: product-release-notes scope: product api_level_changelog: false cadence: monthly format: support-portal articles (HTML), one per product per month machine_readable: false feed: null url: https://support.threatdown.com/hc/en-us/categories/4413798473491-Nebula oneview_url: https://support.threatdown.com/hc/en-us/p/oneview current_version: spec_version: 1.0.0 api_path_version: v1 note: info.version is fixed at 1.0.0 in both harvested specs and is not a release marker. entries: - date: '2026-03' title: Nebula Release Notes - March 2026 url: https://support.threatdown.com/hc/en-us/articles/49561698676627-Nebula-Release-Notes-March-2026 breaking: false additions: - >- iOS Endpoint Agent app updated with the new ThreatDown logo and branding, replacing the previous Malwarebytes logo. - >- iOS Endpoint Agent and the Nebula Download Center support additional Mobile Device Management (MDM) configuration fields to improve endpoint deduplication for MDM-managed iOS and iPadOS devices, reducing duplicate endpoint entries. - >- Audit Log expanded to include full visibility into exclusion management — every instance an exclusion is created, deleted or edited is now tracked. - Security Advisor enabled for Education (EDU) customers. - date: '2025-10' title: Nebula Release Notes - October 2025 url: https://support.threatdown.com/hc/en-us/articles/45574167346323-Nebula-Release-Notes-October-2025 breaking: false additions: - >- "Detect Malware with AI Algorithms" policy setting added under Scan settings, with Enable / Disable / Detect and Report options for detections that use ThreatDown AI Algorithms. - date: '2025-04' title: Nebula Release Notes - April 2025 url: https://support.threatdown.com/hc/en-us/articles/39979393394067-Nebula-Release-Notes-April-2025 breaking: false additions: - >- Networking Isolation and Process Isolation options across all supported operating systems, and Desktop Isolation for Windows, giving granular control over how threats are contained. - date: '2025-04-03' title: Nebula and OneView console domain and single-sign-on update url: https://support.threatdown.com/hc/en-us/articles/36402439667475-April-3-2025-Nebula-and-OneView-console-domain-and-single-sign-on-update breaking: false changes: - >- Console and API domains moved to threatdown.com. The former API domain continues to operate; customers are advised to update code to the new domain at their earliest convenience. cross_reference: lifecycle/malwarebytes-lifecycle.yml - date: '2024-07' title: Nebula Release Notes - July 2024 url: https://support.threatdown.com/hc/en-us/articles/30992607600915-Nebula-Release-Notes-July-2024 breaking: false additions: - >- Nebula now generates events when a vulnerability is resolved, aiding auditing and tracking. - date: '2024-03' title: Nebula Release Notes - March 2024 url: https://support.threatdown.com/hc/en-us/articles/27086162489619-Nebula-Release-Notes-March-2024 breaking: false additions: - AI-powered capabilities introduced on the Endpoints, Detections and Vulnerabilities pages. archive: earliest_seen: '2022-05' earliest_url: https://support.threatdown.com/hc/en-us/articles/6058166079635-Nebula-Release-Notes-May-2022 note: A continuous monthly series exists from May 2022 forward. gaps: - >- No API-specific changelog. New, changed or removed operations, fields, scopes and webhook event types are not enumerated anywhere a consumer can diff. - >- No RSS/Atom feed and no machine-readable release history — the only interface is paginated Zendesk articles. - >- info.version never changes, so a client cannot detect a spec revision without byte-diffing the definition. x-evidence: fetched: '2026-08-04' note: >- support.threatdown.com returns HTTP 403 to plain curl (bot protection). Article URLs and content above were confirmed through web search result snippets of the live Zendesk pages, not fabricated.