Cortex Defender releases
Check the latest production version, endpoint operating systems, AI harness and provider compatibility, validation evidence, and historical release notes.
- Production version0.5.24 · September 4, 2026
- Endpoint platformsManaged desktop and headless Linux
- Version evidenceHarness and provider observations
Faster activity visibility, lower endpoint overhead, and a narrower local trust boundary.
- Channel
- Production
- Released
- September 4, 2026
- Rollout
- 3 platforms
Release 0.5.24
Change log and improvements
What release 0.5.24 changes for an installed fleet, grouped by area. Each entry describes a customer-visible improvement in the current production release.
Performance
Lower endpoint overhead and faster activity visibility in Cortex Atlas.
- Lower idle resource useThe local relay releases idle capture workers, which reduces background CPU and memory on managed desktops during long sessions.
- Faster session indexingActivity indexing runs incrementally, so a long session becomes searchable in Cortex Atlas without waiting for the session to close.
- Quicker time to first activitySign-in and harness discovery run together at startup, which shortens the gap between launch and the first captured event.
Security
Stricter update verification and a narrower local trust boundary.
- Signed update verificationUpdater artifacts are checked against signed manifests before installation on macOS, Windows, and Linux.
- Scoped local relay accessThe local relay accepts connections from the signed-in desktop session only, and rejects requests from other local accounts.
- Wider secret redactionRedaction covers additional provider token formats and runs on the endpoint, before any event leaves the device.
Release 0.5.24
Current compatibility
Match the endpoint platform to the AI harness and upstream provider. Version labels distinguish exact observations from supported paths without a public pin.
Compatibility process
Continuous harness validation
- Every client releaseTested across the supported operating systems.
- Multiple harness versionsIncludes the latest stable release of each AI harness.
- Continuously refreshedAutomated updates to the harness test set and compatibility checks keep observations current. New observations are published on this page.
How to read validation
| Operating system and version | Harness and provider | Harness version | Capture path | Validation |
|---|---|---|---|---|
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 2.1.201 observed2.1.83+ is required for work-context events. | Local relay | Verified | |
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 0.142.4 observedExact client version recorded during validation. | Local relay | Verified | |
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 0.46.0 observedVersioned request fixtures cover the current CLI protocol. | Local relay | Verified | |
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 0.2.105 observedCurrent response protocol is covered from 0.2.82. | Local relay | Verified | |
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 4.0.0 observedDesktop attribution is versioned; CLI remains current-stable. | CLI relay and IDE history | Verified | |
macOS12 or laterApple silicon Windows10 or 11x64 LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | 1.17.4 observedA scrubbed real-session fixture pins this version. | Local relay | Verified | |
LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | Current stableSupported path with no public version pin. | Headless local relay | Version unpinned | |
macOS12 or laterApple silicon LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64 | Current stableSupported path with no public version pin. | Partial local relay | Version unpinned |
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 2.1.201 observed2.1.83+ is required for work-context events.
- Capture path
- Local relay
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 0.142.4 observedExact client version recorded during validation.
- Capture path
- Local relay
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 0.46.0 observedVersioned request fixtures cover the current CLI protocol.
- Capture path
- Local relay
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 0.2.105 observedCurrent response protocol is covered from 0.2.82.
- Capture path
- Local relay
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 4.0.0 observedDesktop attribution is versioned; CLI remains current-stable.
- Capture path
- CLI relay and IDE history
- Operating system and version
- macOS12 or laterApple siliconWindows10 or 11x64LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- 1.17.4 observedA scrubbed real-session fixture pins this version.
- Capture path
- Local relay
- Operating system and version
- LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- Current stableSupported path with no public version pin.
- Capture path
- Headless local relay
- Operating system and version
- macOS12 or laterApple siliconLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
- Harness version
- Current stableSupported path with no public version pin.
- Capture path
- Partial local relay
No published release blockers
Release 0.5.24 has no published customer blocker. Amber rows remain supported paths without an exact public version pin.
Outside published support
macOS before 12, Windows before 10, and Linux distributions not listed in the matrix are outside the published operating-system scope.
Historical archive
Previous releases
0.5.19

Production
Selected changes
- Added a packaged headless Linux service and CLI configuration commands.
- Improved first-party Claude Code routing defaults.
- Prevented imported Cursor history from replaying after a new commit.
- Corrected provider-mix calculations and Linux dependency validation.
0.5.16
Production
Selected changes
- Improved Cursor CLI capture and repair behavior on Windows and Unix.
- Recovered Claude Desktop Cowork prompts and paired logical turns.
- Added opt-in native Grok image capture and Firefox and Arc attribution.
0.5.15
Production
Selected changes
- Improved Cursor activity projection and capture-search performance.
- Added Gemini runtime-event health reporting and repair behavior.
- Improved managed configuration resilience during service outages.
0.5.9
Production
Selected changes
- Published the earlier production baseline for managed desktop deployment.
- Established signed cross-platform updater artifacts for macOS and Windows.
Support policy
Version and rollout practice
Open Settings → About & Updates in Cortex Defender.
We test multiple harness versions on every client release, including current stable versions.
Include Defender, operating system, harness, and provider versions when requesting support.