Release Date: 6 April 2026
ThingsRecon 6.5 is a major release centred on multi-tenant visibility and AI-powered intelligence. As organisations grow more complex—spanning multiple business units, ministries, or customer portfolios—the need for a unified, account-level view of cyber risk becomes critical.
This release directly addresses that need, while also expanding detection capabilities, improving data transparency, and enhancing platform usability.
Key Highlights
Account Dashboard
A new widget-based dashboard provides a consolidated view of risk posture, scan status, priorities, and supply chain health across all projects.
Smart Findings
AI agents now identify cyber hygiene issues from file and script contents, extending the Classic Findings introduced in version 6.3.
Expanded Software Component Detection
Improved detection of WordPress libraries, Axios and JS/CSS version banners enhances dependency visibility and “old components” posture scoring.
API v2.0 Progress:
A new paginated endpoint for test-level asset data enables custom reporting and powers the Account Dashboard.
Account Dashboard
Organisations managing multiple projects—such as MSSPs, enterprises, and public-sector entities—can now access a centralised account-level dashboard.
This dashboard enables users to:
- Prioritise remediation across projects
- Track progress over time
- Identify inactive or high-risk projects quickly
Widget-Based Overview
A time-period selector (current, 1 month, 3 months, 6 months, 1 year) dynamically updates all widgets.
Core widgets include:
- Projects
Total number of active and inactive projects within the selected timeframe
- Last Scan Status
Breakdown of latest scan outcomes (completed, running, failed, not started)
- Priorities
Aggregated counts of: Fix Now, Fix Soon, Monitor, Track
- Cyber Hygiene
Visual distribution of risk scores (A–F), including breakdown by risk type
- Need Attention - highlights projects rated D or F, enabling rapid identification of high-risk areas
Additional Widgets:
- Supplier subscription status
- Supply chain overview (digitally connected suppliers and relationships), including the number of projects (out of the total) where the supplier has been discovered
- Things (domains, applications, and other assets)
Metrics are aggregated across all projects in the account (unless only a subset has been selected, ie via the “Needs attention” function).
Projects Overview (at Account Level):
An enhanced Projects Overview table provides administrators with a comprehensive breakdown of all projects.
Available Columns:
Project Details
- Name
- Last Test Created At
- Last Test Update
Scan Information
- Last Scan Status (completed, running, failed, not started)
- Last Scan Duration
Prioritisation
- Fix Now
- Fix Soon
- Monitor
- Track
(numeric values per project)
Risk Scores (A–F)
- Cyber Hygiene Resilience
- Certificate Risk
- SSL Service Risk
- Network Risk
- Domain Risk
- DNS Risk
- Application Risk
- Software Risk
- Email Risk
- Header Risk
Asset & Supply Chain Metrics
- Things (total assets)
- Parsed Pages (previously “project size”)
- Suppliers
- Subscriptions
UI Improvements
Supply Chain – Widget & View:
The Supply Chain table view is now available to all customers by default. It shows the list of digitally connected suppliers, as well as their proximity and the types of connections. To view business intelligence data and cyber hygiene resilience scores and details, customers must have an active Supply Chain subscription.
Business Intelligence Risk Scores:
Risk scores within Business Intelligence—specifically Geopolitical, Financial, and Compliance—now include descriptive context.
This provides users with clearer insight into:
- The meaning of each score
- The confidence level of the underlying data
Scan Workqueue – WHOIS Data:
Raw WHOIS data is now included in the Test Scan Workqueue table.
This helps users:
- Validate discovered domains
- Determine whether associated results should be included in their dataset
Discovery & Hygiene Indicator Updates:
Indicators have been updated to align with the evolving Findings framework, improving how their impact is represented across different Thing Types and strengthening prioritisation accuracy.
Smart Findings
Following the introduction of Classic Findings in version 6.3, version 6.5 introduces Smart Findings.
Smart Findings:
- Leverage AI agents to analyse file and script contents
- Surface cyber hygiene issues embedded in unstructured data
- Provide deeper, context-aware insights
This enhances detection capabilities beyond traditional scanning methods.
Improved Software Component Detection
Detection capabilities have been expanded to improve visibility into third-party dependencies and software posture.
Enhancements Include:
- Detection of libraries and plugins commonly bundled within WordPress themes and plugins
- Identification of version banners and signature strings in Axios, JS and CSS assets
These improvements:
- Strengthen dependency inventory accuracy
- Improve identification of outdated components
- Enhance “old components” posture scoring with high-confidence evidence
API Version 2.0:
API v2.0 development continues with the introduction of a new endpoint:
POST /v2/projects/{projectId}/data/test-things
This endpoint:
- Returns a paginated list of things (applications, domains, certificates, etc.) for a given test
- Supports filtering by project scope (e.g. business unit ID or domain ID)
Key Benefits:
- Enables efficient handling of large datasets
- Supports custom reporting in external tools
- Powers the Account Dashboard
This functionality is available to all customers.
Bug Fixes & Enhancements
This release also includes:
- General UI refinements
- Performance and robustness improvements based on stress testing conducted in version 6.5.
- Ongoing platform stability enhancements
Read more from our team in the ThingsRecon blog
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article