Introduction
Since the release of VMRay Platform 2026.2, we’ve had a busy start to the summer. In 2026.2, we introduced:
-
Recursive Classification and Threat Names in Parent Sample – more prominently displayed in the Platform
-
Added support for special characters in tags to make grouping, searching, and correlation with external systems easier
-
Launched VMRay Cloud in the AWS European Sovereign Cloud, a new Cloud hosting option for organizations with strict European data residency and operational autonomy requirements.
We hope you’re already seeing the value of these improvements, or that you will be soon. Now, let’s take a look at what’s new in VMRay Platform 2026.3.
From Adaptive to AI Browsing Simulation: Advancing Web Threat Analysis
Modern phishing attacks are increasingly interactive. They often require a user to click a button, accept a prompt, mark a checkbox, or move through a staged web flow before revealing the final malicious payload. To uncover this behavior, VMRay Dynamic Web Analysis includes automated browsing capabilities that interact with suspicious web pages in a user-like way. We are now upgrading this capability with AI Browsing Simulation, the evolution of what was previously known as Adaptive Browsing Simulation.
DOM-based automation powered with AI-assisted visual interaction
Traditional browser automation relies heavily on the Document Object Model (DOM) to identify and interact with page elements. This approach works well when the page structure is stable and accurately reflects what the user sees in the browser.
To keep pace with rapidly evolving phishing pages, we are introducing AI Browsing Simulation that reduces reliance on time-consuming, page-by-page DOM inspection. This is especially useful in cases such as:
In these cases, an element may be clearly visible on screen but difficult to map reliably through the DOM alone.
What is new with AI Browsing Simulation?
AI Browsing Simulation adds a visual perception layer to VMRay’s existing browser automation. The VMRay Platform can now analyze webpage screenshots and identify visible user interface elements using Computer Vision and OCR.
This helps detect and interpret elements such as buttons, checkboxes, visible text labels, clickable prompts, and UI components that may be obscured. DOM-based logic continues to be used where it performs best. The new AI-assisted layer adds validation when the visual page state and DOM structure do not align.
For customers, this means fewer missed interactions and more reliable analysis results, especially for evasive or visually complex phishing pages.
VMRay’s AI Browsing Simulation uses a local AI model as part of the analysis workflow. Customer data is not used to train the model.
Customized IR Mailbox Notifications
Make User Reported Phishing feedback aligned with your organization
Security teams rely on automation to process User Reported Phishing at scale. But automation should not come at the cost of clear communication. When users submit suspicious emails, they need timely, understandable feedback to help them decide what actions to take next.
With the latest update to VMRay IR Mailbox, Cloud Account Managers and On Premises Administrators can now customize automatic email notifications sent to submitters for selected IR Mailbox events and submission verdicts. This gives organizations greater control over the messages users receive after a reported email has been analyzed.
For many security teams, these notifications must follow internal communication standards, use approved wording, reflect company-specific response procedures, and match the organization’s branding. To support different customization needs, two layout options are now available:
VMRay Layout
A ready-to-use layout with built-in VMRay branding and styling. This option is suitable for teams that want to customize notification content while keeping the default format.
Custom Layout
A fully customizable HTML-based layout. This option gives teams control over the email structure, formatting, branding, images, and subject line. The Custom Layout is especially useful for organizations that need IR Mailbox notifications to match internal communication templates or brand guidelines.
Automate What Happens After Email Analysis
Email analysis is most valuable when the results can immediately drive the next action. After a suspicious email has been inspected, security teams often need to pass the outcome to another system, such as a SIEM, a SOAR platform, a ticketing system, or a custom internal process.
With webhooks for IR Mailbox submissions, the VMRay Platform can now help bridge that gap. From this release, when an email submitted through the IR Mailbox has been fully analyzed, VMRay can automatically send a webhook notification to a configured destination. That notification includes key context about the email, including email verdict, verdict reason, classification, threat names, and more.
For SOC teams, this means IR Mailbox can become part of a broader automated response workflow. A malicious verdict can trigger a SOAR playbook. A suspicious email can create a ticket for analyst review. A clean result can update an existing case. Threat names and classifications can enrich alerts, route incidents, or support reporting. The result is less manual inspection and better integration between email threat analysis and the tools security teams already use. Ready to automate your IR Mailbox workflows? Give new webhooks a try.
Smarter Phishing Triage with KnowBe4 Custom Tag Filtering
Phishing investigations move faster when teams can decide which alerts deserve deeper analysis and which can be handled through other workflows. Submitting every reported message to a sandbox can increase workload, consume quota, and delay analysis of relevant threats. To help teams better control their phishing analysis workflow, VMRay now supports KnowBe4 custom tags in the KnowBe4 PhishER integration.
With the new custom tag filtering option, users can now define which KnowBe4 PhishER threats should be automatically submitted to the VMRay Platform. Instead of sending every retrieved alert for analysis, teams can use KnowBe4 tags to submit only messages that match specific criteria. The feature is designed to work with tags already used in KnowBe4 PhishER workflows, including manually assigned tags, rule-based tags, and PhishML/PML tags where enabled.
Final Thoughts
We hope these updates help you get even more value from the VMRay Platform. From AI Browsing Simulation and improvements to the KnowBe4 PhishER integration to new webhook support for IR Mailbox submissions, this release brings several enhancements designed to make phishing analysis more flexible, automated, and effective.
Looking ahead, we will continue refining Live Interaction capabilities, fine-tuning our UniqueSignal threat intelligence feed, and exploring further improvements to help security teams stay ahead of constantly evolving threats.
As we move through 2026, one more release is already on the horizon, with more valuable updates planned by the end of September. Until then, we wish you a productive summer and a smooth holiday season. Stay tuned for what’s next.