• 0

What happens if Webroot SecureAnywhere misses a virus?


Question



In this video Webroot purposely infect a machine running Webroot SecureAnywhere. They even disable the behaviour shield to replicate what would happen if a threat was missed and it executed on your PC.

We estimate there to be somewhere in the region of 50,000 new strains of malware every single day, so it's frankly impossible for the legacy signature-based approaches to keep up with the vast volume of threats.

Webroot SecureAnywhere adopts a new cloud-driven approach, ensuring that users always have access the the latest security "definitions" without needing to download any updates. This, coupled with a 700Kb agent, ensures optimal performance and enhanced security.

Webroot also recognise that the ever-rising volume of malware means that they'll miss threats, too. While they do have industry leading detection rates (See: http://www.av-test.o...er/mayjun-2012/) they have introduced unique protection against information-stealing malware, so even if they do miss something, the data that you really care about cannot be tampered with.

Recommended Posts

  • 0

"Webroot SecureAnywhere adopts a new cloud-driven approach"

That's great and all...until malware kills your internet connection.

Also, is it just me or does the "article" read like an ad?

  • 0

Neowin now sponsors Info-mercials...

Funny how they completely avoid discussing how this would work with an infection which blocks/alters your internet connection so you can't access the cloud.

  • Like 3
  • 0

I guess it kinda is an ad. The video and content came from Webroot themselves. Doesn't mean it can't stir up some interesting debate on a new approach to AV. When was the last time an AV vendor purposely infected a PC running their software....?

There is, of course, offline protection. Some of which is highlighted in the video.

  • 0

There is, of course, offline protection. Some of which is highlighted in the video.

Then it provides no benefit over its competition. My AV checks for updates every hour. If within that hour I get hit with something new which totally blocks my AV from grabbing an update (which may or may not resolve the issue) then I am hosed.

If I run the service you suggest and I get hit within the hour, I can't reach the cloud to grab the update so off-line mode can't fix it. Hosed either way.

  • 0

I like the idea of a constantly-updated "cloud" definition-base, but it would have to work as a hybrid system that also periodically downloads it locally. That way you generally get the very latest definitions, but in the event of malware that kills your internet connection, you still have a relatively-recent offline copy it can use to scan the system. I'm sure that's what er0n mentioned, but I am at work atm and can't view the video, so I can't be sure of how it works.

So then, Rohdekill, the advantage would be that in most cases you have a very up-to-date solution. Not sure which AV you use, but most people's don't update that frequently, so it may provide some benefit for an "average" user.

  • 0

Then it provides no benefit over its competition. My AV checks for updates every hour. If within that hour I get hit with something new which totally blocks my AV from grabbing an update (which may or may not resolve the issue) then I am hosed.

If I run the service you suggest and I get hit within the hour, I can't reach the cloud to grab the update so off-line mode can't fix it. Hosed either way.

Hi Rohdekill,

Let me explain how our offline protection works.

When a new file is introduced to a PC we try to obtain a classification from the Webroot Intelligence Network (cloud). If the connection cannot be established because the user is offline, the file is assumed to be 'unknown'.

Files that have an 'unknown' classification will be executed in a 'Monitor' state. Even though it's running on the endpoint, we're carefully watching the file to make sure it can't make any malicious modifications to your PC. Also, every single change that the file does make to your PC while in the Monitor state will be recorded in a local change-journal database.

Once the connection to the internet has been established, and we send down a 'bad' classification to the PC, all of those changes are perfectly reversed. There is a lot of protection built into the product to protect and verify the integrity of the internet connection, including LSP chain protection and kernel-mode connectivity.

So in summary your endpoint is benefiting from a degree of generic protection to stop your PC being 'trashed' and you're also getting a perfect clean-up routine.

It could be argued that we're no better/worse than the competition at protecting your PC when it's offline, but the benefits when conneced to the internet are clear.

Let me know if you have any other concerns on this topic.

Thanks,

Will

If I run the service you suggest and I get hit within the hour, I can't reach the cloud to grab the update so off-line mode can't fix it. Hosed either way.

Edit: Take a look at the last part of the video and you'll see the journaling and rollback in action. In the unlikely scenario that the situation you describe occurs, the user will be able to manually 'block' the infected file, and every single change it made to the system will be perfectly reversed. This requires no active connection to the internet.

  • 0
I like the idea of a constantly-updated "cloud" definition-base, but it would have to work as a hybrid system that also periodically downloads it locally. That way you generally get the very latest definitions, but in the event of malware that kills your internet connection, you still have a relatively-recent offline copy it can use to scan the system. I'm sure that's what er0n mentioned, but I am at work atm and can't view the video, so I can't be sure of how it works. So then, Rohdekill, the advantage would be that in most cases you have a very up-to-date solution. Not sure which AV you use, but most people's don't update that frequently, so it may provide some benefit for an "average" user.

Honestly, do we need AV that is updated every second? Unless you're a high value target (e.g.: government, banking, super rich...) are you really at risk of being hit with 0-day attacks?

Even if the 0-day threat is real for average users, which I don't think it is, the frequency of the definition downloads are less important than the total time it takes the AV vendor to discover, classify, and add a definition for it... The AV venders don't publish those numbers though...

  • 0

Honestly, do we need AV that is updated every second? Unless you're a high value target (e.g.: government, banking, super rich...) are you really at risk of being hit with 0-day attacks?

Even if the 0-day threat is real for average users, which I don't think it is, the frequency of the definition downloads are less important than the total time it takes the AV vendor to discover, classify, and add a definition for it... The AV venders don't publish those numbers though...

I think most users will be absolutely fine, and it really depends how you use the internet, how highly you value your sensitive data, and how highly you value your time. If you don't do online banking or store your resume/CV on your PC, then you'll probably be fine with one of the legacy signature-based solutions.

Your last comment is exactly why we have decided to take the approach that we have. There are approximately 7 million users currently using Webroot SecureAnywhere today - whenever a new file is observed for the first time on one of our customer's PCs, it's executed on the PC in a isolated sandbox environment where we'll capture the intial behaviour of the file. We'll then make a determination as to whether the behaviour is good or bad - if it's bad, all of our 7 million customers are instantly protected without having to wait for us to publish a signature or get them to download anything.

If the behaviour doesn't appear to be bad, the file is executed on the endpoint but the user/PC is still protected using the methods shown in the video.

The window of exposure to a new threat (1 in ~50,000 per day) is dramatically reduced using this model.

FWIW, 0-day threats are not necessarily targetted attacks. They can spread through software vulnerabilities and infected legitimate web-sites.

P.S. I have no idea whether i'm actually allowed to be posting on this thread. I hope I'm not breaking any rules.

  • Like 2
  • 0

I think most users will be absolutely fine, and it really depends how you use the internet, how highly you value your sensitive data, and how highly you value your time. If you don't do online banking or store your resume/CV on your PC, then you'll probably be fine with one of the legacy signature-based solutions.

Your last comment is exactly why we have decided to take the approach that we have. There are approximately 7 million users currently using Webroot SecureAnywhere today - whenever a new file is observed for the first time on one of our customer's PCs, it's executed on the PC in a isolated sandbox environment where we'll capture the intial behaviour of the file. We'll then make a determination as to whether the behaviour is good or bad - if it's bad, all of our 7 million customers are instantly protected without having to wait for us to publish a signature or get them to download anything.

If the behaviour doesn't appear to be bad, the file is executed on the endpoint but the user/PC is still protected using the methods shown in the video.

The window of exposure to a new threat (1 in ~50,000 per day) is dramatically reduced using this model.

FWIW, 0-day threats are not necessarily targetted attacks. They can spread through software vulnerabilities and infected legitimate web-sites.

P.S. I have no idea whether i'm actually allowed to be posting on this thread. I hope I'm not breaking any rules.

How is this dynamic scanning any different than heuristic engines that have been built into AV scanners for the last decade? Unless you're saying that every file a user opens is transmitted to Webroot for additional analysis?

  • 0

How is this dynamic scanning any different than heuristic engines that have been built into AV scanners for the last decade? Unless you're saying that every file a user opens is transmitted to Webroot for additional analysis?

Hi Frazell,

Traditional AV products typically utilize basic local heuristics which are renowned for generating false positives and being largely ineffective.

Webroot SecureAnywhere sends the behaviour of the file, along with its meta data to the Webroot Intelligence Network (cloud) where the behaviour is compared to tens of thousands of advanced behavioural rules. In addition to the behaviour, Webroot is able to make a more accurate 'estimation' by considering the age (how long it's been known to the Webroot community) and popularity (how many users in the Webroot community are using it). Some other solutions have also started to adopt cloud reputation lookups.

The key thing here is that while our 'heuristics' should be more effective, we recognise that the bag guys are getting smarter, so we don't rely on them. We've implemented generic protection against information-stealing malware and implemented a unique feature for perfect remediation - you can see these features in action in the video in the OP.

  • 0

Webroot_Will,

Why doesn't the product have any kind of email scanning, and what about webpage scanning (ex. sites hacked to run malicous code in an iframe or script)...I also noticed it does not actively scan downloads like NOD32 does, including inside ZIP files.

  • 0

Hi Mr. Black,

Email Scanning isn't a focus for us right now. We tend to find that most home users use Webmail with AV and Anti-Spam built-in, and most businesses use a dedicated email security solution. Besides, if a user were to receive a virus by emal and execute it, we'd catch it at that point, so from a security stand-point the user/PC is still secured. We have a 'Web Threat Shield' designed to prevent the execution of malicious content from web-sites and to prevent software vulnerabilities from being exploited. Even if we 'miss' one of these attacks, something has to execute on the PC in some way for malicious modifications to take place, and we're sitting there at the kernel layer watching every single operating system activity.

From a security stand-point, scanning benign files like Zip files in real-time is unneccessary; a Zip file in itself cannot execute and harm the PC in anyway. As soon as the user extracts the contents or if the Zip file changes in some way so that it could potentially pose a threat, Webroot will step in and protect the PC/user. There are pros and cons to this approach, but our customers really appreciate the performance boost they receive without compromising on security.

  • 0

When was the last time an AV vendor purposely infected a PC running their software....?

Hopefully every single time they test their definitions and heuristics...otherwise without testing it's pointless.

That would be like asking...when was the last time a chef intentionally tasted their own food to make sure that it was good...

You want to be a good chef? You taste your own food.

You want to make sure your AV product works? You infect a system and see what happens.

  • Like 3
  • 0

Hopefully every single time they test their definitions and heuristics...otherwise without testing it's pointless.

That would be like asking...when was the last time a chef intentionally tasted their own food to make sure that it was good...

You want to be a good chef? You taste your own food.

You want to make sure your AV product works? You infect a system and see what happens.

Hi Shane,

The point is that the other vendors would never publish a video showing what happens if they miss a threat. Why not? Because the PC would be trashed and the customer's data would be stolen.

  • 0

Hi Shane,

The point is that the other vendors would never publish a video showing what happens if they miss a threat. Why not? Because the PC would be trashed and the customer's data would be stolen.

Indeed, and the logic behind that is usually these types of attack go after the antivirus/antimalware program first, and disable all of the settings like this and often kill the process itself and prevent it from doing its job.

Then it deploys the keyloggers & various other nasty bits, and then it still steals the data.

So the video only shows what happens IF the virus/malware doesn't target the AV product itself and it can keep itself up and running with its policies in place.

Any 'good' virus/malware these days takes out the security first before doing the dirty work. So what keeps them from attacking the processes that you use and just proceeding?

I ask because with claims of this kind there needs to be some pretty heavy duty assurances in place to prevent that scenario. ;)

  • 0

Indeed, and the logic behind that is usually these types of attack go after the antivirus/antimalware program first, and disable all of the settings like this and often kill the process itself and prevent it from doing its job.

Then it deploys the keyloggers & various other nasty bits, and then it still steals the data.

So the video only shows what happens IF the virus/malware doesn't target the AV product itself and it can keep itself up and running with its policies in place.

Any 'good' virus/malware these days takes out the security first before doing the dirty work. So what keeps them from attacking the processes that you use and just proceeding?

I ask because with claims of this kind there needs to be some pretty heavy duty assurances in place to prevent that scenario. ;)

Hi Shane,

You make a great point, and it's one we've thought long and hard about.

One of the key benefits of being so lightweight (the entire program is <700kb) is that Webroot SecureAnywhere is able to sit at the kernel-layer watching every single operating system event. After a few minutes of being installed on a typical machine, we've normally observed millions of events. If the traditional, heavy-weight solutions tried to do this, the machine would be so slow it would be unusable. This allows us to have exceptional self-protection.

As you will have seen in the video, the first thing we do prior to allowing a file to execute is obtain a classification for the file (Good, bad or unknown). We can assume that a brand new 0-hour virus is unknown, so it will be executed in the monitor state shown in the video. This already limits the malicious modifications the file can make to the system, and it certainly means that we won't let the file get anywhere near terminating the Webroot agent.

We've yet to see a virus which can circumvent this approach. Will it happen in the future? No doubt about it, but I'd like to think we're already a step-ahead of the game.

We can prove that we have an industry leading detection rate (most vendors do!). The difference is we come with a plan B.

with 0day and 0hr infections, no antimalware software can protect you, cloud or traditional. Good luck fighting the battle you already lost.

Hi sc302,

Did you watch the video? Keen to hear your thoughts on why you think this protection model can't protect you.

  • 0

Didn't watch the video. I really don't need to.

How is it that you think you can predict the future or the unknown?

All I can suggest is that if you watch the video, all will become clear.

The key fundamental here is that the Webroot Intelligence Network doesn't just include classifications for known-bad files, it also includes classifications for known-good files. The files inbetween are considered to be unknown, and you get all of the protection benefits highlighted in the video.

  • 0

while your newest software has gotten significantly better reviews than your previous rendition of your cloud based software, I will eventually test your software when I have time or have an infection that I need to dissect to see if it lives up to the reviews. I am sorry I don't believe in videos made by the manufacturer they are a bit one sided and always tout their services and make it seem that theirs is better than everyone elses. I am even a bit skepticle on reviews until it has been proven by myself to work.

  • 0

while your newest software has gotten significantly better reviews than your previous rendition of your cloud based software, I will eventually test your software when I have time or have an infection that I need to dissect to see if it lives up to the reviews. I am sorry I don't believe in videos made by the manufacturer they are a bit one sided and always tout their services and make it seem that theirs is better than everyone elses. I am even a bit skepticle on reviews until it has been proven by myself to work.

Hi sc302,

I can't argue with that - I think you're right to be sceptical, and I'm exactly the same.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft brings Claude to its own Azure infrastructure, powered by Nvidia GB300 Blackwell by Karthik Mudaliar Anthropic's Claude models are now generally available in Microsoft Foundry on Azure and are running on Nvidia's GB300 Blackwell Ultra systems. Nvidia wrote in its announcement that the models are hosted on Microsoft Azure and accelerated by GB300 Blackwell Ultra GPUs, with Quantum-X800 InfiniBand networking used to support larger agentic systems and specialized sub-agents that can operate across business domains. This is great for customers and enterprises that want to build autonomous and domain-specific AI agents using Claude without moving outside Microsoft’s cloud platform. Microsoft currently offers Claude models in Foundry in two forms: “Hosted on Azure,” which runs end-to-end on Azure infrastructure and is generally available, and “Hosted on Anthropic infrastructure,” which remains in preview. This separation is quite important for organizations that have procurement, compliance, data processing, or internal governance requirements tied to Azure. Anthropic currently has 11 Claude models listed in Microsoft Foundry, including Opus 4.8, Sonnet 4.6, and even the unavailable Mythos and Fable models. Billing is handled through Claude Consumption Units (CCUs). Microsoft says CCU is an invoicing unit for Claude models in Foundry, with token usage converted using Anthropic’s published per-model token rates. The usage is billed through Azure Marketplace just like models from other distributors and appears on the customer's Azure invoice, while eligible spend can count against a Microsoft Azure Consumption Commitment. For starters, GB300 NVL72 is a rack-scale, fully liquid-cooled system that combines 72 Blackwell Ultra GPUs and 36 Grace CPUs. Nvidia has listed 37TB of fast memory, 130TB/s of NVLink bandwidth, and FP4 Tensor Core performance of up to 1,440 petaflops with sparsity. The deal is also part of a three-way partnership between Microsoft, Nvidia, and Anthropic. Under the deal, Anthropic has committed to buying $30 billion in Azure compute capacity and contracting additional capacity up to one gigawatt. Nvidia and Microsoft also said they would invest up to $10 billion and $5 billion in Anthropic, respectively.
    • WhatsApp is getting usernames, and you can reserve your preferred one now by Fiza Ali Sharing your phone number isn't always something you want to do, especially with people you've just met. Whether it's someone from a class, a local community group, or a sports team chat, handing over your number can feel like giving away more personal information than necessary. That's exactly the problem WhatsApp is trying to solve with its upcoming usernames feature. The company has announced that users can now reserve a unique WhatsApp username ahead of the feature's wider rollout later this year. Once usernames become available, they'll let people connect without revealing their phone numbers. It's a change that makes a lot of sense for group chats. Right now, everyone in the group can see your phone number. With usernames enabled, that won't necessarily be the case when someone contacts you for the first time. WhatsApp says it's opening username reservations early because more than three billion people use the app, meaning plenty of people are likely to want the same usernames. Reserving one now gives users a better chance of securing the name they actually want before the feature launches more broadly. If your preferred username is already taken, WhatsApp will also offer a built-in username generator to suggest available alternatives. The feature isn't only aimed at individual users. Creators, businesses, and organisations will be able to claim the same username they already use on Instagram or Facebook, making it easier to keep a consistent identity across Meta's apps. Furthermore, privacy is a big part of how WhatsApp is introducing usernames. There won't be a public directory where people can browse or search for usernames. Instead, people will need to know your exact username before they can start a conversation with you. Additionally, users can also choose to enable a username key, which adds another layer of control by requiring people to enter that key before sending a message. Once the feature rolls out, people who choose to use a username will no longer have their phone number shown when messaging a person or business for the first time. If you want to reserve a username, make sure you're running the latest version of WhatsApp, then head to Settings > Account > Username. The tech giant says usernames will roll out gradually over the coming months, and users will receive an in-app notification when the feature becomes available in their country.
    • When I think about a network, there are really two aspects, the hardware and the wiring. So here is what I would do for both. Wiring: Use Cat6A for the patch panel, outlets, and all structured cables (cables installed in walls). Run plenty of Wireless Access Point (WAP) cables, as a general rule, assume a signal can only pass through 2-3 walls and can't pass through a floor (that is conservative, but trust me on this if you want strong WiFi)  Cat6 patch cables are fine for now if you don't plan to run 10gig, those are easy to replace later if needed. Run OS2 single-mode fiber to anywhere you think you may have a server or sub-switch. (yes, single-mode for everything on a small network, don't mess with multimode unless you are at a scale where that minor cost and power savings will matter). If you really want to future proof, also run fiber to any high density WAP locations, it is likely that WiFi 8 and beyond WAPs will push the limits of 10g. Run 6-12 pairs of single-mode fiber between your MDF and the building's MDF, even if you only need 1 or 2 pairs now, those extra pairs will pay off down the road. Hardware: (its easy to say "get all the features incase you need them", so instead of futureproofing, I am going to take approach of suggesting areas worth investing in, and areas you can save money). Don't overspend thinking you need every feature on every port. You don't need 10g on every port, you don't need PoE on every port. Don't overspend on redundancy either, unless you are ready to buy two of everything, don't waste money buying two of some things and not others. Dual power supplies are worthwhile, but probably not HA or multi-path redundancy.  Get 1 "distribution layer" switch that your router/firewall will connect to as well as all your access layer switches below. This should be a fully managed 10g+ switch with a combination of copper and SPF ports, a few 25g uplink ports are nice for this switch. Given that you said it is a small network, I suggest also using that distribution layer switch for servers and WAPs, meaning it will need PoE. Speaking of wireless, get good professional tri-band WAPs, and either turn on the band stirring options, or limit 2.4 to an IoT only SSID. This will provide a solid WiFi capable nearly everything but the highest of bandwidth clients...you could even consider skipping wiring workstations depending on usage. Access layer switch for workstations and printers can be cheaper switches, 2.5g is a good sweet spot between price and future proofing, but even 1g is fine for most individual clients (the kind that could probably be fine on WiFi). You can consider saving a little on access layer switches by only getting 1 PoE switch for whatever needs it (remember your WAPs are connecting to the distribution switch, not here), and non-PoE for your workstations, because desk phones are falling out of favor. You can also save money here by not buying managed switches if you don't need them--but really do some soul searching there, if you go this route, then anything that isn't on your workstation VLAN would either need to be connected to the distribution switch, or its own access layer switch. Also, don't feel like you need a fancy fabric stacking switches for your access layer, that is the point of the higher-end distribution layer, to remove the need for things like that at this level. Home Hardware: I'm realizing the above assumed an office setting, if this if for your house and home lab then the above still applies, but you'll probably want everything managed and PoE, just because, but you probably also don't need multiple access layer switches. If your total port count is below 24, just skip separating distribution layer and access layer and just get one nice switch with the features you want. If you are at the point of considering a 48-port switch, I would instead get a nice high-end distribution switch for things that need it, and cheaper access layer switches with specs based on the needs of connected devices. For home use, don't worry about home running every device to the main switch, there is nothing wrong with running sub-switches for your media areas and office, those essentially become your access layer, just look for sub-switches with a 10g uplink so sharing bandwidth isn't an issue. Just make sure you always connect them to your distribution/main switch, don't daisy chain, the path should never have more steps than Client>Access>Distribution>Firewall>Internet or Client>Access>Distribution>Server if it is local.
    • Google Meet brings Gemini note-taking to AI Pro and Ultra subscribers by Karthik Mudaliar Google's Gemini-powered "Take notes for me" feature inside Google Meet is now available to Google AI Pro and Ultra subscribers. The features work on Google Meet for web as well as on mobile, and Google says that subscribers can use it for meetings they host in many supported languages. As the name suggests, "Take notes for me" allows Gemini to listen to a meeting, generate a summary, identify action items, and save the notes as a Google Doc in the user’s Drive. After the meeting, the organizer receives an email recap with the summary and action items, while the notes can also be attached to the related Calendar event depending on the meeting setup and sharing settings. The feature isn't automatically turned on for everyone, though. Google says that all meeting participants are notified when note-taking is turned on, and users can start it from the pencil icon in Meet or enable it for future calls through Meet’s meeting records settings. For work or school accounts, administrators can also control whether the feature is available and may require explicit participant consent for note-taking, recording, or transcription features. The feature first launched back in 2024, when it was available just for selected Workspace users. Over the years, Google added refinements and more options, including the ability to enable it when scheduling meetings via Google Calendar. Google's support docs say that the feature currently supports English, French, German, Italian, Japanese, Korean, Portuguese, and Spanish, but only one language at a time. Meetings with multiple spoken languages are not currently supported, and Google recommends using the tool for meetings between 15 minutes and eight hours. The new feature makes Google Meet closer to its rivals that have AI tools already built in. Microsoft Teams has recently started offering Copilot and intelligent recap features that summarize meetings, surface highlights, and help with follow-ups, while Zoom’s AI Companion can also generate meeting summaries from desktop and mobile meetings.
    • GnuCash 5.16 by Razvan Serea GnuCash is a personal and small business finance application, freely licensed under the GNU GPL and available for GNU/Linux, BSD, Solaris, Mac OS X and Microsoft Windows. It’s designed to be easy to use, yet powerful and flexible. GnuCash allows you to track your income and expenses, reconcile bank accounts, monitor stock portfolios and manage your small business finances. It is based on professional accounting principles to ensure balanced books and accurate reports. GnuCash can keep track of your personal finances in as much detail as you prefer. If you are just starting out, use GnuCash to keep track of your checkbook. You may then decide to track cash as well as credit card purchases to better determine where your money is being spent. When you start investing, you can use GnuCash to help monitor your portfolio. Buying a vehicle or a home? GnuCash will help you plan the investment and track loan payments. If your financial records span the globe, GnuCash provides all the multiple-currency support you need. Between 5.15 and 5.16, the following bugfixes were accomplished: Bug 421610 - RFE: Include logical dates for View->Filter by "date range"The Select Range section of the Date tab of the register's Filter By dialog box is changed to provide relative, specific date, or days ago options for the start and end of the filter range. The Show number of days item label is changed to Show from days ago to better reflect what it does. Bug 436105 - esc key not working as expected in register: Enable the escape key to cancel a field edit. Bug 797384 - Gnucash doesn't handle commodity prices with big numerator/denominator properly. Bug 798004 - Next gen UI for stock transactions Bug 799314 - Add "enter now" option in scheduled transaction editor. tab to allow users to select the scheduled transactions to be included in a “Since Last Run…” window. If there are no instances of a selected transaction triggered by today’s date, the next instance is triggered. Bug 799751 - autocomplete crash Bug 799759 - Users can't Enable entries via Checkboxes on Scheduled Transactions PageAllow the Enabled box in the list of scheduled transactions to be operated instead of having to open the transaction editor dialog and change the Enabled checkbox. Also added use of the Name column as the secondary column sort for all the other columns. Bug 799762 - Poor handling of cases where hidden/placeholder accounts are used in the account register Bug 799766 - Double line preference not respected in search register Bug 799767 - POST /accounts in bindings/python/example_scripts/rest-api is broken Bug 799777 - `xaccSplitSetParent`: reparenting a committed split silently drops its KVP slots (online_id, cap-gains links) Other changes & improvements: Numeric values may now be selected to copy in the Accounts page. Add new Finance::Quote source Finnhub.io: Free API key (personal/non-professional use) available at https://finnhub.io. Set FINNHUB_API_KEY environment variable to API key to use this source. As of June 2026, free tier API limit is 60 API calls/minute. The Investment Lots report has new optional columns for Computed Annual Growth Rate. Python Bindings: Improved translation of primary object (Account, Transaction, Split, etc.) so that they can be treated as normal Python objects. This is accomplished with SWIG magic so no existing code is obsoleted. Python Bindings: Better conversion of GLists to Python lists. Python Bindings: Destroy the QofSession in the Python Session dtor to prevent leaving the database locked. [engine] Add first-class online_id accessors for Split and Account and make them available to Python bindings, removing the unused Transaction online_id property. Improve C++ implementation of QofBook. Correct the Doxygen doc for qof_instance_get/set_kvp. [gnc-log-replay.cpp] fix incorrect guid dump Add some Boost library requirements needed by libgnucash-guile to CMakeLists.txt so that missing feature will fail at configure time. Use Compile-time Regular Expressions instead of std::regex in gnc-filepath-utils.cpp and instead of boost::regex in the CSV importer, with the CTRE v3.11.1 header added to borrowed [gnc-filepath-utils.cpp] null check char* arguments Add ChartJS licenses. Removed AEX from list of commodities. euronext.com is now using JS based anti-webscraping. [report-core] always offer options summary in reports. This is useful to debug reports. The Add options summary option is removed because it's no longer optional. Remove remaining obsolete IMContext from sheet Fix blurry text in HiDPI offscreen-rendered widgets Add port field to database connection dialog: The convention of appending the port number after the host isn't obvious. When editing a split in the register treat the account as being changed only if it isn't the one selected before editing instead of if the user performed an edit Return immediately from qof_book_destroy if hash_of_collections is null. If qof_book_destroy is called on a QofBook* freshly created with qof_book_new (usually because it was used to create a session that now must be destroyed) it would try to empty the non-existent hash tables, crashing. Clean up Flathub metadata to solve warnings at flatpak build time. Be consistent in naming GncPluginPage and GncPluginPageRegister HTML: Remove unimplemented function declarations. [gnc-html.cpp] remove unused buggy string conversion functions Convert libgnc-html to C++ Apply -Wall -Werr -Wmissing-prototypes to C++ compilation on Windows and fix the resulting errors. New and Updated Translations: Arabic, Croatian, Danish, Dutch, German, Finnish, Hungarian, Korean, Norwegian-Bokmal, Spanish Download: GnuCash 5.16 | 176.0 MB (Open Source) Links: GnuCash Home page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      536
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!