Skip to main content
Protect My Mac — FreeNo credit card required

Product Updates

Changelog

What's new in CoreLock. Every feature, improvement, and fix in one place.

v0.9.0March 2026
New
  • AI Agent Prompt Injection Protection — scans .cursorrules, CLAUDE.md, .clawdbot, and 14 other AI config files for malicious instructions
  • Credential Exfiltration Detection — catches curl/wget commands stealing SSH keys, .env files, AWS credentials, and more
  • Exfiltration Webhook Blocking — flags webhook.site, ngrok, requestbin, and other known data exfil services
  • Hidden Unicode Detection — finds zero-width character sequences used to hide instructions in AI config files
  • Temporal Attack Chain Correlation — credential read followed by network send triggers critical alert within 60s window
  • AI Config → Credential Access correlation — detects when an agent reads a config file then accesses secrets within 120s
Improved
  • Expanded sensitive file coverage — now monitors .npmrc, .netrc, .docker/config.json, .kube/config, .git-credentials, .gnupg, .azure, .terraform.d, GitHub CLI tokens, and browser Login Data/Cookies
  • Smarter curl/wget scoring — file upload flags (-d @, --upload-file, --post-file) now score critical instead of warning
  • On-demand directory scanning for prompt injection via new IPC handler
v0.1.0February 2026
New
  • Initial public release
  • AI-powered security scanning with 9 scanner modules
  • Privacy audit for camera, microphone, and screen access
  • One-click auto-fix for security issues
  • AI chat assistant for security questions
  • Network connection monitoring
  • Code signing verification for all installed apps
  • YARA rules engine for advanced malware detection
  • Cloud sync with Supabase
  • Stripe billing with Free, Pro, and Team plans
  • Cross-platform: macOS (ARM + Intel) and Windows

Stay up to date

Download CoreLock to get every update automatically.

Download CoreLock Free