Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

April 2025

  1. The Subdomain Finder now integrates getallurls (GAU) in the External APIs test, pulling in subdomain data from archived URLs and Wayback content.

    This adds another layer to your discovery workflows, especially valuable for:

    ✅ Early-stage engagement scoping

    ✅ In-depth attack surface mapping

    ✅ Historical asset continuous monitoring with scheduled scans

  2. SonicWall’s Secure Mobile Access 1000 Series has a newly disclosed RCE — CVE-2025-23006 (CVSSv3 9.8) that allows an unauthenticated attacker to run arbitrary code on the target.

    Our Network Vulnerability Scanner can now specifically target and detect this CVE, so you can:

    • Flag affected assets in external infrastructure reviews

    • Stay ahead of exposure with your continuous monitoring flows

    • Deliver remediation-ready reports for stakeholders

  3. Prove real-world risk with these 3 new exploits

    Copy link to “Prove real-world risk with these 3 new exploits”

    Sniper: Auto-Exploiter now supports three high-risk CVEs, helping you validate exploitability with just a few clicks — no manual scripting needed:

    ✅ CVE-2024-11635 (CVSSv3 9.8) – an RCE in WordPress File Upload plugin using the require-once PHP statement, with attacker controllable data as an argument.

    ✅ CVE-2025-0890 (CVSSv3 9.8) – insecure default credentials for the Telnet function in Zyxel devices allowing an attacker to fully compromise your server.

    ✅ CVE-2024-40891 (CVSSv3 8.8) – a post-authentication command injection vulnerability in Zyxel via Telnet.

    For consultants, this means stronger deliverables and faster turnaround. For internal teams, actionable exploitability validation without time-consuming setup.

    Bonus reminder: all these CVEs can be detected with our Network Scanner.

March 2025

  1. Detect CVE-2025-29927, the vulnerability in Next.js middleware, fast and effectively

    Copy link to “Detect CVE-2025-29927, the vulnerability in Next.js middleware, fast and effectively”

    Our Network Scanner now provides fast, reliable detection for the critical Next.js vulnerability, CVE-2025-29927, so you can quickly identify affected applications.

    We've streamlined the detection process to help you pinpoint and address this risk effectively.

    How it works:

    ✅ Run a CVE-focused network vulnerability scan against your Next.js applications.

    ✅ The scanner will automatically check for CVE-2025-29927, highlighting vulnerable instances.

    ✅ Get clear, actionable results to prioritize patching and mitigation.

    Dive deeper: understand and fix CVE-2025-29927

    For a comprehensive understanding of the CVE-2025-29927 vulnerability, its impact, and detailed remediation steps, read our in-depth article.

    This write-up includes:

    • A technical breakdown of the vulnerability.

    • Affected Next.js versions.

    • Practical exploitation scenarios.

    • Business impact examples.

    • Step-by-step mitigation guidance.

  2. Catch email leaks, DOM-based redirects & XSS with ease

    Copy link to “Catch email leaks, DOM-based redirects & XSS with ease”

    This month’s Website Scanner updates help you uncover hard-to-spot web app issues faster:

    📌 Redirects buried in JavaScript can slip past traditional scans. Now our scanner checks for DOM-based open redirects, giving you deeper visibility into vulnerable behavior inside the browser.

    📌 See emails as standalone findings for faster review and better reporting.

    📌 Found an XSS? No need to manually recreate your payload - just click “Exploit with XSS Exploiter” in the Website Scanner and capture screenshots, cookies, and request data every time it gets triggered.

  3. Edit scheduled scan notifications without starting over

    Copy link to “Edit scheduled scan notifications without starting over”

    Need to add a new teammate, client, or just more recipients to scan notifications or change your alerts settings? We heard you loud and clear!

    Now you can edit notification settings for Scheduled Scans without recreating them from scratch.

    ✅ Adjust on the fly
    ✅ Keep your workflow flexible

  4. New scan results & a new Wordpress RCE in Sniper

    Copy link to “New scan results & a new Wordpress RCE in Sniper”

    Proof of exploitation is what separates noise from real risk. Sniper: Auto-Exploiter, our proprietary offensive tool, now supports:

    • CVE-2024-50498 (CVSSv3 9.8) – an RCE in WP Query Console that affects all WordPress versions and can allow code injection.

    Use Sniper to confirm impact and cut straight to remediation.

    As always, remember that if Sniper can exploit it, our Network Scanner can detect it.

    Plus, Sniper is now giving you a clearer view of payloads, responses, and proof of exploitation with the latest in our scan results UI makeover.

  5. Much easier tracking for pentest robot scan results

    Copy link to “Much easier tracking for pentest robot scan results”

    Our pentest robots are becoming increasingly popular for handling large-scale vulnerability assessments. And now, they're even easier to use, especially for those of you who need customized automation.

    We’ve made it simpler to keep track of pentest robots scans: instead of listing all scans individually, the Scans section now displays one entry per pentest robot, making it easier to map your actions to what you see in our product.

    How it works:

    ✅ Each pentest robot now has a single log entry, reducing clutter

    ✅ You can access all scan resulting from a single pentest robot accessed within its own log block

    ✅ Improved clarity helps you focus on results - not on tracking individual scans.

February 2025

  1. Get proof for new high-risk RCEs in these CMSs

    Copy link to “Get proof for new high-risk RCEs in these CMSs”

    Need to prove exploitability for highly targeted CVEs beyond a shadow of a doubt?

    Our proprietary offensive tool, Sniper: Auto-Exploiter, is now even more powerful, helping you get proof of exploitation for critical vulnerabilities in popular content management systems:

    • CVE-2024-10924 (CVSSv3 9.8) - an RCE in the Really Simple Security WordPress plugin that can let an attacker leverage an authentication bypass and compromise your server.

    • CVE-2023-41892 (CVSSv3 9.8) - a Craft CMS Unauthenticated RCE classified as a high-impact, low-complexity attack vector.

    And remember: if it’s exploitable with Sniper, it’s a confirmed risk you can also detect with our Network Vulnerability Scanner.

  2. Brute-force battle: we tested Hydra vs our Password Auditor against 26 web apps!

    Copy link to “Brute-force battle: we tested Hydra vs our Password Auditor against 26 web apps!”

    We ran Hydra, a pentester’s favourite, and our proprietary Password Auditor against 26 web applications — including Microsoft Exchange, WordPress, and Joomla.

    The comparison criteria? Their ability to:

    • Identify login credentials, endpoints and parameters

    • Recognize error messages & protection mechanisms

    • Detect defensive measures like IP blacklisting, CAPTCHA, account lockout, and rate limiting.

    The results make choosing a tool for password auditing much easier: Hydra might be a classic, but our Password Auditor is the real match for modern security defenses.

    Also included in this benchmark: a step-by-step guide to bruteforcing all 26 tested apps, from WordPress to Exchange.

  3. Analyze findings faster with even more refreshed results

    Copy link to “Analyze findings faster with even more refreshed results”

    The UI facelift continues!

    We’ve upgraded the look and feel of scan results for another important part of your security toolbox:

    📌 WAF Scanner

    📌 SQLi Exploiter

    📌 People Hunter

    📌 Subdomain Takeover

    📌 Joomla Scanner

    📌 ICMP Ping

    📌 Whois Lookup

    This means clearer findings and a better organization across the board.

  4. Zero in on critical web app flaws – lightning fast

    Copy link to “Zero in on critical web app flaws – lightning fast”

    To help you get eyes on the most burning security issues as fast as possible, we’ve updated the Website Scanner and the API Scanner to classify the most severe risks as Critical if their CVSSv3 score is over 9.0.

    This means:

    📌 More time to realistically assess business impact

    📌 More accurate risk and mitigation prioritization.

    Plus, this month comes with even more improvements in our Website Scanner:

    • You can now test authentication with headers with the Authentication functionality, before starting a new scan for a better setup configuration.

    • The Find Login Interfaces passive test now detects Basic HTTP/NTLM Authentication — helping you map authentication entry points with greater accuracy.

January 2025

  1. Reduce your attack surface faster with critical network findings

    Copy link to “Reduce your attack surface faster with critical network findings”

    Surfacing critical findings with high precision is our goal with the Network Vulnerability Scanner.

    That’s why it now generates critical findings if the CVSSv3 score is over 9.0, to help you prioritize and address the most urgent vulnerabilities more efficiently.

    Of course, both coverage and depth are important!

    Discover our latest network detections in our Vulnerability & Exploit Database, including one for CVE-2025-0282, a Remote Code Execution vulnerability in Ivanti Connect Secure.

  2. Confirm exploitable CVEs in your environment with Sniper

    Copy link to “Confirm exploitable CVEs in your environment with Sniper”

    Sniper: Auto-Exploiter, our proprietary offensive tool, comes with an expanding arsenal for proving exploitability for high-risk, widespread CVEs.

    Just look at these new vulns for which you can get proof of exploitation:

    • CVE-2024-51567  and CVE-2024-51378 (CVSSv3 9.8) — two CyberPanel RCEs that can let an attacker gain root access on a target machine.

    • CVE-2024-50623 (CVSSv3 9.8) — Arbitrary File Read and Write vulnerabilities in Cleo Harmony, VLTrader, and LexiCom.

    • CVE-2024-11680 (CVSSv3 9.8) — a ProjectSand Authentication Bypass vulnerability

    As always, don’t forget: if it’s exploitable with Sniper, you can detect it with our Network Scanner!

December 2024

  1. Check real-time results with People Hunter

    Copy link to “Check real-time results with People Hunter”

    People Hunter lets you discover email addresses and social media profiles starting from a web application — for a more accurate attack surface assessment.

    Now it’s faster with these two key optimizations:

    • Get results in real-time as the crawler works its ways through the target

    • See external query results when the scan starts.

  2. Turn every web app inside out with new detections

    Copy link to “Turn every web app inside out with new detections”

    Besides finding critical vulnerabilities in web apps, our proprietary Website Scanner automatically validates them to get rid of false positives.

    In the last few weeks, we’ve added even more highly accurate detections for:

    • insecure deserialization in Ruby-based applications with the scanner’s Active module.

    • Python pickle objects, together with an out of band deserialization method so you don’t get any unwanted RCEs in production.

    Wondering what else you can detect with our Website Scanner? Find all our web app detections in the Vulnerability Database by filtering after the tool’s name!