Secrets in custom authentication scripts: Added support for secrets in custom authentication scripts, allowing you to securely manage and test sensitive credentials during automated scans.
Improvements
Extended scan data retention: Improved scan data retention settings to allow you to store scan results for longer periods.
API endpoint accuracy for HTTPS websites: Fixed an issue where API requests for HTTPS websites incorrectly returned HTTP records, ensuring the correct website data is retrieved based on the requested protocol.
Bug fixes
CyberArk NTLM authentication: Fixed an issue where CyberArk secret resolution failed for NTLM authentication, allowing credentials and vault connections to be verified successfully.
Security checks
PolyShell (APSB25-94): Added a security check that identifies Adobe Commerce and Magento installations where the unauthenticated guest-cart REST API allows attackers to upload PHP polyglot files, bypass image validation, and achieve remote code execution.