September
NG Production Release Update - APIsec_cloud_7.9.2.0 ( September 18, 2026 )
This release expands Automated Authentication Discovery to support additional enterprise identity providers, introduces the next-generation Browser Bolt v2 with social login support, and adds Jira Story creation for vulnerability tickets. It also delivers reliability and security improvements for Private Hosted Agents, along with GraphQL scanning and reporting enhancements.
What's New
More Identity Providers for Automated Authentication Discovery
Automated Authentication Discovery now supports AWS Cognito, Keycloak, Duende IdentityServer, and WSO2 Identity Server, in addition to the existing Auth0, Okta, PingOne, and IBM identity providers.
APIsec can identify these providers even when they are not explicitly named in the API specification and build the authentication flow by following the application's redirect.
Why this matters
- Enables authenticated scanning across more enterprise identity platforms
- Reduces manual authentication configuration during API onboarding
- Helps customers get authenticated scans running with less setup
Note: For WSO2 Identity Server, APIsec uses the opaque access token issued for the target API rather than the identity token.
Browser Bolt v2
Browser Bolt v2 improves browser-based API onboarding, including support for capturing authenticated sessions through social login.
Why this matters
- Makes it easier to onboard APIs that require browser-based authentication
- Supports applications using social login during authentication
- Improves the capture experience for authenticated APIs
Availability: Browser Bolt v2 is ready for publication to the Chrome Web Store and will be available for installation once the store review is complete.
Create Jira Issues as Stories
Jira integrations now support Story as an issue type in addition to Bug and Task. The selected issue type is validated against the target Jira project when testing the connection.
Why this matters
- Gives teams more flexibility to align APIsec tickets with their Jira workflow
- Prevents ticket-creation failures caused by unsupported issue types
- Confirms that the selected issue type can be created before vulnerabilities are reported
Improvements
New Private Hosted Agent Image — Reliability & Security Updates
A new Private Hosted Agent image includes reliability and security improvements. Hosted-agent work can now be automatically reclaimed and redelivered when a backend instance becomes unresponsive during a scan, preventing scans from failing due to this type of backend interruption.
Why this matters
- Improves scan reliability for Private Hosted Agent deployments
- Helps scans continue through backend instance interruptions
- Includes the latest security and reliability updates
Note: Customers using Private Hosted Agents should upgrade to the latest image.
OWASP Coverage Report Improvements
Problem
The Percentage of Endpoints at Risk chart in the OWASP Coverage report could show incorrect endpoint counts and percentages, with inconsistencies between the UI and generated PDF.
Solution
Endpoint counts and percentages are now calculated consistently, and the report visualization and vulnerability-category legend have been corrected.
Impact
- Improves the accuracy of OWASP Coverage reporting
- Ensures the UI and PDF present consistent results
- Provides clearer vulnerability-category visualization
GraphQL Scan Improvements
Problem
GraphQL scans could encounter an internal APIsec error during the OIDC/JWKS authentication discovery step, and the discovery-JWKS test was missing its description.
Solution
The authentication discovery workflow has been corrected for GraphQL APIs.
Impact
- GraphQL authentication discovery now completes successfully
- Improves the consistency of GraphQL security testing
NG Production Release Update - APIsec_cloud_7.9.1.0 ( September 11, 2026 )
This release expands APIsec’s security testing and enterprise workflow capabilities with new Numeric Bound Fuzzing and Monetary Integrity tests, automated authentication discovery, enhanced Jira integrations, and new FedRAMP and HIPAA/HITRUST compliance reports. It also adds read-back validation for Mass Assignment findings and improves the accuracy and reliability of authentication, parameter hydration, BOLA testing, reporting, and private Hosted Agent scan improvements.