Skip to main content

September

· 11 min read

NG Production Release Update - APIsec_cloud_7.9.2.0 ( September 18, 2026 )​

This release expands Automated Authentication Discovery to support additional enterprise identity providers, introduces the next-generation Browser Bolt v2 with social login support, and adds Jira Story creation for vulnerability tickets. It also delivers reliability and security improvements for Private Hosted Agents, along with GraphQL scanning and reporting enhancements.

What's New​

More Identity Providers for Automated Authentication Discovery​

Automated Authentication Discovery now supports AWS Cognito, Keycloak, Duende IdentityServer, and WSO2 Identity Server, in addition to the existing Auth0, Okta, PingOne, and IBM identity providers.

APIsec can identify these providers even when they are not explicitly named in the API specification and build the authentication flow by following the application's redirect.

Why this matters

  • Enables authenticated scanning across more enterprise identity platforms
  • Reduces manual authentication configuration during API onboarding
  • Helps customers get authenticated scans running with less setup

Note: For WSO2 Identity Server, APIsec uses the opaque access token issued for the target API rather than the identity token.

Browser Bolt v2​

Browser Bolt v2 improves browser-based API onboarding, including support for capturing authenticated sessions through social login.

Why this matters

  • Makes it easier to onboard APIs that require browser-based authentication
  • Supports applications using social login during authentication
  • Improves the capture experience for authenticated APIs

Availability: Browser Bolt v2 is ready for publication to the Chrome Web Store and will be available for installation once the store review is complete.

Create Jira Issues as Stories​

Jira integrations now support Story as an issue type in addition to Bug and Task. The selected issue type is validated against the target Jira project when testing the connection.

Why this matters

  • Gives teams more flexibility to align APIsec tickets with their Jira workflow
  • Prevents ticket-creation failures caused by unsupported issue types
  • Confirms that the selected issue type can be created before vulnerabilities are reported

Improvements​

New Private Hosted Agent Image — Reliability & Security Updates​

A new Private Hosted Agent image includes reliability and security improvements. Hosted-agent work can now be automatically reclaimed and redelivered when a backend instance becomes unresponsive during a scan, preventing scans from failing due to this type of backend interruption.

Why this matters

  • Improves scan reliability for Private Hosted Agent deployments
  • Helps scans continue through backend instance interruptions
  • Includes the latest security and reliability updates

Note: Customers using Private Hosted Agents should upgrade to the latest image.

OWASP Coverage Report Improvements​

Problem

The Percentage of Endpoints at Risk chart in the OWASP Coverage report could show incorrect endpoint counts and percentages, with inconsistencies between the UI and generated PDF.

Solution

Endpoint counts and percentages are now calculated consistently, and the report visualization and vulnerability-category legend have been corrected.

Impact

  • Improves the accuracy of OWASP Coverage reporting
  • Ensures the UI and PDF present consistent results
  • Provides clearer vulnerability-category visualization

GraphQL Scan Improvements​

Problem

GraphQL scans could encounter an internal APIsec error during the OIDC/JWKS authentication discovery step, and the discovery-JWKS test was missing its description.

Solution

The authentication discovery workflow has been corrected for GraphQL APIs.

Impact

  • GraphQL authentication discovery now completes successfully
  • Improves the consistency of GraphQL security testing

NG Production Release Update - APIsec_cloud_7.9.1.0 ( September 11, 2026 )​

This release expands APIsec’s security testing and enterprise workflow capabilities with new Numeric Bound Fuzzing and Monetary Integrity tests, automated authentication discovery, enhanced Jira integrations, and new FedRAMP and HIPAA/HITRUST compliance reports. It also adds read-back validation for Mass Assignment findings and improves the accuracy and reliability of authentication, parameter hydration, BOLA testing, reporting, and private Hosted Agent scan improvements.

August

· 13 min read

NG Production Release Update - APIsec_cloud_7.8.3.0 ( August 31, 2026 )​

This release expands APIsec's platform capabilities across API lifecycle management, security validation, CI/CD automation, and operational visibility. New capabilities include flexible App Model onboarding controls, GitHub App integration, Platform ID-based API registration for CI/CD, Splunk audit-event forwarding, endpoint change visibility during spec reloads, and Personal Access Token expiry notifications. The release also introduces exploit-validation visibility and new security tests for refresh-token replay.

July

· 15 min read

NG Production Release Update - APIsec_cloud_7.7.4.0 ( July 31, 2026 )​

This release improves scan reliability for hosted-agent deployments, introduces SSO group-to-team mapping, enhances CI/CD automation by preventing duplicate scans, and expands Dashboard V2 with clearer application health and policy visibility. Additional improvements strengthen SSL/TLS and PII detection accuracy, while several workflow enhancements improve the overall user experience.

June

· 14 min read

NG Production Release Update - APIsec_cloud_7.6.3.0 (Jun 24, 2026)​

This release introduces HMAC authentication support, ServiceNow AVR integration, Advanced BOLA testing, Dashboard V2 enhancements, and a new SSL Enforcement detection category. Additional improvements strengthen hosted-agent management, information-detection workflows, and automation capabilities via scan-profile execution APIs.

May

· 13 min read

NG Production Release Update - APIsec_cloud_7.5.3.0 (May 22, 2026)​

This release expands Postman-based onboarding and scan workflows with support for spec reloads via Postman URL and Gateway integrations, Postman Environment variable resolution, and new OAuth-focused security test categories for authorization code replay and open redirect detection.

The release also improves hosted agent resiliency, API token-based scan execution, and Postman variable resolution during endpoint discovery and parameter hydration. Additional fixes improve MySQL injection category accuracy, strengthen the reliability of OAuth parameter hydration, and include platform-wide security hardening updates.

April

· 19 min read

NG Production Release Update - APIsec_cloud_7.4.4.0 (April 29, 2026)​

This release focuses on improving visibility, usability, and scan accuracy across the platform. Key updates include enhanced Developer Reports with full endpoint coverage, and a redesigned Hosted Agent dashboard for better operational visibility. Security testing has been expanded with new detection categories for SSL/TLS vulnerabilities and JWT header injection, helping teams identify critical risks earlier. Additionally, improvements to parameter hydration and UI consistency streamline workflows and reduce manual effort. Several fixes address issues in authentication handling, Postman imports, performance for large APIs, and reporting accuracy—resulting in a more stable and reliable testing experience.

March

· 16 min read

NG Production Release Update - APIsec_cloud_7.3.3.0 ( March 27, 2026 )​

  • Developer Report for Investigation and Remediation
    • A new Developer Report is now available to provide the technical context needed to investigate and remediate vulnerabilities. While the OWASP Coverage report focuses on security posture and coverage, this report focuses on the execution details that developers typically need during troubleshooting.
    • The report includes the necessary evidence and reproduction context, so teams don't need to manually navigate multiple sections to gather logs. This helps streamline how findings are reviewed and handed off between security and engineering teams.

February

· 15 min read

NG Production Release Update - APIsec_cloud_7.2.1.0 ( February 18, 2026 )​

Improved Reset Password Flow – Fewer Blocked Users, Faster Access​

If you've received a message like "I never got the temporary password - what do I do now?", this update is for you.

What was happening before

When a new user signed up but didn’t log in right away:

Their account remained in a "force change password" state.

January

· 9 min read

NG Hotfix Release Update - APIsec_cloud_7.1.1.1 ( January 21, 2026 )​

Azure API Management Integration: Improved Support for Granular Azure RBAC Scopes

We resolved an issue that could prevent APIs discovered through the Azure API Management (APIM) integration from being displayed when using granular resource-scoped credentials.

December

· 11 min read

NG Production Release Update - APIsec_cloud_6.12.2.0 ( December 30, 2025 )​

This release delivers a set of enhancements and fixes focused on secure onboarding, access governance, and testing accuracy. Authentication handling has been improved with automatic extraction of authentication credentials from Postman Collections, greater control over authentication selection during Dry Runs, and clearer validation outcomes to prevent misleading test results.

Access management has been strengthened through multi-user application access controls, enabling administrators to manage permissions at scale with better visibility and flexibility. RBAC-related improvements enhance both the accuracy of access validation and the clarity of security findings.