Changelogs

Acunetix 360 On-Demand

RSS Feed

v25.3.1 - 25 Mar 2025

This Acunetix 360 release version 25.3.1 includes a new feature and resolved issues.

Improvements

  • Added the ability to reset the issue state to its default

Resolved issues

  • Fixed an exception caused by an invalid Target URI in scheduled scans
  • Fixed an issue where proxy credentials were not encrypted when launching InvictiProxy
  • Fixed inconsistent styling in the report policy, ensuring uniform formatting in the vulnerability profile sections

v25.3.0 - 11 Mar 2025

This Acunetix 360 25.3.0 release includes improvements and resolved issues.

Improvements

  • Enhanced technology version identification from URI
  • Improved reporting of multiple technology detections on the same file
  • Scheduled group scans will be initiated in chunks when exceeding 500 websites
  • Updated footer URL in Invicti Enterprise reports
  • The SelfDisable command is no longer sent to the Agent when its state is updated to Disabled
  • Upgraded 3rd party script libraries
  • Added support for encrypting proxy credentials settings in the agent appsettings.json file
  • Updated the Splunk Python SDK for the Splunk Plugin to ensure compliance with the latest Splunk Vetting Policy

Resolved issues

  • Fixed issue with error occurring when sending vulnerabilities to APIHub if externalId is Null
  • Fixed permission issue with unlinking API in APIHub
  • Fixed the issue to enable compatibility with the latest version of GitHub Actions
  • Scheduled scans now remove the URL path after ‘#’ when using the default Scan Profile
  • Fixed sorting issues in the dashboard to use numerical order instead of alphabetical
  • Updated OpenSSL from version 3.3.1 to 3.3.2

API changes

  • The Validate Imported Links API endpoint no longer requires a Target URL when a file is uploaded

v25.2.1 - 25 Feb 2025

Improvements Added a loading state for the Export CSV button to prevent multiple clicks Improved value filling in GraphQL queries Added the ability to re-scan cloned PCI scans on previously scanned targets to apply exceptions Resolved issues Fixed an issue where ‘LaunchInstance’ errors caused GUIDs...

Improvements

  • Added a loading state for the Export CSV button to prevent multiple clicks
  • Improved value filling in GraphQL queries
  • Added the ability to re-scan cloned PCI scans on previously scanned targets to apply exceptions

Resolved issues

  • Fixed an issue where ‘LaunchInstance’ errors caused GUIDs to be stored instead of AWS-generated instance IDs in the database
  • Fixed an issue that caused the Mend vulnerabilities to be reported with incorrect severity
  • Replaced a formatted string in a SQL statement with a prepared statement using SqlCommand and SqlParameter to prevent potential SQL injection
  • Fixed the issue which was causing exports from Invicti Standard to Acunetix 360 to fail
  • The issue preventing the use of the Chromium Extension in Scanner and Verifier Agent has been resolved

v25.2.0 - 13 Feb 2025

This release includes new features, improvements, and resolved issues.

New features

  • Added single-tab crawling for websites that do not allow multiple-tab browsing
  • Upgraded the Shortcut integration API endpoint to v3

    Improvements

    • Added Customizations folder to the Agent Output folder
    • Removed Feature flag and implementation for the ‘HashiCorp-Vault-TLS-certificate-authentication-support-enabled’ flag
    • Improved the performance of searching by profileName on the Scan-Index page

    Resolved issues

    • Updated APIHub npm package to the latest version
    • Resolved scan authentication issues for multiple pages
    • Resolved issues related to screenshots and login processes
    • Fixed Dashboard Widget Active Issue is empty when selecting a specific target
    • Fixed the problem of reverting vulnerability in issue update endpoint to default
    • Fixed removes preferred agent group in update-scheduled API endpoint
    • Fixed an auto-update issue for Verifier Agent
    • Added control for URLs that should not be included in the scope
    • Upgraded the Shortcut (Clubhouse) integration
    • Resolved an issue caused by the Chromium version update by updating Chromium dependencies for the Linux operating system. Refer to the updated scripts to install the required dependencies for Headless Chrome. (Read more)

    v25.1.2-HF - 30 Jan 2025

    Improvements API specifications from sub-organizations in Mulesoft are now synchronized into API Inventory Resolved issues Improved performance of the All Issues page

    Improvements

    • API specifications from sub-organizations in Mulesoft are now synchronized into API Inventory

    Resolved issues

    • Improved performance of the All Issues page

    v25.1.1 - 28 Jan 2025

    New features Improved support for handling gRPC multiple proto imports in the Agent and in the engine New security checks Added detection of cookieconsent2 as a technology in the Vulnerability Database (VDB) Improvements Added pull commands for Docker and OpenShift to the New Agent page...

    New features

    • Improved support for handling gRPC multiple proto imports in the Agent and in the engine

    New security checks

    • Added detection of cookieconsent2 as a technology in the Vulnerability Database (VDB)

    Improvements

    • Added pull commands for Docker and OpenShift to the New Agent page

    • Added the SourceType field to the New Issues API endpoint

    • Enhanced agent mode to better distinguish between verifier and scanner agents
    • Added the ability to replace placeholders in the browser for Authorization Headers
    • Improved report template of JWT Signature is not verified vulnerability

    Resolved issues

    • Resolved an issue where file upload events using LSR/BLR in React forms failed to propagate to body-level listeners

    v25.1.0 - 14 Jan 2025

    New Features Clicking on the scheduled scan icon in the scan summary screen now redirects you to the Recent Scans page with a filtered view, improving navigation and access to relevant scan details Implemented an integration that automatically retrieves the latest Container security results from...

    New Features

    • Clicking on the scheduled scan icon in the scan summary screen now redirects you to the Recent Scans page with a filtered view, improving navigation and access to relevant scan details

    • Implemented an integration that automatically retrieves the latest Container security results from Mend when a DAST scan is initiated

    Improvements

    • Fixed an issue on the 2FA page where the code text field was not automatically focused upon page load
    • Introduces a configurable retention period for HTTP log files, allowing Root users to specify the number of days before log
    • Implemented a restriction to prevent the modification of the Vulnerability Signature Type
    • Enhanced the UI to highlight the menu when API Hub specifications are linked to a scan profile, making it easier for users to identify associated profiles
    • Updated Chromium from version 121 to version 131 for enhanced performance and compatibility
    • Enhanced detection accuracy for Weak Ciphers Enabled by analyzing false positives
    • Administrators can now assign Agent Groups to Teams for greater control over agents and the teams that can use them. Learn more.

    Resolved issues

    • Corrected OTP configuration attachment to personas, ensuring separate secrets and preventing shared changes
    • Resolved issue where the internal agent service stopped after being disabled in the UI. The service now remains active even when the agent is disabled from the web application
    • Updated the SharedAssemblyInfo file to reflect the correct copyright details
    • Fixed an issue where a disabled scan was inadvertently running, leading to an outage
    • Fixed a bug where users were unable to update the website name longer than 40 characters
    • Fixed an issue where the Invicti REST API did not return errors when importing an invalid definition file
    • Resolved the “Internal Server Error” encountered on the Invicti scans/report API endpoint after enabling the “Prevent any sensitive information showing within the product” setting
    • Fixed an issue where the issue state was inadvertently removed when a user, without permission to update the state, added a note to the issue
    • Fixed an issue where the “Notification Settings” hyperlink in notification emails was redirecting incorrectly
    • Resolved the issue where the Agent Verifier was encountering errors when using certificates in a Linux environment
    • Fixed an issue where duplicate tickets were being created in ServiceNow due to integration error
    • Fixed an issue where the severity trend chart was not rendering correctly on the individual website dashboard
    • Node.js v6 has reached its End of Life (EOL), and support for this version has been removed from Azure Pipelines
    • Resolved a coverage issue where the login page reappeared during scans

    v24.12.1 HF (MEND) - 07 Jan 2025

    This update did not include changes to the internal agents. Improvements Added new ‘/issues’ endpoint to return all issues with sorting and filtering options Fixes Fixed an issue that prevents Scheduled Scans to be updated and Scan results to be imported

    This update did not include changes to the internal agents.

    Improvements

    • Added new ‘/issues’ endpoint to return all issues with sorting and filtering options

    Fixes

    • Fixed an issue that prevents Scheduled Scans to be updated and Scan results to be imported

    v24.12.1 - 12 Dec 2024

    This update includes changes to the internal agents. The internal scan agent’s current version is 24.12.1. The internal authentication verifier agent’s current version is 24.12.1. New feature A connector for Mend SCA now available Improvements Added new paths to forced browsing Updated the vulnerability template...

    This update includes changes to the internal agents. The internal scan agent’s current version is 24.12.1. The internal authentication verifier agent’s current version is 24.12.1.

    New feature

    • A connector for Mend SCA now available

    Improvements

    • Added new paths to forced browsing
    • Updated the vulnerability template for the Internal Server Error vulnerability
    • Improved Insecure HTTP Usage detection
    • Improved retry operations to prevent JSONSerializer errors following archiving failures
    • Removed support email addresses from the product
    • Removed cancelled and failed scans after 90 days

    Fixes

    • Fixed an issue in Mulesoft integration where child organizations were not syncing properly
    • Fixed an issue with ServiceNow integrations causing authentication errors by suspending the affected integrations
    • Fixed an issue where JSON responses were incorrectly formatted
    • Fixed an issue where scans failed with a “Failed – Agent is unavailable” error at the end of the scan
    • Fixed an issue where Invicti detected vulnerabilities in multiple parameters of the same URL but didn’t report them due to the vulnerability family mechanism
    1 2 13