Skip to content

2026.08


Features & Enhancements

WebApp Pentest

  • NodeZero's new WebApp pentest crawls, discovers, and tests production, staging, and private web applications for vulnerabilities and weaknesses. It helps security teams validate exploitable risk through route discovery, authenticated testing, attack execution, and proof-based findings.

  • External pentests' Attack Configuration now exposes a set of Web Application Testing options. You can enable these options to initially assess applications' external-facing vulnerabilities, before considering an in-depth WebApp test.


Azure Cloud Pentest

  • The new Azure Cloud pentest is an assumed-breach, black-box assessment. Combining Azure API enumeration with an Internal pentest, this single test assesses both your cloud resources and the workloads running on Azure VMs (virtual machines).

Activity & Artifacts

  • A new Activity tab extends the Action Log from Real-Time View to post-operation results. Both views now include an Artifacts tab, to help security teams and tooling further distinguish NodeZero activity from malicious attacks.

  • Activity events in OCSF (Open Cybersecurity Schema Framework) format can be downloaded as CSV (comma-separated values) files.


Australian Data Residency

  • New AU-specific infrastructure provides a dedicated Australia-based Portal, keeping platform traffic and pentest data within the Australian region. This enables compliance with Australian data-sovereignty requirements, while maintaining full feature parity with NodeZero's US and EU regions.

Risk-Based Exposure Management (RBEM)

  • Added weakness detection for expired SSL/TLS certificates (H3-2021-0025) and public self-signed certificates (H3-2021-0026).

External Asset Discovery

  • Added tiered port scanning to improve host-discovery efficiency.
  • Enabled authorized subdomain-takeover testing for Amazon Simple Storage Service (Amazon S3) buckets.
  • Added more scope information to the External domains table.

Identity & Active Directory

  • Added an Identity Details page with dedicated user and identity information.
  • Expanded Windows credential collection to extract Kerberos tickets from memory.
  • Added just-in-time (JIT) Ticket-Granting Ticket (TGT) refreshes to improve authentication reliability during longer Active Directory (AD) pentests.
  • Enhanced the Identity table with attack-path counts, linked identity names, and navigation counts aligned with the Credentials tab.

Attack Paths & Findings

  • Added subnet details and pagination controls to the Impacts > Hosts tab.
  • Improved data-pilfering behavior to avoid known honeypot patterns.

Rapid Response

  • Added a Sync Ticket button on Rapid Response asset detail views where ticketing integrations are configured and an active ticket exists for that asset.

  • Added Rapid Response API documentation, facilitating discovery and integration of Rapid Response data into SIEMa (Security Information and Event Management systems), ticketing systems, dashboards, and (via the Horizon3 MCP Server) agents.


Endpoint Detection & Response (EDR)

  • Added a distinct empty-state view on the EDR tab when no EDR coverage is detected on target endpoints.

Tripwires

  • Updated Active Directory (AD) Tripwires configuration scripts to enhance deployment across multi-domain forests.

  • Improved AD Tripwires event collection in environments with significant replication delays between domain controllers.

  • Tripwire Jobs no longer require the Remote Access Tool (RAT) to drop AWS Credential File and MySQL Dump File Tripwires. (The RAT is now off by default when you configure these Jobs.) Omitting the RAT mitigates Endpoint Detection and Response (EDR) noise. Windows Suspicious Process Monitor (WSPM) Tripwire Jobs still require the RAT, which defaults to on when configuring these Jobs (and in pentests' Post-Exploitation configuration).


Core Platform

  • Strengthened SSO (Single Sign-On) login by verifying users on every authentication request.
  • Added IP ranges to Scope inputs.
  • Standardized report timestamps in UTC (Coordinated Universal Time) format.
  • Redesigned the pentest picker (card and list views) with expanded categories. These will scale better as we add new assessments, and should make all options more intuitive to find.
  • Generalized the Run Pentest button's label to Run Assessment, and updated the logic that determines when the action is available.

New Attack Content

  • MetabaseCVE-2026-72898
    An unauthenticated SQL injection vulnerability in the password-reset endpoint enables remote attackers to gain administrator access to an affected Metabase instance.

  • GitLab Community Edition (CE) and Enterprise Edition (EE)CVE-2026-19478
    A code injection vulnerability involving a GraphQL directive enables unauthenticated remote attackers, under certain conditions, to modify or delete public projects and user data on affected self-managed GitLab instances.

  • Ivanti Endpoint Manager (EPM)CVE-2024-50330
    An SQL injection vulnerability enables unauthenticated remote attackers to execute code on affected Endpoint Manager systems.


Platform Performance & Stability

  • Optimized the Vulnerability Management Hub (VMH) to improve page-load performance for organizations with large volumes of findings.
  • Improved External Asset Discovery inventory queries to reduce timeouts when loading IP address data.
  • Improved report-generation reliability by reducing HTTP timeout failures during complex exports.
  • Refined data loading and state transitions across Rapid Response Details pages.

Bug Fixes

  • Fixed Runners getting stuck on an outdated (November 2025) version when pulling from the GitHub mirror or CLI. Runners now install and upgrade to current builds, gaining full Runner Queue support.
  • Fixed oversized public subnets being dropped from External pentest scopes.
  • Fixed unlabeled domains appearing in External network inventory.
  • Fixed External Asset Discovery operations continuing beyond the seven-day maximum runtime.
  • Fixed a regression that caused scheduled External pentests to fail.
  • Fixed deleted IP addresses continuing to appear with their associated domains.
  • Fixed credential collection failing against domain controllers configured with RestrictRemoteClients=2.
  • Fixed Rapid Response result count cards not linking to the corresponding results.
  • Fixed Scope input suggestion text.
  • Fixed Runner details page's table height.

Federal

Users of NodeZero Federal might experience a 1–2 week delay in the availability of some features, Attack Content, or bug fixes.