<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
    <atom:link href="https://docs.invicti.com/ie-is/release-notes/Invicti-Standard/rss.xml" rel="self" type="application/rss+xml" />
        <title>Invicti Release Notes – Invicti Standard</title>
        <link>https://docs.invicti.com/ie-is/invicti-standard</link>
        <description>Discover what's new in the latest Invicti Standard release.</description>
        <lastBuildDate>Wed, 11 Mar 2026 17:44:59 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <language>en</language>
        <copyright>Copyright © 2026 Invicti</copyright>
        <item>
            <title><![CDATA[Release v26.3.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2630</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#26.3.0</guid>
            <pubDate>Wed, 11 Mar 2026 17:44:59 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 10 March 2026</em></p>
<h4>New features</h4>
<ul>
<li>Added OWASP Top 10 2025 classification and reporting support</li>
<li>Implemented OWASP Top 10 2025 classification in Report Policies</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Implemented VDB update for auth verifier agent</li>
<li>Improved Web Cache Deception detection accuracy and refined the response validation logic to handle authentication edge cases</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Improved the generation of preference files for client certificate usage in the browser</li>
<li>Fixed an issue that occurred when exporting scan data from Invicti Standard to Invicti Enterprise while OAuth was enabled</li>
<li>Fixed an issue where some nodes were missing in the Knowledge Base under specific scan conditions</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v26.2.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2621</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#26.2.1</guid>
            <pubDate>Wed, 11 Mar 2026 17:44:59 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 24 February 2026</em></p>
<h4>Improvements</h4>
<ul>
<li>&quot;Use HTTP Client&quot; is now a scan policy setting and no longer requires account-level activation</li>
<li>Updated Requester details in the Form Authentication API documentation</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue preventing scans with OAuth2 settings from starting</li>
<li>Fixed malformed masked URL usage in a scan</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v26.2.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2620</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#26.2.0</guid>
            <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added SEM integration support with Client Certificate authentication</li>
<li>Added support to use secrets in the OAuth2 tab</li>
<li>Added .har file download on Authentication Verification</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Updated Node to v20.20.0 for Invicti.Common.Browser.Driver</li>
<li>Upgraded Shark.Java package from version 20 to version 21</li>
<li>Improved login fail notification</li>
<li>Incremental Scan now correctly detects new and modified pages and performs no action when there are no changes</li>
<li>Improved DOM XSS simulation</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue that impacted “Detailed Scan Report” generation</li>
<li>Fixed an issue on creating Knowledge Base items.</li>
<li>Updated information panel of Secrets section</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v26.1.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2610</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#26.1.0</guid>
            <pubDate>Tue, 13 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New feature</h4>
<ul>
<li>Added Browser Network and Console logs to the verification log area</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed TempPath-dependent errors when the path contains whitespace</li>
<li>Fixed OAuth2 3-legged Authorization code issue</li>
<li>Fixed sitemap issue causing URLs with /#/ to be missing</li>
<li>Fixed retest scan launch failure</li>
<li>An issue after the paused and resumed has been fixed</li>
<li>Fixed scan data archiving error</li>
</ul>
<hr>
<h2>2025</h2>
<p>This section summarizes all releases, features, improvements, and fixes for 2025 as they&#39;re added.</p>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.12.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v25120</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.12.0</guid>
            <pubDate>Wed, 10 Dec 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Relocated the <code>InterceptDocumentOnly</code> setting from Advanced settings to Scan policy for improved accessibility</li>
<li>Upgraded the underlying engine to <code>Chromium 137.0.7151.68</code>, delivering critical security patches, improved stability, and better performance</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue where excluded cookies were incorrectly appearing in reports<br>‍</li>
</ul>
<hr>
<h3>Release v25.11.2-Hot fix</h3>
<p><em>Release date: 5 December 2025</em></p>
<h4>New security checks</h4>
<ul>
<li>Implemented security checks for Next.js/React Server Components RCE:<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182">CVE-2025-55182</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478">CVE-2025-66478</a></li>
</ul>
</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.11.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v25110</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.11.0</guid>
            <pubDate>Tue, 11 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Improved the &quot;SameSite Cookie Not Implemented&quot; security check</li>
<li>Improved the &quot;JWT Signature isn&#39;t Verified&quot; security check</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed login failures due to issues with loading authentication profiles</li>
<li>Fixed an issue where Linux/cloud agents couldn&#39;t parse secrets pre-request query parameters</li>
<li>Improved the application&#39;s launch time<br>‍</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.10.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v25100</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.10.0</guid>
            <pubDate>Tue, 14 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New feature</h4>
<ul>
<li>Added WebLogic support for JAVA Shark sensor</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Corrected a typo in the Ivanti RCE CVE-2024-21887 report template</li>
<li>Improved detection of CSP directives</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.8.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2580</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.8.0</guid>
            <pubDate>Wed, 13 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Security checks</h4>
<p>Added detection of Pega Infinity as a technology in the Vulnerability Database (VDB)</p>
<h4>Improvements</h4>
<ul>
<li>Defined the Hawk check delay in the scanning policy</li>
<li>Added a Maximum Cookie Count setting to manage cookie numbers when necessary</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Implemented fix to ensure that manual scanning continues without interruption when using a proxy</li>
<li>Implemented If-Modified-Since header to minimize false positives during vulnerability scans</li>
<li>Fixed logging in Post-Request scripts</li>
<li>Implemented fix to ensure Post-Request script is triggered for all requests in the browser context<br>‍</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.7.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2570</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.7.0</guid>
            <pubDate>Tue, 08 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Security checks</h4>
<ul>
<li>Added a new CVE check for <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19326">CVE-2019-19326</a></li>
<li>Added a new XSS attack for <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11831">CVE-2024-11831</a></li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved XSS detection to reduce noise</li>
<li>Increased the timeout duration for IAST responses to prevent premature failures</li>
<li>Implemented an enhancement to capture the token information present in the response during the OAuth2 Implicit Flow</li>
<li>Implemented an enhancement to enable more effective cookie management when HTTP/2 is enabled</li>
<li>Updated dependencies with known vulnerabilities</li>
<li>Improved prototype-pollution detection to reduce noise</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Enhanced support for using multiple secrets simultaneously within a single custom header</li>
<li>Resolved an issue where duplicate <strong>X-Content-Type-Options</strong> headers triggered false missing header reports</li>
<li>A fix was implemented to prevent the application from crashing due to faulty custom scripts</li>
<li>Addressed an issue encountered during report policy migration</li>
<li>Corrected the MOVEit SQLi check to avoid reporting an incorrect version</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.6.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2560</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.6.0</guid>
            <pubDate>Wed, 18 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Improved Stack Trace Disclosure (Java) detection pattern</li>
<li>Added support for configuring the temp file via appsettings.json or an environment variable</li>
<li>Updated Microsoft.OpenApi to version 2.0 preview to support OpenAPI 3.1.0 for improved API scanning</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a file access conflict issue during VDB update</li>
<li>Resolved an issue where multiple versions of Next.js were not properly displayed in the Technologies dashboard and Scan Reports</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.5.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2551</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.5.1</guid>
            <pubDate>Tue, 27 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added Post-request script feature <a href="/post-request-scripts">Read more</a></li>
</ul>
<h4>New security check</h4>
<ul>
<li>Added a new XSS Security check</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue with verifying the existence of links in the link pool</li>
<li>Improved incremental scanning</li>
<li>Implemented logic to create the UserDocumentsDirectoryPath when it doesn&#39;t already exist</li>
<li>Added support for defining headers and HTTP method during CSV importImproved usage and reliability of SmartCard authentication</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.5.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2550</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.5.0</guid>
            <pubDate>Tue, 06 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Added the ability to add Parent Relations for Azure products, enabling easier hierarchical management</li>
<li>Implemented agent for secure storage and retrieval of passwords for Pre-Request scripts</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed naming issues of WordPress plugin Contact Form 7</li>
<li>Fixed the issue of LoginRequiredUrl and Pre-Request script requests causing bottlenecks in HTTP requests</li>
<li>Fixed an issue that unnecessarily included the code parameter in OAuth2 authorization requests</li>
<li>The scanning engine now correctly processes merged request headers received from browser</li>
<li>Improved usage and reliability of SmartCard authentication</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.4.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2540</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.4.0</guid>
            <pubDate>Tue, 08 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Updated remediation details for outdated AngularJS versions</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed restrictions for JIRA integration</li>
<li>Updated Chromium and Node.js versions, resolving Chromium-related issues, including the unexpected increase in Chromium count</li>
<li>Exclude URL rules now function correctly even when the excluded URL is the target</li>
<li>Fixed an issue with retrieving OAuth2 token data from JSON responses</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.2.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2521</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.2.1</guid>
            <pubDate>Tue, 25 Feb 2025 13:38:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Improved importing GraphQL queries</li>
<li>Added the option to select US2 in the Enterprise Integration section, enabling IS connectivity for US2 instance customers</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved issue preventing the use of the Chromium Extension in Scanner and Verifier Agent</li>
<li>Fixed the issue which was causing exports from Invicti Standard to Acunetix 360 to fail</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.3.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2530</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.3.0</guid>
            <pubDate>Tue, 25 Feb 2025 10:38:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Enhanced technology version identification from URI</li>
<li>Improved reporting of multiple technology detections on the same file</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Implemented a fallback mechanism to mitigate Chrome-related issues</li>
<li>Updated OpenSSL from version 3.3.1 to 3.3.2</li>
<li>Implemented a fix for an import issue caused by gRPC backward compatibility failure</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.2.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2520</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.2.0</guid>
            <pubDate>Thu, 13 Feb 2025 13:32:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added single-tab crawling for websites that do not allow multiple-tab browsing</li>
<li>Upgraded the Shortcut integration API endpoint to v3</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved payload for Log4j detection</li>
<li>Added a feature to automatically override some headers in MFA cases</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved scan authentication issues for multiple pages</li>
<li>Resolved issues related to screenshots and login processes</li>
<li>Fixed security check for popper.js detection</li>
<li>Added control for URLs that should not be included in the scope</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.1.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2511</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.1.1</guid>
            <pubDate>Tue, 28 Jan 2025 11:22:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New security checks</h4>
<ul>
<li>Added detection of cookieconsent2 as a technology in the Vulnerability Database (VDB)</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Added the ability to replace placeholders in the browser for Authorization Headers</li>
<li>Improved report template of JWT Signature is not verified vulnerability</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed tar file import error caused by invalid HAR file syntax that could disclose the local path of the On-Demand web app machine in the error message</li>
<li>Fixed duplicated links issue while importing proto files</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v25.1.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2510</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#25.1.0</guid>
            <pubDate>Tue, 14 Jan 2025 13:56:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Redirected support email addresses to the support.invicti.com link</li>
<li>Updated Chromium from version 121 to version 131 for enhanced performance and compatibility</li>
<li>Enhanced detection accuracy for Weak Ciphers Enabled by analyzing false positives</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved the &quot;Internal Server Error&quot; encountered on the Invicti scans/report API endpoint after enabling the &quot;Prevent any sensitive information showing within the product&quot; setting</li>
<li>Resolved the issue where the Agent Verifier was encountering errors when using certificates in a Linux environment</li>
<li>Resolved a coverage issue where the login page reappeared during scans</li>
</ul>
<hr>
<h2>2024</h2>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.12.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v24121</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.12.1</guid>
            <pubDate>Thu, 12 Dec 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Added new paths to forced browsing</li>
<li>Updated the vulnerability template for the Internal Server Error vulnerability</li>
<li>Improved Insecure HTTP Usage detection</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.12.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v24120</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.12.0</guid>
            <pubDate>Tue, 03 Dec 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added detection of Google Tag Manager as a technology in the Vulnerability Database (VDB)</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Invicti Standard Agent upgraded to .NET 8 for improved performance and compatibility</li>
<li>Improved analysis and remediation capabilities for (Possible) Server-Side Template Injection vulnerabilities</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a missing proxy implementation for ICBD and Puppeteer</li>
<li>Fixed an issue where Retest-type scans did not identify the same vulnerabilities detected during full scans</li>
<li>Fixed high CPU usage in some agents caused by Chromium</li>
<li>Fixed an issue where the Misconfigured Access-Control-Allow-Origin Header vulnerability was not detected</li>
<li>Improved detection of the (Possible) Password Transmitted over Query String vulnerability.</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.11.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v24110</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.11.0</guid>
            <pubDate>Tue, 12 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Multiple .proto files can now be used for scanning gRPC API Web Services</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue where uploading a .proto file caused a &quot;No links found in the file&quot; error</li>
<li>Fixed missing request/response details for some out-of-band vulnerabilities</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.10.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v24101</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.10.1</guid>
            <pubDate>Wed, 30 Oct 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added detection for multiple JavaScript libraries</li>
<li>Added detection for Masa CMS <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47002">CVE-2022-47002</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42183">CVE-2021-42183</a></li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a bug that was disabling the skip scan phase option</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.10.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v24100</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.10.0</guid>
            <pubDate>Tue, 08 Oct 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Updated detection for ActiveMQ - Remote Code Execution <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46604">CVE-2023-46604</a> and TorchServe Management API SSRF <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43654">CVE-2023-43654</a></li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Added &#39;save as new&#39; and &#39;overwrite&#39; options when importing scans</li>
<li>Reporting improvements for the “Unknown Option Used In Referrer-Policy” vulnerability</li>
<li>Added the ability to export/import scan profiles and scan policies between different instances of Invicti Standard</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Various fixes for the verifiers</li>
<li>Out-of-date version for Boolean Based MongoDB Injection is now reported correctly</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.9.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2491</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.9.1</guid>
            <pubDate>Tue, 24 Sep 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added XWiki version disclosure vulnerability and attack patterns.</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed the false negative issue related to <a href="https://polyfill.io/">Polyfill.io</a>.</li>
<li>Fixed an issue related to creating a custom script for a web application using the OIDC method with a login pop-up.</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.9.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2490</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.9.0</guid>
            <pubDate>Tue, 10 Sep 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Adjusted the severity of SSLv3 and TLS 1.0 vulnerabilities to reflect their security risks</li>
<li>Added support for CSP frame-ancestors</li>
<li>Added detection for <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6297">CVE-2024-6297</a>, affecting several WordPress plugins</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Pre-request script now works in DOM as well</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved an issue with a pre-request script that was affecting crawling functionality</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.8.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2481</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.8.1</guid>
            <pubDate>Tue, 27 Aug 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added detection for Jenkins Secret as a Sensitive Data Exposure</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Started to utilize the Microsoft Azure Trusted Signing service for code signing of Invicti Standard</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed chromium-related issues in the agent</li>
<li>Fixed the issue where temp folders could not be deleted and Chromium instances remained open when Puppeteer encountered an error</li>
<li>Fixed the false positive on detection of &quot;Stack Trace Disclosure (Java)&quot;</li>
<li>Fixed an issue related to the Moment.js regex</li>
<li>Fixed the OIDC authentication issue</li>
<li>Fixed the issue where the REST API endpoint returned HTTP 400 instead of HTTP 200 when sending custom values</li>
<li>Fixed the issue preventing proper login to the target URL</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.8.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2480</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.8.0</guid>
            <pubDate>Tue, 13 Aug 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Incorporated the reporting of sensitive information disclosures from Okta</li>
<li>Added a check for Authentication bypass in Fortra&#39;s GoAnywhere MFT <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0204">CVE-2024-0204</a></li>
<li>Added a check for Open SSH server RC <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6387">CVE-2024-6387</a></li>
<li>Added a check for cached pages that contain sensitive data <a href="https://cwe.mitre.org/data/definitions/525.html">CWE-525</a></li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Resolved an issue where scans were failing due to the TLS connection not being established</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved a problem that was causing scans to become stuck</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.7.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2471</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.7.1</guid>
            <pubDate>Thu, 25 Jul 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Disabled the detection of CSRF vulnerabilities from built-in policies</li>
<li>Added custom header support for SSRF registration</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue related to BLR links</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.7.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2470</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.7.0</guid>
            <pubDate>Tue, 09 Jul 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added a new security check to identify supply chain attacks through Polyfill JS</li>
<li>Added a detection for GeoServer SQLi vulnerability <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25157">CVE-2023-25157</a></li>
<li>Added checks for various WordPress plugins</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved Credit Card Disclosure Security Check</li>
<li>Added custom headers for communication between Agents and Invicti Hawk</li>
<li>Set the severity of &#39;Possible XSS&#39; vulnerabilities to &#39;Informational&#39;</li>
<li>Improved various Sensitive Data Exposure security checks</li>
<li>Improved the detection of the Short SSL Key Length vulnerability</li>
<li>Added the capability to check for Sensitive Data in XML responses</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed missing Request Body content in vulnerability details</li>
<li>Fixed an issue with the &#39;IgnoreCertificateErrors&#39; Agent setting for SSL Validation</li>
<li>Fixed a problem in the JWT Engine to resolve a false positive issue</li>
<li>Fixed an issue related to the OTA app scan</li>
<li>Fixed HTTP 413 responses resulting from nonce cookies stacking</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.6.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2460</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.6.0</guid>
            <pubDate>Thu, 13 Jun 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Features</h4>
<ul>
<li>Added functionality for scanning gRPC API Web Services, <a href="https://docs.invicti.com/ie-is/scan-grpc-api-is#scan-grpc-api-web-services">Learn more</a></li>
</ul>
<h4>New Security Checks</h4>
<ul>
<li>Added a new attack pattern for missing Open Redirection</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Added an option to trigger only specified lists of events</li>
<li>Updated all the IAST Sensors: .NET Framework and .NET Core 6.2.0, Java 16.0.0 , Node.js 2.1.3 , PHP 8.0.1</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue with user-agent selection in scan policies that was causing disabled security check vulnerabilities to appear in the dashboards and scan reports</li>
<li>Fixed an issue with user-agent selection in scan policies that was causing disabled security check vulnerabilities to appear in the dashboards and scan reports</li>
<li>Fixed vulnerabilities with the Invicti Scan Agent Docker image</li>
<li>Fixed the disk space utilization issue that was causing the InvictiCommon folder size to increase significantly during scans</li>
<li>Improved the crawling capability to allow for automatic crawling of XHR requests</li>
<li>Fixed an AWS4Signer authentication issue</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.5.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2451</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.5.1</guid>
            <pubDate>Tue, 28 May 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Security Checks</h4>
<ul>
<li>Added detection methods for five more WordPress Templates</li>
<li>Added detection of Fortinet vulnerabilities <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12812">CVE-2020-12812</a> , <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5591">CVE-2019-5591</a> , <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13379">CVE-2018-13379</a></li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Updated CWE IDs for several vulnerabilities</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue in the detection of the &#39;Improper XML parsing leads to Billion Laughs Attack&#39; vulnerability</li>
<li>Resolved an issue with the Business Logic Recorder</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.5.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2450</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.5.0</guid>
            <pubDate>Tue, 07 May 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New Feature</h4>
<ul>
<li>Enabled Korean language support</li>
</ul>
<h4>New Security Checks</h4>
<ul>
<li>Added detection method for Angular</li>
<li>Added a new security check for Oracle EBS RCE</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a scan authentication issue and a crawling issue with Cloud Agents</li>
<li>Fixed the HTTP 401 forbidden response form authentication error</li>
<li>Fixed an issue with the detection method for wp-admin vulnerabilities</li>
<li>Fixed an error that was occurring when generating knowledge base reports</li>
<li>Updated the extraction algorithm for downloaded scan files from Invicti Enterprise</li>
<li>Fixed a scan issue that was producing 413 error responses</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.4.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2440</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.4.0</guid>
            <pubDate>Wed, 17 Apr 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Improved AWS Secret Key ID detection security checks</li>
<li>Improved Google Cloud API Key detection security checks</li>
<li>Updated remediation information for Angular JS related vulnerabilities</li>
<li>Improved Boolean-Based MongoDB Injection detection method</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a validation error when validating Shark settings</li>
<li>Fixed an issue with duplicate custom user agents that was preventing scanning</li>
<li>Fixed an issue where authentication would fail when started with an Authentication profile</li>
<li>Fixed an issue that caused proxy usage for Chromium even when no proxy was selected from the scan policy settings</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.3.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2431</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.3.1</guid>
            <pubDate>Thu, 28 Mar 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Provided a new encryption method of API Token for Agent/Verifier Agent</li>
<li>Added a pre-request script to generate AWS Signature token</li>
</ul>
<h4>New security checks</h4>
<ul>
<li>Added a new security check for TLS/SSL certificate key size too small issue</li>
<li>Improved WP Config detection over backup files</li>
<li>Added a new security check for <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46805">CVE-2023-46805</a> / <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21887">CVE-2024-21887</a></li>
<li>Added detection for exposed WordPress configuration files</li>
<li>Added a new Security Check that allows to report two vulnerabilities: TorchServe Management API Publicly Exposed and TorchServe - Management API SSRF</li>
<li>Command Injection in VMware Aria Operations for Networks can now be detected</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Implemented enhancements: Highlighting and Verification of Response Status Codes</li>
<li>Disabled the BREACH Security Engine</li>
<li>Report template of Possible XSS is updated to cover mime sniffing</li>
<li>Increased the default Severity level of Version Disclosure (Varnish) from &#39;Information&#39; to &#39;Low&#39;</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed the issue where the customer couldn&#39;t scan their target with the additional website properly</li>
<li>Fixed an issue that was causing a memory issue in Javascript Parser</li>
<li>Fixed the inability of the custom script editor to load the form authentication fields</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.3.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2430</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.3.0</guid>
            <pubDate>Tue, 12 Mar 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added the ability to force authentication verifier agents to use incognito mode by default on Chromium browsers</li>
</ul>
<h4>New security checks</h4>
<ul>
<li>Added detection for ActiveMQ RCE to the OOB RCE Attack Pattern <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46604">CVE-2023-46604</a></li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Added a Cookie Source field to the Knowledge Base Cookies screen</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.2.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2420</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.2.0</guid>
            <pubDate>Tue, 20 Feb 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added a new BLR log providing details on BLR execution</li>
</ul>
<h4>New security checks</h4>
<ul>
<li>Implemented a detection and reporting mechanism for the Backup Migration WordPress plugin <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6553">CVE-2023-6553</a></li>
<li>Added detection for TinyMCE</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Updated the &quot;Insecure Transportation Security Protocol Supported (TLS 1.0)&quot; vulnerability to High Severity</li>
<li>Updated the WSDL serialization mechanism</li>
<li>Implemented support for scanning sites with location permission pop-ups</li>
<li>Added support for FreshService API V2</li>
<li>Removed obsolete X-Frame-Options Header security checks</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a bug in the Request/Response tab of Version Disclosure vulnerabilities</li>
<li>Removed the target URL from the scope control list</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.1.1]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2411</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.1.1</guid>
            <pubDate>Tue, 30 Jan 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New security checks</h4>
<ul>
<li>Added a check for dotCMS</li>
<li>Added a check for the Ultimate Member WordPress plugin</li>
<li>Added a new mXSS pattern</li>
<li>Added new signatures to detect JWKs</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved the recommendations for the Weak Ciphers Enabled vulnerability</li>
<li>Improved detection of swagger.json vulnerabilities</li>
<li>Added support for AWS WAFv2 rules</li>
<li>Improved more of our error and warning messages so they are more user friendly</li>
<li>Added Sentry implementation into the Agent repository</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a proxy issue that was impacting the detection of weak ciphers</li>
<li>Fixed a problem with importing WDSL files</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release v24.1.0]]></title>
            <link>https://docs.invicti.com/ie-is/invicti-standard#release-v2410</link>
            <guid isPermaLink="false">https://docs.invicti.com/ie-is/invicti-standard#24.1.0</guid>
            <pubDate>Tue, 09 Jan 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[Discover what's new in the latest Invicti Standard release.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>In the scan settings section, we&#39;ve added a checkbox (under Authentication &gt; Form) to collect all logs about the authentication progress</li>
<li>Enhanced reporting of DOM XSS vulnerabilities</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Updated the Shark Dotnet Sensor to .NET Core 6</li>
<li>Improved site-logout detection</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved a problem with missing information in the report policy database</li>
<li>Fixed an issue with the import of scan data from Invicti Enterprise to Invicti Standard</li>
<li>Fixed a bug in the importing of links</li>
<li>Fixed some vulnerabilities on our Invicti Docker Image by updating the packages</li>
<li>Fixed reporting of some false/positive passive out-of-date vulnerabilities</li>
</ul>
<hr>
]]></content:encoded>
        </item>
    </channel>
</rss>