<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 💾 IT Security Tools]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=5&q=]]></link> 
<description><![CDATA[Cybersecurity Nachrichten ist Ihr zuverlässiger Begleiter in der Welt der IT-Sicherheit. Hier finden Sie aktuelle und relevante Informationen zu Cyberangriffen, Sicherheitslösungen, Gesetzen und Trends. Abonnieren Sie unseren RSS-Feed oder unseren Newsletter, um immer auf dem Laufenden zu bleiben.]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=5&amp;q=_" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[javascript: v0.4.12]]></title> 
<description><![CDATA[0.4.12 (2026-06-04)
Features

#318: add context param to JudgmentRequest for extra judge evaluation input (#554) (1947824)
add GOAT strategy with dynamic technique selection for RedTeamAgent (#346) (2896c97)
ci/#364: add pr-auto-approve.yml as passive observer (PR #1 of 4) (#485) (4d84597)
red-team: zero-friction report dashboard &mdash; auto-save + scenario redteam-report CLI (2896c97)
test/#516: bind PR #511 voice scenarios via vitest-cucumber (retrofit PR-A) (#517) (c247f42)
typescript-sdk/#372: voice agent contract surface (types only, PR1 of N) (#511) (9216d35)
typescript-sdk: voice agent testing &mdash; consolidated clean stack (#561) (5847c4b)

Bug Fixes

deps: bump fast-uri to &gt;=3.1.2 for high severity CVEs (#450) (474ab65)
deps: bump fast-uri to &gt;=3.1.2 to resolve high severity vulnerabilities (474ab65)
deps: bump liquidjs override to &gt;=10.26.0 to close RCE/ReDoS alerts (#591) (daaf9cc)
deps: bump protobufjs to &gt;=7.5.6/&gt;=8.0.2 for high severity CVEs (#463) (f008161)
deps: bump protobufjs to &gt;=8.0.2 for 4 high severity CVEs (#462) (e2c0499)
deps: override hono to &gt;=4.12.18 for JWT NumericDate validation CVE (#477) (d81ff1a)
deps: override langsmith to &gt;=0.6.0 for CVE fix (#471) (4e5237e)
deps: override langsmith to &gt;=0.6.0 for prompt deserialization CVEs (4e5237e)
deps: override minimatch to &gt;=9.0.6 (CVE-2026-26996) (#395) (ceb0b59)
deps: override qs to &gt;=6.14.2 for arrayLimit bypass DoS CVE (#482) (51a2b6d)
deps: resolve 4 high-severity Dependabot security alerts (#393) (97f257d)
examples: stabilize custom LLM judge criteria matching (#396) (f4b536c)
examples: use positional index matching in custom judge examples (f4b536c)
judge: harden forceVerdict so discovery tools cannot leak (JS + Python) (#377) (0e2859f)
red-team: annotate H_attacker when post-hoc injection fires (#326, #334) (2896c97)
security: bump liquidjs override to fix memoryLimit bypass, memory amplification, and DoS CVEs (25ba99d)
security: bump liquidjs to fix 4 additional high-severity CVEs (#412) (25ba99d)
security: delete orphaned vitest lockfile recreated during rebase (ea8a19c)
security: delete orphaned vitest lockfile to fix 8 Dependabot alerts (#426) (ea8a19c)
security: patch @modelcontextprotocol/sdk ReDoS, DNS rebinding, and data leak (#410) (b993066)
security: patch @modelcontextprotocol/sdk ReDoS, DNS rebinding, and data leak CVEs (b993066)
security: patch critical CVEs in protobufjs and handlebars (#390) (de89d50)
security: patch critical vulnerabilities in protobufjs and handlebars (de89d50)
security: patch CVE-2026-27903 in minimatch (#398) (b61cc60)
security: patch flatted prototype pollution via parse() (#421) (3a20e6c)
security: patch langchain serialization injection vulnerability (#420) (89dd094)
security: patch path-to-regexp DoS in openai-realtime-demo (c6e55b0)
security: patch path-to-regexp DoS in openai-realtime-demo (CVE-2026-4926) (#428) (c6e55b0)
security: patch path-to-regexp DoS via sequential optional groups (#416) (752539a)
security: patch rollup arbitrary file write via path traversal (#399) (55a0259)
security: patch rollup path traversal CVE (&gt;= 4.0.0, &lt; 4.59.0) (55a0259)
security: patch trim-newlines uncontrolled resource consumption (#415) (1c507c3)
security: patch vite server.fs.deny bypass and WebSocket file read CVEs (#419) (7bb7af9)
security: upgrade picomatch, @hono/node-server, and glob to fix CVEs (#394) (4395e52)

Miscellaneous

deps: bump @ungap/structured-clone past 1.3.1 (CWE-502) (#544) (f716e46)
deps: bump pnpm/action-setup from 2.4.1 to 5.0.0 (#300) (053cc3a)
deps: remove unused nanoid-cli devDep from vitest examples (#422) (d4a40a5)
main-side cleanup &mdash; docs + spec + python/TS parity (#586) (371f94c)
tests: remove flaky 10-turn travel-planning example test (#423) (bbe86de)
tests: remove flaky live-LLM travel-agent example test (ac911ff)
tests: remove flaky travel-agent example test (#425) (ac911ff)
tests: remove no-op example tests + audit notes (#424) (947f219)
tests: remove no-op example tests that always pass or are skipped (947f219)

Code Refactoring

test/#522: move instanceof assertions from Given to Then in voice contract surface (#559) (c8cca4e)
 ]]></description>
<link>https://tsecurity.de/de/3573199/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.12/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573199/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.12/</guid>
<pubDate>Thu, 04 Jun 2026 18:02:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Release v1.165.0]]></title> 
<description><![CDATA[1.165.0 - 2026-06-03
### Added

Added --max-match-context-size option to limit the number of characters of source code included as context for each match in the output. This prevents matches in minified files (e.g., minified JavaScript where the entire file is a single line) from producing enormous output Set to 0 for unlimited, which is the default value. (ENGINE-2117)

### Changed

Replaced --x-no-python-schema-validation with a value-taking --x-rule-validation=full|core-only|none flag. The default (full) preserves existing Python rule validation behavior; core-only matches the old flag&#039;s semantics (disables Python rule validation and uses semgrep-core RPC validation only); none skips both pre-validation passes, surfacing rule errors at scan-time. --x-no-python-schema-validation is still accepted as a no-op with a deprecation warning, and will be removed in a future release. (x-rule-validation)
Python: Updated Python grammar (LANG-201)

### Fixed

Added bit shift operations to metavar comparison in addition to already present standard arithmetic operators and logical bit ops. (ENGINE-2448)
Reduce intermittent validation_error results on HTTP secret validators (Facebook, Slack, Stripe, Google, Cloudflare, etc.) by retrying transient network failures, mirroring the retry behavior already present for AWS validators. (SCRT-965)
 ]]></description>
<link>https://tsecurity.de/de/3570955/IT+Sicherheit/Cybersecurity+Tools/Release+v1.165.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570955/IT+Sicherheit/Cybersecurity+Tools/Release+v1.165.0/</guid>
<pubDate>Thu, 04 Jun 2026 00:02:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.33.2]]></title> 
<description><![CDATA[What&#039;s Changed

[Swarming] Add backpressure mechanism to SwarmingService by @IvanBM18 in #5284
[Swarming]Pull and push utask_main tasks to Swarming queues by @IvanBM18 in #5283

Full Changelog: v2.33.1...v2.33.2 ]]></description>
<link>https://tsecurity.de/de/3570695/IT+Sicherheit/Cybersecurity+Tools/v2.33.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570695/IT+Sicherheit/Cybersecurity+Tools/v2.33.2/</guid>
<pubDate>Wed, 03 Jun 2026 21:43:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v5.00c]]></title> 
<description><![CDATA[Version ++5.00c (release)
! AFL++ is now an AGPL 3.0 project !
! Files where the license could be switched were moved to AGPL 3.0+, files
that were under Apache 2.0 with contributations stay on that license.
! Commercial license (donate to a good cause - no money for AFL++) is available

Switched https://github.com/AFLplusplus/cov-analysis for outdated afl-cov
MacOS most current version support for afl-fuzz, afl-cc (incl. LTO) and
frida mode!
Refreshed FreeBSD support by jsaunders-rr, thanks!
Linux persistent mode uses futex now which increases speed and reduces
system call overhead (opt out with AFL_FAST_CHILD_SYNC), thanks to
@martinus for most of the implementation!
afl-fuzz:

-I tool call now receives the new crash as a command line parameter
changed to a better map classifier
frameshift is disabled now if AFL_CUSTOM_MUTATOR_ONLY is set
python module fixes
minor speed, leak and zombie enhancements
stability info was lost on fast resume - fixed
somewhere we removed .state/variable/... now it is back :-)


afl-cc:

Add LLVM 23 support
LTO and PCGUARD: new AFL_LLVM_PATH (also AFL_LLVM_LTO_PATH /
AFL_LLVM_PATH_MODE) Ball-Larus per-function path coverage on top
of edge coverage. Three levels: =1 relaxed (collapse all
guard-only BBs), =2 restricted (collapse only 2-successor
guard-only BBs), =3 strict Ball-Larus. LTO additionally composes
with AFL_LLVM_LTO_CALLER. See
instrumentation/README.llvm.md and instrumentation/README.lto.md.
Fixes in the PCGUARD and LTO instrumentation that could lead to sanitizer
triggers in target binaries
new instrumentation: afl-llvm-bug-pass.so provides five runtime
oracles (SCALAR, BUDGET, SIZEFILL, ALLOCSIZE, SLACK) plus a slice-
filter sub-mode for SCALAR, covering arithmetic-bound and logical-
OOB bugs that ASan misses (CVE-2023-4863 / libwebp-Huffman class).
Note: ALLOCSIZE/DERIVE are disabled automatically under
AFL_USE_ASAN to avoid double-instrumentation; see
docs/env_variables.md.

AFL_LLVM_BUG_SCALAR=1   - max-value-per-arithmetic-site coverage,
plus per-loop iteration count
AFL_LLVM_BUG_SCALAR_SLICE=1 - restrict SCALAR instrumentation to
arithmetic that flows into a memory-
size sink (allocator size, GEP index,
memcpy/memset length). Implies SCALAR.
AFL_LLVM_BUG_BUDGET=1   - check ptr += func() write-extent
contract
AFL_LLVM_BUG_SIZEFILL=1  - check NULL-means-size-only idioms
AFL_LLVM_BUG_ALLOCSIZE=1 - track every malloc/calloc/realloc and
feed three signals (headroom IJON-min,
proximity-bucket coverage edge, soft-OOB
tripwire) per in-loop store
AFL_LLVM_BUG_SLACK=1    - per-icmp |op0-op1| feedback, mapped
MIN-style onto the bug map (inverse-
bucket) for tight-comparison signal
AFL_LLVM_BUG_ALLOCSIZE_FUNCS=Name1,Name2,... - extend tracking
to user-listed custom allocators
AFL_LLVM_BUG_ALLOCSIZE_FREE_FUNCS=Name1,Name2,... - matching
custom-free functions for the above
AFL_LLVM_BUG_ALLOCSIZE_DERIVE=1 - log tracked allocation sizes
into CmpLog RTN slots for -l Z
AFL_LLVM_BUG=1           - enable all bug-pass modes
Per-site bug-map slots are kept in a private MAP_SIZE_BUG region and
tracked max-rule (compatible with the IJON model)


cmplog scheduling extensions (companion to bug-pass):

-l M (afl-fuzz) - predicate-tightness scheduling. Treat any
new per-site minimum slack on an inequality CmpLog cmp as a
coverage event and mark the queue entry favoured. Catches the
libwebp-1.3.1 / CVE-2023-4863 input pattern (validation
predicates simultaneously at their tight edges).
AFL_LLVM_BUG_ALLOCSIZE_DERIVE=1 or AFL_LLVM_BUG=1
(compile-time) and
-l Z (afl-fuzz) - size-derive logging. On every freed tracked
allocation, write (computed_size, max_observed_offset) into a
CmpLog RTN slot keyed by alloc-site. The existing CmpLog
dictionary mining harvests computed_size as a magic constant
and feeds the producing input bytes back into havoc.




afl-cmin*:

nyx_mode is now working for all minimizer variants


afl-showmap:

no more .afl-showmap-temp-* files lying around


IJON dist was changed to original IJON implementation: initial matching
bytes, max length is 1024
lib* tools:

MacOS support is back, thanks to @Jay-1409 !


 ]]></description>
<link>https://tsecurity.de/de/3570226/IT+Sicherheit/Cybersecurity+Tools/v5.00c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570226/IT+Sicherheit/Cybersecurity+Tools/v5.00c/</guid>
<pubDate>Wed, 03 Jun 2026 17:52:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.5]]></title> 
<description><![CDATA[What&#039;s Changed

[INS-461] Add test to ensure new detectors are registered in defaults.go by @mustansir14 in #4915
[INS-455] Unify common logic in Atlassian Data Center detectors by @mustansir14 in #4907
fix(github): cache repo info under original URL on redirect by @kashifkhan0771 in #4958
Added GitLab OAuth Detector by @shahzadhaider1 in #4729
Box Detector: Extract Subject ID for Analyzer Integration by @shahzadhaider1 in #4761
[INS-346] SpectralOps Personal API Key Detector by @MuneebUllahKhan222 in #4770
[INS-335] Added AWS Appsync Detector by @MuneebUllahKhan222 in #4803
fix(twilio): deduplicate matches to prevent O(N&times;M) result explosion by @kashifkhan0771 in #4954
Automate corpora testing in CI by @mustansir14 in #4927
Enable errcheck and staticcheck for golangci-lint v2 and resolve all issues by @amanfcp in #4924
feat: add host, db and username to ExtraData for database detectors by @mariocj89 in #4849
Remove over speculation from Corpora CI workflow by @mustansir14 in #4974
Fix line numbers for duplicate secrets within a chunk by @amanfcp in #4910
Add feature flags for Pinecone, Cloudinary, and GitLab OAuth detectors by @camgunz in #4961
Update Go security dependencies by @cursor[bot] in #4986
Pin GitHub Actions to SHA digests by @bryanbeverly in #4985
Update CODEOWNERS: replace 5 slugs with scanning + integrations by @bryanbeverly in #4983
Added source config flags to sharepoint proto by @MuneebUllahKhan222 in #4972
[SCAN-795] HTML decoder: ASPX and entity-encoded HTML support by @mustansir14 in #4981
adds some debugging info for APKs and fixes issues parsing obfuscated APKs by @johannestaas-trufflesec in #4991

New Contributors

@mariocj89 made their first contribution in #4849
@cursor[bot] made their first contribution in #4986
@johannestaas-trufflesec made their first contribution in #4991

Full Changelog: v3.95.3...v3.95.5 ]]></description>
<link>https://tsecurity.de/de/3566852/IT+Sicherheit/Cybersecurity+Tools/v3.95.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566852/IT+Sicherheit/Cybersecurity+Tools/v3.95.5/</guid>
<pubDate>Tue, 02 Jun 2026 18:10:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 8.0.2]]></title> 
<description><![CDATA[Malwoverview 8.0.2 ]]></description>
<link>https://tsecurity.de/de/3566483/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566483/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.2/</guid>
<pubDate>Tue, 02 Jun 2026 16:24:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.4]]></title> 
<description><![CDATA[What&#039;s Changed

[INS-461] Add test to ensure new detectors are registered in defaults.go by @mustansir14 in #4915
[INS-455] Unify common logic in Atlassian Data Center detectors by @mustansir14 in #4907
fix(github): cache repo info under original URL on redirect by @kashifkhan0771 in #4958
Added GitLab OAuth Detector by @shahzadhaider1 in #4729
Box Detector: Extract Subject ID for Analyzer Integration by @shahzadhaider1 in #4761
[INS-346] SpectralOps Personal API Key Detector by @MuneebUllahKhan222 in #4770
[INS-335] Added AWS Appsync Detector by @MuneebUllahKhan222 in #4803
fix(twilio): deduplicate matches to prevent O(N&times;M) result explosion by @kashifkhan0771 in #4954
Automate corpora testing in CI by @mustansir14 in #4927
Enable errcheck and staticcheck for golangci-lint v2 and resolve all issues by @amanfcp in #4924
feat: add host, db and username to ExtraData for database detectors by @mariocj89 in #4849
Remove over speculation from Corpora CI workflow by @mustansir14 in #4974
Fix line numbers for duplicate secrets within a chunk by @amanfcp in #4910
Add feature flags for Pinecone, Cloudinary, and GitLab OAuth detectors by @camgunz in #4961
Update Go security dependencies by @cursor[bot] in #4986
Pin GitHub Actions to SHA digests by @bryanbeverly in #4985
Update CODEOWNERS: replace 5 slugs with scanning + integrations by @bryanbeverly in #4983
Added source config flags to sharepoint proto by @MuneebUllahKhan222 in #4972
[SCAN-795] HTML decoder: ASPX and entity-encoded HTML support by @mustansir14 in #4981
adds some debugging info for APKs and fixes issues parsing obfuscated APKs by @johannestaas-trufflesec in #4991

New Contributors

@mariocj89 made their first contribution in #4849
@cursor[bot] made their first contribution in #4986
@johannestaas-trufflesec made their first contribution in #4991

Full Changelog: v3.95.3...v3.95.4 ]]></description>
<link>https://tsecurity.de/de/3565105/IT+Sicherheit/Cybersecurity+Tools/v3.95.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565105/IT+Sicherheit/Cybersecurity+Tools/v3.95.4/</guid>
<pubDate>Tue, 02 Jun 2026 08:20:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.33.1]]></title> 
<description><![CDATA[What&#039;s Changed

Fix UWORKER initialization crash by bypassing Wi-Fi Datastore queries in Android by @jardondiego in #5290
Swarming: Adds CountTasks endpoint &amp; Refactors swarming Prpc request by @IvanBM18 in #5277
Fix bypass Datastore access in uworker for job definition by @jardondiego in #5293
Match libfuzzer&#039;s timeout for reproduction in centipede by @g-ortuno in #5291
[Swarming] Push preprocess tasks to swarming queue by @IvanBM18 in #5282
Optimize reboots with Android emulator initialization by @jardondiego in #5280
Fix legacy Datastore access in data_handler.py for UWORKERs by @jardondiego in #5294
Adds option to override the default queue for tworkers by @IvanBM18 in #5295
Creates PubSubTaskQueue module  by @IvanBM18 in #5296

New Contributors

@g-ortuno made their first contribution in #5291

Full Changelog: v2.33.0...v2.33.1 ]]></description>
<link>https://tsecurity.de/de/3564387/IT+Sicherheit/Cybersecurity+Tools/v2.33.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564387/IT+Sicherheit/Cybersecurity+Tools/v2.33.1/</guid>
<pubDate>Mon, 01 Jun 2026 23:29:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[release: v0.71.0 [main] (#10638)]]></title> 
<description><![CDATA[Co-authored-by: repo-trivy-write-33ed3c[bot]  ]]></description>
<link>https://tsecurity.de/de/3563138/IT+Sicherheit/Cybersecurity+Tools/release%3A+v0.71.0+%5Bmain%5D+%28%2310638%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563138/IT+Sicherheit/Cybersecurity+Tools/release%3A+v0.71.0+%5Bmain%5D+%28%2310638%29/</guid>
<pubDate>Mon, 01 Jun 2026 14:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.380.0]]></title> 
<description><![CDATA[What&#039;s Changed

bundler: avoid adding Bundler checksum for lockfiles using 4.0.0-4.0.10 by @thavaahariharangit in #15164
Remove beta ecosystem flag handling for Deno by @markhallen in #15173
[bun] Add lockfile generator for bun by @brrygrdn in #14882
Pass --config.minimumReleaseAge=0 for pnpm security updates to bypass pnpm-workspace.yaml by @yeikel in #15170
build(deps): bump terraform to 1.15.3 by @HorizonNet in #15055
Change cron schedule from Thursday to Monday by @robaiken in #15181
Add specific error for missing .NET SDK in discovery by @brettfo in #15168
Throw UnparseableFileException when slnx parsing fails by @brettfo in #15167
v0.380.0 by @dependabot-core-action-automation[bot] in #15192

Full Changelog: v0.379.0...v0.380.0 ]]></description>
<link>https://tsecurity.de/de/3562676/IT+Sicherheit/Cybersecurity+Tools/v0.380.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562676/IT+Sicherheit/Cybersecurity+Tools/v0.380.0/</guid>
<pubDate>Mon, 01 Jun 2026 12:31:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Forensic Implications of Apple Stolen Device Protection]]></title> 
<description><![CDATA[If you extract data from iPhones for a living, Stolen Device Protection is the change you can no longer afford to ignore. It does something deceptively simple: it puts Face ID or Touch ID in front of the &ldquo;Trust This Computer&rdquo; prompt. The practical result is that an examiner who knows the device passcode still [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3562407/IT+Sicherheit/Cybersecurity+Tools/Forensic+Implications+of+Apple+Stolen+Device+Protection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562407/IT+Sicherheit/Cybersecurity+Tools/Forensic+Implications+of+Apple+Stolen+Device+Protection/</guid>
<pubDate>Mon, 01 Jun 2026 10:47:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.1.0]]></title> 
<description><![CDATA[

PentAGI 2.1 &mdash; File Management, Knowledge Base, ToolCall Observability, and Assistant Flow Control
This release adds a complete file management layer (user resource libraries and flow workspace files with container sync), a first-class Knowledge Base with semantic search and anonymization, real-time ToolCall logging, and assistant tools to monitor and steer running flows. It also refreshes model configurations across OpenAI, Anthropic, Gemini, DeepSeek, Qwen, Kimi, and GLM, a broad frontend modernization pass (React 19, Apollo Client v4, Vite 8), and a wide range of stability and security fixes.
⠀


Major Features
User Resources &amp; Flow Files
A new file management layer lets users bring their own files into PentAGI and share them with agents.

User Resources &mdash; a persistent, per-user file library with MD5-deduplicated storage and a virtual path filesystem. Full REST and GraphQL CRUD (upload, mkdir, move, copy, delete, download), real-time subscriptions, and atomic multi-source / multi-path batch operations.
Flow files &mdash; per-flow workspace files that sync into worker containers at /work/uploads and /work/resources. Files can be pulled back out of a running container and promoted into the user library. Attached files are injected into agent system prompts as a structured  block, so the assistant is aware of what the user provided.
File Manager UI &mdash; a reusable tree component with multi-select, keyboard navigation, drag-and-drop, sortable columns, bulk actions, and an overwrite workflow. Used by both the new /resources page and the flow Files tab.
Limits and hardening &mdash; enforced on both ends: 300 MB per file, 1000 files per request, 2 GB total, 255-byte names. Upload paths are protected against directory traversal and symlink escapes.

Knowledge Base Management
The pgvector memory store is now a first-class, user-manageable resource rather than agent-only auto-storage.

GraphQL/REST CRUD plus semantic search over the knowledge store, with admin/user scoping, per-user document ownership, re-embedding on update, and real-time subscriptions.
A new /knowledges interface with list and detail pages, a TipTap markdown editor, partial updates, inline rename/delete, and a collapsible semantic-search input (hotkey-accessible).
Text anonymization &mdash; a new anonymizeText service (GraphQL/REST) to scrub sensitive data, surfaced directly in the knowledge editor.
The vector search engine was rewritten onto direct, parameterized SQL queries &mdash; fixing a bug where document IDs were dropped and removing unsafe SQL string interpolation.

ToolCall Observability
Individual agent tool calls are now logged through a dedicated provider and exposed via GraphQL queries and subscriptions plus a REST API, giving real-time, inspectable visibility into every command, search, and action an agent performs during a flow.
Assistant Flow Management
The interactive assistant can now observe and steer active flows without leaving the chat. New tools let the assistant read flow status (with multiple detail levels), stop a flow, submit input to a waiting flow, patch subtasks, and block until a task completes. A summarizer cache avoids redundant LLM calls when reporting flow state.
Unified Agent Language Policy
A single, consistent language policy now spans all agent prompts: vector-store and search-engine queries are forced to English for retrieval consistency, while user-facing messages follow the engagement language. Template variables and tool access were aligned with each agent&#039;s actual runtime tool set.

New Capabilities
Updated Provider Configurations &amp; Models
Built-in model configurations were refreshed across multiple providers &mdash; OpenAI, Anthropic, Gemini, DeepSeek, Qwen, Kimi, and GLM &mdash; to match the current model landscape, with updated model lists, pricing, and context windows.

Per-role thinking control &mdash; reasoning models such as DeepSeek and Qwen now toggle thinking mode per agent role, so utility roles run without thinking (and honor their sampling parameters) while reasoning, tool-use, and security-analysis roles keep it enabled.
New reference configurations &mdash; vLLM Qwen 3.6 (thinking and non-thinking, including 35B FP8 variants) bundled in the Docker image, and an Azure OpenAI example.
Ollama now surfaces a clear, actionable error when the selected model does not support tool/function calling, instead of a deeply nested stack trace.

Per-Model Analytics
A new query surfaces token usage broken down by model and agent type within a single flow, integrated into the flow dashboard.
Configuration

TERMINAL_TOOL_TIMEOUT &mdash; configurable terminal command timeout (default raised to 1200 seconds, with clamping for out-of-range values).
PostgreSQL connection pooling &mdash; shared pools for sqlc, GORM, and pgvector with new tunables DB_MAX_OPEN_CONNS, DB_MAX_IDLE_CONNS, and DB_VECTOR_MAX_CONNS.
EMBEDDING_MAX_TEXT_BYTES &mdash; caps the text size sent to the embedding model.
The Settings API now exposes version and isDevelopMode.


Frontend Modernization
A broad pass touched nearly every list and detail page.

Unified list tables &mdash; URL-synced filtering, pagination, sorting, and column visibility, with multi-column search (&quot;Search in&quot; column picker) and contextual empty states.
Detail navigation &mdash; Prev/Position/Next navigation between sibling records, with an in-sheet searchable list.
Inline actions &mdash; rename, finish, and delete directly from flow, template, and knowledge headers and list rows.
Per-route document titles &mdash; browser tabs now reflect the actual page (including live flow titles), driven by a centralized title registry.
Mobile UX &mdash; responsive headers that collapse to icon-only buttons, a unified flow attachment/template picker, and a compact dashboard period switcher.
Performance &mdash; dashboard period-switch interaction latency reduced from 434 ms to 134 ms, the PDF renderer is lazy-loaded (cutting the report route&#039;s initial JS by ~1.5 MB), the knowledge provider is scoped to its own routes (avoiding a ~2.1 MB payload on every page), filtering is debounced, and rename/favorite actions update optimistically for instant feedback.
Platform upgrades &mdash; React 19, Apollo Client v4, Vite 8 (Rolldown), TypeScript 6, Zod v4, the graphql-codegen v6/v7 toolchain, and the shadcn new-york-v4 component style. The frontend test suite grew from 475 to 541 tests.
Accessibility &mdash; aria-labels across icon-only buttons, form-field id/name fixes, and Radix dialog compliance.


Bug Fixes &amp; Reliability
Flow &amp; Agent Execution

Task cancellation &mdash; subtask generation now runs under a cancellable context, so cancelling a task no longer reports a false success.
Custom prompts &mdash; user prompt overrides saved in Settings &rarr; Prompts are now actually applied to new assistant and flow sessions (they were silently using the defaults).
Malformed tool-call JSON &mdash; truncated or invalid LLM arguments now fall back to an empty object instead of triggering LiteLLM 400 errors and infinite retry loops; literal control characters in arguments are sanitized before storage.
Subscription backpressure &mdash; events are dropped for slow or disconnected subscribers after a timeout, preventing goroutine accumulation.
Deadlock fixes &mdash; resolved a deadlock in the log worker and a nil-channel deadlock when finishing an assistant session.
Browser tool &mdash; small/empty page content now returns a warning rather than an error, binary URLs are reported clearly, and a failed screenshot no longer discards successfully fetched page content.

Knowledge &amp; Data

Vector search safety hardened (parameterized queries, memory documents excluded at the SQL level).
Fixed recursive resource retrieval over GraphQL, and resource move/copy responses now return the correct entries for client cache consistency.

Frontend

Fixed a production crash on flow detail pages caused by the minifier stripping function names from document-title components.
Eliminated several table state races (filter clearing, pagination URL loops, batched URL updates) and a GraphQL codegen issue that emitted duplicate types and broke the dev server.
API token names are no longer lost when a subscription refetches the table mid-edit; the default button type no longer triggers accidental form submits.


Security

Flow file uploads are hardened against path traversal and symlink escapes, with size and count limits enforced on both the backend and the frontend.
Knowledge vector search uses parameterized queries, removing prior string-interpolated SQL.
New endpoints enforce user/admin privilege scoping, with dedicated privileges (anonymize.call, toolcall access) added via migration.
Text anonymization is available to scrub sensitive data from stored knowledge.


Documentation
Extensive user-facing documentation was added, including a first-use guide, a pentesting prompt methodology guide, memory lifecycle across flows, capability boundaries, OAuth callback setup, a Docker mirror guide for restricted networks, OSINT integration scenarios, the flow Files tab, DeepSeek V4 migration and pricing, and a clarification that Vertex AI is reachable today only via an OpenAI-compatible gateway. Two design RFCs &mdash; flow concurrency with completion webhooks, and MCP client integration &mdash; were added under examples/proposals/ as design proposals with no runtime code yet.

Upgrade Notes

DeepSeek: deployments using the legacy deepseek-chat / deepseek-reasoner model names should migrate to deepseek-v4-flash / deepseek-v4-pro before the upstream deprecation on 2026-07-24.
Database: connection-pool settings were consolidated to DB_MAX_OPEN_CONNS, DB_MAX_IDLE_CONNS, and DB_VECTOR_MAX_CONNS &mdash; verify against .env.example.
Terminal timeout: TERMINAL_TOOL_TIMEOUT default raised from 600 to 1200 seconds; review if a lower value was intentional.
Frontend development now requires pnpm (previously npm).
Database migrations apply automatically at startup. After pulling, rebuild and restart: docker compose build &amp;&amp; docker compose up -d.


Contributors
Core Team

@asdek (Dmitry Nagibin) &mdash; User resources &amp; flow files backend, knowledge base API and vector search, ToolCall logging, anonymizer, assistant flow management tools, agent language policy, provider model updates, database connection pooling, and flow reliability fixes
@sirozha (Sergey Kozyrenko) &mdash; File Manager component, resources/knowledges/flow-files UI, unified list tables and multi-column search, detail navigation, document titles, mobile UX, frontend platform upgrade (React 19 / Apollo v4 / Vite 8), and performance &amp; accessibility work

External Contributors

@mason5052 &mdash; Custom prompts fix, Ollama tool-support error clarity, DeepSeek V4 migration, flow file upload hardening, and extensive documentation and design RFCs (flow concurrency, MCP client integration, evidence chain)
@Kairos-T &mdash; Documentation mermaid syntax fix (PR#259)


Full Changelog: v2.0.0...v2.1.0 ]]></description>
<link>https://tsecurity.de/de/3557523/IT+Sicherheit/Cybersecurity+Tools/2.1.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557523/IT+Sicherheit/Cybersecurity+Tools/2.1.0/</guid>
<pubDate>Fri, 29 May 2026 20:25:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.379.0]]></title> 
<description><![CDATA[What&#039;s Changed

Fix duplicate updated dependencies in multi-directory group refresh by @markhallen in #15098
Recategorise lockfile generation errors as known types by @brrygrdn in #15084
[Graph Job] Do not treat Dependabot::UnexpectedExternalCode as a hard failure by @brrygrdn in #15075
[Graph] Fix handling of multiple version resolution by @brrygrdn in #15099
Bun: Upgrade to Node JS 24 by @yeikel in #14964
Add API integration to fetch blocked versions at job construction by @kbukum1 in #14917
Fix go modules error in package details fetcher due to subpath issue by @AbhishekBhaskar in #15096
add common pattern for directory specification by @brettfo in #15108
raise generic error without path information by @brettfo in #15088
Add HasNoWarnNU1701 merge logic in project discovery by @brettfo in #15090
NuGet: Auto-patch NuGet.Config to allow insecure HTTP feeds by @brettfo in #15092
NuGet: Filter out submodule paths during discovery by @brettfo in #15093
Implement a &quot;dealias_packages&quot; flag for npm file parsing by @brrygrdn in #15070
fix(docker_compose): support folded scalar and docker.io-prefixed image values by @thavaahariharangit in #15100
Suppress Docker digest-only updates when tag version is unchanged by @markhallen in #15103
generate and submit dependency graphs by @brettfo in #14956
Revert &quot;Add API integration to fetch blocked versions at job construction&quot; by @robaiken in #15120
change test for file path to account for empty string by @brettfo in #15109
NuGet: Add circular dependency detection to MSBuildHelper.ThrowOnError by @brettfo in #15116
Catch FatalProtocolException from source repository initialization by @brettfo in #15117
NuGet: Remove redundant GetPackageGraphForDependencies and use discovery DependencyGraph by @brettfo in #15122
Add API integration to fetch blocked versions at job updates by @kbukum1 in #15123
Fix yarn berry security updates resolving to latest instead of target version by @kbukum1 in #15091
Fix misleading Terraform registry error when TLS certificate verification fails by @yeikel in #15131
Fix cooldown ignored in additional_dependencies issue by @AbhishekBhaskar in #15124
Remove beta ecosystems feature flag for sbt by @AbhishekBhaskar in #15151
NuGet: Fix binding redirect XML parse error to report unparseable file by @brettfo in #15147
fix(npm_and_yarn): handle engines OR constraints and split caret-expanded bounds by @thavaahariharangit in #15144
Pass --min-release-age=0 for npm security updates to bypass .npmrc by @yeikel in #15139
Add deno lockfile support by @sbs44 in #15153
NuGet: Fix version range double-wrapping in temp project creation by @brettfo in #15152
Check ProjectAssetsFile exists before reading by @brettfo in #15160
fix: use configured github source when checking GitHub Actions pre-release status by @yeikel in #15004
ERR_PNPM_INVALID_DEPENDENCY_NAME handler in PnpmLockfileUpdater by @Copilot in #15165
Read npm min-release-age from .npmrc and apply as cooldown by @yeikel in #15132
v0.379.0 by @dependabot-core-action-automation[bot] in #15162

Special Thanks
Big thanks to @yeikel for driving the min-release-age support for the JavaScript ecosystems!
Full Changelog: v0.378.0...v0.379.0 ]]></description>
<link>https://tsecurity.de/de/3555080/IT+Sicherheit/Cybersecurity+Tools/v0.379.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555080/IT+Sicherheit/Cybersecurity+Tools/v0.379.0/</guid>
<pubDate>Thu, 28 May 2026 19:11:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[3.1.0-20260528]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/2131e7d45087c39cb15c4aa12b8f631c23d51d24/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Add version number to HOTFIX file by @TOoSmOotH in #15924
use multiple or combined input by @reyesj2 in #15925
check for stale logstash pipeline name in local pillar by @reyesj2 in #15930
keep logstash lumberjack pipeline name update unified by @reyesj2 in #15934
3.1.0 hotfix by @TOoSmOotH in #15936

Full Changelog: 3.1.0-20260521...3.1.0-20260528 ]]></description>
<link>https://tsecurity.de/de/3554502/IT+Sicherheit/Cybersecurity+Tools/3.1.0-20260528/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554502/IT+Sicherheit/Cybersecurity+Tools/3.1.0-20260528/</guid>
<pubDate>Thu, 28 May 2026 16:30:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v4.14.6-rc1]]></title> 
<description><![CDATA[Manager
Removed

Removed unused SSL/TLS transport option from cluster. (#35648)

Fixed

Improved message decompression handling in remoted. (#35773)
Improved agent name validation to reject names starting with dot. (#35833)
Fixed segfault in vulnerability scanner module shutdown when disabled. (#36011)
Fixed string buffer handling in version comparison function. (#36059)
Improved cluster file synchronization security. (#36060)
Improved cluster file synchronization error handling on invalid task identifiers. (#36129)
Improved cluster merged file parameter validation to prevent directory escape. (#36204)
Improved tmp_file path validation in cluster DAPI. (#36246)
Improved cluster non-merged file path validation during worker file processing. (#36296)
Improved cluster node name format validation in the hello handler. (#36460)
Fixed missing agent.host.ip in inventory documents when agent IP is empty. (#35475)
Fixed stale agent synced status after hot reload on cluster worker nodes. (#6726)

Agent
Fixed

Fixed agent registration not running on reinstall after apt-get remove. (#35727)
Fixed MS-Graph integration handling for relationships containing /. (#35431)
Fixed macOS syscollector to skip package receipts whose payload is no longer installed. (#35380)
Fixed missing eBPF create, modify and delete events on Ubuntu 24/26 and improved FIM whodata healthcheck. (#35838)
Hardened FIM database path lookups by migrating to parameterized SQL queries. (#36399)

RESTful API
Fixed

Escaped control characters in API usernames in access logs. (#35866)
Added input validation in cluster result handling and authentication. (#35757)
Fixed current user resolution in the update-user endpoint to enforce admin protection. (#35442)

Ruleset
Fixed

Updated rootcheck trojan signatures to avoid false positives on modern distributions (Debian 13, Ubuntu 26, Arch Linux). (#35927)

Other
Changed

Updated cryptography, urllib3 and python-multipart Python dependencies. (#35982)
Updated eBPF libraries: libbpf to 1.7.0 and bpftool to 7.7.0. (#36467)
 ]]></description>
<link>https://tsecurity.de/de/3553772/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.6-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553772/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.6-rc1/</guid>
<pubDate>Thu, 28 May 2026 12:06:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Release v1.164.0]]></title> 
<description><![CDATA[1.164.0 - 2026-05-26
### Added

Dart: typed metavariables ($X as T) and metavariable-type,
metavariable binding inside string interpolations, and function-definition
patterns that match Dart function definitions. (gh-11678)

### Changed

The default memory limit for Pro interfile scans on Linux now adapts to the container&#039;s cgroup memory limit (90% of it) instead of the previous fixed 5 GiB, with an 8 GiB fallback when no cgroup limit is detected. (ENGINE-2568)
Lower the glibc contraint from &gt;=2.35 to &gt;=2.34, allowing users on distros
that ship glibc 2.34 (e.g RHEL 9 &amp; AL2023) to install the semgrep wheel. (gh-11622)

### Fixed


Baseline diff scans (semgrep ci and --baseline-commit) no longer treat every finding on a file as newly introduced when rule(s) failed during the baseline run.
Per-rule failures (for example a timeout for a single rule) on baseline analysis now hide only that rule&#039;s matches on that file from the &quot;new vs baseline&quot; comparison.
Other rules on the same file are still taken in comparison for the &quot;new vs baseline&quot; comparison.
Per-file, rule-independent failures now hide all findings on that file from the &quot;new vs baseline&quot; comparison. (LANG-515)


Fixed a yarn.lock parse error on Yarn Berry entries written
in YAML explicit-key form. Affected lockfiles previously failed to parse. (SC-3479)


The (beta) SBT resolver with --allow-local-builds now correctly identifies dependencies as part of the Maven ecosystem. (SC-3522)


Fix --sarif-output and --sarif causing nosemgrep-suppressed findings to be reported in CLI scan output and to block scans. Suppressed findings are now correctly excluded from terminal text output, the scan-summary count, and the CLI&#039;s exit code. (engine-1824)


Fixed a bug that could cause unreliable target filtering in parallel scans. (gh-6313)


Dart: improved parser fidelity for Dart 3 grammar features and routed
pattern parsing for statements beginning with await, rethrow, and other
statement keywords. Eliminates a large class of PartialParsing errors on
real-world pub.dev packages. (gh-11678)


### Infra/Release Changes

pro: macOS: Fixed dynamic library lookup for semgrep-core-proprietary so the binary works when semgrep install-semgrep-pro is invoked, and semgrep is installed via Homebrew. (pro-binary-homebrew)
Pro: Added optional .named_ast.expect golden files for tests/intrafile/maturity/ fixtures, exercised by Unit_maturity_named_asts. (LANG-287)
 ]]></description>
<link>https://tsecurity.de/de/3551520/IT+Sicherheit/Cybersecurity+Tools/Release+v1.164.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551520/IT+Sicherheit/Cybersecurity+Tools/Release+v1.164.0/</guid>
<pubDate>Wed, 27 May 2026 16:35:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.44.0]]></title> 
<description><![CDATA[chore(cmake): bump libs to `0.25.2`

Signed-off-by: Leonardo Di Giovanna  ]]></description>
<link>https://tsecurity.de/de/3548330/IT+Sicherheit/Cybersecurity+Tools/0.44.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548330/IT+Sicherheit/Cybersecurity+Tools/0.44.0/</guid>
<pubDate>Tue, 26 May 2026 16:29:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Downloading iPhone and iPad backups from Apple iCloud]]></title> 
<description><![CDATA[Pulling a backup out of iCloud is one of the more technically demanding jobs in cloud forensics. An iCloud backup is not a single, ready-to-download file; instead, it is assembled from a large number of separate fragments that have to be collected and stitched back together into a coherent backup. Recent changes to Apple&rsquo;s communication [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3547239/IT+Sicherheit/Cybersecurity+Tools/Downloading+iPhone+and+iPad+backups+from+Apple+iCloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547239/IT+Sicherheit/Cybersecurity+Tools/Downloading+iPhone+and+iPad+backups+from+Apple+iCloud/</guid>
<pubDate>Tue, 26 May 2026 10:00:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.44.0-rc2]]></title> 
<description><![CDATA[chore(cmake): bump libs to `0.25.2`

Signed-off-by: Leonardo Di Giovanna  ]]></description>
<link>https://tsecurity.de/de/3546204/IT+Sicherheit/Cybersecurity+Tools/0.44.0-rc2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546204/IT+Sicherheit/Cybersecurity+Tools/0.44.0-rc2/</guid>
<pubDate>Mon, 25 May 2026 20:36:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.33.0]]></title> 
<description><![CDATA[What&#039;s Changed

Bulter.py: Adds preprocess butler script for local preprocess by @IvanBM18 in #5266
Swarming: Add TasksCountRequest and TasksCount to swarming.proto by @IvanBM18 in #5276
Provide context on how to correctly call butler in AGENTS.md by @IvanBM18 in #5286
Update Android SDK tools and bundled binaries by @jardondiego in #5279
Ignore rows which are missing stats during daily aggregation by @dylanjew in #5287
Fix Android UWORKER initialization crash bypassing test account provisioning by @jardondiego in #5288
Add MAX_EXECUTIONS environment variable limit by @jardondiego in #5272

Full Changelog: v2.32.1...v2.33.0 ]]></description>
<link>https://tsecurity.de/de/3545783/IT+Sicherheit/Cybersecurity+Tools/v2.33.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545783/IT+Sicherheit/Cybersecurity+Tools/v2.33.0/</guid>
<pubDate>Mon, 25 May 2026 16:23:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[A Decade of BitLocker Vulnerabilities: What’s Patched, What’s Not, and What Still Works]]></title> 
<description><![CDATA[A few days ago we wrote about YellowKey, the newest entry in what has become a remarkably long list of BitLocker bypasses. That article walked through one specific attack with a practical workflow. This follow-up steps back and surveys the broader landscape: where BitLocker has been broken before, where it is still broken today, and [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3538848/IT+Sicherheit/Cybersecurity+Tools/A+Decade+of+BitLocker+Vulnerabilities%3A+What%E2%80%99s+Patched%2C+What%E2%80%99s+Not%2C+and+What+Still+Works/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538848/IT+Sicherheit/Cybersecurity+Tools/A+Decade+of+BitLocker+Vulnerabilities%3A+What%E2%80%99s+Patched%2C+What%E2%80%99s+Not%2C+and+What+Still+Works/</guid>
<pubDate>Fri, 22 May 2026 10:20:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[3.1.0-20260521]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/141a61f5b53d44e647350ac2c4b48be1708fd807/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Version Bump by @TOoSmOotH in #15699
Update SOUP_BRANCH to use 3/main instead of 2.4/main by @TOoSmOotH in #15701
soup fix by @TOoSmOotH in #15702
pr/workflow changes by @jertel in #15704
Merge pr/workflow changes back to dev by @jertel in #15705
Fix JA4+ license link in soc_zeek.yaml by @TOoSmOotH in #15724
License Link to dev by @TOoSmOotH in #15725
ES 9.3.2 by @reyesj2 in #15727
foxtrot version by @reyesj2 in #15728
filestream integration policy updates by @reyesj2 in #15733
ensure max-files is 1 at minimum by @m0duspwnens in #15741
define options in annotation files by @m0duspwnens in #15745
Assistant: charsPerTokenEstimate by @mc-wright in #15742
rework elasticsearch index template generation by @reyesj2 in #15751
initialize vars by @reyesj2 in #15754
rework elasticsearch template load script -- for core templates by @reyesj2 in #15761
only append &quot;-mappings&quot; to component template names as needed by @reyesj2 in #15762
start loading addon integration index templates by @reyesj2 in #15763
elasticsearch ilm policy load script by @reyesj2 in #15764
3/dev by @reyesj2 in #15765
support minion node descriptions containing spaces by @jertel in #15766
ES 9.3.3 by @reyesj2 in #15768
enable elastic agent patch release for 9.3.3 by @reyesj2 in #15770
Improve test scenario for node descriptions by @jertel in #15769
soup to 3.1.0 by @reyesj2 in #15772
check for addon-index templates dir before attempting to load addon i&hellip; by @reyesj2 in #15775
ES 9.3.3 by @reyesj2 in #15776
supress noisy warning from ES 9.3.3 by @reyesj2 in #15780
add wait_for_so-elasticsearch state and split elasticsearch cluster c&hellip; by @reyesj2 in #15786
fix template annotation by @jertel in #15797
more error handling during image updates by @jertel in #15803
urlencode elasticsearch version by @reyesj2 in #15807
postgres follow-ups: fan manager cred + so-yaml.py replace fix by @TOoSmOotH in #15806
monitor raid for vms by @m0duspwnens in #15800
Fix soup by @TOoSmOotH in #15712
split up Elastic Fleet state by @reyesj2 in #15813
numeric test description by @jertel in #15822
typo by @reyesj2 in #15823
fix reinstall issue with salt by @m0duspwnens in #15824
readonly soc and kratos enabled by @m0duspwnens in #15828
heavynode should run es cluster state by @reyesj2 in #15826
fix reinstall by @m0duspwnens in #15829
exclude more transform job errors by @reyesj2 in #15833
fix sominion_setup reactor by @m0duspwnens in #15835
Add so-postgres Salt states and infrastructure by @TOoSmOotH in #15749
check current fleet policy cert against cert on disk by @reyesj2 in #15837
Fix/docker refresh multiarch pull by @TOoSmOotH in #15838
drop postgres module from soc defaults injection by @TOoSmOotH in #15839
Open postgres in DOCKER-USER firewall everywhere influxdb is open by @TOoSmOotH in #15840
so-elastic-fleet-outputs-update now checks for cert drift. Remove run&hellip; by @reyesj2 in #15842
update default elastic agent logging level to warning by @reyesj2 in #15844
reauthorize unhealthy transform jobs using kibana 9.3.3 auth flow by @reyesj2 in #15851
fleet package registry health check by @reyesj2 in #15857
Fix unsafe PyYAML load in filecheck by @TOoSmOotH in #15858
Ensure python3-pyyaml is installed before continuing setup by @TOoSmOotH in #15846
update grok type conversion to convert processor by @reyesj2 in #15864
Management bond1 by @TOoSmOotH in #15866
sanitize minion ids for hypervisor reactors / orchestration by @m0duspwnens in #15867
cleanup status code by @defensivedepth in #15872
proc_creation per OS type by @defensivedepth in #15875
New Sigma rules pipeline mapping for M365 and Fortigate by @marcopedrinazzi in #15579
Initial commit by @defensivedepth in #15880
add ingest latency metrics by @reyesj2 in #15878
use temp files to prevent jq arg too long by @reyesj2 in #15883
rename strelka ScanLNK - ScanLnk by @reyesj2 in #15884
remove stig from hypervisor and managerhype by @m0duspwnens in #15887
Change Telegraf output from BOTH to INFLUXDB by @TOoSmOotH in #15888
add zeek.ja4d ingest pipeline by @reyesj2 in #15889
update redis index template by @reyesj2 in #15877
Fix module name by @defensivedepth in #15792
Tweak for nginx upgrade by @defensivedepth in #15894
Fix rename and password leaking into the log. by @TOoSmOotH in #15893
Make so-postgres-backup fail-safe against silent corruption by @TOoSmOotH in #15896
exclude fps by @jertel in #15898
use -verify flag during grid agent install to ensure agent health by @reyesj2 in #15895
Revert &quot;use -verify flag during grid agent install to ensure agent health&quot; by @reyesj2 in #15899
sync elastic agent packages to fleet nodes by @reyesj2 in #15902
Verify compatibility for all ES nodes in the cluster by @reyesj2 in #15907

New Contributors

@marcopedrinazzi made their first contribution in #15579

Full Changelog: 3.0.0-20260331...3.1.0-20260521 ]]></description>
<link>https://tsecurity.de/de/3537652/IT+Sicherheit/Cybersecurity+Tools/3.1.0-20260521/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537652/IT+Sicherheit/Cybersecurity+Tools/3.1.0-20260521/</guid>
<pubDate>Thu, 21 May 2026 21:45:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v5.0.0 Beta 2]]></title> 
<description><![CDATA[What&#039;s Changed

Coding style clang format by @jotacarma90 in #35051
Dovecot decoders don&#039;t match correctly by @hossam1522 in #35089
Fixing CIS 35675 and 35689 rules bug by @hossam1522 in #35088
Improve buffer handling in regex match processing by @vikman90 in #35106
Fix empty-message failure in Windows enrollment integration test by @hernanvalenzuela in #35078
Use daily marker for GuardDuty log collector by @anromerom in #35110
Fix rate limit handling for /events endpoint by @javiersanchz in #35077
Upload Size Limit Config Mismatch - Implementation by @jnasselle in #35141
Update embedded Python and dependencies by @javiersanchz in #35135
Escape document id in delete bulk operations by @ignaciogalle12git in #35174
Add length validation after decompression in ReadSecMSG by @MiguelazoDS in #35193
Fix uncontroller memory allocation in cluster by @FrancoRivero2025 in #35173
Limit nested JSON depth in API requests - Implementation by @jnasselle in #35224
Fix clang-format version resolution in CI by @jotacarma90 in #35180
Align plugin decoder arguments with existing call path by @matigarciadev in #35176
Add groups path validation by @TomasTurina in #35230
Fix audit log cache overflow for events with many records by @vikman90 in #35285
Update dependencies: cryptography, requests by @javiersanchz in #35331
Fix memory allocation for long registry paths in syscheck by @Darioortegaleyva in #35287
Fix for rootcheck not generating findings by @jpcerrone in #35297
Bump 4.14.6 branch by @wazuhci in #35379
Fix coverity findings in group validation paths by @TomasTurina in #35384
Fix active config endpoint and Integration tests by @FrancoRivero2025 in #35412
Server integration tests flaky test by @Antoniogm03 in #35353
Skip macOS receipts that are no longer installed by @anromerom in #35380
Revert tag references to main after v5.0.0-beta1 by @jotacarma90 in #35447
Improve the code to hide information when a user doesn&#039;t have permission by @FrancoRivero2025 in #35307
Validate current user in update-user endpoint by @vikman90 in #35442
Complete wazuh server requirements docs by @TomasTurina in #35459
Optimize error handling geoip locator by @LucioDonda in #35187
wazuh-engine: /logtest endpoint cleanup temporary fields by @matigarciadev in #35420
Add fast metrics module by @NahuFigueroa97 in #35142
Bump 4.14.5 branch by @wazuhci in #35465
Update changelog for v4.14.5-rc1 by @jotacarma90 in #35467
Fix guardduty.py size in check files by @MarcelKemp in #35472
Update uninstall procedure for Windows. by @rjcausarano in #35451
Ms-graph - handle relationships that contain &#039;/&#039; by @jpcerrone in #35431
Validate IP address format in host_ip field for Windows by @cborla in #35418
Avoid using keyentries counter as index by @MiguelazoDS in #35456
Linux  test integration workflow improvements  by @rovogel in #35060
Enhancement/35084 improve it mac os by @rovogel in #35289
Resume modules before manager sync to reduce coordination pause window by @lchico in #35357
Check first scan termination before sync start by @anromerom in #35455
Remove dead python code by @TomasTurina in #35533
Include source IP in wazuh-remoted log messages by @20syldev in #35358
Feed update re-scan revision by @ignaciogalle12git in #35271
Backport: Fix FIM flaky integration tests by @Nicogp in #35535
Migrate CM store-crud resources to native JSON flow by @jam300 in #35172
wazuh-engine: Engine rename archiver module to event dumper by @matigarciadev in #35477
Update inventory sync documentation by @TomasTurina in #35587
Fix workflow input name: set-as-main &rarr; set_as_main in bumper workflow by @jotacarma90 in #35592
Remove leftover code from deprecated Agent 0 by @fcontrerasc in #35195
Synchronize Syscollector and VD queue databases during the flush process by @rjcausarano in #35518
Add manager architecture documentation by @TomasTurina in #35607
Early populate metadata after handshake by @fcontrerasc in #35387
Fix script injection vulnerabilities in CI workflows by @jpcerrone in #35480
(4x) Fix script injection vulnerabilities in CI workflows by @jpcerrone in #35598
Update manager index names to sync by @juliancnn in #35527
Suppress unexpected stateless events after SCA initial scan by @jr0me in #35432
Dynamic getWazuhHome by @jepalfer in #35232
Improve fast metrics interface managment and test by @NahuFigueroa97 in #35540
Engine - Add Filter Sync by @NahuFigueroa97 in #35613
Persist VD first-sync state in table_metadata by @anromerom in #35590
Merge branch &#039;4.14.5&#039; into &#039;4.14.6&#039; by @jotacarma90 in #35655
Normalize stateless check fields by @AnDumu in #35404
Fix token validation race condition after revoke by @javiersanchz in #35218
unify sandbox and trace into a single static parameter in policy creation by @LucioDonda in #35541
Flush feed RocksDB memtable before marking feed ready on download completion by @Nicogp in #35639
Remove unused SSL/TLS transport option from cluster by @vikman90 in #35648
Fix WUA hotfix collection regression in Windows Agent v5.0.0 by @nbertoldo in #35662
Handle stop signal during vulnerability feed download by @fcontrerasc in #35657
Bump main branch by @wazuhci in #35699
Revert &quot;Merge pull request #35699 from wazuh/enhancement/wqa35624-bum&hellip; by @TomasTurina in #35700
Emit WCS-aligned JSON for agent-start and buffer-status events by @lchico in #35671
Support revert bump by @TomasTurina in #35660
wazuh-engine: add retention policies for streamlog module by @matigarciadev in #35565
Support revert bump by @jotacarma90 in #35714
Merge 4.14.6 into main by @TomasTurina in #35705
Fix rootcheck and security API IT by @TomasTurina in #35722
Improve Active Response Custom Script Documentation by @nbertoldo in #35723
Update GDPR control mappings in SCA rulesets by @Johnng007 in #35711
Fix flaky API IT by @TomasTurina in #35724
Fix agents API IT by @TomasTurina in #35746
wazuh-engine: Improve graceful shutdown (fast shudown) by @juliancnn in #35585
Remove legacy unclassified category by @jam300 in #35542
Fix SCA YAML size drift + missing workflow path triggers by @jr0me in #35748
Add cluster validations by @TomasTurina in #35757
Prevent agent.host.ip from being silently dropped when agent IP is empty by @jotacarma90 in #35475
Apply register_configure_agent.sh on reinstall after apt-get remove by @Miguevrgo in #35727
Directory layout improvement by @jepalfer in #35622
Improve message handling robustness in wazuh-remoted by @vikman90 in #35773
Fix stale generated headers after clean by @jr0me in #35777
Fix agent 5x sends trailing null byte 0 in messages by @jr0me in #35658
Improve Python security scans - Implementation by @jnasselle in #35653
Skip vdFirst and polling for vdSync when a feedUpdate occurs by @Antoniogm03 in #35421
Fix SCA integration tests flakiness and deadlocks on Windows by @Darioortegaleyva in #35461
Adapt support-new-oss template by @rafabailon in #35326
Separate public and private APIs and split OpenAPI specs by @jam300 in #35614
Update decoders and filters Jschemas by @NahuFigueroa97 in #35760
engine: Improve devContainer for e2e by @juliancnn in #35775
Improve agent name validation by @vikman90 in #35833
Don&#039;t trigger manager checks in draft PR by @TomasTurina in #35842
Don&#039;t trigger the agent&#039;s PR checks in drafts by @MarcelKemp in #35852
Vulnerability scanner -  CVSSV4.0 support. by @MiguelazoDS in #35759
Change VD provider name by @jotacarma90 in #35863
Send wodle command event in a WCS JSON compatible format. by @rjcausarano in #35703
Validate user name in API by @TomasTurina in #35866
OS_type field addition to db by @jepalfer in #35794
Preserve manager files during package upgrades by @ignaciogalle12git in #35580
Add wazuh.event.id to correlate events from a single log by @jam300 in #35840
Add workflow_dispatch to engine unit and integration tests by @cborla in #35892
Fix labels for dedicated arm64 runner by @AlexRuiz7 in #35920
Add unit tests and a test tool for the Indexer-Connector Module by @LucioDonda in #35720
wazuh-engine: Async router worker pool by @matigarciadev in #35868
Solved the deliminer bug in enrich protocol by @NahuFigueroa97 in #35972
Improve manual dispatch for it workflows by @Nicogp in #35971
Enhancement/33940 implement use cases by @LucioDonda in #35970
Prevent segfault when stopping disabled vulnerability scanner module by @vikman90 in #36011
Graceful termination via cooperative cancellation by @jotacarma90 in #35953
Fix Coverity findings in SCA, sync protocol, router init, and command cleanup by @fcontrerasc in #35985
wazuh-engine: Architecture doc by @juliancnn in #36028
Engine metrics collection, normalization and indexing by @Darioortegaleyva in #35774
Remove selinux from manager by @Antoniogm03 in #35965
Added new CVE5 fields by @MiguelazoDS in #36030
Restart Wazuh service on version check  by @hernanvalenzuela in #36003
Add caller module context to indexer connector logging by @jotacarma90 in #35963
Fix wrong value of wazuh.cluster.name field in metrics indices by @Darioortegaleyva in #36012
Align threat fields under wazuh by @NahuFigueroa97 in #35902
Revert the changes that preserve all configuration files when upgrading an agent by @MarcelKemp in #36050
Add code coverage reporting to legacy unit test workflows by @Nicogp in #36047
Update JSON property names in Wodle event by @rjcausarano in #36031
Remove msgpack and pacman from external dependencies by @jotacarma90 in #35987
Defer engine sync while indexer is updating by @juliancnn in #35945
Add protection for double VDFirst scan by @TomasTurina in #36004
Update python requirements by @TomasTurina in #35990
Update cryptography and python multipart by @TomasTurina in #35982
Fix string handling in version comparison function by @vikman90 in #36059
Dependency Reduction Evidence &mdash; Debian/Ubuntu by @Miguevrgo in #36027
Improve cluster file handling path validation in end_receiving_file by @vikman90 in #36060
Solve agent disconnect on direct 4.13&rarr;5.0 custom WPK upgrade by @lchico in #36052
Prevent Windows agent restart abort when service is already stopping by @cborla in #35991
Remove /bin and /sbin from monitored directories on usrmerge distros by @Darioortegaleyva in #36058
Fix Coverity Medium Impact Defects - Release 5.0.0 Beta 1 (Agent) by @nbertoldo in #35959
Removal of unused dependencies by @jepalfer in #36010
Deprecate API IT tier 2 by @TomasTurina in #36074
Expand Windows environment variables in SCA rule inputs by @fcontrerasc in #36054
Update wodle command arg construction for Windows paths by @anromerom in #35973
fix: Coverity Low Impact Defects by @rovogel in #36032
Include os_type in agent keepalive cluster sync by @jotacarma90 in #36075
Resolve relative indexer certificate paths by @jotacarma90 in #36090
wazuh-engine: Improve wic index deteccion by @juliancnn in #36087
Adapted curl call for old system on wazuh-control by @juliancnn in #36094
Remove 4_X workflows code from main by @Miguevrgo in #36044
Update changelog for 4.14.6 by @jotacarma90 in #36110
Merge 4.14.6 into main by @jotacarma90 in #36109
Build binutils 2.41 in the deb-agent amd64 builder image by @jr0me in #36128
Ensure all workflows use specific OS by @TomasTurina in #36104
Refresh apt index before installing flex/bison for binutils 2.41 by @jr0me in #36133
Improve json schema for optional time by @juliancnn in #36136
Improve Unit test&#039;s readme by @jpcerrone in #36055
Refresh deb-agent amd64 checkfiles sizes for ld 2.41 by @jr0me in #36144
Local wazuh-manager installation by @MiguelazoDS in #36100
Update support new OSs issue template for devOps team by @Enaraque in #36154
Unchecked return value defects reported by coverity by @hernanvalenzuela in #36056
Add workflow to upgrade external dependencies by @jr0me in #36048
Upgrade external deps: curl, sqlite, xz, libarchive (DEPS_VERSION 99-29734) by @jr0me in #36152
Honor shutdown signal in agent-upgrade StartMQ to avoid timeout by @cborla in #36141
Add keystore and indexer connector component tests workflows by @MiguelazoDS in #36142
DockerListener messages as log by @rovogel in #36179
Drop orphan paths before promoting on agent startup by @jr0me in #36198
Build windows externals inside compile_windows_agent image by @jr0me in #36206
Make sync_end_delay interruptible to remove stale modulesd.pid by @lchico in #36240
Restore vulnerability scanner database workflow by @jotacarma90 in #36254
Bump main branch by @wazuhci in #36294
Update CHANGELOG for v5.0.0 Beta 2 by @jotacarma90 in #36295
Complete v5.0.0 Beta 2 stage bump and align spec.yaml blob URLs by @jotacarma90 in #36297

New Contributors

@hossam1522 made their first contribution in #35089
@20syldev made their first contribution in #35358
@Enaraque made their first contribution in #36154

Full Changelog: v5.0.0-beta1...v5.0.0-beta2 ]]></description>
<link>https://tsecurity.de/de/3536717/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v5.0.0+Beta+2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536717/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v5.0.0+Beta+2/</guid>
<pubDate>Thu, 21 May 2026 16:10:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.27]]></title> 
<description><![CDATA[0.7.27 (2026-05-21)
Features

#350: voice agents &mdash; first-class voice in scenario.run() (#355) (128ac94)
#452: voice docs surface &mdash; legacy deprecation + new section scaffold (#456) (1b07abb)
add GOAT strategy with dynamic technique selection for RedTeamAgent (#346) (2896c97)
ci/#364: add pr-auto-approve.yml as passive observer (PR #1 of 4) (#485) (4d84597)
red-team: zero-friction report dashboard &mdash; auto-save + scenario redteam-report CLI (2896c97)

Bug Fixes

deps: bump filelock to &gt;=3.20.3 for TOCTOU/symlink CVEs (#481) (479ec82)
deps: bump pytest to &gt;=9.0.3 for CVE-2025-71176 (#479) (4f4ffd4)
deps: bump python-liquid to &gt;=2.2.0 for high severity CVE (#459) (60bad76)
deps: bump urllib3 to &gt;=2.7.0 for high severity CVEs (#457) (50c3cea)
deps: bump virtualenv to &gt;=20.36.1 for CVE-2026-22702 (#483) (8f10690)
deps: override minimatch to &gt;=9.0.6 (CVE-2026-26996) (#395) (ceb0b59)
deps: resolve 4 high-severity Dependabot security alerts (#393) (97f257d)
docs: exclude scenario.report.app from pdoc to unblock Publish Docs (#388) (3736c87)
examples: stabilize custom LLM judge criteria matching (#396) (f4b536c)
examples: stabilize vegetarian-agent parallel tests on python-ci (#389) (e40eee3)
examples: strengthen vegetarian-agent prompt to stabilize parallel tests (e40eee3)
examples: use positional index matching in custom judge examples (f4b536c)
judge: harden forceVerdict so discovery tools cannot leak (JS + Python) (#377) (0e2859f)
red-team: annotate H_attacker when post-hoc injection fires (#326, #334) (2896c97)
security: bump litellm to fix 4 high-severity CVEs (#411) (f6ff8a3)
security: patch CVE-2026-27903 in minimatch (#398) (b61cc60)
security: patch flatted prototype pollution via parse() (#421) (3a20e6c)
security: patch glob CLI command injection in lovable_clone npm lockfile (#413) (d1b3297)
security: patch glob CLI command injection in lovable_clone template npm lockfile (d1b3297)
security: patch picomatch ReDoS in lovable_clone npm lockfile (#409) (70a5ff9)
security: patch react-router XSS and open redirect CVEs (#418) (2b6797a)
security: patch rollup arbitrary file write via path traversal (#399) (55a0259)
security: patch rollup path traversal CVE (&gt;= 4.0.0, &lt; 4.59.0) (55a0259)
security: upgrade aiohttp to fix zip bomb and other CVEs (#417) (a747624)
security: upgrade black to fix arbitrary file write CVE (#403) (6583942)
security: upgrade black to fix arbitrary file write via cache file name (6583942)
security: upgrade mcp Python SDK to fix DoS and DNS rebinding CVEs (#406) (25e2e1c)
security: upgrade pyasn1 to fix DoS via unbounded recursion (2880a73)
security: upgrade pyasn1 to fix DoS vulnerabilities (#401) (2880a73)
security: upgrade pydantic-ai to fix SSRF vulnerability (#405) (f7ec414)
security: upgrade python-multipart to fix arbitrary file write CVE (#407) (1f2bb80)
security: upgrade starlette to fix DoS via Range header merging (#402) (11135a7)
security: upgrade urllib3 to fix decompression bomb CVEs (#404) (1b00ea2)
voice: render audio messages cleanly in the terminal (#497) (bb4ff9b)
voice: stub bot barge-in cancelled STT mid-pipeline, dropping user transcripts (#499) (5cb3596)

Miscellaneous

deps-dev: bump vite, @vitejs/plugin-react-swc and lovable-tagger (e43f938)
deps-dev: bump vite, @vitejs/plugin-react-swc and lovable-tagger in /python/examples/lovable_clone/template (#429) (e43f938)
deps: bump black from 25.1.0 to 26.3.1 in /python (#431) (07db40a)
deps: bump gitpython from 3.1.49 to 3.1.50 in /python (#447) (3fcd1fa)
deps: bump mako from 1.3.10 to 1.3.12 in /python (#448) (ab4d576)
deps: bump protobuf from 5.29.5 to 5.29.6 in /python (#433) (6ea6ed7)
deps: bump pyasn1 from 0.6.1 to 0.6.3 in /python (#432) (ee837e7)
deps: bump python-multipart from 0.0.20 to 0.0.26 in /python (#430) (0b29bbb)
deps: bump python-multipart from 0.0.26 to 0.0.27 in /python (#449) (e5467b3)
deps: bump starlette from 0.47.0 to 0.49.1 in /python (#434) (5263fed)
deps: bump urllib3 from 1.26.20 to 2.6.3 in /python (#435) (1793d64)
 ]]></description>
<link>https://tsecurity.de/de/3536640/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536640/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.27/</guid>
<pubDate>Thu, 21 May 2026 16:03:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.44.0-rc1]]></title> 
<description><![CDATA[feat(engine): support string comparator modifiers

Signed-off-by: Roberto Scolaro  ]]></description>
<link>https://tsecurity.de/de/3536106/IT+Sicherheit/Cybersecurity+Tools/0.44.0-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536106/IT+Sicherheit/Cybersecurity+Tools/0.44.0-rc1/</guid>
<pubDate>Thu, 21 May 2026 13:06:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.378.0]]></title> 
<description><![CDATA[What&#039;s Changed

fix(opentofu): strip v prefix in cooldown version comparison by @diofeher in #15044
Use POM last-modified as Gradle plugin release date fallback by @thavaahariharangit in #15006
Add blocked versions support to updater job by @kbukum1 in #14915
Add blocked versions support to dry-run script by @kbukum1 in #14916
Strip surrounding quotes from go.env values before writing by @yeikel in #15060
Require dependabot-deno in updater setup by @markhallen in #15064
fix(docker): use manifests endpoint for manifest-list digests by @devantler in #14691
Fix NuGet lock file tracking when no lock file exists by @brettfo in #15030
chore: Remove group_membership_enforcement experiment flag by @markhallen in #14861
redo recursive directory matching with logging by @brettfo in #15072
(fix) Handle Poetry group metadata without dependencies table by @julia-thorn in #14689
Fix cooldown breaking Docker updates when registry API calls fail by @Copilot in #14149
Upgrade Python versions and deprecate Python 3.9 by @kbukum1 in #15058
Remove NuGet.Core package dependency by @brettfo in #15037
NuGet: Add FindRootDirectory experiment to resolve root entry points by @brettfo in #15021
Sync uv Dockerfile Python versions with python ecosystem by @kbukum1 in #15087
Detect NoWarn NU1701 in SDK project discovery and warn during report by @brettfo in #15052
handle errant whitespace in global.json by @brettfo in #15086
fix(github_actions): align SHA updates with cooldown-filtered latest version by @thavaahariharangit in #15078
v0.378.0 by @dependabot-core-action-automation[bot] in #15095

New Contributors

@devantler made their first contribution in #14691
@julia-thorn made their first contribution in #14689

Full Changelog: v0.377.0...v0.378.0 ]]></description>
<link>https://tsecurity.de/de/3535685/IT+Sicherheit/Cybersecurity+Tools/v0.378.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535685/IT+Sicherheit/Cybersecurity+Tools/v0.378.0/</guid>
<pubDate>Thu, 21 May 2026 10:48:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.10.4: Merge pull request #36211 from wazuh/fix/4.10.4-workflows]]></title> 
<description><![CDATA[Backport 4.10.4: Update workflows names ]]></description>
<link>https://tsecurity.de/de/3535559/IT+Sicherheit/Cybersecurity+Tools/v4.10.4%3A+Merge+pull+request+%2336211+from+wazuh%2Ffix%2F4.10.4-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535559/IT+Sicherheit/Cybersecurity+Tools/v4.10.4%3A+Merge+pull+request+%2336211+from+wazuh%2Ffix%2F4.10.4-workflows/</guid>
<pubDate>Tue, 19 May 2026 18:49:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[suricata-7.0.16]]></title> 
<description><![CDATA[Tag Suricata 7.0.16 release ]]></description>
<link>https://tsecurity.de/de/3529591/IT+Sicherheit/Cybersecurity+Tools/suricata-7.0.16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529591/IT+Sicherheit/Cybersecurity+Tools/suricata-7.0.16/</guid>
<pubDate>Tue, 19 May 2026 16:55:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[suricata-8.0.5]]></title> 
<description><![CDATA[Tag Suricata 8.0.5 release ]]></description>
<link>https://tsecurity.de/de/3529590/IT+Sicherheit/Cybersecurity+Tools/suricata-8.0.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529590/IT+Sicherheit/Cybersecurity+Tools/suricata-8.0.5/</guid>
<pubDate>Tue, 19 May 2026 17:01:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.32.1]]></title> 
<description><![CDATA[What&#039;s Changed

[BlackboxBenchmarking] Replace INTERVAL duration fields with DOUBLE duration_seconds by @dylanjew in #5278

Full Changelog: v2.32.0...v2.32.1 ]]></description>
<link>https://tsecurity.de/de/3527139/IT+Sicherheit/Cybersecurity+Tools/v2.32.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527139/IT+Sicherheit/Cybersecurity+Tools/v2.32.1/</guid>
<pubDate>Mon, 18 May 2026 21:01:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[YellowKey: An Unexpected Backdoor into BitLocker, and Why You Should Be Paying Attention]]></title> 
<description><![CDATA[On May 12, 2026, a researcher operating under the handles Chaotic Eclipse and Nightmare-Eclipse dropped a working proof-of-concept on GitHub for a Windows zero-day called YellowKey. In short, it lets anyone with brief physical access to a BitLocker-protected Windows 11, Windows Server 2022, or Windows Server 2025 machine pop a command prompt with full read [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3525884/IT+Sicherheit/Cybersecurity+Tools/YellowKey%3A+An+Unexpected+Backdoor+into+BitLocker%2C+and+Why+You+Should+Be+Paying+Attention/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525884/IT+Sicherheit/Cybersecurity+Tools/YellowKey%3A+An+Unexpected+Backdoor+into+BitLocker%2C+and+Why+You+Should+Be+Paying+Attention/</guid>
<pubDate>Mon, 18 May 2026 13:59:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.377.0]]></title> 
<description><![CDATA[What&#039;s Changed

Implement sbt metadata finder by @AbhishekBhaskar in #15011
Bump NuGet.Client to release/7.6.x and pin dotnet-core to v10.0.8 by @JamieMagee in #14995
feat(opentofu): resolve locals references in module version constraints by @diofeher in #15009
simplify line indent detection by @brettfo in #14980
Fix flaky test: use unique git.store path to avoid parallel race condition by @brettfo in #14944
Update OpenTelemetry packages to 1.15.3 by @brettfo in #15029
Add SBT ecosystem to CI, Docker images, and runtime registration by @kbukum1 in #15012
v0.377.0 by @dependabot-core-action-automation[bot] in #15033

Full Changelog: v0.376.0...v0.377.0 ]]></description>
<link>https://tsecurity.de/de/3520917/IT+Sicherheit/Cybersecurity+Tools/v0.377.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520917/IT+Sicherheit/Cybersecurity+Tools/v0.377.0/</guid>
<pubDate>Sat, 16 May 2026 00:07:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.376.0]]></title> 
<description><![CDATA[What&#039;s Changed

Julia: filter yanked versions from get_available_versions by @IanButterworth in #14939
Add blob_oid metadata to manifests in dependency snapshots by @juxtin in #14857
Fix Maven released? check for non-jar packaging types (e.g., aar) by @kbukum1 in #14886
(Python): Move Pip file filtering to grapher by @Copilot in #14856
detect central package version scheme by @brettfo in #14927
allow insecure feeds if explicitly requested by @brettfo in #14891
don&#039;t warn on deprecated framework by @brettfo in #14936
migrate sln to slnx by @brettfo in #14943
fix(maven): parse Artifactory-style HTML listings for cooldown release dates by @thavaahariharangit in #14949
Fix Maven &quot;No files changed!&quot; error for externally managed dependency versions by @kbukum1 in #14885
Fix shell operator escaping in uv run_in_parsed_context by @kbukum1 in #14979
Add trailing slash when listing directories for Maven repositories by @apupier in #14870
opentofu: accept terraform_registry credentials for private registries by @diofeher in #14865
Update all lockfiles in multi-module Gradle projects by @v-HaripriyaC in #14879
Handle pub workspace resolution errors gracefully by @AbhishekBhaskar in #14940
Bump the prod-dependencies group across 2 directories with 16 updates by @dependabot[bot] in #14878
Bump nix from 2.34.5 to 2.34.7 by @JamieMagee in #14993
Upgrade swift to 6.3.1 by @yeikel in #14972
Nix: reject input names Nix&#039;s CLI can&#039;t parse by @JamieMagee in #14992
Enable pipe-operators, fetch-closure, and parse-toml-timestamps for Nix by @JamieMagee in #14994
Cache image builds with Buildx GHA cache backend by @JamieMagee in #14996
feat(bundler): enable Bundler 4 runtime support in helper flow by @thavaahariharangit in #14988
fix: do not cache EOF-backed Excon socket errors in RegistryClient by @thavaahariharangit in #15002
uv: don&#039;t parse non-requirements .txt support files as Python requirements by @Copilot in #14986
Implement sbt file updater and fix issues in file parser by @AbhishekBhaskar in #14999
Fix Composer V1 helper invocation: always return V2 from composer_version by @Copilot in #14712
Handle pubspec validation errors gracefully by @AbhishekBhaskar in #15000
npm_and_yarn: handle pnpm no-change lockfile updates by @thavaahariharangit in #15017
v0.376.0 by @dependabot-core-action-automation[bot] in #15014

New Contributors

@juxtin made their first contribution in #14857
@apupier made their first contribution in #14870

Full Changelog: v0.375.0...v0.376.0 ]]></description>
<link>https://tsecurity.de/de/3517798/IT+Sicherheit/Cybersecurity+Tools/v0.376.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517798/IT+Sicherheit/Cybersecurity+Tools/v0.376.0/</guid>
<pubDate>Thu, 14 May 2026 22:03:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[coverity-w20-4.14.6: Merge pull request #36060 from wazuh/fix/4791-cluster-path-validation]]></title> 
<description><![CDATA[Improve cluster file handling path validation in end_receiving_file ]]></description>
<link>https://tsecurity.de/de/3516792/IT+Sicherheit/Cybersecurity+Tools/coverity-w20-4.14.6%3A+Merge+pull+request+%2336060+from+wazuh%2Ffix%2F4791-cluster-path-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516792/IT+Sicherheit/Cybersecurity+Tools/coverity-w20-4.14.6%3A+Merge+pull+request+%2336060+from+wazuh%2Ffix%2F4791-cluster-path-validation/</guid>
<pubDate>Wed, 13 May 2026 15:05:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v4.10.4-rc1]]></title> 
<description><![CDATA[Manager
Changed

Masked authd.pass in configuration API responses for users without update permissions. (#34128)

Fixed

Fixed analysisd plugin decoder argument alignment. (#35222)
Fixed path traversal in authd via agent group name validation. (#35258)
Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling. (#35256)
Fixed DAPI callable resolution to restrict invocations to exposed resources only. (#35256)
Fixed admin protection in update user endpoint. (#35469)
Fixed protected settings checks when multiple  blocks are present. (#34690)
Restricted cluster file transfer write paths. (#34659)
Improved cluster file synchronization path handling by adding safe path joins. (#35008)
Fixed Vulnerability Detector offset DB update to occur only after processing (backport from 4.12.0). (#31901)

Agent
Added

Added detection of the -a never,task Audit rule in FIM whodata for Linux. (#34661)

Changed

Changed sync primitive disposal to stop and soften teardown failures. (#34680)

Fixed

Fixed Windows FIM Registry scan crash on non-null-terminated values. (#34679)

Other
Changed

Updated curl dependency to 8.12.1. (#34687)
Updated starlette dependency to 0.49.1. (#33383)
Upgraded Python embedded interpreter to 3.10.19. (#32790)
 ]]></description>
<link>https://tsecurity.de/de/3516545/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.10.4-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516545/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.10.4-rc1/</guid>
<pubDate>Thu, 14 May 2026 13:26:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.32.0]]></title> 
<description><![CDATA[What&#039;s Changed

[BlackboxBenchmarking] Remove dry run arg from aggregate_fuzzer_stats cron by @dylanjew in #5271
[build_manager] Raise exception on disk exhaustion instead of fatal exit by @PauloVLB in #5270
[BlackboxBenchmarking] Adds return True for aggregate fuzzer stats cron by @dylanjew in #5274
Fix butler deploy by setting CLOUDSDK_PYTHON by @ViniciustCosta in #5273
add project number from batch.yaml for creating batch jobs by @PauloVLB in #5275

Full Changelog: v2.31.0...v2.32.0 ]]></description>
<link>https://tsecurity.de/de/3515153/IT+Sicherheit/Cybersecurity+Tools/v2.32.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515153/IT+Sicherheit/Cybersecurity+Tools/v2.32.0/</guid>
<pubDate>Thu, 14 May 2026 00:02:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v1.163.0]]></title> 
<description><![CDATA[Release 1.163.0 ]]></description>
<link>https://tsecurity.de/de/3514781/IT+Sicherheit/Cybersecurity+Tools/v1.163.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514781/IT+Sicherheit/Cybersecurity+Tools/v1.163.0/</guid>
<pubDate>Wed, 13 May 2026 20:49:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.3]]></title> 
<description><![CDATA[What&#039;s Changed

Renamed AnypointOAuth2 detector&#039;s AnalysisInfo keys to make it consistent with its Analyzer by @MuneebUllahKhan222 in #4906
Rename AnalysisInfo field to SecretParts on detectors.Result by @mcastorina in #4911
Document SecretParts contract in detector-authoring docs by @mcastorina in #4912
Add a static check for detectors that don&#039;t set SecretParts by @mcastorina in #4913
Populate SecretParts on all detectors by @mcastorina in #4919
Make checksecretparts required in CI by @mcastorina in #4921
Deduplicate concurrent credential verification requests via singleflight by @kashifkhan0771 in #4314
log non-critical chunk errors at V(2).Info instead of Error by @johnelliott in #4928
[INS-320] Cloudinary detector by @MuneebUllahKhan222 in #4747
ci: bump JS actions to Node 24 majors (incl. CodeQL v4 + WIF auth v3) by @bryanbeverly in #4933
chore: bump golangci-lint-action v7 &rarr; v9 (Node 24) by @bryanbeverly in #4936
Add default Content-Type: application/json header for custom detector verification request by @MuneebUllahKhan222 in #4947
Make detector Result.SecretParts initialization stricter by @mcastorina in #4948
Add Pinecone API key detector by @dylanTruffle in #4917
adding customizable successRanges and rotatedRanges to customDetector by @jordanTunstill in #4892

Full Changelog: v3.95.2...v3.95.3 ]]></description>
<link>https://tsecurity.de/de/3508173/IT+Sicherheit/Cybersecurity+Tools/v3.95.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508173/IT+Sicherheit/Cybersecurity+Tools/v3.95.3/</guid>
<pubDate>Mon, 11 May 2026 20:38:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.31.0]]></title> 
<description><![CDATA[What&#039;s Changed

[BlackboxBenchmarking] Add daily cron job to aggregate fuzzer stats by @dylanjew in #5265

Full Changelog: v2.30.2...v2.31.0 ]]></description>
<link>https://tsecurity.de/de/3507772/IT+Sicherheit/Cybersecurity+Tools/v2.31.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507772/IT+Sicherheit/Cybersecurity+Tools/v2.31.0/</guid>
<pubDate>Mon, 11 May 2026 18:29:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Using the Extraction Agent in 2026: Compatibility, Signing, Firewall, and Extraction Tips]]></title> 
<description><![CDATA[Over the years, we have published several articles about the extraction agent. However, the underlying technology changes quickly, and incremental changes often have significant cumulative effects. As a result, many of our older posts are no longer relevant and can be misleading if followed to the letter today. While last year&rsquo;s recap, Installing and Troubleshooting [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3506735/IT+Sicherheit/Cybersecurity+Tools/Using+the+Extraction+Agent+in+2026%3A+Compatibility%2C+Signing%2C+Firewall%2C+and+Extraction+Tips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506735/IT+Sicherheit/Cybersecurity+Tools/Using+the+Extraction+Agent+in+2026%3A+Compatibility%2C+Signing%2C+Firewall%2C+and+Extraction+Tips/</guid>
<pubDate>Mon, 11 May 2026 13:00:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.8]]></title> 
<description><![CDATA[New Features

WAF: OpenAPI schema validation (#4097) @blotus

Improvements

WAF: enforce body size limitation (#4355) @blotus
Decision stream: move to chunked transfer by default (#4413) @blotus
cscli: add --quick flag to enroll command (#4350) @blotus
propose an alternative, cleaner configuration for appsec-config (#4397) @buixor

Bug Fixes

cscli metrics: don&#039;t attempt to create a DB client if there&#039;s no DB config (#4451) @blotus
papi: don&#039;t spam logs if chan is closed (#4439) @blotus
alerts: use single transaction when creating alert and all related items (#4438) @blotus
LAPI: enforce maximum body size for decompression

Chore / Deps

build(deps): bump the gomod group across 1 directory with 34 updates (#4453) @dependabot[bot]
build(deps): bump the github-actions group with 2 updates (#4447) @dependabot[bot]
build(deps): bump alpine from 3.21 to 3.23 in /build/docker in the docker group across 1 directory (#4441) @dependabot[bot]
build(deps): bump the github-actions group with 7 updates (#4443) @dependabot[bot]
build(deps): bump the uv group in /build/docker/test with 3 updates (#4442) @dependabot[bot]
db: add some missing indexes (#4435) @blotus
Dependencies update (#4412) @blotus
add PAPI metrics (#4411) @blotus
build(deps): bump github.com/aws/aws-lambda-go from 1.47.0 to 1.54.0 (#4402) @dependabot[bot]
build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#4403) @dependabot[bot]
build(deps): bump github.com/google/go-querystring from 1.1.0 to 1.2.0 (#4400) @dependabot[bot]
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#4404) @dependabot[bot]
build(deps): bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.42.3 to 1.42.25 (#4405) @dependabot[bot]
build(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.1 (#4381) @dependabot[bot]
build(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4388) @dependabot[bot]
build(deps): bump schneegans/dynamic-badges-action from 1.7.0 to 1.8.0 (#4393) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.6.0 to 8.0.0 (#4394) @dependabot[bot]
build(deps): bump github/codeql-action from 4.33.0 to 4.35.1 (#4395) @dependabot[bot]
update dependabot config (#4440) @blotus
build(deps): bump requests from 2.32.5 to 2.33.0 in /build/docker/test (#4389) @dependabot[bot]
build(deps): bump cryptography from 46.0.5 to 46.0.6 in /build/docker/test (#4391) @dependabot[bot]
build(deps): bump pygments from 2.19.2 to 2.20.0 in /build/docker/test (#4396) @dependabot[bot]

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3506172/IT+Sicherheit/Cybersecurity+Tools/v1.7.8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506172/IT+Sicherheit/Cybersecurity+Tools/v1.7.8/</guid>
<pubDate>Mon, 11 May 2026 09:57:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 6.0.1]]></title> 
<description><![CDATA[Malwoverview 6.0.1 ]]></description>
<link>https://tsecurity.de/de/3501521/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.0.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501521/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.0.1/</guid>
<pubDate>Tue, 12 Nov 2024 01:43:19 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 6.1.0]]></title> 
<description><![CDATA[Malwoverview 6.1.0.
This version:
[+] Introduces -vx option for Virus Exchange.[
[+] Introduces -ip option for IPView and BGPView.
[+] Introduces -O option to save samples in a central directory.
[+] Fixes multiple other issues. ]]></description>
<link>https://tsecurity.de/de/3501518/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.1.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501518/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.1.0/</guid>
<pubDate>Thu, 12 Dec 2024 15:34:48 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 6.1.1]]></title> 
<description><![CDATA[[+] Modifies the code to not require to registers all APIs at the first usage.
[+] Add a new section in the README (this file) about required APIs. ]]></description>
<link>https://tsecurity.de/de/3501516/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.1.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501516/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.1.1/</guid>
<pubDate>Sat, 14 Dec 2024 00:17:44 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 6.2]]></title> 
<description><![CDATA[This version:

Modifies Malware Bazaar option to use Auth-Key.
Modifies Threat Fox option to use Auth-Key.
 ]]></description>
<link>https://tsecurity.de/de/3501513/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501513/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+6.2/</guid>
<pubDate>Tue, 22 Jul 2025 02:57:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 7.0]]></title> 
<description><![CDATA[This version:
    * Introduces options to search for vulnerabilites on NIST.
    * Fixes multiples URLHaus options.
    * Removes InQuest and Virus Exchange options.
    * Fixes and modificates multiple minor issues.
    * Fixes Python requirements file.
    * Fixes setup.py file.  
 ]]></description>
<link>https://tsecurity.de/de/3501509/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501509/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.0/</guid>
<pubDate>Tue, 20 Jan 2026 02:15:15 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 7.1]]></title> 
<description><![CDATA[Malwoverview 7.1 | Vulncheck ]]></description>
<link>https://tsecurity.de/de/3501506/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501506/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1/</guid>
<pubDate>Tue, 10 Mar 2026 19:22:35 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 7.1.1]]></title> 
<description><![CDATA[Malwoverview 7.1.1 ]]></description>
<link>https://tsecurity.de/de/3501503/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501503/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1.1/</guid>
<pubDate>Tue, 10 Mar 2026 21:25:13 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 7.1.2]]></title> 
<description><![CDATA[Malwoverview 7.1.2 ]]></description>
<link>https://tsecurity.de/de/3501501/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501501/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+7.1.2/</guid>
<pubDate>Wed, 11 Mar 2026 02:17:34 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 8.0.0]]></title> 
<description><![CDATA[Malwoverview 8.0 (codename: Revolutions) ]]></description>
<link>https://tsecurity.de/de/3501497/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501497/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.0/</guid>
<pubDate>Sat, 21 Mar 2026 15:23:11 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malwoverview 8.0.1]]></title> 
<description><![CDATA[Malwoverview 8.0.1 ]]></description>
<link>https://tsecurity.de/de/3501494/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501494/IT+Sicherheit/Cybersecurity+Tools/Malwoverview+8.0.1/</guid>
<pubDate>Fri, 17 Apr 2026 01:49:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[4.10c]]></title> 
<description><![CDATA[Version ++4.10c (release)

afl-fuzz:

default power schedule is now EXPLORE, due a fix in fast schedules
explore is slightly better now.
fixed minor issues in the mutation engine, thanks to @futhewo for
reporting!
better deterministic fuzzing is now available, benchmarks have shown
to improve fuzzing. Enable with -D. Thanks to @kdsjZh for the PR!


afl-cc:

large rewrite by @SonicStark which fixes a few corner cases, thanks!
LTO mode now requires llvm 12+
workaround for ASAN with gcc_plugin mode


instrumentation:

LLVM 18 support, thanks to @devnexen!
Injection (SQL, LDAP, XSS) fuzzing feature now available, see
instrumentation/README.injections.md how to activate/use/expand.
compcov/LAF-intel:

floating point splitting bug fix by @hexcoder
due a bug in LLVM 17 integer splitting is disabled there!
when splitting floats was selected, integers were always split as well,
fixed to require AFL_LLVM_LAF_SPLIT_COMPARES or _ALL as it should


dynamic instrumentation filtering for LLVM NATIVE, thanks @mozilla!
see utils/dynamic_covfilter/README.md


qemu_mode:

plugins are now activated by default and a new module is included that
produces drcov compatible traces for lighthouse/lightkeeper/...
thanks to @JRomainG to submitting!


updated Nyx checkout (fixes a bug) and some QOL
updated the custom grammar mutator
document afl-cmin does not work on macOS (but afl-cmin.bash does)
 ]]></description>
<link>https://tsecurity.de/de/3501318/IT+Sicherheit/Cybersecurity+Tools/4.10c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501318/IT+Sicherheit/Cybersecurity+Tools/4.10c/</guid>
<pubDate>Sat, 03 Feb 2024 12:11:08 +0100</pubDate>
</item>
<item> 
<title><![CDATA[4.20c]]></title> 
<description><![CDATA[Version ++4.20c (release)
! A new forkserver communication model is now introduced. afl-fuzz is
backward compatible to old compiled targets if they are not built
for CMPLOG/Redqueen, but new compiled targets will not work with
old afl-fuzz versions!
! Recompile all targets that are instrumented for CMPLOG/Redqueen!

AFL++ now supports up to 4 billion coverage edges, up from 6 million.
New compile option: make PERFORMANCE=1 - this will enable special
CPU dependent optimizations that make everything more performant - but
the binaries will likely won&#039;t work on different platforms. Also
enables a faster hasher if the CPU requirements are met.
The persistent record feature (see config.h) was expanded to also
support replay, thanks to @quarta-qti !
afl-fuzz:

the new deterministic fuzzing feature is now activated by default,
deactivate with -z. Parameters -d and -D are ignored.
small improvements to CMPLOG/redqueen
workround for a bug with MOpt -L when used with -M - in the future
we will either remove or rewrite MOpt.
fix for -t xxx+ feature
-e extension option now saves the queue items, crashes, etc. with the
extension too
fixes for trimmming, correct -V time and reading stats on resume by eqv
thanks a lot!


afl-cc:

added collision free caller instrumentation to LTO mode. activate with
AFL_LLVM_LTO_CALLER=1. You can set a max depth to go through single
block functions with AFL_LLVM_LTO_CALLER_DEPTH (default 0)
fixes for COMPCOV/LAF and most other modules
fix for GCC_PLUGIN cmplog that broke on std::strings


afl-whatsup:

now also displays current average speed
small bugfixes


Fixes for aflpp custom mutator and standalone tool
Minor edits to afl-persistent-config
Prevent temporary files being left behind on aborted afl-whatsup
More CPU benchmarks added to benchmark/
 ]]></description>
<link>https://tsecurity.de/de/3501317/IT+Sicherheit/Cybersecurity+Tools/4.20c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501317/IT+Sicherheit/Cybersecurity+Tools/4.20c/</guid>
<pubDate>Sat, 13 Apr 2024 11:51:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[4.20c]]></title> 
<description><![CDATA[Version ++4.20c (release)
! A new forkserver communication model is now introduced. afl-fuzz is
backward compatible to old compiled targets if they are not built
for CMPLOG/Redqueen, but new compiled targets will not work with
old afl-fuzz versions!
! Recompile all targets that are instrumented for CMPLOG/Redqueen!

AFL++ now supports up to 4 billion coverage edges, up from 6 million.
New compile option: make PERFORMANCE=1 - this will enable special
CPU dependent optimizations that make everything more performant - but
the binaries will likely won&#039;t work on different platforms. Also
enables a faster hasher if the CPU requirements are met.
The persistent record feature (see config.h) was expanded to also
support replay, thanks to @quarta-qti !
afl-fuzz:

the new deterministic fuzzing feature is now activated by default,
deactivate with -z. Parameters -d and -D are ignored.
small improvements to CMPLOG/redqueen
workround for a bug with MOpt -L when used with -M - in the future
we will either remove or rewrite MOpt.
fix for -t xxx+ feature
-e extension option now saves the queue items, crashes, etc. with the
extension too
fixes for trimmming, correct -V time and reading stats on resume by eqv
thanks a lot!


afl-cc:

added collision free caller instrumentation to LTO mode. activate with
AFL_LLVM_LTO_CALLER=1. You can set a max depth to go through single
block functions with AFL_LLVM_LTO_CALLER_DEPTH (default 0)
fixes for COMPCOV/LAF and most other modules
fix for GCC_PLUGIN cmplog that broke on std::strings


afl-whatsup:

now also displays current average speed
small bugfixes


Fixes for aflpp custom mutator and standalone tool
Minor edits to afl-persistent-config
Prevent temporary files being left behind on aborted afl-whatsup
More CPU benchmarks added to benchmark/
 ]]></description>
<link>https://tsecurity.de/de/3501316/IT+Sicherheit/Cybersecurity+Tools/4.20c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501316/IT+Sicherheit/Cybersecurity+Tools/4.20c/</guid>
<pubDate>Sat, 13 Apr 2024 11:51:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.30c]]></title> 
<description><![CDATA[Version ++4.30c (release)
! afl-gcc and afl-clang funcionality is now removed !

afl-fuzz:

fastresume feature added. if you abort fuzzing and resume fuzzing
with -i - or AFL_AUTORESUME=1 and the target binary has not changed
then a dump will be loaded and the calibration phase skipped.
to disable this feature set AFL_NO_FASTRESUME=1
zlib compression is used if zlib is found at compile time
improved seed selection algorithm
added AFL_CUSTOM_MUTATOR_LATE_SEND=1 to call the custom send()
function after the target has been restarted.
because of bad math and undefined behaviour fixes we have to change
the CMPLOG map. YOU NEED TO RECOMPILE CMPLOG TARGETS
fixed custom_post_process for calibration
fixes for AFL_EXIT_ON_TIME and AFL_EXIT_WHEN_DONE, changed behaviour of
AFL_EXIT_WHEN_DONE to finish when really done :-)


frida_mode:

AFL_FRIDA_PERSISTENT_ADDR can now be be any reachable address not just
a function entry
AFL_DEBUG is now the same as AFL_FRIDA_VERBOSE
AFL_FRIDA_DEBUG_MAPS now works as expected


qemu_mode:

new hooks supported (optional), see qemu_mode/hooking_bridge - thanks to
@CowBoy4mH3LL


unicorn_mode:

fix install and forkserver (thanks aarnav!)
pin unicorn version


nyx_mode:

bugfixes


custom mutators:

custom_send_tcp custom mutator added, thanks to @dergoegge


afl-cc

fix to support pointless changes in LLVM 20
new runtime (!) variable: AFL_OLD_FORKSERVER to use the old vanilla
AFL type forkserver. Useful for symcc/symqemu/nautilus/etc. with
AFL_LLVM_INSTRUMENT=CLASSIC
new compile time variable: AFL_OPT_LEVEL to set a specific optimization
level, default is 3
correctly explain how to get the correct map size for large targets
small fix for weird LLVM defines in redhat


code formatting updated to llvm 18
improved custom_mutators/aflpp/standalone/aflpp-standalone
added custom_mutators/autotokens/standalone/autotokens-standalone
AFL++ headers are now installed to $PREFIX/include/afl
 ]]></description>
<link>https://tsecurity.de/de/3501314/IT+Sicherheit/Cybersecurity+Tools/v4.30c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501314/IT+Sicherheit/Cybersecurity+Tools/v4.30c/</guid>
<pubDate>Tue, 03 Dec 2024 15:48:51 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v4.21c]]></title> 
<description><![CDATA[Version ++4.21c (release)

afl-fuzz

fixed a regression in afl-fuzz that resulted in a 5-10% performace loss
do a switch from gettimeofday() to clock_gettime() which should be rather
three times faster. The reason for this is unknown.
new queue selection algorithm based on 2 core years of queue data
analysis. gives a noticable improvement on coverage although the results
seem counterintuitive :-)
added AFL_DISABLE_REDUNDANT for huge queues
added AFL_NO_SYNC environment variable that does what you think it does
fix AFL_PERSISTENT_RECORD
run custom_post_process after standard trimming
prevent filenames in the queue that have spaces
minor fix for FAST schedules
more frequent stats update when syncing (todo: check performance impact)
now timing of calibration, trimming and syncing is measured seperately,
thanks to @eqv!
-V timing is now accurately the fuzz time (without syncing), before
long calibration times and syncing could result in now fuzzing being
made when the time was already run out until then, thanks to @eqv!
fix -n uninstrumented mode when ending fuzzing
enhanced the ASAN configuration
make afl-fuzz use less memory with cmplog and fix a memleak


afl-cc:

re-enable i386 support that was accidently disabled
fixes for LTO and outdated afl-gcc mode for i386
fix COMPCOV split compare for old LLVMs
disable xml/curl/g_ string transform functions because we do not check
for null pointers ... TODO
ensure shared memory variables are visible in weird build setups
compatability to new LLVM 19 changes


afl-cmin

work with input files that have a space


afl-showmap

fix memory leak on shmem testcase usage (thanks to @ndrewh)
minor fix to collect coverage -C (thanks to @bet4it)


Fixed a shmem mmap bug (that rarely came up on MacOS)
libtokencap: script generate_libtoken_dict.sh added by @a-shvedov
 ]]></description>
<link>https://tsecurity.de/de/3501315/IT+Sicherheit/Cybersecurity+Tools/v4.21c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501315/IT+Sicherheit/Cybersecurity+Tools/v4.21c/</guid>
<pubDate>Sun, 09 Jun 2024 19:10:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.31c]]></title> 
<description><![CDATA[Version ++4.31c (release)

SAND mode added (docs/SAND.md) for more effecient fuzzing with sanitizers
(thanks to @wtdcode !)
afl-fuzz:

splicing phase is now DISABLED by default because research showed
it is counterproductive. New command line parameter -u to enable
it. Splicing is auto-enabled if two cycles without finds happen.
Python 3.13+ support
loose file and shared memory permissions on Android and iPhone


afl-cc:

LLVM 20 support (again - please don&#039;t change the API all the time ...)
-fsanitize=fuzzer now inserts libAFLDriver.a addtionally early to help
compiling if LLVMFuzzerTestOneOnput is in an .a archive
added _sanitizer_weak_hook* functions (in case that is helpful in
weird setups)
fix bug with large map sizes when multiple libraries are loaded after
the shared memory was obtained.


 ]]></description>
<link>https://tsecurity.de/de/3501313/IT+Sicherheit/Cybersecurity+Tools/v4.31c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501313/IT+Sicherheit/Cybersecurity+Tools/v4.31c/</guid>
<pubDate>Mon, 10 Feb 2025 13:43:11 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v4.32c]]></title> 
<description><![CDATA[Version ++4.32c (release)

Fixed a bug where after a fast restart of a full fuzzed corpus afl-fuzz
terminates with &quot;need at least one valid input seed that does not crash&quot;
Small improvements to afl-*-config
afl-fuzz:

memory leak fixes by @kcwu - thanks!
many more nits and small memory saves thanks to @kcwu
remove deprecated files from queue/.state
fix bitmap update function if no current trace is present
fix for afl_custom_queue_get
various small nits


afl-cc:

fix pass support for LLVM 20 (passes were run too early)
dropped plugin support for LLVM 13
fix AFL_OLD_FORKSERVER
various minor fixes


frida_mode:

fixes for new MacOS + M4 hardware


 ]]></description>
<link>https://tsecurity.de/de/3501312/IT+Sicherheit/Cybersecurity+Tools/v4.32c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501312/IT+Sicherheit/Cybersecurity+Tools/v4.32c/</guid>
<pubDate>Sat, 26 Apr 2025 15:55:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.33c]]></title> 
<description><![CDATA[Version ++4.33c (release)

afl-fuzz:

Use AFL_PRELOAD_DISCRIMINATE_FORKSERVER_PARENT if you use AFL_PRELOAD
to disable fork, see docs (thanks to @alexandredoyen29)
Fix for FAST power schedules (introduced in 4.32c) (thanks to @kcwu)
Colors for NO_UI output (thanks to @smoelius)
Fix potential sync issues when resuming sessions and when instances in a
campaign are restarted and skip entries that were synced from itself
(thanks to @kcwu for raising the issues and providing support!)
Fix for when fast resuming failed
more 64 bit archicture support by @maribu


afl-cc:

Added instrumenting hidden edges (approx 5% edges were not instrumented,
LLVM sancov overall misses 8% of edges compared to our implementation)
Note that is is currently only implemented for our PCGUARD plugin, not
LTO, CLASSIC, etc.!
Fix to make AFL_SAN_NO_INST work with gcc_plugin
MacOS aflpp driver compilation fix (-fsanitize=fuzzer implementation)
Make AFL_DUMP_MAP_SIZE work even if the target has sanitizer issues


qemuafl:

Better MIPS persistent mode support
AFL_EXITPOINT support added
AFL_QEMU_BLOCK_COV block coverage support added


afl-cmin:

New afl-cmin.py which is much faster, will be executed by default via
afl-cmin if it executes successfully (thanks to @kcwu!)
Nyx mode now fully works for minimizing (with afl-cmin.py which is
called by afl-cmin if python is available) - before the map size was
fixed and so large targets lost coverage.


New desocketing library: utils/libaflppdesock

Likely works when all other desocketing options fail


nyx_mode:

Properly determine map size


 ]]></description>
<link>https://tsecurity.de/de/3501311/IT+Sicherheit/Cybersecurity+Tools/v4.33c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501311/IT+Sicherheit/Cybersecurity+Tools/v4.33c/</guid>
<pubDate>Sat, 28 Jun 2025 22:32:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.34c]]></title> 
<description><![CDATA[Version ++4.34c (release)

IJON integration by @vi3tL0u1s - thanks a lot!!

see docs/IJON.md on how to use it


unicorn_mode:

UnicornAFL v3!! thanks to @wtdcode!


qemu_mode:

fix compilation for a few platforms


afl-fuzz

larger improvements to CMPLOG, thanks to @am009
scroll down before clearing the screen to not loose content
minor bug fixes


afl-showmap

fix -C parameter breakage introduced in v4.33c


afl-cc:

enabled LLVM 22
new env: AFL_COMPILER_LAUNCHER to allow ccache usage (thanks to @nbars)
fix a offset calculation bug in AFL++ PCGUARD
make AFL_DUMP_MAP_SIZE work for CLASSIC modes
fix a crash when running with LLVM 20 when compiling PCGUARD with LTO
fix deprecation warnings for LLVM 20+
fix 128 bit support for cmplog-switches pass
fix 32 bit cmplog support
skip blocks for instrumentation that are already instrumented


Building:

new NO_UNICORN and NO_QEMU and NO_FRIDA build options
build fixes for FreeBSD


custom_mutators:

added AIXCC Team Atlanta&#039;s zero-mq plugin to add testcases from remote


 ]]></description>
<link>https://tsecurity.de/de/3501310/IT+Sicherheit/Cybersecurity+Tools/v4.34c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501310/IT+Sicherheit/Cybersecurity+Tools/v4.34c/</guid>
<pubDate>Wed, 01 Oct 2025 09:46:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v4.35c]]></title> 
<description><![CDATA[Version ++4.35a (release)

GUIFuzz++ merged: Unleashing Grey-box Fuzzing on Desktop Graphical User
Interfacing Applications
https://futures.cs.utah.edu/papers/25ASE.pdf
afl-fuzz:

fix syncing issues with crashes and custom mutators by @AndyH-1
another attempt to kill every client, thanks to @leonasdev


afl-cc:

Huge refactor for default pcguard instrumentation, several minor and
medium bug fixes, complete hidden decision coverage
LTO: also added complete hidden decision coverage
Various small fixes by @nbars, thanks!
IJON fix to search for the necessary include
Allow compiling the gcc plugin with clang++, thanks to @exoosh
Fix for unusual bit sizes in cmplog-instructions-pass by @forzafedor


qemu_mode:

IJON support, thanks to @nj00001! see qemu_mode/README.md
leaner, less warnings, thanks to @McSinyx!


afl-tmin

fix custom trimmings, thanks to @renatahodovan!


custom mutators:

Gramatron: fixes + cjson switch by @CarvedCoder, fix by @jubnzv


 ]]></description>
<link>https://tsecurity.de/de/3501309/IT+Sicherheit/Cybersecurity+Tools/v4.35c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501309/IT+Sicherheit/Cybersecurity+Tools/v4.35c/</guid>
<pubDate>Fri, 26 Dec 2025 13:05:18 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v4.40c]]></title> 
<description><![CDATA[Version ++4.40c (release)

afl-fuzz:

FrameShift integrated and enabled by default, disable with
AFL_FRAMESHIFT_DISABLE and configure effort via
AFL_FRAMESHIFT_MAX_OVERHEAD. In extensive fuzzbench analysis at worst
(on average) it does nothing, at best it improves time to new coverage
and total coverage unlocked. https://arxiv.org/pdf/2507.05421
Thanks to @hgarrereyn for the PR!
Fixed several potential crashes when using IJON
added AFL_FORCE_FASTRESUME which will ignore the saved hash of the
target - but note it will only work if the coverage map size did not
change
prevent further executed instrumented programs by the fuzz target to
manipulate the coverage


afl-cc:

LLVM 22 support (they are again switching around include files ...)
g_/curl_/xml_ string support for COMPCOV, thanks to @Prajwal-kp-18
optimized hidden CFG instrumentation (don&#039;t instrument vector selects)
plugin optimization and fixes by @nbars, @kyakdan and @koltiradw
marked GCC plugins as unmaintained. We need someone who know gimple and
is willing to fix the plugin issues, workarounds for gcc bugs and
overall improve the plugin.
env AFL_LLVM_DENY_EXEC will abort any common exec calls


afl-cmin:

new implementation in C by @kcwu - it is currenlty not built though
because of maturity issues, e.g. does not work with Nyx
afl-cmin.py was changing behaviour to hash the original filenames,
this was reverted.
afl-cmin and afl-cmin.py honor AFL_SHA1_FILENAMES now


afl-showmap:

-f support added by Prajwal-kp-18 - thanks!
faster stream mode by @nbars


qemu_mode:

fix when AFL_EXITPOINT is not set, which could prevent detecting crashes


afl-plot:

multiple AFL++ out directories now supported, thanks to @Jay-1409 !


 ]]></description>
<link>https://tsecurity.de/de/3501308/IT+Sicherheit/Cybersecurity+Tools/v4.40c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501308/IT+Sicherheit/Cybersecurity+Tools/v4.40c/</guid>
<pubDate>Fri, 13 Mar 2026 10:24:49 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v2.27.0]]></title> 
<description><![CDATA[What&#039;s Changed

Swarming: Avoids mounting volume by @IvanBM18 in #5213
Add Swarming service for Remote Task Gate by @jardondiego in #5206
stack analyzer: Ignore v8::internal::Isolate::PushStackTraceAndDie by @backes in #5220
stack analyzer: Suppress more numbers by @mi-ac in #5221
Swarming: Fetch credential with scope &amp; Capitalize&#039;s OS in request (#5222) by @IvanBM18 in #5222

Full Changelog: v2.26.1...v2.27.0 ]]></description>
<link>https://tsecurity.de/de/3501307/IT+Sicherheit/Cybersecurity+Tools/v2.27.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501307/IT+Sicherheit/Cybersecurity+Tools/v2.27.0/</guid>
<pubDate>Tue, 31 Mar 2026 21:21:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.27.1]]></title> 
<description><![CDATA[What&#039;s Changed

Update FATAL_ERROR_REGEX to support missing file/line information by @backes in #5226
Bump the bundler group across 1 directory with 4 updates by @dependabot[bot] in #5216
Use job default arguments when checking for bad builds. by @backes in #5219

Full Changelog: v2.27.0...v2.27.1 ]]></description>
<link>https://tsecurity.de/de/3501306/IT+Sicherheit/Cybersecurity+Tools/v2.27.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501306/IT+Sicherheit/Cybersecurity+Tools/v2.27.1/</guid>
<pubDate>Thu, 02 Apr 2026 16:29:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.28.1]]></title> 
<description><![CDATA[What&#039;s Changed

Handle HTTP errors when fetching revisions by @hunsche in #5234

Full Changelog: v2.28.0...v2.28.1 ]]></description>
<link>https://tsecurity.de/de/3501304/IT+Sicherheit/Cybersecurity+Tools/v2.28.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501304/IT+Sicherheit/Cybersecurity+Tools/v2.28.1/</guid>
<pubDate>Tue, 07 Apr 2026 15:01:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.28.0]]></title> 
<description><![CDATA[What&#039;s Changed

Enforce same security flag in variant-based grouping by @ViniciustCosta in #5231

Full Changelog: v2.27.1...v2.28.0 ]]></description>
<link>https://tsecurity.de/de/3501305/IT+Sicherheit/Cybersecurity+Tools/v2.28.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501305/IT+Sicherheit/Cybersecurity+Tools/v2.28.0/</guid>
<pubDate>Mon, 06 Apr 2026 18:57:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.29.0]]></title> 
<description><![CDATA[What&#039;s Changed

Add Fuzzer.created_at field by @dylanjew in #5227
Swarming: Removes Unnecessary DB calls by @IvanBM18 in #5223
Add local butler script to upload a fuzzer to clusterfuzz by @dylanjew in #5236
Fix duplicate proto copyright generation by @dylanjew in #5241
Add test for utask_main FuzzingSession by @dylanjew in #5240
Add caching for the privileged group check by @ViniciustCosta in #5242
Add script to execute a fuzzing task directly by @jardondiego in #5233
Swarming: Calculates CF zip url in preprocess to be used in main by @IvanBM18 in #5235

New Contributors

@dylanjew made their first contribution in #5227

Full Changelog: v2.28.1...v2.29.0 ]]></description>
<link>https://tsecurity.de/de/3501303/IT+Sicherheit/Cybersecurity+Tools/v2.29.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501303/IT+Sicherheit/Cybersecurity+Tools/v2.29.0/</guid>
<pubDate>Mon, 13 Apr 2026 21:48:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.29.2]]></title> 
<description><![CDATA[What&#039;s Changed

Swarming: Avoids mounting directories at startup by @IvanBM18 in #5246

Full Changelog: v2.29.1...v2.29.2 ]]></description>
<link>https://tsecurity.de/de/3501301/IT+Sicherheit/Cybersecurity+Tools/v2.29.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501301/IT+Sicherheit/Cybersecurity+Tools/v2.29.2/</guid>
<pubDate>Mon, 20 Apr 2026 20:10:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.29.1]]></title> 
<description><![CDATA[What&#039;s Changed

Protect testcase task-log downloads by @M0nd0R in #5243
Add additional JobRun stats for blackbox fuzzers by @dylanjew in #5238

New Contributors

@M0nd0R made their first contribution in #5243

Full Changelog: v2.29.0...v2.29.1 ]]></description>
<link>https://tsecurity.de/de/3501302/IT+Sicherheit/Cybersecurity+Tools/v2.29.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501302/IT+Sicherheit/Cybersecurity+Tools/v2.29.1/</guid>
<pubDate>Wed, 15 Apr 2026 21:30:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.30.0]]></title> 
<description><![CDATA[What&#039;s Changed

[BlackboxAudit] Add butler script to download a fuzzer config by @dylanjew in #5244
Swarming: Fix double base64 encoding of secret_bytes in swarming tasks by @IvanBM18 in #5249
Fix Base image build by @javanlacerda in #5254
Custom logger for Swarming &amp; Removes circular dependency at logs.py by @IvanBM18 in #5247
immutable new folder by @javanlacerda in #5256
Update CHROME_CHECK_FAILURE_REGEX to match new format. by @letitz in #5253
Override centipede default rss_limit_mb for Google/chromium targets by @aakallam in #5255
Allow bots with RUN_TIMEOUT flash devices by @Xeicker in #5251

New Contributors

@Xeicker made their first contribution in #5251

Full Changelog: v2.29.2...v2.30.0 ]]></description>
<link>https://tsecurity.de/de/3501300/IT+Sicherheit/Cybersecurity+Tools/v2.30.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501300/IT+Sicherheit/Cybersecurity+Tools/v2.30.0/</guid>
<pubDate>Tue, 28 Apr 2026 00:31:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.30.1]]></title> 
<description><![CDATA[What&#039;s Changed

[BlackboxAudit] Only update fuzzer.source when creating a fuzzer by @dylanjew in #5252

Full Changelog: v2.30.0...v2.30.1 ]]></description>
<link>https://tsecurity.de/de/3501299/IT+Sicherheit/Cybersecurity+Tools/v2.30.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501299/IT+Sicherheit/Cybersecurity+Tools/v2.30.1/</guid>
<pubDate>Mon, 04 May 2026 19:51:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.30.2]]></title> 
<description><![CDATA[What&#039;s Changed

Swarming: Tag metrics with swarming runtime. by @IvanBM18 in #5248
[internal/LibFuzzer] Add option to set cwd to BUILD_DIR based on environment by @notvictorl in #5260
Handle broken symlinks in devcontainer set up by @dylanjew in #5250
Temp disable k8s e2e test by @ViniciustCosta in #5268
[BlackboxBenchmarking] Index the Fuzzer.builtin field by @dylanjew in #5263

New Contributors

@notvictorl made their first contribution in #5260

Full Changelog: v2.30.1...v2.30.2 ]]></description>
<link>https://tsecurity.de/de/3501298/IT+Sicherheit/Cybersecurity+Tools/v2.30.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501298/IT+Sicherheit/Cybersecurity+Tools/v2.30.2/</guid>
<pubDate>Wed, 06 May 2026 23:38:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[coverity-w19-4.14.6: Merge pull request #35866 from wazuh/fix/4713-api-log]]></title> 
<description><![CDATA[Validate user name in API ]]></description>
<link>https://tsecurity.de/de/3499780/IT+Sicherheit/Cybersecurity+Tools/coverity-w19-4.14.6%3A+Merge+pull+request+%2335866+from+wazuh%2Ffix%2F4713-api-log/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499780/IT+Sicherheit/Cybersecurity+Tools/coverity-w19-4.14.6%3A+Merge+pull+request+%2335866+from+wazuh%2Ffix%2F4713-api-log/</guid>
<pubDate>Mon, 04 May 2026 22:02:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.375.0]]></title> 
<description><![CDATA[What&#039;s Changed

Implement SBT UpdateChecker to fetch available versions by @AbhishekBhaskar in #14918
Handle Artifactory directory listings for Gradle release dates by @thavaahariharangit in #14938
feat: Add Deno support to Dependabot Omnibus Gem Spec by @kbukum1 in #14941
v0.375.0 by @dependabot-core-action-automation[bot] in #14942

Full Changelog: v0.374.0...v0.375.0 ]]></description>
<link>https://tsecurity.de/de/3497387/IT+Sicherheit/Cybersecurity+Tools/v0.375.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497387/IT+Sicherheit/Cybersecurity+Tools/v0.375.0/</guid>
<pubDate>Thu, 07 May 2026 22:41:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.374.0]]></title> 
<description><![CDATA[What&#039;s Changed

Force all invocations of dotnet msbuild to ignore response files by @brettfo in #14868
Implement sbt version and requirement classes by @AbhishekBhaskar in #14871
Fix &#039;Sourced from&#039; link formatting for scoped packages #13972 by @v-HaripriyaC in #14833
Implement sbt file fetcher by @AbhishekBhaskar in #14874
[npm] Add dependency relationships to graphs produced for npm, pnpm and yarn by @brrygrdn in #14876
Fix uv workspace dependency updating by @andre-dsm in #14627
Use GitHub Repo Activity API to fetch Nix branch tips by @JamieMagee in #14840
Implement sbt file parser by @AbhishekBhaskar in #14890
go_modules: Add go.work workspace support by @casey-robertson-paypal in #14909
Add Deno ecosystem support by @sbs44 in #14364
[bun] Implement a first pass on graphing the bun package manager by @brrygrdn in #14881
Consolidate docker_compose into docker directory by @Copilot in #13834
add type for package management method by @brettfo in #14880
Fix Poetry git dependencies with extras losing extras during freeze by @markhallen in #14887
Fix security_update_not_possible when a dependency is hoisted during the update by @jasonpaulos in #14884
opentofu: support OCI modules end-to-end by @diofeher in #14858
fix: builtin/terraform error while updating OpenTofu by @diofeher in #13628
v0.374.0 by @dependabot-core-action-automation[bot] in #14931

New Contributors

@andre-dsm made their first contribution in #14627
@casey-robertson-paypal made their first contribution in #14909
@sbs44 made their first contribution in #14364

Full Changelog: v0.373.0...v0.374.0 ]]></description>
<link>https://tsecurity.de/de/3496973/IT+Sicherheit/Cybersecurity+Tools/v0.374.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496973/IT+Sicherheit/Cybersecurity+Tools/v0.374.0/</guid>
<pubDate>Thu, 07 May 2026 19:37:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Release v1.162.0]]></title> 
<description><![CDATA[1.162.0 - 2026-05-07
### Added

pro: Improved support for tracking taint through nested functions. (LANG-95)
Added indexes to file targeting to improve performance of semgrepignore matching. (gh-27830)

### Changed

Faster JSON rule parsing: rule files in JSON format now parse roughly 5x faster end-to-end (measured ~134s &rarr; ~28s on a 382MB rule pack) by going through a new hand-written RFC 8259 parser instead of the previous JS-parser-based chain. (ENGINE-2725)
Scala projects are now identified for Supply Chain only by their root build.sbt, rather than treating each build.sbt as a different subproject. (SC-3293)
MCP semgrep_findings tool: added a refs parameter to filter findings by branch (defaults to the primary branch when not specified), and made autotriage_verdict optional so that findings without an AI verdict can also be returned. (engine-2723)

### Fixed

jsonnet: import and importstr now reject paths that resolve outside the
rule file&#039;s parent directory. (ENGINE-2727)
semgrep ci: redact URL-embedded credentials and Authorization header
values from git error messages and from the captured tracebacks sent to
the fail-open telemetry endpoint, preventing leaks of secrets like
CI_JOB_TOKEN from a failed git fetch in GitLab CI. Also closes
ENGINE-2731 (raw, unsanitized tracebacks in fail-open telemetry). (ENGINE-2728)
semgrep ci no longer transmits SCM tokens to the Semgrep Platform. (ENGINE-2729)
semgrep CLI: the on-disk log file (~/.semgrep/semgrep.log or $SEMGREP_LOG_FILE) now respects the requested log level instead of always being written at DEBUG. This narrows the surface for credentials to land on disk via CI runner filesystems or job artifacts; pass --debug to restore the previous behavior. (ENGINE-2730)
jsonnet rules: bound recursion in both rule loading and evaluation so a
malicious rule can no longer hang semgrep via mutually-recursive imports
or runtime function calls that recurse forever. (ENGINE-2727-dos)
Scala: Merging consecutive top-level package declarations into a single package path. (LANG-374)
Fixed PHP parse errors during highly-parallel parsing. (gh-6197)
Fixed Scala parse errors during highly-parallel parsing. (gh-6198)
Surface a clearer error from the MCP scan tool when metrics is off and auto config is specified (gh-11649)
Fixed unknown option error when spawning the MCP daemon (gh-11660)
 ]]></description>
<link>https://tsecurity.de/de/3496737/IT+Sicherheit/Cybersecurity+Tools/Release+v1.162.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496737/IT+Sicherheit/Cybersecurity+Tools/Release+v1.162.0/</guid>
<pubDate>Thu, 07 May 2026 18:03:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.8-rc1]]></title> 
<description><![CDATA[New Features

WAF: OpenAPI schema validation (#4097) @blotus

Improvements

WAF: enforce body size limitation (#4355) @blotus
Decision stream: move to chunked transfer by default (#4413) @blotus
cscli: add --quick flag to enroll command (#4350) @blotus
propose an alternative, cleaner configuration for appsec-config (#4397) @buixor

Bug Fixes

cscli metrics: don&#039;t attempt to create a DB client if there&#039;s no DB config (#4451) @blotus
papi: don&#039;t spam logs if chan is closed (#4439) @blotus
alerts: use single transaction when creating alert and all related items (#4438) @blotus

Chore / Deps

build(deps): bump the gomod group across 1 directory with 34 updates (#4453) @dependabot[bot]
build(deps): bump the github-actions group with 2 updates (#4447) @dependabot[bot]
build(deps): bump alpine from 3.21 to 3.23 in /build/docker in the docker group across 1 directory (#4441) @dependabot[bot]
build(deps): bump the github-actions group with 7 updates (#4443) @dependabot[bot]
build(deps): bump the uv group in /build/docker/test with 3 updates (#4442) @dependabot[bot]
db: add some missing indexes (#4435) @blotus
Dependencies update (#4412) @blotus
add PAPI metrics (#4411) @blotus
build(deps): bump github.com/aws/aws-lambda-go from 1.47.0 to 1.54.0 (#4402) @dependabot[bot]
build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#4403) @dependabot[bot]
build(deps): bump github.com/google/go-querystring from 1.1.0 to 1.2.0 (#4400) @dependabot[bot]
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#4404) @dependabot[bot]
build(deps): bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.42.3 to 1.42.25 (#4405) @dependabot[bot]
build(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.1 (#4381) @dependabot[bot]
build(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4388) @dependabot[bot]
build(deps): bump schneegans/dynamic-badges-action from 1.7.0 to 1.8.0 (#4393) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.6.0 to 8.0.0 (#4394) @dependabot[bot]
build(deps): bump github/codeql-action from 4.33.0 to 4.35.1 (#4395) @dependabot[bot]
update dependabot config (#4440) @blotus
build(deps): bump requests from 2.32.5 to 2.33.0 in /build/docker/test (#4389) @dependabot[bot]
build(deps): bump cryptography from 46.0.5 to 46.0.6 in /build/docker/test (#4391) @dependabot[bot]
build(deps): bump pygments from 2.19.2 to 2.20.0 in /build/docker/test (#4396) @dependabot[bot]

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3490278/IT+Sicherheit/Cybersecurity+Tools/v1.7.8-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490278/IT+Sicherheit/Cybersecurity+Tools/v1.7.8-rc1/</guid>
<pubDate>Tue, 05 May 2026 17:54:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[1.0]]></title> 
<description><![CDATA[Weblogic RCE CVE 2018 2894 ]]></description>
<link>https://tsecurity.de/de/3487998/IT+Sicherheit/Cybersecurity+Tools/1.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487998/IT+Sicherheit/Cybersecurity+Tools/1.0/</guid>
<pubDate>Thu, 26 Jul 2018 19:15:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.0]]></title> 
<description><![CDATA[Files JPEG -&gt; JPG + Tag v2 ]]></description>
<link>https://tsecurity.de/de/3487997/IT+Sicherheit/Cybersecurity+Tools/2.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487997/IT+Sicherheit/Cybersecurity+Tools/2.0/</guid>
<pubDate>Sat, 17 Nov 2018 14:40:12 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2022.1 - PayloadsAllTheThings - INTELWRITER]]></title> 
<description><![CDATA[A long due release with all the new payloads and techniques from the last 3 years.
Lots of new things happened in the Methodology and Resources folder, check it out if you like Internal Pentesting and Active Directory 😉 ]]></description>
<link>https://tsecurity.de/de/3487996/IT+Sicherheit/Cybersecurity+Tools/2022.1+-+PayloadsAllTheThings+-+INTELWRITER/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487996/IT+Sicherheit/Cybersecurity+Tools/2022.1+-+PayloadsAllTheThings+-+INTELWRITER/</guid>
<pubDate>Thu, 30 Jun 2022 16:41:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.3: new prompts]]></title> 
<description><![CDATA[
Design new prompt interaction.

Follow msfconsole type of prompt interaction.
Add auto-complete functions


Prompt optimization for better stability.

This version is for chatGPT plus members. GPT-4 is used.


 ]]></description>
<link>https://tsecurity.de/de/3487995/IT+Sicherheit/Cybersecurity+Tools/v0.3%3A+new+prompts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487995/IT+Sicherheit/Cybersecurity+Tools/v0.3%3A+new+prompts/</guid>
<pubDate>Fri, 14 Apr 2023 08:45:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.4 logging]]></title> 
<description><![CDATA[In v0.4, the test report can be automatically logged and generated now. More details in the documentation.

Add logging
Fix some minor login issue.
 ]]></description>
<link>https://tsecurity.de/de/3487994/IT+Sicherheit/Cybersecurity+Tools/v0.4+logging/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487994/IT+Sicherheit/Cybersecurity+Tools/v0.4+logging/</guid>
<pubDate>Sat, 22 Apr 2023 11:45:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.5]]></title> 
<description><![CDATA[Add new local reasoning function. Now the command more will lead to a new reasoning section, which allows the user dig into the local subtask. ]]></description>
<link>https://tsecurity.de/de/3487993/IT+Sicherheit/Cybersecurity+Tools/v0.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487993/IT+Sicherheit/Cybersecurity+Tools/v0.5/</guid>
<pubDate>Wed, 26 Apr 2023 17:29:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.6: OpenAI API Support]]></title> 
<description><![CDATA[The new version includes support for OpenAI API.
More details will be released soon in the README documentation. ]]></description>
<link>https://tsecurity.de/de/3487992/IT+Sicherheit/Cybersecurity+Tools/v0.6%3A+OpenAI+API+Support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487992/IT+Sicherheit/Cybersecurity+Tools/v0.6%3A+OpenAI+API+Support/</guid>
<pubDate>Sun, 30 Apr 2023 16:56:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.7: official OpenAI API support]]></title> 
<description><![CDATA[The latest version contains two connection approaches:

ChatGPT Plus
OpenAI API

Run python3 test_connection.py to check if you have the proper access to either of them. More details in documentation. ]]></description>
<link>https://tsecurity.de/de/3487991/IT+Sicherheit/Cybersecurity+Tools/v0.7%3A+official+OpenAI+API+support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487991/IT+Sicherheit/Cybersecurity+Tools/v0.7%3A+official+OpenAI+API+support/</guid>
<pubDate>Mon, 01 May 2023 17:58:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.8 Allow users to save sessions and continue]]></title> 
<description><![CDATA[If the user is using cookie login, they can save the sessions and continue from the previous tests now.
The test results are stored under the test_history directory. ]]></description>
<link>https://tsecurity.de/de/3487990/IT+Sicherheit/Cybersecurity+Tools/v0.8+Allow+users+to+save+sessions+and+continue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487990/IT+Sicherheit/Cybersecurity+Tools/v0.8+Allow+users+to+save+sessions+and+continue/</guid>
<pubDate>Fri, 12 May 2023 15:46:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.9: support Local LLM and custom API endpoint]]></title> 
<description><![CDATA[In this version, local LLMs are supported and users can create their custom API endpoints for the LLMs.
For more details, please refer to the examples of OpenAI API endpoint under pentestgpt/utils/APIs.
In v0.9.1, a bug in the previous version is fixed. ]]></description>
<link>https://tsecurity.de/de/3487989/IT+Sicherheit/Cybersecurity+Tools/v0.9%3A+support+Local+LLM+and+custom+API+endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487989/IT+Sicherheit/Cybersecurity+Tools/v0.9%3A+support+Local+LLM+and+custom+API+endpoint/</guid>
<pubDate>Tue, 25 Jul 2023 18:40:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2024.1 - PayloadsAllTheThings - CHIPMUNKFEED]]></title> 
<description><![CDATA[2 years after the latest release, it is time for a new one 🥳
Many pages have been updated with new payloads and descriptions.
Every pages under &quot;Methodology and Resources&quot; have been moved in their own repository (InternalAllTheThings)
This repository is now available as a website with nice features such as a &quot;complete search bar&quot;, &quot;dark/light mode&quot;, and buttons to share a specific page on your favorite social networks.
The &quot;AllTheThings&quot; family is expanding, check out the other projects

InternalAllTheThings
HardwareAllTheThings
 ]]></description>
<link>https://tsecurity.de/de/3487988/IT+Sicherheit/Cybersecurity+Tools/2024.1+-+PayloadsAllTheThings+-+CHIPMUNKFEED/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487988/IT+Sicherheit/Cybersecurity+Tools/2024.1+-+PayloadsAllTheThings+-+CHIPMUNKFEED/</guid>
<pubDate>Fri, 26 Apr 2024 16:50:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2019.1 - Kali Linux Repository - GLOBALSHIP]]></title> 
<description><![CDATA[PayloadsAllTheThings is now ready for the Kali Linux repository.
You can install it with apt install payloadsallthethings.
Thanks to @g0tmi1k ]]></description>
<link>https://tsecurity.de/de/3487987/IT+Sicherheit/Cybersecurity+Tools/2019.1+-+Kali+Linux+Repository+-+GLOBALSHIP/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487987/IT+Sicherheit/Cybersecurity+Tools/2019.1+-+Kali+Linux+Repository+-+GLOBALSHIP/</guid>
<pubDate>Fri, 26 Apr 2024 16:53:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.13.0 Official Support For GPT4o]]></title> 
<description><![CDATA[What&#039;s Changed

format code with black by @deepsource-autofix in #146
Fix typo in argument name by @Anth0rx in #147
Fast bugfix by @RiccardoRobb in #154
README Fix by @RiccardoRobb in #155
Info Fix by @RiccardoRobb in #156
style: format code with Black by @deepsource-autofix in #157
Fix start with no API KEY by @RiccardoRobb in #159
Fix session bug by @RiccardoRobb in #158
Add description for selection options in README by @RiccardoRobb in #163
Add description for the &quot;choose of information&quot; selection by @RiccardoRobb in #162
style: format code with Black by @deepsource-autofix in #161
style: format code with Black by @deepsource-autofix in #160
Typos and cURL fix by @RiccardoRobb in #166
Update prompt_class_v2.py by @zhangj111 in #167
Langfuse by @GreyDGL in #172
🐛 Unable to use GPT4all with default setup by @wouterdebruijn in #179
update readme and fix for key binding by @GreyDGL in #180
fix typos by @RainRat in #186
Fix a tiny typo in main.py by @sadra-barikbin in #193
Poetry Upgrade by @GreyDGL in #201
Poetry upgrade by @GreyDGL in #202
fix: 🐛 fix default models used by @GreyDGL in #205
Add support for customizing API Base URL using environment variables by @wyl2003 in #207
Gpt4all Dev by @GreyDGL in #217
fix typos by @RainRat in #216
OPENAI_BASEURL environment not working fixes by @Kuromesi in #221
Gemini dev by @davidbakerrobinson in #225
fix: 🐛 fix OPENAI key setting issue and update readme by @GreyDGL in #228
fix typos by @RainRat in #223
Vision Model by @GreyDGL in #229
Vision by @GreyDGL in #230

New Contributors

@Anth0rx made their first contribution in #147
@RiccardoRobb made their first contribution in #154
@zhangj111 made their first contribution in #167
@wouterdebruijn made their first contribution in #179
@RainRat made their first contribution in #186
@sadra-barikbin made their first contribution in #193
@wyl2003 made their first contribution in #207
@Kuromesi made their first contribution in #221
@davidbakerrobinson made their first contribution in #225

Full Changelog: v0.9.1...v0.13.0 ]]></description>
<link>https://tsecurity.de/de/3487986/IT+Sicherheit/Cybersecurity+Tools/v0.13.0+Official+Support+For+GPT4o/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487986/IT+Sicherheit/Cybersecurity+Tools/v0.13.0+Official+Support+For+GPT4o/</guid>
<pubDate>Tue, 14 May 2024 12:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.14.0]]></title> 
<description><![CDATA[What&#039;s Changed

Openai compatability by @GreyDGL in #231
Support gpt4o by @GreyDGL in #233

Full Changelog: v0.13.0...v0.14.0 ]]></description>
<link>https://tsecurity.de/de/3487985/IT+Sicherheit/Cybersecurity+Tools/v0.14.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487985/IT+Sicherheit/Cybersecurity+Tools/v0.14.0/</guid>
<pubDate>Wed, 15 May 2024 10:27:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2024.2 - PayloadsAllTheThings - BOOKSQUIRREL]]></title> 
<description><![CDATA[🎉 Major Milestone: 8 Years of Progress &amp; a New Beginning
After 8 years since this project first came to life, today marks an incredible milestone
The first release of PayloadsAllTheThings as an Ebook on Leanpub.
Over the years, we&#039;ve grown, learned, and built something amazing together.
This release represents not just how far we&rsquo;ve come, but also the start of an exciting new chapter.
About the release:

Most pages have been completely rewritten
Summaries and links have been fixed
References are consistently formatted across all pages.
Updates on the repository will be reflected on the PDF version at every new release
 ]]></description>
<link>https://tsecurity.de/de/3487984/IT+Sicherheit/Cybersecurity+Tools/2024.2+-+PayloadsAllTheThings+-+BOOKSQUIRREL/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487984/IT+Sicherheit/Cybersecurity+Tools/2024.2+-+PayloadsAllTheThings+-+BOOKSQUIRREL/</guid>
<pubDate>Wed, 04 Dec 2024 12:10:42 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v8.25.1]]></title> 
<description><![CDATA[Changelog

d1c7759 fix(detect): test all allowlists (#1845)

Big thanks @rgmz ]]></description>
<link>https://tsecurity.de/de/3487983/IT+Sicherheit/Cybersecurity+Tools/v8.25.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487983/IT+Sicherheit/Cybersecurity+Tools/v8.25.1/</guid>
<pubDate>Wed, 30 Apr 2025 15:52:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.26.0]]></title> 
<description><![CDATA[Changelog

78eebac Percent/URL Decoding Support (#1831)
6f967ca fix(kubernetes): remove slow element from pat (#1848)
88f56d3 feat: identify slow file (#1479)
9609928 rm 1password detect test since we test it in cfg gen
23cb69f feat(rules): Add 1Password secret key detection (#1834)

Calling this one @bplaxco&#039;s release as he introduced a really clever method for mixed decoding without sacrificing too much performance. As I stated in his PR, I think he&#039;s either a wizard or some time traveling AI. Dude is wicked smaht
Anyways, Gitleaks now supports the following decoders: hex, percent(url enconding), and b64. It&#039;s relatively straight forward to add a new decoder so if you&#039;re motivated, community contributions are welcomed!
Here&#039;s an example:
~/code/gitleaks-org/gitleaks (master) cat decode.txt
text below
aGVsbG8sIHdvcmxkIQ%3D%3D%0A
text above
~/code/gitleaks-org/gitleaks (master) ./gitleaks dir decode.txt --max-decode-depth=2 --log-level=debug

    ○
    │╲
    │ ○
    ○ ░
    ░    gitleaks

4:08PM DBG using stdlib regex engine
4:08PM DBG unable to load gitleaks config from decode.txt/.gitleaks.toml since --source=decode.txt is a file, using default config
4:08PM DBG found .gitleaksignore file: .gitleaksignore
4:08PM DBG segment found: original=[29,38] pos=[29,38]: &quot;%3D%3D%0A&quot; -&gt; &quot;==\n&quot;
4:08PM DBG segment found: original=[11,38] pos=[11,31]: &quot;aGVsbG8sIHdvcmxkIQ==&quot; -&gt; &quot;hello, world!&quot;
4:08PM INF scanned ~50 bytes (50 bytes) in 1.5ms
4:08PM INF no leaks found
 ]]></description>
<link>https://tsecurity.de/de/3487982/IT+Sicherheit/Cybersecurity+Tools/v8.26.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487982/IT+Sicherheit/Cybersecurity+Tools/v8.26.0/</guid>
<pubDate>Mon, 12 May 2025 23:13:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.27.0]]></title> 
<description><![CDATA[Changelog

782f310 Archive support (#1872)
489d13c Update README.md
d29ee55 Reduce aws-access-token false positives (#1876)
611db65 Set pass_filenames to false for Docker hook (#1850)
0589ae0 unicode decoding (#1854)
82f7e32 Diagnostics (#1856)
f97a9ee chore: include decoder in debug log (#1853)

Got another @bplaxco release. Cheers!
Archive Scanning
Sometimes secrets are packaged within archive files like zip files or tarballs,
making them difficult to discover. Now you can tell gitleaks to automatically
extract and scan the contents of archives. The flag --max-archive-depth
enables this feature for both dir and git scan types. The default value of
&quot;0&quot; means this feature is disabled by default.
Recursive scanning is supported since archives can also contain other archives.
The --max-archive-depth flag sets the recursion limit. Recursion stops when
there are no new archives to extract, so setting a very high max depth just
sets the potential to go that deep. It will only go as deep as it needs to.
The findings for secrets located within an archive will include the path to the
file inside the archive. Inner paths are separated with !.
Example finding (shortened for brevity):
Finding:     DB_PASSWORD=8ae31cacf141669ddfb5da
...
File:        testdata/archives/nested.tar.gz!archives/files.tar!files/.env.prod
Line:        4
Commit:      6e6ee6596d337bb656496425fb98644eb62b4a82
...
Fingerprint: 6e6ee6596d337bb656496425fb98644eb62b4a82:testdata/archives/nested.tar.gz!archives/files.tar!files/.env.prod:generic-api-key:4
Link:        https://github.com/leaktk/gitleaks/blob/6e6ee6596d337bb656496425fb98644eb62b4a82/testdata/archives/nested.tar.gz

This means a secret was detected on line 4 of files/.env.prod. which is in
archives/files.tar which is in testdata/archives/nested.tar.gz.
Currently supported formats:
The compression
and archive
formats supported by mholt&#039;s archives package
are supported. ]]></description>
<link>https://tsecurity.de/de/3487981/IT+Sicherheit/Cybersecurity+Tools/v8.27.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487981/IT+Sicherheit/Cybersecurity+Tools/v8.27.0/</guid>
<pubDate>Sun, 01 Jun 2025 18:43:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.27.1]]></title> 
<description><![CDATA[Changelog

80468ef Merge branch &#039;master&#039; of github.com:gitleaks/gitleaks
ef82237 fix(atlassian): reduce false-positives for v1 pattern (#1892)
2463f11 Fix log suppresion issue (#1887)
6f251ee Added Heroku API Key New Version (#1883)
20f9a1d Add Platform Bitbucket (#1886)
722ce82 Add Platform Gitea (#1884)
79780b8 Merge branch &#039;master&#039; of github.com:gitleaks/gitleaks
c5683ca prevent default warn message when max-archive-depth not set (#1881)
0357c3c prevent default warn message when max-archive-depth not set
 ]]></description>
<link>https://tsecurity.de/de/3487980/IT+Sicherheit/Cybersecurity+Tools/v8.27.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487980/IT+Sicherheit/Cybersecurity+Tools/v8.27.1/</guid>
<pubDate>Sun, 08 Jun 2025 04:03:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.27.2]]></title> 
<description><![CDATA[Changelog

c7acf33 Merge branch &#039;master&#039; of github.com:gitleaks/gitleaks
9faaa4a Add experimental allowlist optimizations (#1731)
79068b3 Detect Notion Public API Keys #1889 (#1890)
 ]]></description>
<link>https://tsecurity.de/de/3487979/IT+Sicherheit/Cybersecurity+Tools/v8.27.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487979/IT+Sicherheit/Cybersecurity+Tools/v8.27.2/</guid>
<pubDate>Mon, 09 Jun 2025 02:42:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.4.160-20250625]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/7e746b87c5a822fca75e737ce99067cbe3a029c7/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Get ready for .160 by @TOoSmOotH in #14614
improve consistency by @jertel in #14619
Update soup by @TOoSmOotH in #14621
Cogburn/playbooks by @coreyogburn in #14623
logstash isn&#039;t running on receivers or manager when kafka is the glob&hellip; by @reyesj2 in #14629
Add RulesetName to Rule Repos by @coreyogburn in #14639
Add parsing for Playbook by @defensivedepth in #14638
Tighten parsing by @defensivedepth in #14643
Backport Hotfix to dev by @jertel in #14651
use zeek network.community_id when available by @reyesj2 in #14668
FIX: Improve annotation for Elasticsearch index deletion #14682 by @dougburks in #14683
FIX: so-suricata-testrule should disable pcap logging #14685 by @dougburks in #14687
FIX: so-elasticsearch-ilm-start needs shebang #14688 by @dougburks in #14689
add echo to end of so-elasticsearch-ilm-start and so-elasticsearch-ilm-stop by @dougburks in #14691
Use Stable branch by @defensivedepth in #14697
add so-elasticsearch-index-growth by @reyesj2 in #14698
fix system integration time overwrite and delete unused ingest pipeline by @reyesj2 in #14676
Updated Playbook Repo Config by @coreyogburn in #14700
upgrade registry to 3.0.0 by @jertel in #14701
update to new config location by @jertel in #14711
enable STS for browser redirects by @jertel in #14714
Add support for Airgap for Playbooks by @defensivedepth in #14718
Airgap tweaks by @defensivedepth in #14719
Supress alerts by @defensivedepth in #14721
Add nsm bind by @defensivedepth in #14722
Create dir if needed by @defensivedepth in #14723
Add support for dns.resolved_ip by @defensivedepth in #14759
refactor airgap playbook to eliminate dupe code and shrink ISO by @jertel in #14764
fix logging by @jertel in #14765
change salt upgrade process by @m0duspwnens in #14770
Revert &quot;change salt upgrade process&quot; by @m0duspwnens in #14771
2.4.160 by @TOoSmOotH in #14772

Full Changelog: 2.4.150-20250522...2.4.160-20250615 ]]></description>
<link>https://tsecurity.de/de/3487978/IT+Sicherheit/Cybersecurity+Tools/2.4.160-20250625/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487978/IT+Sicherheit/Cybersecurity+Tools/2.4.160-20250625/</guid>
<pubDate>Thu, 26 Jun 2025 13:33:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.28.0]]></title> 
<description><![CDATA[Changelog

4fb4382 cant count
b1c9c7e Composite rules (#1905)
72977e4 feat: add Anthropic API key detection (#1910)
7b02c98 fix(git): handle port (#1912)
2a7bcff dont prematurely calculate fragment newlines (#1909)
bd79c3e feat(allowlist): promote optimizations (#1908)
7fb4eda Fix: CVEs on go and go crypto (#1868)
a044b81 feat: add artifactory reference token and api key detection (#1906)
bf380d4 silly
f487f85 Update gitleaks.yml
958f55a add just like that, no leaks

Optimizations
#1909 waits to find newlines until a match. This ends up saving a boat load of time since before we were finding newlines for every fragment regardless if a rule matched or not.
#1908 promoted @rgmz excellent stopword optimization
Composite Rules (Multi-part or required Rules) #1905
In v8.28.0 Gitleaks introduced composite rules, which are made up of a single &quot;primary&quot; rule and one or more auxiliary or required rules. To create a composite rule, add a [[rules.required]] table to the primary rule specifying an id and optionally withinLines and/or withinColumns proximity constraints. A fragment is a chunk of content that Gitleaks processes at once (typically a file, part of a file, or git diff), and proximity matching instructs the primary rule to only report a finding if the auxiliary required rules also find matches within the specified area of the fragment.
Proximity matching: Using the withinLines and withinColumns fields instructs the primary rule to only report a finding if the auxiliary required rules also find matches within the specified proximity. You can set:

withinLines: N - required findings must be within N lines (vertically)
withinColumns: N - required findings must be within N characters (horizontally)
Both - creates a rectangular search area (both constraints must be satisfied)
Neither - fragment-level matching (required findings can be anywhere in the same fragment)

Here are diagrams illustrating each proximity behavior:
p = primary captured secret
a = auxiliary (required) captured secret
fragment = section of data gitleaks is looking at


    *Fragment-level proximity*               
    Any required finding in the fragment
          ┌────────┐                       
   ┌──────┤fragment├─────┐                 
   │      └──────┬─┤     │ ┌───────┐       
   │             │a│◀────┼─│✓ MATCH│       
   │          ┌─┐└─┘     │ └───────┘       
   │┌─┐       │p│        │                 
   ││a│    ┌─┐└─┘        │ ┌───────┐       
   │└─┘    │a│◀──────────┼─│✓ MATCH│       
   └─▲─────┴─┴───────────┘ └───────┘       
     │    ┌───────┐                        
     └────│✓ MATCH│                        
          └───────┘                        
                                           
                                           
   *Column bounded proximity*
   `withinColumns = 3`                    
          ┌────────┐                       
   ┌────┬─┤fragment├─┬───┐                 
   │      └──────┬─┤     │ ┌───────────┐   
   │    │        │a│◀┼───┼─│+1C ✓ MATCH│   
   │          ┌─┐└─┘     │ └───────────┘   
   │┌─┐ │     │p│    │   │                 
┌──▶│a│  ┌─┐  └─┘        │ ┌───────────┐   
│  │└─┘ ││a│◀────────┼───┼─│-2C ✓ MATCH│   
│  │       ┘             │ └───────────┘   
│  └── -3C ───0C─── +3C ─┘                 
│  ┌─────────┐                             
│  │ -4C ✗ NO│                             
└──│  MATCH  │                             
   └─────────┘                             
                                           
                                           
   *Line bounded proximity*
   `withinLines = 4`                      
         ┌────────┐                        
   ┌─────┤fragment├─────┐                  
  +4L─ ─ ┴────────┘─ ─ ─│                  
   │                    │                  
   │              ┌─┐   │ ┌────────────┐   
   │         ┌─┐  │a│◀──┼─│+1L ✓ MATCH │   
   0L  ┌─┐   │p│  └─┘   │ ├────────────┤   
   │   │a│◀──┴─┴────────┼─│-1L ✓ MATCH │   
   │   └─┘              │ └────────────┘   
   │                    │ ┌─────────┐      
  -4L─ ─ ─ ─ ─ ─ ─ ─┌─┐─│ │-5L ✗ NO │      
   │                │a│◀┼─│  MATCH  │      
   └────────────────┴─┴─┘ └─────────┘      
                                           
                                           
   *Line and column bounded proximity*
   `withinLines = 4`                      
   `withinColumns = 3`                    
         ┌────────┐                        
   ┌─────┤fragment├─────┐                  
  +4L   ┌└────────┴ ┐   │                  
   │            ┌─┐     │ ┌───────────────┐
   │    │       │a│◀┼───┼─│+2L/+1C ✓ MATCH│
   │         ┌─┐└─┘     │ └───────────────┘
   0L   │    │p│    │   │                  
   │         └─┘        │                  
   │    │           │   │ ┌────────────┐   
  -4L    ─ ─ ─ ─ ─ ─┌─┐ │ │-5L/+3C ✗ NO│   
   │                │a│◀┼─│   MATCH    │   
   └───-3C────0L───+3C┴─┘ └────────────┘   
 ]]></description>
<link>https://tsecurity.de/de/3487977/IT+Sicherheit/Cybersecurity+Tools/v8.28.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487977/IT+Sicherheit/Cybersecurity+Tools/v8.28.0/</guid>
<pubDate>Sun, 20 Jul 2025 18:24:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2025.1 - PayloadsAllTheThings - FERRETEDITOR]]></title> 
<description><![CDATA[This update brings significant new content, including dedicated pages for new vulnerability classes, fresh exploitation techniques for existing topics, and numerous quality-of-life improvements across the knowledge base.
📚 New Vulnerability Pages

External Variable Modification: Complete new section covering PHP extract() function vulnerabilities, variable pollution, and security implications
Reverse Proxy Misconfigurations: Covering common Nginx misconfigurations.

🔄 Enhanced Sections


Command Injection:

Added worstfit technique for argument injection
Enhanced with fullwidth character bypass methods



CSV Injection:

New Google Sheets exploitation section
Added formulas like IMPORTXML, IMPORTRANGE for data exfiltration
Enhanced with remote resource access techniques



File Inclusion:

New lightyear tool for blind file read primitives
Enhanced PHP filter exploitation techniques



Headless Browser:

New CVE exploitation section
Enhanced debugging port security implications
Added insecure flags and PDF rendering attack vectors



Java Deserialization:

Comprehensive JSON deserialization section (Jackson etc)
Enhanced with multiple attack vectors and exploitation techniques



SQL Injection:

New PDO Prepared Statements section



🐛 Bug Fixes &amp; Corrections

Fixed numerous formatting inconsistencies
Corrected broken internal links
Updated deprecated tool references
Standardized code block formatting
Standardized bullet points and list formatting across all sections
Automated markdown linting detection now runs on all pull requests and commits.

🌐 What&#039;s Changed

csv injection: google sheets formulas by @noraj in #759
Update YOUTUBE.md by @Tednoob17 in #765
Add missing -r flag for xxe excel file rebuilding with zip command by @sehraramiz in #768
Fix extra parentheses in MySQL Injection.md by @DoongPark in #769
FIX broken link by @Diebbo in #772
Add support for || (concatenation) operator in PostgreSQL for time based SQL injection by @florianamette in #779
Update README.md by @stenzzor in #781

👌New Contributors

@Tednoob17 made their first contribution in #765
@sehraramiz made their first contribution in #768
@DoongPark made their first contribution in #769
@Diebbo made their first contribution in #772
@florianamette made their first contribution in #779
@stenzzor made their first contribution in #781

Full Changelog: 4.1...4.2 ]]></description>
<link>https://tsecurity.de/de/3487976/IT+Sicherheit/Cybersecurity+Tools/2025.1+-+PayloadsAllTheThings+-+FERRETEDITOR/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487976/IT+Sicherheit/Cybersecurity+Tools/2025.1+-+PayloadsAllTheThings+-+FERRETEDITOR/</guid>
<pubDate>Sat, 26 Jul 2025 22:28:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.4.170-20250812]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/ae0ffc4977eb560685022328d30564fc83320257/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

2.4/dev by @m0duspwnens in #14200
Get ready for .160 by @TOoSmOotH in #14614
improve consistency by @jertel in #14619
Update soup by @TOoSmOotH in #14621
Cogburn/playbooks by @coreyogburn in #14623
logstash isn&#039;t running on receivers or manager when kafka is the glob&hellip; by @reyesj2 in #14629
Add RulesetName to Rule Repos by @coreyogburn in #14639
Add parsing for Playbook by @defensivedepth in #14638
Tighten parsing by @defensivedepth in #14643
Backport Hotfix to dev by @jertel in #14651
use zeek network.community_id when available by @reyesj2 in #14668
FIX: Improve annotation for Elasticsearch index deletion #14682 by @dougburks in #14683
FIX: so-suricata-testrule should disable pcap logging #14685 by @dougburks in #14687
FIX: so-elasticsearch-ilm-start needs shebang #14688 by @dougburks in #14689
add echo to end of so-elasticsearch-ilm-start and so-elasticsearch-ilm-stop by @dougburks in #14691
Use Stable branch by @defensivedepth in #14697
add so-elasticsearch-index-growth by @reyesj2 in #14698
fix system integration time overwrite and delete unused ingest pipeline by @reyesj2 in #14676
Updated Playbook Repo Config by @coreyogburn in #14700
upgrade registry to 3.0.0 by @jertel in #14701
update to new config location by @jertel in #14711
enable STS for browser redirects by @jertel in #14714
Add support for Airgap for Playbooks by @defensivedepth in #14718
Airgap tweaks by @defensivedepth in #14719
Supress alerts by @defensivedepth in #14721
Add nsm bind by @defensivedepth in #14722
Create dir if needed by @defensivedepth in #14723
Add support for dns.resolved_ip by @defensivedepth in #14759
refactor airgap playbook to eliminate dupe code and shrink ISO by @jertel in #14764
fix logging by @jertel in #14765
change salt upgrade process by @m0duspwnens in #14770
Revert &quot;change salt upgrade process&quot; by @m0duspwnens in #14771
2.4.160 by @TOoSmOotH in #14772
2.4.160 by @TOoSmOotH in #14773
Update VERSION by @TOoSmOotH in #14775
soup 2.4.170 by @reyesj2 in #14776
hardware virtualization by @m0duspwnens in #14784
allow standalone and managersearch to run salt.cloud state by @m0duspwnens in #14791
allow libvirt states by @m0duspwnens in #14792
Refactors playbook repo configuration by @coreyogburn in #14793
only run storage state if box has nvme by @m0duspwnens in #14800
ensure hypervisor is remove from salt cloud profiles when key is deleted by @m0duspwnens in #14803
es 8.18.3 by @reyesj2 in #14813
Add user.name to kratos query by @defensivedepth in #14816
es 8.18.3 by @reyesj2 in #14824
ES 8.18.3 by @reyesj2 in #14825
check required files exist before loading map file by @reyesj2 in #14827
exclude component updates indexes with error in the name by @jertel in #14828
split up bulk install of integrations by @reyesj2 in #14830
fix typo by @jertel in #14832
templates with error in name by @reyesj2 in #14833
kibana listingLimit by @reyesj2 in #14840
Issues #14836 #14837 #14838 by @dougburks in #14842
Simplify UniFi dashboards #14838 by @dougburks in #14845
hosted image. sos hw support by @m0duspwnens in #14848
ja4 by @reyesj2 in #14850
ja4 ignore empty strings by @reyesj2 in #14854
elasticsearch troubleshoot script by @reyesj2 in #14856
fix incorrect file ownership by @reyesj2 in #14858
Add JA4 support by @TOoSmOotH in #14860
don&#039;t allow bootstrap-salt to start daemons. splay non manager highstates 120 seconds by @m0duspwnens in #14865
UPGRADE: Zeek Ethercat plugin #14783 by @dougburks in #14867
add some retry to so-elastic-fleet-integration-upgrade by @reyesj2 in #14868
add pack only holding package if installed. remove redundant hold on salt-master package by @m0duspwnens in #14869
8.18.4 by @reyesj2 in #14870
FIX: opencanary startup logs cause ingest error by @reyesj2 in #14871
update ASN organization name field by @reyesj2 in #14880
increase so-elasticsearch-roles-load timeout by @reyesj2 in #14883
only show data nodes in disk usage output by @reyesj2 in #14889
exclude so_agent_installer dir from config backups by @reyesj2 in #14890
match user soqemussh, allow user additions to persist, for ssh config.  by @m0duspwnens in #14892
fix hyper bridge setup. simplify cpu/mem regex by @m0duspwnens in #14896
handle - in hypervisor hostname by @m0duspwnens in #14899
Vlb2 by @m0duspwnens in #14909
remove managerhype from whiptail by @m0duspwnens in #14910
2.4.170 by @TOoSmOotH in #14916
2.4.170 by @TOoSmOotH in #14918
2.4.170 by @TOoSmOotH in #14919
2.4.170 by @TOoSmOotH in #14917

Full Changelog: 2.4.150-20250522...2.4.170-20250812 ]]></description>
<link>https://tsecurity.de/de/3487975/IT+Sicherheit/Cybersecurity+Tools/2.4.170-20250812/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487975/IT+Sicherheit/Cybersecurity+Tools/2.4.170-20250812/</guid>
<pubDate>Tue, 12 Aug 2025 17:04:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.4.180-20250916]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/456cad1adad30b1b4c8d6a4b84ea56519c4f6532/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

hardware virtualization by @m0duspwnens in #14778
Vlb2 by @m0duspwnens in #14893
Update VERSION by @TOoSmOotH in #14922
firewall allow hypervisor for managersearch and standalone by @m0duspwnens in #14925
Vlb2 by @m0duspwnens in #14930
profile update by @reyesj2 in #14933
update pcap permissions when no stenographer user exists by @reyesj2 in #14949
180 soup base by @m0duspwnens in #14950
Ruleset Name UiElement by @coreyogburn in #14956
rpt by @jertel in #14959
and nic channel customization by @m0duspwnens in #14971
enable additional fleetnode state by @reyesj2 in #14957
only manage bond script if bond0 exists by @m0duspwnens in #14978
Mikebond by @TOoSmOotH in #14980
ES 8.18.6 upgrade by @reyesj2 in #14975
Move EnableReverseLookup by @coreyogburn in #14986
so-elastic-agent-monitor by @reyesj2 in #14996
manager do hypervisor things by @m0duspwnens in #14998
Make it clear that Fleet Nodes will need to be reinstalled by @defensivedepth in #15003
Cogburn/wip module by @coreyogburn in #14991
Fix Index Patterns by @coreyogburn in #15008
fix repo files to remove by @m0duspwnens in #15010
so-elastic-agent-monitor  by @reyesj2 in #15009
don&#039;t show sensoroni config changes by @m0duspwnens in #15011
add configurable realert threshold per agent by @reyesj2 in #15012
lower filestream fingerprint length by @reyesj2 in #15019
suricata metadata index rollover 1d -&gt; 30d by @reyesj2 in #15020
receiver custom fqdn by @reyesj2 in #15022
update kafka output policy by @reyesj2 in #15013
fix analyzers and upgrade deps by @reyesj2 in #15024
Parsing fix by @defensivedepth in #15025
zeek dns.resolved_ip by @reyesj2 in #14941
fix role check by @m0duspwnens in #15026
agent monitor template &amp; dataset name update by @reyesj2 in #15028
8.18.6 agent by @reyesj2 in #15033
run so-elastic-agent-gen-installers by @reyesj2 in #15034
fix case of broken kafka output policy when new receiver is added and&hellip; by @reyesj2 in #15031
2.4.180 by @dougburks in #15040
Merge pull request #14917 from Security-Onion-Solutions/2.4/dev by @dougburks in #15042
2.4.180 by @dougburks in #15043

Full Changelog: 2.4.170-20250812...2.4.180-20250916 ]]></description>
<link>https://tsecurity.de/de/3487974/IT+Sicherheit/Cybersecurity+Tools/2.4.180-20250916/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487974/IT+Sicherheit/Cybersecurity+Tools/2.4.180-20250916/</guid>
<pubDate>Wed, 17 Sep 2025 20:18:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.4.190-20251024]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/39572f36f43289fa700d84d7453f682fbf1246be/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

bump version by @jertel in #15044
Update 2-4.yml by @dougburks in #15045
add oom check to so-log-check by @reyesj2 in #15051
rework fleet scripts by @reyesj2 in #15047
typo by @reyesj2 in #15064
make sure fleet-default-output is not set as either default output p&hellip; by @reyesj2 in #15070
Updated default investigation prompt by @mc-wright in #15071
retry kratos pulls since this is the first image to install during setup by @jertel in #15072
update so-elastic-fleet-setup by @reyesj2 in #15075
restart registry after upgrading images (in airgap mode) by @jertel in #15080
fix hypervisor bridge setup by @m0duspwnens in #15082
less strict exits for fleet configuration by @reyesj2 in #15086
New field for assistant health check by @coreyogburn in #15087
Made lowBalanceColorAlert global by @mc-wright in #15091
updates for wiretap lib by @jertel in #15092
byoh by @m0duspwnens in #15103
update logstash fleet output policy by @reyesj2 in #15105
Filters by @TOoSmOotH in #15114
UPGRADE: ES 8.18.8 by @reyesj2 in #15111
support non-async state apply by @jertel in #15118
ignore error for elastic-fleet agent by @reyesj2 in #15124
csv delimiter and query name by @jertel in #15127
missed commit by @jertel in #15130
allow user to create VMs that mount virtual disk for /nsm. new nsm_total grain by @m0duspwnens in #15137
Update so-saltstack-update by @m0duspwnens in #15063
New Config Entries by @coreyogburn in #15142
event.module elasticsearch by @reyesj2 in #15139
logstash helpers by @reyesj2 in #15141
implement host os overhead based on role by @m0duspwnens in #15144
Should be multiline by @coreyogburn in #15145
omit new hypervisor state name fp by @m0duspwnens in #15147
do not log set_timezone in setup by @m0duspwnens in #15148
update log4j2 policy for ES json output by @reyesj2 in #15151
log4j2 settings by @reyesj2 in #15153
add exclusion toggle by @jertel in #15161
2.4.190 by @TOoSmOotH in #15166
2.4.190 by @TOoSmOotH in #15167

Full Changelog: 2.4.180-20250916...2.4.190-20251024 ]]></description>
<link>https://tsecurity.de/de/3487973/IT+Sicherheit/Cybersecurity+Tools/2.4.190-20251024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487973/IT+Sicherheit/Cybersecurity+Tools/2.4.190-20251024/</guid>
<pubDate>Fri, 24 Oct 2025 23:40:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v8.29.0]]></title> 
<description><![CDATA[Changelog

ed65b65 Add trace log for skipped archive file when not enabled (#1961)
c5ccbb9 Respect contexts with timeouts (#1948)
3821f30 Config min version (#1955)
d223718 fix(config): validate rules when [extend] is used (#1592)
87d9629 feat: add Amazon Bedrock API key detection (#1935)
228396b Add GitHub Sponsors section and Discord link
a82bc53 feat: improve regex  to detect Sonar tokens with prefixes (#1931)
 ]]></description>
<link>https://tsecurity.de/de/3487972/IT+Sicherheit/Cybersecurity+Tools/v8.29.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487972/IT+Sicherheit/Cybersecurity+Tools/v8.29.0/</guid>
<pubDate>Wed, 05 Nov 2025 02:23:31 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v8.29.1]]></title> 
<description><![CDATA[Changelog

fb5d707 thats a paddlin
50493db feat: document stdout report path (#1990)
 ]]></description>
<link>https://tsecurity.de/de/3487971/IT+Sicherheit/Cybersecurity+Tools/v8.29.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487971/IT+Sicherheit/Cybersecurity+Tools/v8.29.1/</guid>
<pubDate>Wed, 19 Nov 2025 22:22:58 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v8.30.0]]></title> 
<description><![CDATA[Changelog

6eaad03 0 to 5 - notes on recursive decoding (#1994)
09242ce Add new Looker client ID and client secret rules (#1947)
c98e5e0 feat: add Airtable Personnal Access Token detection (#1952)
4ed0ca4 build: upgrade Go &amp; alpine version (#1989)
 ]]></description>
<link>https://tsecurity.de/de/3487970/IT+Sicherheit/Cybersecurity+Tools/v8.30.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487970/IT+Sicherheit/Cybersecurity+Tools/v8.30.0/</guid>
<pubDate>Wed, 26 Nov 2025 19:08:28 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2.4.200-20251216]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/ddd6935e50fc319f44926a58f1903d75a8b052e5/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

managerhype by @m0duspwnens in #14966
Vlb2 by @m0duspwnens in #14972
merge with 2.4/dev by @m0duspwnens in #14990
pass pillar properly by @m0duspwnens in #14994
Vlb2 by @m0duspwnens in #15015
Vlb2 by @m0duspwnens in #15056
only update mine for managerhype during setup by @m0duspwnens in #15061
update service file, use salt.minion state to update mine_functions by @m0duspwnens in #15065
set interface for network.ip_addrs for hypervisors by @m0duspwnens in #15066
Vlb2 by @m0duspwnens in #15067
Vlb2 by @m0duspwnens in #15076
Byoh by @m0duspwnens in #15098
nsm virtual disk and new nsm_total grain by @m0duspwnens in #15122
bump version by @jertel in #15169
bump version by @jertel in #15170
estimate elasticsearch retention by @reyesj2 in #15176
create libvirt volumes directory by @m0duspwnens in #15181
add manager role to elasticsearch ingest time spent by @reyesj2 in #15182
Upgrade Salt 3006.16 by @m0duspwnens in #15185
Available Models by @coreyogburn in #15188
Salt 3006.16 by @m0duspwnens in #15193
move off of cmd.script with args \ by @reyesj2 in #15194
ensure previous setup outcomes are cleared by @jertel in #15198
strelka use single master image by @reyesj2 in #15192
update so-elasticsearch-retention-estimate by @reyesj2 in #15201
rename forward node -&gt; sensor node by @reyesj2 in #15207
Update defaults.yaml by @TOoSmOotH in #15209
Suricata 8.0.2 by @m0duspwnens in #15211
reduce pcapMaxCount to fit better with max upload size by @jertel in #15213
add support to so-yaml for using yaml file content for values by @jertel in #15219
update so-elasticsearch-retention-estimate by @reyesj2 in #15204
configure salt, then install. update bootstrap-salt. reduce salt install fail timeout by @m0duspwnens in #15223
CompressContextPrompt by @coreyogburn in #15221
wait for 200 from registry before proceeding by @m0duspwnens in #15228
Add Enabled Flag to Models by @coreyogburn in #15229
pcap annotations by @jertel in #15225
suricata pipeline updates by @reyesj2 in #15230
fix so-setup error duplicate bond0 by @reyesj2 in #15231
rm salt keyring and repo file for deb by @m0duspwnens in #15237
update zeek pipelines by @reyesj2 in #15234
communicate to the viewer that OS patches may take some time by @jertel in #15240
suricata capture file by @reyesj2 in #15244
Notify user of hypervisor environment setup failures by @m0duspwnens in #15247
clarify hypervisor annotation by @m0duspwnens in #15248
use timestamp in volume path to prevent duplicates by @m0duspwnens in #15251
Add JA4D option to config.zeek.ja4 by @TOoSmOotH in #15271
add force &amp; certs flag to update fleet certs as needed by @reyesj2 in #15264
add new so-yaml_test for removefromlist by @m0duspwnens in #15275
need additional line bw class by @m0duspwnens in #15277
reserve group ids by @m0duspwnens in #15280
skip continue prompt if user cannot actually continue by @jertel in #15281
FEATURE: Advanced ILM actions via SOC UI by @reyesj2 in #15241
Idstools refactor by @defensivedepth in #15232
Fixup Airgap by @defensivedepth in #15283
Make sure local salt dir is created by @defensivedepth in #15284
be more verbose by @defensivedepth in #15286
Rework ordering by @defensivedepth in #15287
match correct custom ruleset name by @defensivedepth in #15290
Fix custom name by @defensivedepth in #15292
Remove Claude Sonnet 4 model configuration by @TOoSmOotH in #15293
small fixes by @defensivedepth in #15297
Fixup logic by @defensivedepth in #15298
Update Assistant Models by @TOoSmOotH in #15289
Rework backup by @defensivedepth in #15301
Add Airgap check by @defensivedepth in #15303
fix cleaning repos on remote nodes if airgap by @m0duspwnens in #15304
Add trailing nl if it doesnt already exist by @defensivedepth in #15308
Update so-minion by @TOoSmOotH in #15311

Full Changelog: 2.4.190-20251024...2.4.200-20251216 ]]></description>
<link>https://tsecurity.de/de/3487969/IT+Sicherheit/Cybersecurity+Tools/2.4.200-20251216/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487969/IT+Sicherheit/Cybersecurity+Tools/2.4.200-20251216/</guid>
<pubDate>Tue, 16 Dec 2025 17:21:58 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v1.0.0]]></title> 
<description><![CDATA[Highlights

Agentic penetration testing pipeline
Terminal UI with real-time activity feed
86.5% success rate on XBOW benchmark (90/104)
Docker-based deployment

See benchmark results for details.&quot; ]]></description>
<link>https://tsecurity.de/de/3487968/IT+Sicherheit/Cybersecurity+Tools/v1.0.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487968/IT+Sicherheit/Cybersecurity+Tools/v1.0.0/</guid>
<pubDate>Wed, 24 Dec 2025 18:25:30 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2.4.201-20260114]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/c63c6dc68bfe3d2248c3176282a3f041ff646885/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

2.4.201 by @TOoSmOotH in #15385
2.4.201 by @TOoSmOotH in #15386

Full Changelog: 2.4.200-20251216...2.4.201-20260114 ]]></description>
<link>https://tsecurity.de/de/3487967/IT+Sicherheit/Cybersecurity+Tools/2.4.201-20260114/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487967/IT+Sicherheit/Cybersecurity+Tools/2.4.201-20260114/</guid>
<pubDate>Thu, 15 Jan 2026 20:25:43 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.93.6]]></title> 
<description><![CDATA[What&#039;s Changed

GH_TOKEN needed for gh by @bill-rich in #4772
Move verify flag into detectableChunk by @rosecodym in #4558

Full Changelog: v3.93.5...v3.93.6 ]]></description>
<link>https://tsecurity.de/de/3487966/IT+Sicherheit/Cybersecurity+Tools/v3.93.6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487966/IT+Sicherheit/Cybersecurity+Tools/v3.93.6/</guid>
<pubDate>Fri, 27 Feb 2026 16:25:04 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2.4.210-20260302]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/a9d2be8131ac1cf7eb5ee175c1eab20da8cd2b18/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Update VERSION by @TOoSmOotH in #15320
Un-Advanced Assistant ApiUrl by @coreyogburn in #15323
expose login form lifespan in config scr by @jertel in #15347
update kratos index template by @reyesj2 in #15353
exempt kratos online check by @jertel in #15358
suppress config diffs to avoid false positive errors by @jertel in #15359
Assistant: Session Report Template by @mc-wright in #15355
ES 9.0.8 by @reyesj2 in #15363
Case Report Update for AI Session Attachments by @mc-wright in #15367
Add version 2.4.201 to discussion template by @jertel in #15389
Fixmerge201210 by @m0duspwnens in #15390
2.4.201 into dev by @TOoSmOotH in #15387
follow symlinks for docker cp by @reyesj2 in #15391
add additional retries within scripts before salt re-runs the entire &hellip; by @reyesj2 in #15393
remove usage of deprecated &#039;logs&#039; integration in favor of &#039;filestream&#039; by @reyesj2 in #15394
Fstes by @m0duspwnens in #15397
break out ssl state by @m0duspwnens in #15400
allow logstash.ssl for eval and import. fix soup create_ca_pillar by @m0duspwnens in #15402
create dir if nonexistent by @m0duspwnens in #15405
reinstall agent on grid nodes when service wasn&#039;t cleanly removed. eg&hellip; by @reyesj2 in #15404
fix include by @m0duspwnens in #15406
more better by @reyesj2 in #15407
fix kafka state by @reyesj2 in #15408
fix auto soup - check for compatible versions and fallback to a known&hellip; by @reyesj2 in #15410
add retries to so-resources repo pull by @reyesj2 in #15411
missing  updates to variables by @reyesj2 in #15412
ignore kratos file mapping error by @reyesj2 in #15414
exclude known error by @reyesj2 in #15420
update redis log file path by @reyesj2 in #15424
update heavynode&#039;s elastic-agent standalone policy by @reyesj2 in #15418
include all so-grid-nodes_* policies in automatic EA upgrades by @reyesj2 in #15435
run fleet ssl state in fleet.config to ensure all required certs are &hellip; by @reyesj2 in #15436
ensure exclude_files excludes log rotation pattern by @reyesj2 in #15438
initialize specific indices as needed by @reyesj2 in #15442
use logstash merged values for logstash metric collection by @reyesj2 in #15447
keep logsdb disabled by @reyesj2 in #15448
Cogburn/gemini by @coreyogburn in #15443
allow network installs to use ISO for faster soupin by @reyesj2 in #15465
don&#039;t set is_airgap when using nonairgap_useiso: not a true airgap sy&hellip; by @reyesj2 in #15468
default roles by @jertel in #15472
Remove QWEN 235B model from defaults.yaml by @TOoSmOotH in #15473
clarify url_base description by @jertel in #15482
Config Tweaks for AI by @coreyogburn in #15481
Upgrade Salt 3006.19 by @m0duspwnens in #15491
fix sensor and heavynode first highstate failure by @m0duspwnens in #15494
Revert &quot;don&#039;t set is_airgap when using nonairgap_useiso: not a true airgap sy&hellip;&quot; by @reyesj2 in #15496
Revert &quot;allow network installs to use ISO for faster soupin&quot; by @reyesj2 in #15497
Assistant: Investigated Query Toggle Filter by @mc-wright in #15492
upgrade docker by @m0duspwnens in #15500
Add OpenAI Protocols by @coreyogburn in #15501
rework autosoup for intermediate upgrades by @reyesj2 in #15499
upgrade docker by @m0duspwnens in #15506
healthTimeoutSeconds should be an int by @coreyogburn in #15507
upgrade docker by @m0duspwnens in #15509
New so-yaml.py Functions for Gemini Cypress Test Support by @mc-wright in #15505
upgrade docker by @m0duspwnens in #15510
migrate managed_integrations pillar by @reyesj2 in #15503
upgrade analyzer deps by @reyesj2 in #15511
fix consecutive comments by @m0duspwnens in #15513
fix soup failure if salt-relay isn&#039;t running by @m0duspwnens in #15519
Add Support for upgrading to 3.0 by @TOoSmOotH in #15517
Rename model ID from &#039;sonnet-4.5&#039; to &#039;sonnet&#039; by @TOoSmOotH in #15522
fix field conflicts by @reyesj2 in #15524
fix suricata filestream dataset by @reyesj2 in #15523
fix agentstatus script by @reyesj2 in #15525
do not allow auth redirection to login page or home page; that serves&hellip; by @jertel in #15526
exclude transient ghcr.io network errors since it retries during setup by @jertel in #15532
Cleanup idstools by @defensivedepth in #15531
restart salt minion before failing if not ready by @m0duspwnens in #15534
prevent caching of main doc to ensure logged out detection is processed by @jertel in #15535
Move rm to post by @defensivedepth in #15536
prepare for nextgen docs by @jertel in #15539
2.4.210 by @TOoSmOotH in #15541
2.4.210 by @TOoSmOotH in #15542

Full Changelog: 2.4.201-20260114...2.4.210-20260302 ]]></description>
<link>https://tsecurity.de/de/3487965/IT+Sicherheit/Cybersecurity+Tools/2.4.210-20260302/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487965/IT+Sicherheit/Cybersecurity+Tools/2.4.210-20260302/</guid>
<pubDate>Mon, 02 Mar 2026 21:07:53 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.93.7]]></title> 
<description><![CDATA[What&#039;s Changed

[INS-331] Fix the issue causing the tests file system soruce tests to fail on windows by @MuneebUllahKhan222 in #4743
Thread original chunk data through engine pipeline by @dustin-decker in #4780
Added detector for JFrog Artifactory Reference Tokens by @shahzadhaider1 in #4684
Fix JDBC detector regex truncating trailing non-alphanumeric password characters by @amanfcp in #4755

Full Changelog: v3.93.6...v3.93.7 ]]></description>
<link>https://tsecurity.de/de/3487964/IT+Sicherheit/Cybersecurity+Tools/v3.93.7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487964/IT+Sicherheit/Cybersecurity+Tools/v3.93.7/</guid>
<pubDate>Wed, 04 Mar 2026 17:14:07 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.364.0]]></title> 
<description><![CDATA[What&#039;s Changed

Fix flaky Composer UpdateChecker test: mock VersionResolver instead of stubbing PHP subprocess HTTP calls by @Copilot in #14266
feat: Add PR message formatting for dependency-name groups by @markhallen in #14289
refactor: Remove group_by_dependency_name feature flag by @markhallen in #14292
Add uv dependency grapher by @Nishnha in #14295
Bump octokit from 7.2.0 to 10.0.0 in /updater by @dependabot[bot] in #14241
Bump sentry-ruby from 5.23.0 to 5.28.1 in /updater by @dependabot[bot] in #14242
Bump gitlab from 5.1.0 to 6.1.0 in /updater by @dependabot[bot] in #14240
Bump sentry-opentelemetry and sentry-ruby in /updater by @dependabot[bot] in #14308
Bump terminal-table from 3.0.2 to 4.0.0 in /updater by @dependabot[bot] in #14239
Bump the dev-dependencies group across 2 directories with 1 update by @dependabot[bot] in #14311
Bump the prod-dependencies group across 2 directories with 4 updates by @dependabot[bot] in #14310
Bump minimatch from 3.0.4 to 3.1.5 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14305
Bump minimatch from 3.1.2 to 3.1.5 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14287
Bump lodash from 4.17.21 to 4.17.23 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14017
Bump lodash from 4.17.21 to 4.17.23 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #13993
Bump minimatch from 3.1.2 to 3.1.5 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14303
Bump minimatch from 3.1.2 to 3.1.5 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14299
Bump lodash from 4.17.21 to 4.17.23 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #13996
Bump lodash from 4.17.21 to 4.17.23 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #13995
Bump Microsoft.Web.Xdt from 3.2.0 to 3.2.3 by @dependabot[bot] in #14252
Bump the all-actions group with 3 updates by @dependabot[bot] in #14316
Bump System.CommandLine from 2.0.0-beta6.25358.103 to 2.0.3 by @dependabot[bot] in #14319
Bump regclient/regctl from v0.11.1 to v0.11.2 in /docker in the regclient group by @dependabot[bot] in #14317
Bump Microsoft.Build.Tasks.Core and Microsoft.Build.Utilities.Core by @dependabot[bot] in #14187
Bump dotnet-sdk from 9.0.302 to 9.0.303 in /nuget/helpers/lib/NuGetUpdater by @dependabot[bot] in #12666
Bump Newtonsoft.Json from 13.0.3 to 13.0.4 by @dependabot[bot] in #14253
Bump minimatch in /bun/helpers by @dependabot[bot] in #14312
Bump minimatch in /npm_and_yarn/helpers by @dependabot[bot] in #14304
Update Composer to the latest 2.9 version (2.9.5) by @T2L in #14267
Bump library/rust from 1.93.0-bookworm to 1.93.1-bookworm in /cargo by @dependabot[bot] in #14177
Bump library/golang from 1.25.7-bookworm to 1.26.0-bookworm in /go_modules by @dependabot[bot] in #14179
Bump ajv from 6.12.6 to 6.14.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14244
Bump ajv from 6.12.6 to 6.14.0 in /bun/helpers by @dependabot[bot] in #14245
Bump golang.org/x/mod from 0.27.0 to 0.33.0 in /go_modules/helpers by @dependabot[bot] in #14178
Bump org.apache.maven.plugins:maven-dependency-plugin from 3.8.1 to 3.9.0 in /maven/lib/dependabot/maven by @dependabot[bot] in #13233
Bump prettier from 3.7.4 to 3.8.1 in /npm_and_yarn/helpers in the dev-dependencies group by @dependabot[bot] in #14180
Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #14315
Bump js-yaml from 3.14.1 to 3.14.2 in /npm_and_yarn/helpers by @dependabot[bot] in #13613
Bump the pnpm-dependencies group in /npm_and_yarn/helpers with 2 updates by @dependabot[bot] in #10361
Update ESLint configuration file to new format by @bohdanhusak in #13785
Bump eslint from 9.39.1 to 10.0.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14182
Bump pip-tools from 7.4.1 to 7.5.0 in /python/helpers in the pip-tools group by @dependabot[bot] in #12770
Bump gradle from 8.14.3-jdk21-ubi-minimal to 9.0.0-jdk21-ubi-minimal in /gradle by @dependabot[bot] in #13971
Bump globals from 16.5.0 to 17.4.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14325
Fetch pre-commit additional dependencies language field from hook source repository by @AbhishekBhaskar in #14300
fix(npm_and_yarn): avoid group refresh NoChangeError for non-pnpm support-file updates by @thavaahariharangit in #14331
Set smoke test max parallelism to 10 by @JamieMagee in #14307
Bump System.ComponentModel.Composition from 9.0.7 to 10.0.3 by @dependabot[bot] in #14326
fix(go_modules): normalize Azure DevOps module paths to include /_git/ by @thavaahariharangit in #14302
Bump System.Threading.Tasks.Dataflow from 9.0.13 to 10.0.3 by @dependabot[bot] in #14329
Bump System.Security.Cryptography.Pkcs from 9.0.7 to 10.0.3 by @dependabot[bot] in #14327
Fix GitHub Actions SHA-pinned refs being downgraded when mixed with tag refs by @jurre in #14349
Fix ignore option for gitsubmodule by @etan-status in #14352
cargo: Bypass Cargo credential providers, rely on proxy for registry auth by @jeffwidman in #14340
bundler: use replaces_base credential for gemspec-only deps by @jeffwidman in #14348
Bump NuGet.Client submodule from release-6.12.x to release-6.14.x by @JamieMagee in #14343
nuget: switch NuGetUpdater target framework to net10.0 by @JamieMagee in #14345
Disable scheduled CI workflow in forks by @martincostello in #14314
Remove beta ecosystems feature flag for pre-commit by @AbhishekBhaskar in #14341
Enhance Docker update checker to handle non-semver tags by @jpinz in #14337
Remove enable_shared_helpers_command_timeout feature flag by @Copilot in #14125
cargo: strip credential-provider from .cargo/config.toml via TOML parsing by @jeffwidman in #14359
Remove enable_record_ecosystem_meta feature flag by @Copilot in #14353
feat: Extend Swift FileFetcher for Xcode-managed SwiftPM (.xcodeproj) support by @markhallen in #14332
v0.364.0 by @dependabot-core-action-automation[bot] in #14366

New Contributors

@T2L made their first contribution in #14267

Full Changelog: v0.363.0...v0.364.0 ]]></description>
<link>https://tsecurity.de/de/3487963/IT+Sicherheit/Cybersecurity+Tools/v0.364.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487963/IT+Sicherheit/Cybersecurity+Tools/v0.364.0/</guid>
<pubDate>Thu, 05 Mar 2026 21:08:53 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.93.8]]></title> 
<description><![CDATA[What&#039;s Changed

fix: make LDAP verification context-aware by @mariduv in #4768
Stop growing filesystem resume data by @rosecodym in #4797

Full Changelog: v3.93.7...v3.93.8 ]]></description>
<link>https://tsecurity.de/de/3487962/IT+Sicherheit/Cybersecurity+Tools/v3.93.8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487962/IT+Sicherheit/Cybersecurity+Tools/v3.93.8/</guid>
<pubDate>Mon, 09 Mar 2026 21:19:07 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.365.0]]></title> 
<description><![CDATA[What&#039;s Changed

add Poetry grapher by @jakecoffman in #14362
fix: poetry grapher should prefer poetry.lock for relevant_dependency_file by @Copilot in #14378
Fix elm Elm19LatestVersionFinder to respect ignore conditions by @kbukum1 in #14372
Bump System.Text.Json from 9.0.11 to 10.0.3 by @dependabot[bot] in #14388
Bump library/golang from 1.26.0-bookworm to 1.26.1-bookworm in /go_modules by @dependabot[bot] in #14385
Bump @npmcli/arborist from 9.3.0 to 9.4.0 in /npm_and_yarn/helpers in the npm-dependencies group by @dependabot[bot] in #14321
Bump eslint from 10.0.2 to 10.0.3 in /npm_and_yarn/helpers in the dev-dependencies group by @dependabot[bot] in #14384
Bump the all-actions group across 1 directory with 6 updates by @dependabot[bot] in #14393
Bump xunit.v3 from 3.0.0 to 3.2.2 by @dependabot[bot] in #14389
Bump @pnpm/dependency-path from 5.1.3 to 1001.1.10 in /npm_and_yarn/helpers in the pnpm-dependencies group by @dependabot[bot] in #14322
Upgrade uv to v0.10.9 by @edgarrmondragon in #14381
Bump library/rust from 1.93.1-bookworm to 1.94.0-bookworm in /cargo by @dependabot[bot] in #14383
bazel: Remove Label() scanning from .bzl file fetching by @redsun82 in #14395
python:block constraints update that conflicts by @thavaahariharangit in #14375
Bump silent/tests go.mod to Go 1.26 by @jeffwidman in #14401
Replace gh release download with go install for Dependabot CLI by @jeffwidman in #14400
feat: Add Swift FileParser support for Xcode-managed SwiftPM projects by @markhallen in #14360
Extract TitleBuilder for PR title composition by @kbukum1 in #14285
gradle: fix wrapper updater crash when only some wrapper files define checksum by @pedromfmachado in #14399
Extract pre-commit dependency version from comment in PR description by @AbhishekBhaskar in #14403
Maven: skip unresolvable properties by @yeikel in #14344
fix(npm_and_yarn): prevent path traversal and make temp dependency file writes deterministic by @thavaahariharangit in #14405
Test ARM64 Docker builds in CI by @Copilot in #14396
fix(npm_and_yarn): pass private registry env vars to corepack fallback by @thavaahariharangit in #14413
don&#039;t fail if nuget feed returns unexpected 404 by @brettfo in #14409
Add Pipenv support to Python DependencyGrapher by @Copilot in #14402
v0.365.0 by @dependabot-core-action-automation[bot] in #14422

New Contributors

@redsun82 made their first contribution in #14395
@pedromfmachado made their first contribution in #14399

Full Changelog: v0.364.0...v0.365.0 ]]></description>
<link>https://tsecurity.de/de/3487961/IT+Sicherheit/Cybersecurity+Tools/v0.365.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487961/IT+Sicherheit/Cybersecurity+Tools/v0.365.0/</guid>
<pubDate>Thu, 12 Mar 2026 09:54:59 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2.4.211-20260312]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/79b30e43d9a0c553a87cbcf24ed4c44c58fad925/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Add date to HOTFIX file by @TOoSmOotH in #15570
Bump version from 2.4.210 to 2.4.211 by @TOoSmOotH in #15582
fix enable/disable suricata pcap by @m0duspwnens in #15583
remove 10T virtual disk limit. URL_BASE to vm hosts file by @m0duspwnens in #15584
clear HOTFIX file by @m0duspwnens in #15588
Add support for version 2.4.211 in soup script by @TOoSmOotH in #15586
set container ulimits to default by @m0duspwnens in #15593
2.4.211 by @TOoSmOotH in #15597

Full Changelog: 2.4.210-20260302...2.4.211-20260312 ]]></description>
<link>https://tsecurity.de/de/3487960/IT+Sicherheit/Cybersecurity+Tools/2.4.211-20260312/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487960/IT+Sicherheit/Cybersecurity+Tools/2.4.211-20260312/</guid>
<pubDate>Thu, 12 Mar 2026 18:24:19 +0100</pubDate>
</item>
<item> 
<title><![CDATA[javascript: v0.4.8]]></title> 
<description><![CDATA[0.4.8 (2026-03-13)
Features

dual conversation histories for RedTeamAgent (#282) (fa45876)
support optional runId in RunOptions (#284) (d5fd769)
 ]]></description>
<link>https://tsecurity.de/de/3487959/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487959/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.8/</guid>
<pubDate>Fri, 13 Mar 2026 13:45:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.21]]></title> 
<description><![CDATA[0.7.21 (2026-03-13)
Features

dual conversation histories for RedTeamAgent (#282) (fa45876)

Bug Fixes

resolve CI flaky tests (#277) (de1a00b)
 ]]></description>
<link>https://tsecurity.de/de/3487958/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.21/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487958/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.21/</guid>
<pubDate>Fri, 13 Mar 2026 14:04:51 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.366.0]]></title> 
<description><![CDATA[What&#039;s Changed

Add scanned_manifests_path metadata to snapshots by @brrygrdn in #14406
Fix regex pattern in pre-commit file parser and file-updater by @AbhishekBhaskar in #14429
Handle unhandled uv errors prefixed with CPython interpreter info by @thavaahariharangit in #14433
Handle Docker API version mismatch in script/build by @thavaahariharangit in #14436
Remove avoid_duplicate_updates_package_json FF from dependabot-core by @Copilot in #14428
Avoid sheering off directories by using manifest_file.directory by @brrygrdn in #14439
Fix: Bundler ignore rules now suppress path_dependencies_not_reachable errors during file fetching by @Copilot in #14435
Extend Swift UpdateChecker to support Xcode-managed SwiftPM projects by @AbhishekBhaskar in #14411
Extend Swift file updater to support xcode swiftpm dependency update by @AbhishekBhaskar in #14394
strip extras from Python PURLs in DG payload by @jakecoffman in #14462
only try to create pr if update operations were performed by @brettfo in #14463
additional unparseable file message by @brettfo in #14464
fix(github_actions): use most specific version tag when updating comments by @jeffwidman in #14461
fix(uv): strip extras from dependency names in PURL generation by @Copilot in #14468
Update corepack to 0.34.6 by @yeikel in #14371
Bump maven from 3.9.12 to 3.9.14 in /maven by @dependabot[bot] in #14446
honor update-types in grouped/ungrouped updater by @brettfo in #14475
feat: add .xcworkspace support for xcode swiftpm by @markhallen in #14459
fix(hex): correct tuple order for Hex.Repo.get_public_key response by @georgeguimaraes in #14380
Bump patch-package from 8.0.0 to 8.0.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14445
Fix &quot;Multiple sources!&quot; error for case-variant Terraform/OpenTofu provider declarations by @Copilot in #14434
v0.366.0 by @dependabot-core-action-automation[bot] in #14481

New Contributors

@georgeguimaraes made their first contribution in #14380

Full Changelog: v0.365.0...v0.366.0 ]]></description>
<link>https://tsecurity.de/de/3487957/IT+Sicherheit/Cybersecurity+Tools/v0.366.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487957/IT+Sicherheit/Cybersecurity+Tools/v0.366.0/</guid>
<pubDate>Thu, 19 Mar 2026 17:49:56 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.94.0]]></title> 
<description><![CDATA[What&#039;s Changed

Use trContext instead of context throughout Filesystem source by @camgunz in #4804
Make naming more consistent in the Filesystem source by @camgunz in #4805
Rearrange some method parameters in the Filesystem source by @camgunz in #4806
[INS-254] Datadog detector verification fix and endpoint configuration by @MuneebUllahKhan222 in #4616
[INS-241] Datadogapikey detector by @MuneebUllahKhan222 in #4627
Analysis info now uses snake case by @MuneebUllahKhan222 in #4765
Add anypoint oauth2 detector to defaults.go by @mustansir14 in #4722
Update README formatting and CLI help output by @bryanbeverly in #4758
Add test cases for escaped unicode by @casey-tran in #4812
Confine symlink state handling to scanSymlink in Filesystem source by @camgunz in #4807
Expand tilde manually in TUI by @mcastorina in #4827

New Contributors

@bryanbeverly made their first contribution in #4758

Full Changelog: v3.93.8...v3.94.0 ]]></description>
<link>https://tsecurity.de/de/3487956/IT+Sicherheit/Cybersecurity+Tools/v3.94.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487956/IT+Sicherheit/Cybersecurity+Tools/v3.94.0/</guid>
<pubDate>Fri, 20 Mar 2026 16:08:04 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v8.30.1]]></title> 
<description><![CDATA[Changelog

83d9cd6 update goreleaser
8d1f98c Removed unnecessary functions from report template (#2040)
ca20267 its the simple things (#2020)
b66ac75 build: switch to Go 1.24 (#2002)
 ]]></description>
<link>https://tsecurity.de/de/3487955/IT+Sicherheit/Cybersecurity+Tools/v8.30.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487955/IT+Sicherheit/Cybersecurity+Tools/v8.30.1/</guid>
<pubDate>Sat, 21 Mar 2026 03:20:30 +0100</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.22]]></title> 
<description><![CDATA[0.7.22 (2026-03-22)
Features

add scenario role and run_id attributes to agent spans (#294) (d7e31cc)
 ]]></description>
<link>https://tsecurity.de/de/3487954/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487954/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.22/</guid>
<pubDate>Mon, 23 Mar 2026 00:56:50 +0100</pubDate>
</item>
<item> 
<title><![CDATA[javascript: v0.4.9]]></title> 
<description><![CDATA[0.4.9 (2026-03-22)
Features

add scenario role and run_id attributes to agent spans (#294) (d7e31cc)
 ]]></description>
<link>https://tsecurity.de/de/3487953/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487953/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.9/</guid>
<pubDate>Mon, 23 Mar 2026 00:57:18 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.94.1]]></title> 
<description><![CDATA[What&#039;s Changed

use struct-based SourceMetadataFunc signature across git sources by @amanfcp in #4813

Full Changelog: v3.94.0...v3.94.1 ]]></description>
<link>https://tsecurity.de/de/3487952/IT+Sicherheit/Cybersecurity+Tools/v3.94.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487952/IT+Sicherheit/Cybersecurity+Tools/v3.94.1/</guid>
<pubDate>Wed, 25 Mar 2026 17:32:52 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.367.0]]></title> 
<description><![CDATA[What&#039;s Changed

Fix rev handling for quoted values in pre-commit configs by @robaiken in #14486
Add top level permissions to images-latest workflow by @truggeri in #14479
Maven: Ignore repositories from profiles that are not activated by @yeikel in #14154
Add support for versions using git revision suffixes for Maven and Gradle by @yeikel in #13998
Bump npm to 11.8.0 by @yeikel in #14141
uv: Fix extras normalization mismatch in pyproject.toml updates by @awinogradov in #14419
Remove unused corepack references from the bun ecosystem by @thavaahariharangit in #14483
Fetch release notes for the Gradle Wrapper by @yeikel in #14132
Fix XCode SwiftPM issues with pinned dependencies and multiple sources error during PR generation by @AbhishekBhaskar in #14495
Bump flatted from 3.3.1 to 3.4.2 in /bun/helpers by @dependabot[bot] in #14490
Bump flatted from 3.3.1 to 3.4.2 in /npm_and_yarn/helpers by @dependabot[bot] in #14489
Add latest_release and latest_tag methods to PackageLatestVersionFinder by @kbukum1 in #14502
Initial nix support by @JamieMagee in #14498
fix(uv): grapher not preferring lockfile by @jakecoffman in #14518
hook up uv to the smoke tests by @jakecoffman in #14519
Fix Xcode SwiftPM update job errors by @AbhishekBhaskar in #14512
Add top level permissions to workflows by @truggeri in #14501
fix(python): Dependency name correct when extras are present by @jakecoffman in #14476
Convert npm and yarn helpers to TypeScript &amp; enforce prettier by @jasonpaulos in #14493
Poetry grapher generates lockfiles to determine versions in pyproject by @jakecoffman in #14524
Fix XCode SwiftPM version range requirement update error by @AbhishekBhaskar in #14522
Add support for npm overrides and sub-dependency updates by @robaiken in #14530
enable direct update of centrally managed transitive package by @brettfo in #14532
v0.367.0 by @dependabot-core-action-automation[bot] in #14537

New Contributors

@awinogradov made their first contribution in #14419

Full Changelog: v0.366.0...v0.367.0 ]]></description>
<link>https://tsecurity.de/de/3487951/IT+Sicherheit/Cybersecurity+Tools/v0.367.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487951/IT+Sicherheit/Cybersecurity+Tools/v0.367.0/</guid>
<pubDate>Thu, 26 Mar 2026 15:58:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[PentAGI v0.1.0 - First Public Alpha Release]]></title> 
<description><![CDATA[🎯 Current State
PentAGI is in early alpha stage, focusing on core functionality and system stability. This release demonstrates the basic capabilities of our autonomous penetration testing system while actively being developed and improved.
✨ Available Features
Core Functionality

🤖 Multi-agent system (Researcher, Developer, Executor)
🛡️ Integration with essential security testing tools
🧠 Basic memory system with vector storage
🔄 Autonomous decision-making capabilities

Technical Implementation

🐳 Docker-based deployment
📊 Basic monitoring (Grafana + OpenTelemetry)
📝 LLM operations tracking (Langfuse)
🔌 Support for OpenAI/Anthropic APIs

⚠️ Important Notes

This is an alpha release intended for testing and feedback
Not recommended for production use
Expect frequent updates and changes
Some features may be unstable or incomplete
Limited documentation available

🚀 Quick Start
mkdir pentagi &amp;&amp; cd pentagi
curl -O https://raw.githubusercontent.com/vxcontrol/pentagi/main/docker-compose.yml
curl -o .env https://raw.githubusercontent.com/vxcontrol/pentagi/main/.env.example
# Configure your .env file
docker compose up -d

For detailed documentation and latest updates, please visit README file. ]]></description>
<link>https://tsecurity.de/de/3487950/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.1.0+-+First+Public+Alpha+Release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487950/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.1.0+-+First+Public+Alpha+Release/</guid>
<pubDate>Sun, 29 Mar 2026 14:30:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PentAGI v0.2.0 - New frontend]]></title> 
<description><![CDATA[🚀 New Features
Frontend Architecture

✨ Implemented modern React 18 architecture with TypeScript for enhanced type safety
🎨 Added shadcn/ui components with Radix UI primitives for consistent design
🌓 Introduced dark/light theme support with Tailwind CSS
📱 Added responsive design support for mobile, tablet, and desktop layouts
⚡ Optimized build process with Vite and module chunking

Core Features

💬 Real-time chat interface with AI agents using WebSocket subscriptions
🤖 Multi-agent system with specialized roles (Researcher, Developer, Executor)
📊 Terminal integration with real-time output monitoring
🎯 Task tracking system with subtasks and progress monitoring
🔍 Integrated search capabilities with vector store
📸 Screenshot capture and management system

Security &amp; Authentication

🔐 Multi-provider authentication support
🔑 OAuth integration with GitHub and Google
🛡️ SSL/TLS support for secure communications
🔒 Environment-based configuration management

🐛 Bug Fixes

Fixed WebSocket connection handling for GraphQL subscriptions
Improved error handling in terminal output
Resolved theme switching persistence issues
Fixed mobile layout responsiveness

🔄 Changes

Migrated from CRA to Vite for better build performance
Updated all dependencies to latest stable versions
Improved code organization with feature-based structure
Enhanced type definitions for better TypeScript support

📚 Documentation

Added comprehensive frontend documentation
Included development setup instructions
Added component architecture documentation
Updated environment configuration guide

🛠️ Technical Details

React 18.3.1
TypeScript 5.6.2
Vite 5.4.7
GraphQL 16.9.0
Tailwind CSS 3.4.13

🔜 Coming Soon

Enhanced performance monitoring
Improved error reporting
Extended test coverage
Additional UI components

🙏 Acknowledgments

Thanks to @sirozha for new frontend version

What&#039;s Changed

Feature/frontend by @sirozha in #1

New Contributors

@sirozha made their first contribution in #1

Full Changelog: v0.1.0...v0.2.0 ]]></description>
<link>https://tsecurity.de/de/3487949/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.2.0+-+New+frontend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487949/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.2.0+-+New+frontend/</guid>
<pubDate>Sun, 29 Mar 2026 14:30:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PentAGI v0.3.0 - First Public Beta Release]]></title> 
<description><![CDATA[


🚀 Join the Community! Connect with security researchers, AI enthusiasts, and fellow ethical hackers. Get support, share insights, and stay updated with the latest PentAGI developments.

⠀


🎯 Major Features
🤖 Assistant Mode - Complete interactive AI assistant with streaming responses, persistent chat sessions, and intelligent agent delegation. Create multiple chat sessions and seamlessly switch between manual assistance and automated penetration testing workflows.
🧪 Professional Testing Suite - Three specialized testing utilities:

ctester: Test LLM agent configurations with parallel execution and detailed reporting
etester: Manage vector embeddings with provider testing and database optimization
ftester: Debug individual functions and AI behaviors with interactive mock modes

🔍 Enhanced Search Capabilities - Integrated Perplexity AI and DuckDuckGo search engines alongside existing providers, plus multi-provider embedding system supporting OpenAI, Ollama, Mistral, Jina, HuggingFace, GoogleAI, and VoyageAI.
🛡️ Custom Kali Linux Environment - Dedicated Docker image optimized for penetration testing with enhanced security tools and network admin capabilities. The open-source build configuration is available under MIT license with automated multi-platform builds and security attestations.
⚡ Enhanced LLM Integration - PentAGI now uses a custom fork of langchaingo with significant improvements for better LLM provider compatibility, enhanced function calling, streaming responses, and optimized external service integrations.
🚀 New Features

Community Launch: Official Discord and Telegram channels for community support, knowledge sharing, and collaboration between security researchers and AI enthusiasts
Flexible LLM Configuration: YAML/JSON configuration system for custom providers with per-agent model specifications (examples)
Advanced Report Generation: Comprehensive Markdown and PDF reports for flows, tasks, and subtasks
Smart Context Management: Enhanced conversation summarization with configurable preservation settings
Message Copy &amp; Search: Copy messages in Markdown format with text highlighting across all interfaces
Provider Management: Visual icons and improved status indicators for OpenAI, Anthropic, and custom providers

🎨 UI/UX Improvements

Streamlined Assistant Interface: New tab with chat creation, management, and persistent state
Enhanced Navigation: Improved breadcrumbs with status and provider information
Better Authentication: Enhanced GitHub/Google OAuth with password change functionality
Improved Flow Management: Better status handling with proper state transitions and input blocking
Professional Tooltips: Fixed positioning and enhanced visual feedback

🐛 Key Fixes

Flow Status Synchronization: Resolved issues with status updates when switching between flows
Assistant Integration: Fixed problems launching assistants on new and completed flows
Terminal Synchronization: Improved command execution display between automated and manual agents
Message Chain Consistency: Enhanced restoration and context handling after interruptions
Configuration Issues: Resolved Docker, environment variables, and provider setup problems

🔧 Infrastructure Improvements

Enhanced Container Security: Improved isolation with controlled network capabilities
Environment Flexibility: ASK_USER interactive mode, proxy support, and SSL/TLS enhancements
Build Optimization: Golang 1.24 upgrade, dependency updates, and improved Docker builds
Configuration Management: Pre-built provider configs for OpenRouter, DeepInfra, and DeepSeek
Custom Docker Images: Open-source Kali Linux containers with automated builds, multi-platform support, and security attestations

🔄 Performance &amp; Architecture

Agent System Refactoring: Major improvements to core execution logic with better modularity
Memory Optimization: Enhanced context management and chain summarization for reduced footprint
Database Performance: Optimized queries and improved vector storage operations
Enhanced Prompt System: Unified templates with shared components and simplified handling
LLM Library Improvements: Migration to custom langchaingo fork with enhanced streaming, function calling, and provider compatibility


📖 Documentation: For detailed setup instructions, visit the README and Quick Start Guide

New Contributors

@dependabot made their first contribution in #4
@hhktony made their first contribution in #32


Full Changelog: v0.2.0...v0.3.0 ]]></description>
<link>https://tsecurity.de/de/3487948/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.3.0+-+First+Public+Beta+Release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487948/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v0.3.0+-+First+Public+Beta+Release/</guid>
<pubDate>Sun, 29 Mar 2026 14:30:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PentAGI v1.0.0 - Production Release]]></title> 
<description><![CDATA[


🎉 PentAGI 1.0 - Production Ready! The first stable release of our autonomous penetration testing platform, bringing enterprise-grade features, enhanced AI capabilities, and a completely redesigned user experience.

⠀


🎯 Major Features
🧠 Graphiti Knowledge Graph Integration - Revolutionary memory system using Graphiti, a temporal knowledge graph that maintains context across penetration testing sessions. Configure deployment modes (embedded, external, or disabled) and leverage graph-based reasoning for more intelligent agent decisions.
⚙️ Interactive Installer - Professional setup wizard with comprehensive system checks, Docker volume detection, and step-by-step configuration for all services including LLM providers, search engines, and observability stack. Available for Linux, macOS, and Windows.
🎨 Modern Frontend Redesign - Complete UI/UX overhaul with React 19, Tailwind CSS v4, and enhanced architecture:

Advanced flow management with filters by agents, tasks, tools, and vector stores
Improved settings interface with tabular data views and form validation
Real-time toast notifications and responsive design
Enhanced favorites system and sidebar navigation

🔧 Provider Management System - Unified configuration for LLM providers with support for:

AWS Bedrock (with temporary credentials and session tokens)
Google Gemini (2.5 Flash and Pro models)
Ollama (local deployment)
Custom OpenAI-compatible endpoints

🔍 Enhanced Search Ecosystem - Integrated SearXNG meta-search engine with privacy-focused searching, complementing existing Perplexity and DuckDuckGo providers.
⚡ Patch Refiner - Intelligent result refinement system that automatically improves agent outputs, validates findings, and ensures accuracy before presenting final results.
🚀 New Features

Prompt &amp; Agent Management: Create, edit, and test custom AI agent configurations through the web interface
Provider Testing UI: Built-in testing functionality for validating LLM provider configurations with detailed reports
SSL/TLS Configuration: External certificate support with custom CA paths and insecure mode for development
Enhanced Container Management: Configurable Docker images for penetration testing with improved isolation
Installation ID &amp; Licensing: PentAGI Cloud API integration with license key management
Volume Persistence Detection: Automatic Docker volume existence checks for Pentagi and Langfuse services

🎨 UI/UX Improvements

React 19 Migration: Upgraded to latest React version with improved performance and new features
Tailwind v4: Modern styling system with better customization and smaller bundle size
Flow Components Refactoring: Renamed and restructured chat components to flow-based architecture
Responsive Filter Forms: Advanced filtering UI with input groups for agents, tools, and vector stores
Delete Confirmation Dialogs: User-friendly confirmation prompts for destructive actions
Hybrid Model Selector: Combined input/dropdown for flexible model selection

🐛 Key Fixes

Long Subtask Descriptions: Fixed issue #72 with truncating overly detailed subtask descriptions
Large Result Storage: Resolved database issues when storing extensive task and subtask results
Provider Configuration: Fixed empty provider config creation in web UI (issue #63)
Manual Task Stopping: Improved handling when stopping tasks during refiner operations
URL Resolution: Enhanced browser tool logic for local domain handling
UTF-8 Sanitization: Moved database UTF-8 sanitization to common package for consistency

🔧 Infrastructure Improvements

Go 1.24: Updated to latest Golang version with performance improvements
Docker Optimization: Removed unnecessary cleanup steps, optimized layer caching
Dependency Updates:

Docker SDK 28.2.2 &rarr; 28.3.3
Ollama 0.9.6 &rarr; 0.10.0
golang.org/x/crypto security updates
Frontend dependencies (Vite, axios, jsPDF)


Alpine 3.22.1: Latest base image with security patches
Enhanced Logging: Improved logging throughout the application with better context

🔄 Performance &amp; Architecture

Graphite Docker Compose: Separate docker-compose-graphiti.yml for modular deployment
Parallel Workers: Increased default from 8 to 16 for improved testing performance
Apollo Cache Optimization: Added keyFields normalization for better provider handling
Agent Configuration: Refactored to use AgentConfigType enum for clarity
Settings Refactoring: Streamlined provider, prompt, and agent management architecture

📚 Documentation

Installer Documentation: Comprehensive guide for installation wizard components
Flow Execution Guide: Enhanced launch configuration documentation
Graphiti Setup: Instructions for running knowledge graph stack
Provider Examples: Updated configuration examples for all supported providers
Prerequisites Guide: Detailed Docker installation and permissions documentation


📖 Documentation: For detailed setup instructions, visit the README and Quick Start Guide

New Contributors

@stoykovstoyk made their first contribution in #53
@PeterDaveHello made their first contribution in #50
@kaikreuzer made their first contribution in #90
@zavgorodnii made their first contribution in #93


Full Changelog: v0.3.0...v1.0.0 ]]></description>
<link>https://tsecurity.de/de/3487947/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v1.0.0+-+Production+Release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487947/IT+Sicherheit/Cybersecurity+Tools/PentAGI+v1.0.0+-+Production+Release/</guid>
<pubDate>Sun, 29 Mar 2026 14:31:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[1.0.1]]></title> 
<description><![CDATA[🐛 Bug Fixes &amp; Improvements
Enhanced Error Diagnostics

Added stop reason to error messages when LLM fails to generate tool calls
If stop reason is length, increase max_tokens parameter for the affected agent in provider settings
Improves troubleshooting and configuration optimization

DuckDuckGo Search Stability

Migrated to new DuckDuckGo API with HTML response parsing
Added comprehensive test coverage with real-world search scenarios
Significantly improved reliability and result quality

Provider Guardrails Bypass

Added explicit authorization framework to all agent prompts
Prevents blocking by OpenAI, Anthropic, and Google Gemini content filters
Clarified penetration testing context as pre-authorized activity

OpenAI Configuration Updates

Temporarily switched from gpt-5 to o4-mini for primary agent and assistant due to OpenAI prompt evaluation instability
Increased max_tokens limits across multiple agents for better output capacity
Recommendation: Enable Human-in-the-loop mode (ASK_USER=true in .env) when using OpenAI provider for improved stability

Additional Improvements

Enhanced message formatting in vector store communications with document match scores
Improved clarity in generator and refiner prompts for user task interpretation
Added customer interaction protocol for AskUser tool


Full Changelog: v1.0.0...v1.0.1 ]]></description>
<link>https://tsecurity.de/de/3487946/IT+Sicherheit/Cybersecurity+Tools/1.0.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487946/IT+Sicherheit/Cybersecurity+Tools/1.0.1/</guid>
<pubDate>Sun, 29 Mar 2026 14:31:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[1.1.0]]></title> 
<description><![CDATA[🔧 Bug Fixes &amp; Improvements
LiteLLM Passthrough Support

Fixed Gemini provider compatibility issues preventing proper LiteLLM integration
All providers now support LiteLLM passthrough mode with standardized endpoints:

OpenAI: http://litellm:4000/openai/v1
Anthropic: http://litellm:4000/anthropic/v1
Gemini: http://litellm:4000/gemini


Tested and verified with LiteLLM v1.80.11-stable.1
Enhanced Gemini provider with custom HTTP transport for API key injection and URL rewriting

Windows File Path Compatibility

Changed file mounting scheme in PentAGI container to resolve Windows path format issues
Migrated from host path mapping to fixed container paths for better cross-platform compatibility
Updated volume mounts:

PENTAGI_LLM_SERVER_CONFIG_PATH &rarr; /opt/pentagi/conf/custom.provider.yml
PENTAGI_OLLAMA_SERVER_CONFIG_PATH &rarr; /opt/pentagi/conf/ollama.provider.yml
PENTAGI_DOCKER_CERT_PATH &rarr; /opt/pentagi/docker/ssl


Migration: Installer v1.0.0 automatically migrates old settings to new schema
Users can now specify absolute paths in their host filesystem through installer forms

Ollama Single Model Configuration

Added OLLAMA_SERVER_MODEL environment variable to select a single model for all agents
Eliminates need to create custom provider configuration files for simple setups
Additional fine-tuning options:

OLLAMA_SERVER_PULL_MODELS_ENABLED - Control automatic model downloads (default: false)
OLLAMA_SERVER_LOAD_MODELS_ENABLED - Query available models on startup (default: false)
OLLAMA_SERVER_PULL_MODELS_TIMEOUT - Timeout for model pulls in seconds (default: 600)


Default model: llama3.1:8b-instruct-q8_0

Installer v1.0.0

Bumped installer version to 1.0.0 with comprehensive stability improvements
Full Windows support with all configuration scenarios matching Linux and macOS
Disabled ANSI formatting in Docker Compose commands on Windows for cleaner console output
Automatic settings migration from old path variables to new schema:

DOCKER_CERT_PATH &rarr; PENTAGI_DOCKER_CERT_PATH
LLM_SERVER_CONFIG_PATH &rarr; PENTAGI_LLM_SERVER_CONFIG_PATH
OLLAMA_SERVER_CONFIG_PATH &rarr; PENTAGI_OLLAMA_SERVER_CONFIG_PATH


Enhanced error handling and validation throughout installation process
Recommended: Download latest installer, run &quot;Apply changes&quot; to migrate to new file mounting scheme, then navigate to Maintenance tab and execute &quot;Update PentAGI&quot; to download the new version that supports these options

Enhanced Terminal Command Handling

Improved agents&#039; understanding of empty results from synchronous terminal commands
Enhanced background command processing with asynchronous result capture
Introduced quick check timeout for background command execution
Clearer feedback on command failures and silent successes
More accurate success messages reflecting actual command execution outcomes

Additional Improvements

Fixed nil pointer dereference in Graphiti client methods
Enhanced error handling for invalid server and proxy URLs during provider initialization
Improved Docker Compose command handling on Windows systems
Added comprehensive tests for Gemini API key injection and URL rewriting


Full Changelog: v1.0.1...v1.1.0 ]]></description>
<link>https://tsecurity.de/de/3487945/IT+Sicherheit/Cybersecurity+Tools/1.1.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487945/IT+Sicherheit/Cybersecurity+Tools/1.1.0/</guid>
<pubDate>Sun, 29 Mar 2026 14:31:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[1.2.0]]></title> 
<description><![CDATA[


🚀 PentAGI 1.2 - Enhanced AI Capabilities! Major upgrade bringing latest reasoning models, token caching, comprehensive analytics, and REST API access for seamless integration with automation platforms.

⠀


🎯 Major Features
🧠 Latest Reasoning Models Support - Complete integration of cutting-edge AI models with native reasoning capabilities:

Gemini 2.5/3.0 family with thinking tokens support
Anthropic Claude Sonnet 4+ with extended reasoning
DeepSeek R1 and Kimi K2.5 in reasoning mode
OpenAI o-series models with signature thoughts
OpenRouter and OpenAI-compatible endpoints with reasoning content preservation

💰 Token Caching &amp; Cost Optimization - Intelligent prompt caching reduces input token costs by 40-70% in multi-turn agent conversations:

Native caching support for Anthropic (ephemeral cache controls) and Gemini (pre-created content caching)
Automatic cache hit tracking with detailed analytics
Particularly effective for long-context penetration testing sessions
Standardized cache token reporting across all providers

📊 Usage Analytics &amp; Monitoring - Comprehensive REST API endpoints for detailed resource utilization tracking:

Token usage breakdown by agent type (researcher/developer/executor)
Cost analysis with cache read/write separation
Execution time metrics per flow and subtask
Tool call frequency statistics
Foundation for visual analytics dashboard (coming in v1.3)

🔑 API Token Management - JWT-based API authentication enables programmatic access to PentAGI:

Generate and manage API tokens through web interface
Full REST and GraphQL API access for automation
OpenAPI specifications for client code generation in any language
Integration-ready for n8n, OpenClaw, Claude Desktop, and custom solutions
Foundation for official MCP server (planned for future releases)

🔍 Sploitus Integration - Experimental support for vulnerability search engine:

Cloudflare-protected service requires IP reputation verification
Use built-in ftester utility to check your IP reputation before enabling
Configure via SPLOITUS_ENABLED environment variable

📡 Langfuse v3 Observability - Complete migration to Langfuse v3 standard with enhanced LLM operations tracking:

Observation type separation: Spans, Generations, Agents, Tools, Chains, Retrievers, Evaluators, Embeddings, Guardrails
Enhanced message chain visualization with Playground mode navigation
Detailed Score metrics and execution time logging
Improved variable and metadata tracking across all observation types

🚀 New Features

Reasoning Content Preservation: Smart message chain summarization that maintains reasoning signatures for models requiring strict conversation structure
Tool Call ID Templates: Configurable tool call ID format enforcement for LLM backends with strict validation requirements
User Preferences System: Favorite flows management with persistent preferences storage
GraphQL Subscriptions: Real-time flow updates with user-specific event publishing
Docker Build Versioning: Embedded version and revision information in container images with dedicated build scripts for Linux/macOS/Windows
Enhanced Error Diagnostics: Stop reason included in error messages (e.g., length indicates need to increase max_tokens)
PDF Report Generation: Export flow results to PDF using @react-pdf/renderer library
User Favorites: Add and manage favorite flows with dedicated GraphQL mutations
Podman Support: Official documentation for running PentAGI with Podman in rootless mode

🎨 UI/UX Improvements

Enhanced Theme Handling: Improved dark/light/system theme switching with automatic system preference detection
Better Authentication Flow: Safe return URL handling with validation to prevent open redirect vulnerabilities
Google OAuth Fix: Resolved CORS issues and improved cookie handling for Google OAuth integration
Flow Subscriptions: Real-time flow updates in UI via GraphQL subscriptions with user-scoped events
Settings Form Validation: Stronger password requirements with visibility toggles
Enhanced Report Generation: Fixed markdown rendering issues in flow reports

🐛 Key Fixes

Resource Leak Prevention: Fixed response body leaks in browser tool, added tar header size validation in terminal operations, properly close tarWriter to prevent incomplete archives (#101)
Security Hardening:

OAuth state parameter validation with explicit CSRF checks (#101)
Session expiry enforcement in authentication middleware
SameSite cookie attributes for CSRF protection
Browser tool HTTP client timeout (30s) to prevent indefinite hangs
Authorization string typos fixed (trailing quotes causing ACL failures)


TLS Configuration: Respect EXTERNAL_SSL_INSECURE config in Langfuse client, load custom CA certificates from EXTERNAL_SSL_CA_PATH, use system cert pool as base (#132)
Terminal Command Logic: Corrected terminal command handling logic (#124)
Swagger Documentation: Fixed missing closing quotes in OpenAPI annotations
Code Quality: Removed debug console.log statements from production code
Traversaal API: Updated integration after vendor-side API specification changes
Nil Pointer Checks: Added nil checks for Langfuse client before ForceFlush operations

🔧 Infrastructure Improvements

LangChainGo v0.1.14-update.1: Major dependency update with 6 months of accumulated improvements:

Signature thoughts support for Anthropic, Gemini, OpenAI providers
Message chain caching for Gemini and Anthropic with token savings tracking
Standardized usage format across all providers with unified field names
Comprehensive test coverage for LLM scenarios including multi-turn conversations, function calling, caching validation
Migrated Google AI provider to google.golang.org/genai from deprecated SDK
Bedrock Converse API support for Anthropic Claude models
Enhanced streaming with proper resource cleanup (memory leak fixes)


Alpine 3.23.3: Updated base Docker image with latest security patches
Model Updates: Switched from deprecated gemini-2.0-flash-lite to gemini-2.5-flash-lite with adjusted pricing
GitHub Actions Modernization: Upgraded all workflows for Node 24 compatibility
Dependency Security Updates:

axios 1.13.2 &rarr; 1.13.5
lodash 4.17.21 &rarr; 4.17.23
diff 5.2.0 &rarr; 5.2.2
jspdf 4.1.0 &rarr; 4.2.0


External Network Access: Comprehensive documentation for configuring PentAGI accessibility from other machines with firewall setup instructions
Entrypoint Script: SSL certificate generation management for enhanced security setup

🔄 Performance &amp; Architecture

Standardized Token Usage: All LLM providers now return consistent token fields (PromptTokens, CompletionTokens, TotalTokens, CacheCreationTokens, CacheReadTokens)
Enhanced Logging: Enriched log fields with flow/task/subtask IDs for better traceability
Observation Framework: Refactored observability with W3C Trace Context compliance (newSpanID/newTraceID functions)
Chain Summarization: Enhanced algorithm with critical guarantees preserving last N QA sections even if exceeding size limits, ensuring reasoning signatures retention
Improved Metadata Handling: Stop reason tracking in generation metadata for better observability

📚 Documentation

Typo Fixes: Comprehensive typo corrections across documentation and code comments (#121):

&quot;PegtAGI&quot; &rarr; &quot;PentAGI&quot; in frontend README
&quot;Depp Infra&quot; &rarr; &quot;Deep Infra&quot;, &quot;Traversal&quot; &rarr; &quot;Traversaal&quot; in EULA
OAuth environment variable names aligned with .env.example
Fixed filename typos (sreenshots.go &rarr; screenshots.go, wizard-integation &rarr; wizard-integration)


External Access Guide: Step-by-step instructions for PENTAGI_LISTEN_IP, PUBLIC_URL, CORS_ORIGINS configuration
Podman Documentation: Running PentAGI with Podman in rootless mode with non-privileged ports


📖 Documentation: For detailed setup instructions, visit the README and Quick Start Guide

New Contributors

@mason5052 made their first contribution in #120
@Priyanka-2725 made their first contribution in #124
@SkyFlyingMouse made their first contribution in #128
@Vaibhavee Singh made their first contribution (documentation for external network access)
@salmanmkc made their first contribution in #111
@s-b-repo made their first contribution in #83


Full Changelog: v1.1.0...v1.2.0 ]]></description>
<link>https://tsecurity.de/de/3487944/IT+Sicherheit/Cybersecurity+Tools/1.2.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487944/IT+Sicherheit/Cybersecurity+Tools/1.2.0/</guid>
<pubDate>Sun, 29 Mar 2026 14:31:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[3.0.0-20260331]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/434a2e7866b7a6f7379b47b88749f6850baef581/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Update VERSION by @TOoSmOotH in #15320
Un-Advanced Assistant ApiUrl by @coreyogburn in #15323
expose login form lifespan in config scr by @jertel in #15347
update kratos index template by @reyesj2 in #15353
exempt kratos online check by @jertel in #15358
suppress config diffs to avoid false positive errors by @jertel in #15359
Assistant: Session Report Template by @mc-wright in #15355
ES 9.0.8 by @reyesj2 in #15363
Case Report Update for AI Session Attachments by @mc-wright in #15367
Add version 2.4.201 to discussion template by @jertel in #15389
Fixmerge201210 by @m0duspwnens in #15390
2.4.201 into dev by @TOoSmOotH in #15387
follow symlinks for docker cp by @reyesj2 in #15391
add additional retries within scripts before salt re-runs the entire &hellip; by @reyesj2 in #15393
remove usage of deprecated &#039;logs&#039; integration in favor of &#039;filestream&#039; by @reyesj2 in #15394
Fstes by @m0duspwnens in #15397
break out ssl state by @m0duspwnens in #15400
allow logstash.ssl for eval and import. fix soup create_ca_pillar by @m0duspwnens in #15402
create dir if nonexistent by @m0duspwnens in #15405
reinstall agent on grid nodes when service wasn&#039;t cleanly removed. eg&hellip; by @reyesj2 in #15404
fix include by @m0duspwnens in #15406
more better by @reyesj2 in #15407
fix kafka state by @reyesj2 in #15408
fix auto soup - check for compatible versions and fallback to a known&hellip; by @reyesj2 in #15410
add retries to so-resources repo pull by @reyesj2 in #15411
missing  updates to variables by @reyesj2 in #15412
ignore kratos file mapping error by @reyesj2 in #15414
exclude known error by @reyesj2 in #15420
update redis log file path by @reyesj2 in #15424
update heavynode&#039;s elastic-agent standalone policy by @reyesj2 in #15418
include all so-grid-nodes_* policies in automatic EA upgrades by @reyesj2 in #15435
run fleet ssl state in fleet.config to ensure all required certs are &hellip; by @reyesj2 in #15436
ensure exclude_files excludes log rotation pattern by @reyesj2 in #15438
Change version from 2.4.201 to UNRELEASED by @TOoSmOotH in #15440
initialize specific indices as needed by @reyesj2 in #15442
use logstash merged values for logstash metric collection by @reyesj2 in #15447
keep logsdb disabled by @reyesj2 in #15448
Cogburn/gemini by @coreyogburn in #15443
allow network installs to use ISO for faster soupin by @reyesj2 in #15465
don&#039;t set is_airgap when using nonairgap_useiso: not a true airgap sy&hellip; by @reyesj2 in #15468
default roles by @jertel in #15472
Remove QWEN 235B model from defaults.yaml by @TOoSmOotH in #15473
clarify url_base description by @jertel in #15482
Config Tweaks for AI by @coreyogburn in #15481
Upgrade Salt 3006.19 by @m0duspwnens in #15491
fix sensor and heavynode first highstate failure by @m0duspwnens in #15494
Revert &quot;don&#039;t set is_airgap when using nonairgap_useiso: not a true airgap sy&hellip;&quot; by @reyesj2 in #15496
Revert &quot;allow network installs to use ISO for faster soupin&quot; by @reyesj2 in #15497
Assistant: Investigated Query Toggle Filter by @mc-wright in #15492
upgrade docker by @m0duspwnens in #15500
Add OpenAI Protocols by @coreyogburn in #15501
rework autosoup for intermediate upgrades by @reyesj2 in #15499
upgrade docker by @m0duspwnens in #15506
healthTimeoutSeconds should be an int by @coreyogburn in #15507
upgrade docker by @m0duspwnens in #15509
New so-yaml.py Functions for Gemini Cypress Test Support by @mc-wright in #15505
upgrade docker by @m0duspwnens in #15510
migrate managed_integrations pillar by @reyesj2 in #15503
upgrade analyzer deps by @reyesj2 in #15511
fix consecutive comments by @m0duspwnens in #15513
fix soup failure if salt-relay isn&#039;t running by @m0duspwnens in #15519
Add Support for upgrading to 3.0 by @TOoSmOotH in #15517
Rename model ID from &#039;sonnet-4.5&#039; to &#039;sonnet&#039; by @TOoSmOotH in #15522
fix field conflicts by @reyesj2 in #15524
fix suricata filestream dataset by @reyesj2 in #15523
fix agentstatus script by @reyesj2 in #15525
do not allow auth redirection to login page or home page; that serves&hellip; by @jertel in #15526
exclude transient ghcr.io network errors since it retries during setup by @jertel in #15532
Cleanup idstools by @defensivedepth in #15531
restart salt minion before failing if not ready by @m0duspwnens in #15534
prevent caching of main doc to ensure logged out detection is processed by @jertel in #15535
Move rm to post by @defensivedepth in #15536
prepare for nextgen docs by @jertel in #15539
2.4.210 by @TOoSmOotH in #15541
2.4.210 by @TOoSmOotH in #15542
3/dev merge fix by @TOoSmOotH in #15544
3/dev by @TOoSmOotH in #15543
Add version 3.0.0 to discussion template by @TOoSmOotH in #15545
Support additional alt names in web cert by @m0duspwnens in #15555
update repo readme by @jertel in #15554
update 2.4 references to 3 by @jertel in #15556
remove steno by @jertel in #15563
pcapout still used for extracts by @jertel in #15566
Update so-suricata-testrule for idstools removal by @defensivedepth in #15572
Refactor upgrade functions and version checks by @TOoSmOotH in #15567
cleanup steno. sensor run pcap.cleanup by @m0duspwnens in #15575
set container ulimits to default by @m0duspwnens in #15594
remove 10T virtual disk limit. URL_BASE to vm hosts file by @m0duspwnens in #15591
Add version 2.4.211 to discussion template by @TOoSmOotH in #15599
Remove version 3.0.0 from 2.4 discussion template by @dougburks in #15603
Update version check to include 2.4.211 by @TOoSmOotH in #15595
pcap cleanup state. enable/disable pcap for suricata in soc by @m0duspwnens in #15574
Improve soup version checks and migrate pcap to suricata by @TOoSmOotH in #15608
Moresoup by @TOoSmOotH in #15609
API errors will no longer redirect by @jertel in #15612
initialize pcap-log by @m0duspwnens in #15615
forcedType bool by @m0duspwnens in #15618
Remove support for non-Oracle Linux 9 operating systems by @TOoSmOotH in #15619
Remove non-Oracle Linux 9 support from salt states by @TOoSmOotH in #15620
Add -r flag to so-yaml get and migrate pcap pillar to suricata by @TOoSmOotH in #15610
fix health check for new hydra version by @jertel in #15622
Rebuild analyzer source-packages wheels for Python 3.14 by @TOoSmOotH in #15621
fix hydra health check by @jertel in #15623
Add SOC UI toggle for JA4+ fingerprinting by @TOoSmOotH in #15624
old code cleanup. add ja4 toggle in soc. by @m0duspwnens in #15627
Add salt states for custom Zeek package loading by @TOoSmOotH in #15628
Add customizable ulimit settings for all Docker containers by @TOoSmOotH in #15629
use elasticsearch recommended vm.max_map_count by @reyesj2 in #15630
update helpLink references for new documentation by @dougburks in #15634
Customulimit by @m0duspwnens in #15636
remove .jinja from daemon.json by @m0duspwnens in #15638
ignore redis restart warning in logstash log by @jertel in #15637
fix global override settings affecting non-data stream indices by @reyesj2 in #15632
ensure valid ulimit names by @m0duspwnens in #15640
more doc updates by @jertel in #15642
fix so-idh and so-redis datastream config by @reyesj2 in #15644
fix casing to match annotation docs by @jertel in #15643
Support docker ulimit customization by @m0duspwnens in #15641
Hyperlink to JA4+ license by @TOoSmOotH in #15648
Enabled / Disabled Buttons for SOC Grid Configuration  by @m0duspwnens in #15652
add yes/no to true/false conversion for suricata to soup postupgrade by @m0duspwnens in #15653
Add support for websockets by @defensivedepth in #15656
do not attempt to redirect to a source map after login by @jertel in #15658
exclude oscap profile from gitleaks by @reyesj2 in #15662
Remove hardcoded path by @defensivedepth in #15663
allow negation in suricata address-group vars by @m0duspwnens in #15665
update stig profile v1r3 by @reyesj2 in #15661
Enable clean option for Zeek configuration by @TOoSmOotH in #15667
Lowercase network transport by @defensivedepth in #15669
update yara template by @defensivedepth in #15672
Make AI adapter settings visible by @TOoSmOotH in #15676
ensure bool sliders soc by @m0duspwnens in #15690
revisit workflows by @jertel in #15691
Remove hardcoded index by @defensivedepth in #15694
3.0.0 by @TOoSmOotH in #15695
Merge 3/main into 3/dev by @TOoSmOotH in #15698
3.0.0 by @TOoSmOotH in #15696

Full Changelog: 2.4.201-20260114...3.0.0-20260331 ]]></description>
<link>https://tsecurity.de/de/3487943/IT+Sicherheit/Cybersecurity+Tools/3.0.0-20260331/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487943/IT+Sicherheit/Cybersecurity+Tools/3.0.0-20260331/</guid>
<pubDate>Tue, 31 Mar 2026 19:51:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.94.2]]></title> 
<description><![CDATA[What&#039;s Changed

Skip TestAPKHandler by @shahzadhaider1 in #4841
fix: replace release-guard workflow with revert-latest job by @sysread in #4838
Deprecated GoogleAPIKey Detector by @nabeelalam in #4853
todoist: replace deprecated verification endpoint by @rai1612 in #4828
Add Shopify OAuth Detector by @amanfcp in #4738
[INS-425] Updated google.golang.org/grpc v1.78.0 --&gt; v1.79.3 by @MuneebUllahKhan222 in #4852
[INS-421] Re-enabled TestAPKHandler test and updated artifact url by @MuneebUllahKhan222 in #4856

New Contributors

@sysread made their first contribution in #4838
@rai1612 made their first contribution in #4828

Full Changelog: v3.94.1...v3.94.2 ]]></description>
<link>https://tsecurity.de/de/3487942/IT+Sicherheit/Cybersecurity+Tools/v3.94.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487942/IT+Sicherheit/Cybersecurity+Tools/v3.94.2/</guid>
<pubDate>Wed, 01 Apr 2026 15:19:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.368.0]]></title> 
<description><![CDATA[What&#039;s Changed

Add package manager detection and enhance NoChangeError logging by @robaiken in #14539
Fix Incorrect Compare Link in Generated PR Body by @thavaahariharangit in #14531
Include PR title and body in update_pull_request API calls by @Copilot in #14492
Load nix ecosystem in updater setup by @JamieMagee in #14548
Fix invalid update to Pre-Commit dependencies with mixed versioning schemes by @AbhishekBhaskar in #14538
Fix crash with terraform modules using host:port sources by @jurre in #14541
Upgrade Erlang OTP major version to 27 by @vbalazs in #14485
fix broken pip-compile test by @jakecoffman in #14562
fix python fetching when environment markers present by @jakecoffman in #14559
Preserve npm workspace manifest updates in PR files by @thavaahariharangit in #14542
bundler cooldown feature; Remove GPR special-casing, add fallback for registries that don&#039;t support the necessary API endpoint by @jeffwidman in #14551
Bump brace-expansion from 1.1.11 to 1.1.13 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14565
Bump brace-expansion in /npm_and_yarn/helpers by @dependabot[bot] in #14558
Bump brace-expansion from 1.1.12 to 1.1.13 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14564
Bump brace-expansion from 1.1.11 to 1.1.13 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14563
nix: fix permission denied on /nix/var/nix/db/big-lock by @JamieMagee in #14568
fix: Handle Excon::Error::Socket in RegistryClient and PackageDetailsFetcher by @markhallen in #14557
hex: add regression test for Hex.Repo.get_public_key/1 tuple order by @Copilot in #14407
fix Python update when the same dependency appears multiple times with different extras by @jakecoffman in #14578
feat: update Xcode pbxproj for Swift SPM by @markhallen in #14587
fix(conda): don&#039;t treat compound version constraints as fully qualified specs by @thavaahariharangit in #14586
[python][pip-compile] Fix constraint files (-c) in .in files not being fetched by @Copilot in #14588
Fix pre-commit tag prefix matching for monorepos with mixed tag prefixes by @AbhishekBhaskar in #14582
Add support for update-types in allow block by @Copilot in #12925
pip: Warn when ownership changes by @martincostello in #14235
terraform: handle private/unresolvable providers during lockfile updates by @jurre in #14585
Fix Python MetadataFinder leaking private package names to public PyPI by @jurre in #14590
Promote Nix ecosystem from beta to GA by @JamieMagee in #14597
Fix allow update-types filtering for individual dependency updates by @kbukum1 in #14598
v0.368.0 by @dependabot-core-action-automation[bot] in #14604

New Contributors

@vbalazs made their first contribution in #14485

Full Changelog: v0.367.0...v0.368.0 ]]></description>
<link>https://tsecurity.de/de/3487941/IT+Sicherheit/Cybersecurity+Tools/v0.368.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487941/IT+Sicherheit/Cybersecurity+Tools/v0.368.0/</guid>
<pubDate>Thu, 02 Apr 2026 18:48:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.4.211-20260407]]></title> 
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/55af7eb541f086c4e7d6d3182fb2bc4fbc2b9e21/DOWNLOAD_AND_VERIFY_ISO.md
What&#039;s Changed

Cherry-pick suricata bpf fix and HOTFIX update by @TOoSmOotH in #15726
2.4.211 hotfix by @TOoSmOotH in #15731
Hotfix 2.4.211 by @TOoSmOotH in #15732

Full Changelog: 2.4.211-20260312...2.4.211-20260407 ]]></description>
<link>https://tsecurity.de/de/3487940/IT+Sicherheit/Cybersecurity+Tools/2.4.211-20260407/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487940/IT+Sicherheit/Cybersecurity+Tools/2.4.211-20260407/</guid>
<pubDate>Tue, 07 Apr 2026 19:24:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.94.3]]></title> 
<description><![CDATA[What&#039;s Changed

Add release bot workflow by @bryanbeverly in #4835
handle AADSTS50173 as explicit revocation signal for azure refresh tokens by @jordanTunstill in #4842
Add AnalysisInfo to verified results by @hxnyk in #4862
Add nil check and error context to GitHub analyzer by @johnelliott in #4858
[CSM-1857] Fix expired Azure secrets being silently dropped by @dipto-truffle in #4845
Add HTML decoder for secret detection in HTML-formatted sources by @alafiand in #4840
Split out detector types into separate proto file in order to narrow CODEOWNERS scope by @casey-tran in #4871

New Contributors

@johnelliott made their first contribution in #4858
@dipto-truffle made their first contribution in #4845
@alafiand made their first contribution in #4840

Full Changelog: v3.94.2...v3.94.3 ]]></description>
<link>https://tsecurity.de/de/3487939/IT+Sicherheit/Cybersecurity+Tools/v3.94.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487939/IT+Sicherheit/Cybersecurity+Tools/v3.94.3/</guid>
<pubDate>Wed, 08 Apr 2026 19:24:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.369.0]]></title> 
<description><![CDATA[What&#039;s Changed

Allow updates for sub-dependencies in XCode SwiftPM projects by @AbhishekBhaskar in #14619
bun: Add --ignore-scripts to bun install/update commands by @RyPeck in #14373
feat: centralize semver-aware cooldown calculation by @markhallen in #14600
Add tests for Pythons Native Helpers by @robaiken in #14646
Bump nix from 2.34.1 to 2.34.5 by @JamieMagee in #14657
Fix corepack fallback for private npm registries by @thavaahariharangit in #14654
Regression added to bun --ignore scripts changes by @thavaahariharangit in #14641
Handle terraform registry 404s gracefully by @jurre in #14556
Add support for JSR (jsr.io) registry in npm_and_yarn by @Copilot in #14647
feat: handle hybrid Poetry v2 dependency updates by @markhallen in #14658
feat: add cooldown filter for github_actions using existing git_commit_checker and available_latest_version_tag by @v-HaripriyaC in #14621
v0.369.0 by @dependabot-core-action-automation[bot] in #14663

New Contributors

@RyPeck made their first contribution in #14373
@v-HaripriyaC made their first contribution in #14621

Full Changelog: v0.368.0...v0.369.0 ]]></description>
<link>https://tsecurity.de/de/3487938/IT+Sicherheit/Cybersecurity+Tools/v0.369.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487938/IT+Sicherheit/Cybersecurity+Tools/v0.369.0/</guid>
<pubDate>Thu, 09 Apr 2026 22:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.23]]></title> 
<description><![CDATA[0.7.23 (2026-04-08)
Bug Fixes

force verdict on judge discovery exhaustion instead of hard-failing (#315) (197f567)
judge off-by-one, auto-run on script exhaustion, assertion criteria, marathon_script cleanup (#289) (91f76d1)
 ]]></description>
<link>https://tsecurity.de/de/3487937/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.23/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487937/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.23/</guid>
<pubDate>Fri, 10 Apr 2026 13:11:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[javascript: v0.4.10]]></title> 
<description><![CDATA[0.4.10 (2026-04-10)
Bug Fixes

default scenarioSetId to &#039;default&#039; for all events (#305) (7bbc8c6)
default scenarioSetId to &quot;default&quot; when not provided (7bbc8c6), closes #304
force verdict on judge discovery exhaustion instead of hard-failing (#315) (197f567)
judge off-by-one, auto-run on script exhaustion, assertion criteria, marathon_script cleanup (#289) (91f76d1)
revert audio model and reduce multilingual test turns (#314) (177cdb6)
revert audio model to gpt-4o-audio-preview and reduce multilingual test turns (177cdb6)

Miscellaneous

use gpt-5-mini everywhere, enable telemetry, fix reasoning model compat (#311) (2384fb2)
 ]]></description>
<link>https://tsecurity.de/de/3487936/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487936/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.10/</guid>
<pubDate>Fri, 10 Apr 2026 13:12:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2.0.0]]></title> 
<description><![CDATA[

PentAGI 2.0 &mdash; Broader Model Support, Analytics, Runtime Flexibility, and Agent Guardrails
This release expands the LLM provider ecosystem with four new providers, introduces a full analytics dashboard, enables runtime provider switching mid-flow, adds Docker host network mode for OOB attack scenarios, and ships a comprehensive set of stability and reliability improvements. It also includes significant test coverage expansion across the backend codebase.
⠀


Major Features
Four New LLM Providers: DeepSeek, GLM, Kimi, Qwen
Native support for four providers from the Chinese LLM ecosystem &mdash; DeepSeek, GLM (Zhipu AI), Kimi (Moonshot AI), and Qwen (Alibaba Cloud). Each is available through the standard provider configuration interface with API key and server URL environment variables (DEEPSEEK_API_KEY, GLM_API_KEY, KIMI_API_KEY, QWEN_API_KEY). All four providers are registered in the GraphQL schema and settings UI, and come with pre-configured model lists and pricing information. Unit test coverage for all four providers is included (~71% coverage per provider).
Ollama Cloud Support
In addition to local Ollama deployments, PentAGI now ships a pre-built ollama-cloud.provider.yml configuration with 7 cloud-hosted models assigned per agent type: nemotron-3-super, qwen3-coder-next, glm-5, minimax-m2.7, qwen3.5:397b, and devstral-2:123b. Both Free Tier and Paid Tier setup options are documented. The configuration is bundled in the Docker image at /opt/pentagi/conf/ollama-cloud.provider.yml.
Analytics Dashboards
A new analytics dashboard surfaces usage statistics and cost data collected from the REST API analytics endpoints introduced in v1.2.0. The dashboard shows:

Token usage and cost breakdown per flow and per agent type (primary, pentester, coder, installer, searcher, adviser, etc.)
Cache hit rates and cache read/write cost separation for Anthropic and Gemini providers
Tool call frequency and execution time metrics per flow and subtask
Per-model cost detail, useful when running multiple provider configurations simultaneously

Runtime Provider Switching
It is now possible to switch the active LLM provider for a running flow without restarting the application. To switch providers: pause the flow using the stop button, navigate to provider settings to change the active provider or update configuration, then resume the flow with a message directing the agent. The backend applies conditional chain normalization to preserve the reasoning cache when the provider is unchanged, and converts tool call IDs when switching providers. The modelProvider parameter has been added to the relevant GraphQL mutations to support this workflow.
Agent Supervision System (Beta)
Two optional supervision mechanisms are now available and disabled by default:

AGENT_PLANNING_STEP_ENABLED=true &mdash; enables a planning step before each specialist agent starts work, where a planner generates a 3&ndash;7 step execution plan to scope the subtask and prevent drift.
EXECUTION_MONITOR_ENABLED=true &mdash; enables automatic detection of unproductive agent behavior: consecutive identical tool calls (EXECUTION_MONITOR_SAME_TOOL_LIMIT, default 5) and excessive exploration (EXECUTION_MONITOR_TOTAL_TOOL_LIMIT, default 10) trigger automatic mentor intervention to redirect the agent.

Reworked Langfuse Observability
The Langfuse integration has been significantly overhauled for clearer visualization of agent activity. Observation types are now separated into Spans, Generations, Agents, Tools, Chains, Retrievers, Evaluators, Embeddings, and Guardrails. Each agent&#039;s tool calls, LLM calls, and intermediate results are tracked as distinct observations, making it straightforward to trace why an agent made a particular decision, what input it received, and what output it produced. Score metrics, timing data, and variable tracking have been improved across all observation types.

New Capabilities
Docker Host Network Mode
Setting DOCKER_NETWORK=host instructs PentAGI to create worker containers using the host network stack instead of a bridge network. This gives containers direct access to local network interfaces, which is necessary for OOB (out-of-band) attack techniques that require binding to local interfaces &mdash; such as setting up reverse shells where the listener must be reachable from the target network. Agent prompts include mandatory guidance on OOB port allocation for this mode.
HTTP Client Timeout
A new environment variable HTTP_CLIENT_TIMEOUT (default: 600 seconds / 10 minutes) applies a timeout to all outbound HTTP connections &mdash; including every LLM provider, search tool, and external API call. Previously, connections to unresponsive backends could hang indefinitely, blocking agent goroutines. When the config is nil, a client with the default timeout is returned instead of Go&#039;s http.DefaultClient (which has no timeout).
Agent Tool Call Limits
Hard limits are now enforced on the number of tool calls per agent invocation:

MAX_GENERAL_AGENT_TOOL_CALLS (default: 100) &mdash; applies to primary and specialist agents
MAX_LIMITED_AGENT_TOOL_CALLS (default: 20) &mdash; applies to focused agents (reflector, mentor, etc.)

When the limit is reached, the agent is guided to a graceful completion using barrier tools rather than being abruptly terminated.
Tool Call ID Generation
A configurable tool call ID template mechanism has been added for LLM backends that require a specific tool call ID format. This prevents validation errors from providers with strict ID format requirements and is set per provider configuration.
vLLM Reference Configuration
A tested reference configuration for qwen3.5-27b under vLLM is included, aimed at fully air-gapped or isolated environments where cloud LLM providers are unavailable. The configuration covers model parameters optimized for the agent roles PentAGI uses.
Flow Templates
Flows can now be saved as templates and reused. The templates management interface is available in the frontend, with full GraphQL API support for creating, updating, and launching flows from templates.
Novita AI Provider (Optional)
Novita AI is available as an optional provider via custom provider YAML configuration (novita.provider.yml). The default model assignment uses moonshotai/kimi-k2.5 for primary agents.

LLM Provider Improvements
Updated Model Configurations
All built-in provider configurations have been updated to reflect the current model landscape:

OpenAI: updated to GPT-5.4 series with revised pricing and token limits
Anthropic: increased max_tokens limits and updated to latest Claude Sonnet/Opus variants
Gemini: updated model assignments including Gemini 2.5-class models
Bedrock: added support for Default AWS SDK credential chain, Bearer token, and static credentials (Access Key + Secret Key), in addition to the existing session token method

Function Call and Thinking Signatures
Provider-level support for function call signatures and thinking signatures ensures that reasoning-capable models (Claude extended thinking, Gemini thinking tokens, DeepSeek R1 reasoning mode) produce well-formed conversations that preserve reasoning context across multi-turn interactions. This is particularly important for chain summarization, which now retains thinking signatures when compressing long conversations.
Improved Token Caching
Token caching has been further optimized for Anthropic (ephemeral cache controls) and Gemini (pre-created content caching) to reduce costs in long-running flows. Cache hit and cache write token counts are tracked separately per turn and are visible in the analytics dashboard.

Bug Fixes
Bedrock Provider Compatibility
Two distinct Bedrock issues have been resolved:

Fixed ValidationException errors when using the Converse API with tool schemas generated by Go&#039;s jsonschema reflector. The $schema field is now automatically stripped from tool parameters before sending to Bedrock.
Fixed a runtime failure where toolConfig was undefined for message chains containing toolUse/toolResult blocks. WithTools is now applied last in both CallEx and CallWithTools to prevent provider config options from overwriting tool definitions.

Detached Terminal Command Hangs
Background (detach mode) terminal commands previously inherited the parent agent context. When the parent context was cancelled (e.g., due to agent delegation timeout), the background goroutine was also terminated. Fixed by using context.WithoutCancel for detached goroutines, which preserves context values (tracing, logging) while preventing parent cancellation propagation. The command&#039;s own timeout continues to work as expected.
Infinite Agent Loop Prevention
Two complementary safeguards are now in place:

A hard cap of 100 iterations on the main agent chain loop prevents infinite execution when a model repeatedly calls the same tool.
After 3 consecutive identical tool calls, the agent receives a soft &quot;please try another approach&quot; message. After 7 identical consecutive calls in total, the loop terminates with an error.
Infinite reflector recursion has been independently fixed by moving retry guards to reflector entry points.

Logging and Log Worker Fixes
Several issues with agent activity logging were resolved: fixed log update propagation in the flow assistant log worker, corrected empty log entries being created when no updates occurred during assistant processing, improved streaming log throttling to prevent excessive cache updates, and fixed log worker initialization in assistant mode (missing agent call limits and execution monitoring).
QA Summarization Double-Summarization
Fixed an issue where already-summarized sections could be summarized a second time, producing degraded summaries in long-running flows with many completed phases.
Search Tool HTTP Client Safety
tavily.go and traversaal.go were mutating Go&#039;s global http.DefaultClient.Transport when configuring proxy settings, creating a data race for concurrent requests. Both tools now create a new http.Client instance when a proxy is configured.
Browser Tool Screenshot Handling
A screenshot failure in the browser tool no longer discards successfully-fetched page content. The screenshot is treated as a non-critical side effect; on failure, a warning is logged and the page content is returned with an empty screenshot reference.
Google Search Proxy Configuration
The Google search tool was constructing a proxy-configured options slice but then ignoring it and using a hardcoded option.WithAPIKey in the actual service creation call. The proxy configuration is now correctly applied.
User-Defined Provider Precedence
Fixed an issue (#220) where built-in provider configurations could override user-defined custom configurations with the same provider identifier. User-defined providers now always take precedence.
Security: CA Private Key Cleanup
After the server certificate is signed during container startup, the CA private key, CSR, and serial file are now immediately removed from disk. These files are not needed at runtime and their presence increases the attack surface if the container filesystem is compromised.
Auth Session Management
Improved session handling in the frontend: WebSocket connections on public pages are prevented, 401/403 errors in WebSocket, GraphQL, and HTTP requests trigger automatic session refresh, and the OAuth providers list is always fetched fresh on the login page to reflect newly added providers without cache clearing.

Test Coverage
Backend test coverage has been significantly expanded in this release. Key package coverage after new tests:



Package
Coverage




pkg/terminal
83.3%


pkg/queue
89.4%


pkg/schema
86.5%


pkg/server/auth
87.7%


pkg/server/response
100.0%


pkg/server/context
100.0%


pkg/csum
84.0%


pkg/cast
87.3%


pkg/config
75.7%


pkg/providers/bedrock
81.1%


pkg/providers/custom
79.2%


pkg/providers/embeddings
74.0%


pkg/providers/deepseek
71.4%


pkg/providers/glm
71.4%


pkg/providers/kimi
71.4%


pkg/providers/qwen
71.4%


pkg/providers/tester
78.7%



Tests also cover agent context management, tool registry completeness, executor helpers, terminal formatting utilities, langfuse helpers and noop observer, graphiti disabled mode, server/models validation, and JSON Schema validation.

Infrastructure

Docker Compose healthcheck: pg_isready healthcheck added to the pgvector service so the application waits for the database to be fully ready before starting.
License compliance: CONTRIBUTING.md with license compliance guidelines for contributors, and Dockerfile tooling to generate frontend and backend dependency license reports.
Frontend terminal: Modular architecture refactor, Unicode rendering fix, and security hardening.


Documentation

Added CONTRIBUTORS.md recognizing all contributors across the full project history (see note below).
Updated README with Ollama Cloud setup instructions (Free Tier and Paid Tier).
Added reference documentation for Docker host network mode and OOB attack scenarios.
Documented agent supervision settings (AGENT_PLANNING_STEP_ENABLED, EXECUTION_MONITOR_ENABLED, MAX_GENERAL_AGENT_TOOL_CALLS, MAX_LIMITED_AGENT_TOOL_CALLS, HTTP_CLIENT_TIMEOUT).


A Note on Repository History
On March 29, 2026, the repository history prior to that date was rewritten into a single squash commit to resolve a licensing matter. Individual commit history from January 2025 through March 2026 is no longer visible in the GitHub interface. The CONTRIBUTORS.md file was created to permanently record all contributions made during that period.

Contributors
Core Team

@asdek (Dmitry Nagibin) &mdash; Architecture, backend infrastructure, agent system, provider integrations, observability, project coordination
@sirozha (Sergey Kozyrenko) &mdash; React UI, settings interfaces, GraphQL integration, frontend architecture, analytics dashboard, terminal component
@zavgorodnii (Andrei Zavgorodnii) &mdash; Graphiti integration, patch refiner, knowledge graph implementation

External Contributors

@mason5052 &mdash; Comprehensive test coverage across 20+ packages, multiple critical bug fixes (detached context isolation, infinite loop cap, HTTP client mutation, browser screenshot handling, CA key cleanup, OAuth state validation, Google search proxy, and more)
@niuqun2003 &mdash; DeepSeek, GLM, Kimi, and Qwen LLM provider implementations (PR#154)
@Priyanka-2725 &mdash; AWS Bedrock toolConfig runtime fix, Sploitus integration, terminal command handling fix (PR#166, PR#133, PR#124)
@efe-arv / @liri-ha &mdash; HTTP client configurable timeout (PR#205)
@manusjs &mdash; Bedrock toolConfig fix for toolUse/toolResult blocks (PR#196)
@Alex-wuhu &mdash; Novita AI provider integration (PR#162)
@octo-patch &mdash; User-defined provider precedence fix (PR#234)
@haosenwang1018 &mdash; .gitignore improvements (PR#163)
@stoykovstoyk &mdash; SearXNG meta-search integration (PR#53)
@kaikreuzer &mdash; AWS temporary credentials support (PR#90)
@mrigankad &mdash; Security and bug fixes (PR#104)
@salmanmkc &mdash; GitHub Actions modernization (PR#111, PR#112)
@Vaibhavee89 &mdash; External network access configuration guide
@PeterDaveHello &mdash; Dockerfile optimization (PR#50)
@s-b-repo &mdash; File size limit and path escaping security improvements (PR#83)
@SkyFlyingMouse &mdash; Docker client constant name fix (PR#128)
@hhktony &mdash; README improvements (PR#32)


Full Changelog: v1.2.0...v2.0.0 ]]></description>
<link>https://tsecurity.de/de/3487935/IT+Sicherheit/Cybersecurity+Tools/2.0.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487935/IT+Sicherheit/Cybersecurity+Tools/2.0.0/</guid>
<pubDate>Sun, 12 Apr 2026 00:10:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.370.0]]></title> 
<description><![CDATA[What&#039;s Changed

Bump OpenTelemetry gems to latest versions by @JamieMagee in #14676
Clean-up of XCode Swift PM feature flag by @AbhishekBhaskar in #14680
Extends github-actions updater to support wider CalVer format by @lorengordon in #14678
feat: Support Poetry v2 requires-poetry version constraint by @markhallen in #14684
Improve support for PEP 621 and PEP 508 by @robaiken in #14652
Add *.lscache to nuget/.gitignore by @JamieMagee in #14688
Fix python bump versions strategy for range requirements by @AbhishekBhaskar in #14666
Fix python library detection for projects not published on PyPI by @AbhishekBhaskar in #14709
Nix: update pinned tag refs and versioned branch refs in flake.nix by @JamieMagee in #14710
feat: Install Poetry requires-plugins before running Poetry commands by @markhallen in #14707
Fix revision updates not being grouped by @dmitry-pogodin-tracebit in #14653
Poetry Dynamic dependency handling by @robaiken in #14706
test: Verify Poetry v2 lock file groups/markers handling by @markhallen in #14724
v0.370.0 by @dependabot-core-action-automation[bot] in #14738

New Contributors

@dmitry-pogodin-tracebit made their first contribution in #14653

Full Changelog: v0.369.0...v0.370.0 ]]></description>
<link>https://tsecurity.de/de/3487934/IT+Sicherheit/Cybersecurity+Tools/v0.370.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487934/IT+Sicherheit/Cybersecurity+Tools/v0.370.0/</guid>
<pubDate>Thu, 16 Apr 2026 13:30:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.24]]></title> 
<description><![CDATA[0.7.24 (2026-04-18)
Features

add GOAT strategy with dynamic technique selection for RedTeamAgent (#306) (e62c292)
python: add async-native scenario.arun for loop-bound resources (#369) (a797773)
 ]]></description>
<link>https://tsecurity.de/de/3487933/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487933/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.24/</guid>
<pubDate>Sat, 18 Apr 2026 16:18:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.0]]></title> 
<description><![CDATA[What&#039;s Changed

Upgrade golangci-lint in CI runner and Makefile by @amanfcp in #4861
Deprecate SquareUp Detector by @nabeelalam in #4855
[INS-397] Fix git version parser panic on non-numeric patch versions by @shahzadhaider1 in #4882
Fix Bitbucket line highlighting URLs by @shahzadhaider1 in #4854
[INS-403] Support Custom endpoint config in hashicorpvaultauth Detector by @MuneebUllahKhan222 in #4825
[INS-398] Added tests to ensure that custom endpoint configuration works in artifactory detectors by @MuneebUllahKhan222 in #4832
Host ldap-verify library in trufflesecurity by @trufflesteeeve in #4859
Add AnalysisError type and wrap all analyzer error paths by @johnelliott in #4779
dep-updates: Go 1.25 and dependency refreshes by @dustin-decker in #4888
Fix nil pointer panics in GitHub analyzer gist/repo binding functions by @shahzadhaider1 in #4864
[INS-399] Added Bitbucket data center(on prem) PAT detector by @MuneebUllahKhan222 in #4883
[INS-402] Add Jira Data Center PAT Detector by @mustansir14 in #4872
Add man page generation for trufflehog by @bryanbeverly in #4894
Add Confluence Data Center PAT detector by @amanfcp in #4886

Full Changelog: v3.94.3...v3.95.0 ]]></description>
<link>https://tsecurity.de/de/3487932/IT+Sicherheit/Cybersecurity+Tools/v3.95.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487932/IT+Sicherheit/Cybersecurity+Tools/v3.95.0/</guid>
<pubDate>Tue, 21 Apr 2026 19:56:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.1]]></title> 
<description><![CDATA[What&#039;s Changed

[INS-444] Fix verification logic in Mesibo detector by @mustansir14 in #4884

Full Changelog: v3.95.0...v3.95.1 ]]></description>
<link>https://tsecurity.de/de/3487931/IT+Sicherheit/Cybersecurity+Tools/v3.95.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487931/IT+Sicherheit/Cybersecurity+Tools/v3.95.1/</guid>
<pubDate>Tue, 21 Apr 2026 20:28:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.95.2]]></title> 
<description><![CDATA[What&#039;s Changed

Revert &quot;[INS-397] Fix git version parser panic on non-numeric patch versions&quot; by @trufflesteeeve in #4903

Full Changelog: v3.95.1...v3.95.2 ]]></description>
<link>https://tsecurity.de/de/3487930/IT+Sicherheit/Cybersecurity+Tools/v3.95.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487930/IT+Sicherheit/Cybersecurity+Tools/v3.95.2/</guid>
<pubDate>Tue, 21 Apr 2026 22:45:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.371.0]]></title> 
<description><![CDATA[What&#039;s Changed

Add test coverage for Poetry non-package mode (package-mode = false) by @markhallen in #14731
Extract Maven repo interaction logic for JVM ecosystems reuse by @AbhishekBhaskar in #14721
uv: Use env vars for index auth when URL matches pyproject.toml by @thavaahariharangit in #14744
Keep pinned git references by @robaiken in #14729
fix(github_actions): apply cooldown to ref rewrites by @shaanmajid in #14734
feat: Populate PoetryPackageManager version metadata by @markhallen in #14745
fix: Guard against nil dependencies in Poetry group sections by @markhallen in #14751
Fix TypeError on VCS repository credentials missing registry field in Composer by @Copilot in #14732
Fix Python libraries misclassification regression due to PR 14709 by @AbhishekBhaskar in #14747
Extract Maven metadata lookup logic into shared metadata finder for ecosystem reuse by @AbhishekBhaskar in #14756
cargo: Fix duplicate Cargo.lock entries for feature-gated git dependencies by @jurre in #14725
Poetry v2 feature tests by @robaiken in #14771
test: Add end-to-end security update tests for Poetry v2 PEP 621 projects by @markhallen in #14773
Refactor Maven shared version finder for SBT and Gradle ecosystem reuse by @AbhishekBhaskar in #14774
percent-encode npm releaser names in Maintainer changes section by @v-HaripriyaC in #14638
Fix npm vulnerability auditor for workspace Link nodes by @thavaahariharangit in #14754
Swift: support trailing commas in .package() declarations by @struuuuggle in #14755
fix(uv): derive --index URLs from uv.lock registry sources instead of credential index-url by @thavaahariharangit in #14779
Fix python update_not_possible error with bump_versions strategy by @AbhishekBhaskar in #14785
fix(python): filter non-requirements .txt files using filename regex patterns by @Nishnha in #14786
add a new PackageReference element next to existing PackageReference elements by @brettfo in #14796
Remove unused Properties from ProjectDiscoveryResult and delete Property type by @brettfo in #14776
Fix nullability warnings in DependencyConflictResolver.cs by @brettfo in #14784
detect file indentation characters by @brettfo in #14797
don&#039;t do a build on legacy projects by @brettfo in #14748
v0.371.0 by @dependabot-core-action-automation[bot] in #14800

New Contributors

@shaanmajid made their first contribution in #14734
@struuuuggle made their first contribution in #14755

Full Changelog: v0.370.0...v0.371.0 ]]></description>
<link>https://tsecurity.de/de/3487929/IT+Sicherheit/Cybersecurity+Tools/v0.371.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487929/IT+Sicherheit/Cybersecurity+Tools/v0.371.0/</guid>
<pubDate>Thu, 23 Apr 2026 11:13:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[javascript: v0.4.11]]></title> 
<description><![CDATA[0.4.11 (2026-04-23)
Features

add GOAT strategy with dynamic technique selection for RedTeamAgent (#306) (e62c292)

Miscellaneous

relicense from AGPLv3 to Apache 2.0 (66ad733)
relicense to Apache 2.0 (#378) (66ad733)
 ]]></description>
<link>https://tsecurity.de/de/3487928/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487928/IT+Sicherheit/Cybersecurity+Tools/javascript%3A+v0.4.11/</guid>
<pubDate>Thu, 23 Apr 2026 13:37:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.25]]></title> 
<description><![CDATA[0.7.25 (2026-04-23)
Miscellaneous

relicense from AGPLv3 to Apache 2.0 (66ad733)
relicense to Apache 2.0 (#378) (66ad733)
 ]]></description>
<link>https://tsecurity.de/de/3487927/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.25/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487927/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.25/</guid>
<pubDate>Thu, 23 Apr 2026 13:38:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.372.0]]></title> 
<description><![CDATA[What&#039;s Changed

Fix crash when devcontainer ecosystem group is specified by @brooke-hamilton in #14775
Fix failing pre-commit and uv unit test failures by @AbhishekBhaskar in #14809
treat all warnings as errors by @brettfo in #14799
Add commit message support to PR update flow by @kbukum1 in #14808
v0.372.0 by @dependabot-core-action-automation[bot] in #14803

New Contributors

@brooke-hamilton made their first contribution in #14775

Full Changelog: v0.371.0...v0.372.0 ]]></description>
<link>https://tsecurity.de/de/3487926/IT+Sicherheit/Cybersecurity+Tools/v0.372.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487926/IT+Sicherheit/Cybersecurity+Tools/v0.372.0/</guid>
<pubDate>Thu, 23 Apr 2026 23:23:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[python: v0.7.26]]></title> 
<description><![CDATA[0.7.26 (2026-04-28)
Bug Fixes

events: dual-emit auth + graceful empty-key handling in Python EventReporter (#383) (f9a87aa)
 ]]></description>
<link>https://tsecurity.de/de/3487925/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487925/IT+Sicherheit/Cybersecurity+Tools/python%3A+v0.7.26/</guid>
<pubDate>Tue, 28 Apr 2026 12:09:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.373.0]]></title> 
<description><![CDATA[What&#039;s Changed

Disable NuGetAudit in Directory.Build.props by @brettfo in #14818
Remove unused properties from dependency discovery and rename property. by @brettfo in #14811
log project file discovery status by @brettfo in #14819
fix(gradle): honor replaces-base for Maven Central fallback by @thavaahariharangit in #14822
Fix conventional commit style detection in pr_name_prefixer by @kbukum1 in #14817
Audit fix fallback by @robaiken in #14589
Add infrastructure setup for new sbt ecosystem by @AbhishekBhaskar in #14801
Prioritize configured registries and stop on first registry where successful dependency details found by @thavaahariharangit in #14831
Fix Nix cooldown fallback for commit refs by @JamieMagee in #14829
Mount nix sources in docker-dev-shell by @JamieMagee in #14837
Revert &quot;Prioritize configured registries and stop on first registry where successful dependency details found&quot; by @thavaahariharangit in #14847
Upgrade uv to 0.11.8 by @edgarrmondragon in #14832
Fix Cargo old toolchain detection for rustup installation failures by @kbukum1 in #14810
Extract Maven requirement into shared requirement class which can be reused by Gradle and Sbt by @AbhishekBhaskar in #14839
Python/UV: Failed ephemeral lockfiles tag snapshots as degraded by @brrygrdn in #14804
Reduce noisy git config subprocess logging by @thavaahariharangit in #14863
Update sbt infrastructure to add native helpers support by @AbhishekBhaskar in #14859
Align npm ephemeral lockfile handling with recent Python improvements by @brrygrdn in #14867
v0.373.0 by @dependabot-core-action-automation[bot] in #14873

Full Changelog: v0.372.0...v0.373.0 ]]></description>
<link>https://tsecurity.de/de/3487924/IT+Sicherheit/Cybersecurity+Tools/v0.373.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487924/IT+Sicherheit/Cybersecurity+Tools/v0.373.0/</guid>
<pubDate>Thu, 30 Apr 2026 18:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.11.0-final]]></title> 
<description><![CDATA[v2.11.0-final ]]></description>
<link>https://tsecurity.de/de/3487907/IT+Sicherheit/Cybersecurity+Tools/v2.11.0-final/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487907/IT+Sicherheit/Cybersecurity+Tools/v2.11.0-final/</guid>
<pubDate>Mon, 14 Aug 2017 21:36:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v2.12.0-final]]></title> 
<description><![CDATA[Version bump. ]]></description>
<link>https://tsecurity.de/de/3487906/IT+Sicherheit/Cybersecurity+Tools/v2.12.0-final/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487906/IT+Sicherheit/Cybersecurity+Tools/v2.12.0-final/</guid>
<pubDate>Fri, 02 Mar 2018 18:31:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.2]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-2-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487905/IT+Sicherheit/Cybersecurity+Tools/v3.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487905/IT+Sicherheit/Cybersecurity+Tools/v3.2/</guid>
<pubDate>Sun, 30 Aug 2020 18:22:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.2.1 (bug fix release)]]></title> 
<description><![CDATA[Bug fix of the 3.2 release (https://www.spiderfoot.net/spiderfoot-3-2-open-source-release/) addressing the issue of running scans by use case not working. ]]></description>
<link>https://tsecurity.de/de/3487904/IT+Sicherheit/Cybersecurity+Tools/v3.2.1+%28bug+fix+release%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487904/IT+Sicherheit/Cybersecurity+Tools/v3.2.1+%28bug+fix+release%29/</guid>
<pubDate>Wed, 09 Sep 2020 08:14:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.3]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-3-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487903/IT+Sicherheit/Cybersecurity+Tools/v3.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487903/IT+Sicherheit/Cybersecurity+Tools/v3.3/</guid>
<pubDate>Sun, 24 Jan 2021 21:42:34 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.4]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-4-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487902/IT+Sicherheit/Cybersecurity+Tools/v3.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487902/IT+Sicherheit/Cybersecurity+Tools/v3.4/</guid>
<pubDate>Mon, 23 Aug 2021 11:19:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.1]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-1-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487901/IT+Sicherheit/Cybersecurity+Tools/v3.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487901/IT+Sicherheit/Cybersecurity+Tools/v3.1/</guid>
<pubDate>Mon, 23 Aug 2021 11:20:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.0-final]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-0-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487900/IT+Sicherheit/Cybersecurity+Tools/v3.0-final/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487900/IT+Sicherheit/Cybersecurity+Tools/v3.0-final/</guid>
<pubDate>Mon, 23 Aug 2021 11:20:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.5]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-3-5-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487899/IT+Sicherheit/Cybersecurity+Tools/v3.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487899/IT+Sicherheit/Cybersecurity+Tools/v3.5/</guid>
<pubDate>Wed, 10 Nov 2021 21:01:40 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v4.0]]></title> 
<description><![CDATA[Release notes: https://www.spiderfoot.net/spiderfoot-4-0-open-source-release/ ]]></description>
<link>https://tsecurity.de/de/3487898/IT+Sicherheit/Cybersecurity+Tools/v4.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487898/IT+Sicherheit/Cybersecurity+Tools/v4.0/</guid>
<pubDate>Thu, 07 Apr 2022 08:55:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2023.3]]></title> 
<description><![CDATA[Third release of 2023!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487897/IT+Sicherheit/Cybersecurity+Tools/2023.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487897/IT+Sicherheit/Cybersecurity+Tools/2023.3/</guid>
<pubDate>Tue, 15 Aug 2023 23:47:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2023.4]]></title> 
<description><![CDATA[Fourth (and final) release of 2023!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487896/IT+Sicherheit/Cybersecurity+Tools/2023.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487896/IT+Sicherheit/Cybersecurity+Tools/2023.4/</guid>
<pubDate>Thu, 23 Nov 2023 19:06:26 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2024.1]]></title> 
<description><![CDATA[First release of 2024!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487895/IT+Sicherheit/Cybersecurity+Tools/2024.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487895/IT+Sicherheit/Cybersecurity+Tools/2024.1/</guid>
<pubDate>Fri, 16 Feb 2024 17:04:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2024.2]]></title> 
<description><![CDATA[Second release of 2024!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487894/IT+Sicherheit/Cybersecurity+Tools/2024.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487894/IT+Sicherheit/Cybersecurity+Tools/2024.2/</guid>
<pubDate>Tue, 11 Jun 2024 19:06:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2024.3]]></title> 
<description><![CDATA[Third release of 2024!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487893/IT+Sicherheit/Cybersecurity+Tools/2024.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487893/IT+Sicherheit/Cybersecurity+Tools/2024.3/</guid>
<pubDate>Mon, 12 Aug 2024 21:57:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2024.4]]></title> 
<description><![CDATA[Fourth (and final) release of 2024!
🎉 This release includes multiple updates from the community =)
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487892/IT+Sicherheit/Cybersecurity+Tools/2024.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487892/IT+Sicherheit/Cybersecurity+Tools/2024.4/</guid>
<pubDate>Wed, 20 Nov 2024 11:42:28 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2025.1]]></title> 
<description><![CDATA[🎉 The first release of 2025! 🎉
Lead Contributor: @ItsIgnacioPortal
Highlights
This release adds new documentation for many wordlists. Duplicate and obsolete wordlists have been removed, and the following new wordlist has been incorporated into the project:

🌟 2024-200_most_used_passwords.txt


The Discovery/Web-Content/trickest-robots-disallowed-wordlists/top-10000.txt wordlist has been fixed, which caused problems when cloning the project on Windows. (#397)
The .fuzz suffix has been removed from many more wordlists, improving clarity in the wordlist filenames.
A great number of wordlists have been properly categorized, improving the overall usability of Seclists.
Full Changelog
🌟 New content

🌟 feat(wordlist): Add filepaths for testing Single-page applications. (#1159)
🌟 feat(wordlist): Add IIS default page and image files. (#1158)
🌟 feat(wordlist): Added &#039;2024-200_most_used_passwords.txt&#039; wordlist
🌟 feat(wordlist): Added &#039;daloradius&#039; to common.txt
🌟 feat(wordlist): Added &#039;Web-Server&#039; prefix to wordlist filenames
🌟 feat(wordlist): Added missing words in API &#039;actions&#039; wordlists
🌟 feat(wordlist): Added more endpoints to common.txt
🌟 feat(wordlist): Added more LLM data-leakage payloads
🌟 feat(wordlist): Added more subdomains to &#039;combined_subdomains.txt&#039;
🌟 feat(wordlist): Added protobuf mimetypes
🌟 feat(wordlist): Expanded the List-Of-Swear-Words &quot;fr-CA-u-sd-caqc.txt&quot; wordlist
🌟 feat(wordlist): Greatly improved &quot;Amounts&quot; wordlists
🌟 feat(wordlist): Update spring-boot.txt to v2.1.7

🛠 Fixes &amp; Improvements

🛠 feat(docs): Improved formatting of the PR template.
🛠 feat(docs): Replace repository details with badges for better visibility.
🛠 fix(cicd): Fixed line-ending normalization on &quot;remote-wordlists-updater.yml&quot;
🛠 fix(wordlist): Fixed bad formatting in raft-* wordlists
🛠 chore(docs): Removed &#039;.fuzz&#039; from multiple wordlist filenames

📖 Documentation

📖 feat(docs): Added documentation for &#039;AdobeCQ-AEM.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;AdobeXML.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Apache-Axis.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Apache.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;ApacheTomcat.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;CGI-HTTP-POST-Windows.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;CGI-HTTP-POST.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;CGI-Microsoft.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Frontpage.fuzz.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;fully-qualified-java-classes.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;IIS-POST.txt&#039;
📖 feat(docs): Added documentation for &#039;iis-systemweb.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;iplanet.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;JBoss.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Keycloak-Identity-Access-Management.txt&#039;
📖 feat(docs): Added documentation for &#039;Microsoft-Forefront-Identity-Manager.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Oracle-EBS-wordlist.txt&#039; wordlist
📖 feat(docs): Added documentation for &#039;Oracle-WebLogic.txt&#039;
📖 feat(docs): Added documentation for &#039;raft-*&#039; wordlists
📖 feat(docs): Added documentation for &#039;reverse-proxy-inconsistencies.txt&#039;
📖 feat(docs): Added documentation for &#039;Web-Server-Glassfish-Sun-Microsystems.txt&#039; wordlist
📖 feat(docs): Added documentation for the &#039;graphql.txt&#039; wordlist
📖 feat(docs): Added note about outdated contents for the &#039;AdobeCQ-AEM.txt&#039; wordlist

🪦 Removed content

🪦 chore(wordlist): Removed &#039;KitchensinkDirectories.fuzz.txt&#039; wordlist
🪦 chore(wordlist): Removed &#039;Randomfiles.fuzz.txt&#039; wordlist
🪦 chore(wordlist): Removed &#039;tests.txt&#039; wordlist
🪦 chore(wordlist): Removed &#039;Vignette.fuzz.txt&#039; wordlist
🪦 chore(wordlist): Removed BiblePass project
🪦 chore(wordlist): Removed duplicate wordlist &#039;500-worst-passwords.txt&#039;
🪦 chore(wordlist): Removed duplicate wordlist &#039;without_spaces.txt&#039;
🪦 chore(wordlist): Removed obsolete &#039;dirsearch.txt&#039; wordlist
🪦 chore(wordlist): Removed obsolete &#039;IBM Lotus iNotes&#039; wordlist
🪦 chore(wordlist): Removed obsolete hyperion wordlists
🪦 chore(wordlist): Removed obsolete IOCs wordlists
🪦 fix(wordlist): Removed &#039;FatwireCMS.fuzz.txt&#039; wordlist
🪦 fix(wordlist): Removed &#039;fnf-fuzz.txt&#039; wordlist
🪦 fix(wordlist): Removed duplicate wordlist &#039;iplanet.txt&#039;
🪦 fix(wordlist): Removed duplicate wordlist &#039;jrun.txt&#039;
🪦 fix(wordlist): Removed duplicate wordlist &#039;sunas.txt&#039;

🌐 Other changes

🌐 chore(wordlist): Moved CGI wordlists into the &#039;LEGACY-SERVICES/CGIs&#039; directory
🌐 feat(docs): Moved programming-language-specific wordlists into their own directory
🌐 feat(docs): Moved Web-Server wordlists into their own directory
🌐 feat(docs): Removed mis-categorized &#039;Web-Services&#039; folder
🌐 feat(docs): Renamed &#039;axis.txt&#039; to &#039;Apache-Axis.txt&#039;
🌐 feat(docs): Renamed &#039;SVNDigger&#039; folder to a more descriptive folder name
🌐 fix(cicd): Added automatic clean-up to wordlist updater
🌐 fix(cicd): Fixed crash on &quot;remote-wordlists-updater.yml&quot;
🌐 fix(docs): Added &quot;Ignacio Portal&quot; to the project credits.
🌐 fix(docs): Moved &#039;AdobeCQ-AEM.txt&#039; into the CMS directory
🌐 fix(docs): Moved &#039;aem2.txt&#039; into the CMS directory
🌐 fix(docs): Moved &#039;axis.txt&#039; into the Web-Servers directory
🌐 fix(docs): Moved &#039;Confluence-Administration.txt&#039; into the Service-Specific directory
🌐 fix(docs): Moved &#039;forefront-identity-management.txt&#039; into the Service-Specific directory
🌐 fix(docs): Moved &#039;jboss.txt&#039; into the Web-Servers directory
🌐 fix(docs): Moved &#039;Jenkins-Hudson.txt&#039; into the Service-Specific directory
🌐 fix(docs): Moved &#039;nginx.txt&#039; into the Web-Servers directory
🌐 fix(docs): Moved &#039;Oracle-EBS-wordlist.txt&#039; into the CMS directory
🌐 fix(docs): Moved &#039;sharepoint-ennumeration.txt&#039; into the CMS directory
🌐 fix(docs): Moved &#039;spring-boot.txt&#039; into the Programming-Language-Specific directory
🌐 fix(docs): Moved &#039;swagger.txt&#039; into the Service-Specific directory
🌐 fix(wordlist): Merged duplicate &#039;Apache Tomcat&#039; wordlists
🌐 fix(wordlist): Merged duplicate Apache wordlists
🌐 fix(wordlist): Merged duplicate Microsoft Frontpage wordlists
🌐 fix(wordlist): Merged duplicate Oracle EBS wordlists
🌐 fix(wordlist): Merged duplicate Sharepoint wordlists
🌐 fix(wordlist): Moved &#039;HTTP-POST-Microsoft.fuzz.txt&#039; into &#039;Web-Servers\IIS-POST.txt&#039;
🌐 fix(wordlist): Moved &#039;pulsesecure.txt&#039; into &#039;Service-Specific\PulseSecure-VPN.txt&#039;
🌐 fix(wordlist): Moved &#039;websphere.txt&#039; into &#039;Service-Specific\IBM-WebSphere-Application-Server.txt&#039;
🌐 fix(wordlist): Moved *200_most_used_passwords to Common-Credentials directory
🌐 fix(wordlist): Removed duplicates from &#039;2024-200_most_used_passwords.txt&#039; wordlist
🌐 fix(wordlist): Removed redundant linejumps from CommonAdminBase64.txt
🌐 fix(wordlist): Renamed &#039;2024-200_most_used_passwords.txt&#039; to &#039;2024-197_most_used_passwords.txt&#039;
🌐 fix(wordlist): Renamed &#039;hpsmh.txt&#039; to &#039;HP-System-Management-Homepage.txt&#039;
🌐 fix(wordlist): Renamed &#039;proxy-conf.fuzz.txt&#039; to &#039;Proxy-Auto-Configuration-Files.txt&#039;
🌐 fix(wordlist): Renamed &#039;sap.txt&#039; to &#039;SAP-NetWeaver.txt&#039;
🌐 fix(wordlist): Renamed wordlist &#039;Frontpage.fuzz.txt&#039; to &#039;Microsoft-Frontpage.txt&#039;
🌐 fix(wordlist): Renamed wordlist &#039;IIS.fuzz.txt&#039; to &#039;IIS.txt&#039;
🌐 fix(wordlist): Renamed wordlist &#039;Sharepoint.fuzz.txt&#039; to &#039;Sharepoint.txt&#039;
🌐 fix(wordlist): Renamed wordlist &#039;SunAppServerGlassfish.fuzz.txt&#039; to &#039;Web-Server-Glassfish-Sun-Microsystems.txt&#039;
🌐 fix(wordlist): Revert &quot;Update metadata.txt&quot;
🌐 fix(wordlist): Transformed &quot;local-ports.txt&quot; into &quot;Ports-1-To-65535.txt&quot;

Shout-out to: @curiv, @emmanuelgautier, @goosvorbook, @guillermodotn, @eltociear, @ivan-sincek, @jorelpaddick, @jthack, @NihaoKangkang, @mtremr, @napz99, @ola456, @onurkarasalihoglu, @cosad3s, and @V0idSeek3r
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487891/IT+Sicherheit/Cybersecurity+Tools/2025.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487891/IT+Sicherheit/Cybersecurity+Tools/2025.1/</guid>
<pubDate>Sat, 22 Feb 2025 10:24:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2025.2]]></title> 
<description><![CDATA[🎉 The second release of 2025! 🎉
Lead Contributor: @ItsIgnacioPortal
Highlights
🌟 Two new tools for creating and manipulating wordlists have been added to the main readme:

CeWL
WL

🌟 Two 10 Million+ wordlists have been added for subdomain fuzzing/discovery (contributed by @CYFARE):

Discovery/DNS/FUZZSUBS_CYFARE_1.txt
Discovery/DNS/FUZZSUBS_CYFARE_2.txt

🛠 All words wordlists have been moved into the directory Miscellaneous/Words/.
🌐 And many other miscellaneous fixes and improvements.
Full Changelog
🌟 New content

🌟 feat(wordlist): Add more keyboard walks (PR #1183) - BuildAndDestroy
🌟 feat(wordlist): Added &#039;Pipfile&#039; entries to &#039;common.txt&#039; (PR #1187) - Dominique RIGHETTO
🌟 feat(wordlist): Added image/jpg to web-all-content-types.txt (PR #1190) - bl13pbl03p
🌟 feat(wordlist): Added DNS subdomain &#039;take-survey&#039; (PR #1182) - jvardikar
🌟 feat(wordlist): Added new combo to &#039;ssh-betterdefaultpasslist.txt&#039; Implements #1180 - ItsIgnacioPortal
🌟 feat(wordlist): Content type application/x-httpd-php - zar3bski
🌟 feat(wordlist): Created 10 Million+ List For Subdomain Fuzzing/Discovery - CYFARE

🛠 Fixes &amp; Improvements

🛠 fix(wordlist): Added missing terms to API Actions wordlist - ItsIgnacioPortal
🛠 fix(wordlist): Fixed file extension of the &#039;corporate_passwords&#039; wordlist - ItsIgnacioPortal
🛠 fix(wordlist): Merged duplicate dutch wordlists - ItsIgnacioPortal
🛠 fix(wordlist): Removed religious term from wordlist (PR #1181) - Machiavelli
🛠 fix(wordlist): Renamed &#039;german_misc.txt&#039; to &#039;German-words.txt&#039; - ItsIgnacioPortal
🛠 fix(wordlist): Renamed &#039;richelieu&#039; french passwords wordlists - ItsIgnacioPortal
🛠 fix(docs): Added reference to the pwdb-public project - ItsIgnacioPortal
🛠 fix(docs): Fixed bad formatting on Discovery/Web-Content readme - ItsIgnacioPortal
🛠 fix(docs): Fixed formatting on EFF-Dice documentation - ItsIgnacioPortal
🛠 fix(docs): Fixed wording on the &#039;Cook&#039; tool description - ItsIgnacioPortal
🛠 fix(docs): Removed duplicate content from readme - ItsIgnacioPortal
🛠 fix(cicd): More descriptive workflow names - ItsIgnacioPortal
🛠 fix(cicd): Updated &#039;GITHUB_REPOSITORY&#039; variable name - ItsIgnacioPortal
🛠 fix(cicd): Updated &#039;tj-actions/changed-files&#039; from v34 to v45.0.7 - ItsIgnacioPortal

📖 Documentation

📖 feat(docs): Added &#039;CeWL&#039; tool - ItsIgnacioPortal
📖 feat(docs): Added &#039;wl&#039; tool - ItsIgnacioPortal
📖 feat(docs): Added &#039;Wordlist Tools&#039; category to main README - ItsIgnacioPortal
📖 feat(docs): Added documentation for &#039;French-common-password-list-top-*&#039; - ItsIgnacioPortal
📖 feat(docs): Added documentation for &#039;probable-v2-top*&#039; - ItsIgnacioPortal
📖 feat(docs): Added documentation for the &#039;Miscellaneous/Words&#039; directory - ItsIgnacioPortal
📖 feat(docs): Added link descriptions to associated projects and tools in main README - ItsIgnacioPortal
📖 feat(docs): Added warning to CONTRIBUTING.md about uploading data breaches - ItsIgnacioPortal
📖 feat(docs): Improved formatting for &#039;dsstorewordlist.txt&#039; docs - ItsIgnacioPortal

🪦 Removed content

🪦 chore(wordlist): Removed &#039;UserPassCombo-Jay.txt&#039; wordlist - ItsIgnacioPortal
🪦 chore(wordlist): Removed duplicate pwdb &#039;Frequent-Passwords&#039; - ItsIgnacioPortal

🌐 Other changes

🌐 [Github Action] Automated readme update. - github-actions[bot]
🌐 [Github Action] Automated trickest wordlists update. - github-actions[bot]
🌐 [Github Action] Updated combined_directories.txt - github-actions[bot]
🌐 [Github Action] Updated combined_words.txt - github-actions[bot]
🌐 chore(wordlist): Moved &#039;Dutch_passwordlist.txt&#039; into the &#039;Common-Credentials/Language-Specific&#039; directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved all words wordlists into the same directory (PR #1193) - ItsIgnacioPortal
🌐 chore(wordlist): Moved darkweb2017* wordlists into the Common-Credentials directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved Dutch-words.txt into /Miscellaneous/Words/ - ItsIgnacioPortal
🌐 chore(wordlist): Moved EFF-Dice into /Miscellaneous/Words/ - ItsIgnacioPortal
🌐 chore(wordlist): Moved french passwords wordlists into the Language-Specific directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved German-words.txt into /Miscellaneous/Words/ - ItsIgnacioPortal
🌐 chore(wordlist): Moved moby project files into their own directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved Moby-Project into /Miscellaneous/Words/ - ItsIgnacioPortal
🌐 chore(wordlist): Moved probable-v2* wordlists into the Common-Credentials directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved pwdb passwords wordlists into the Common-Credentials directory - ItsIgnacioPortal
🌐 chore(wordlist): Moved Pwdb-Public Language-Specific wordlists into the Language-Specifics directory - ItsIgnacioPortal
🌐 chore(wordlist): Renamed darkweb files - ItsIgnacioPortal
🌐 chore(wordlist): Renamed probable-v2 files - ItsIgnacioPortal
🌐 chore(wordlist): Renamed pwdb language-specific wordlists - ItsIgnacioPortal
🌐 chore(wordlist): Renamed pwdb password wordlists - ItsIgnacioPortal
🌐 chore(cicd): Temporarily disabled the &#039;wordlist-validator.yml&#039; workflow - ItsIgnacioPortal
🌐 feat(cicd): Added more workflow_dispatch event triggers - ItsIgnacioPortal

Shout-out to: @MachiavelliII, @CYFARE, @BuildAndDestroy, @righettod, @bl13pbl03p, @zar3bski, and &quot;jvardikar&quot;.
🥇 Thank you everyone  ]]></description>
<link>https://tsecurity.de/de/3487890/IT+Sicherheit/Cybersecurity+Tools/2025.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487890/IT+Sicherheit/Cybersecurity+Tools/2025.2/</guid>
<pubDate>Sat, 26 Apr 2025 01:58:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[7.0.11]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-7-0-11-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/219
Download
https://www.openinfosecfoundation.org/download/suricata-7.0.11.tar.gz
https://www.openinfosecfoundation.org/download/suricata-7.0.11.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-7.0.11 ]]></description>
<link>https://tsecurity.de/de/3487889/IT+Sicherheit/Cybersecurity+Tools/7.0.11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487889/IT+Sicherheit/Cybersecurity+Tools/7.0.11/</guid>
<pubDate>Tue, 08 Jul 2025 17:18:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[8.0.0]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-8-0-0-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/194
Download
https://www.openinfosecfoundation.org/download/suricata-8.0.0.tar.gz
https://www.openinfosecfoundation.org/download/suricata-8.0.0.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-8.0.0 ]]></description>
<link>https://tsecurity.de/de/3487888/IT+Sicherheit/Cybersecurity+Tools/8.0.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487888/IT+Sicherheit/Cybersecurity+Tools/8.0.0/</guid>
<pubDate>Tue, 08 Jul 2025 18:49:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.4.9]]></title> 
<description><![CDATA[What&#039;s Changed
Other Changes

feat: fixed output event for skipped hosts by @Ice3man543 in #6415

Full Changelog: v3.4.8...v3.4.9 ]]></description>
<link>https://tsecurity.de/de/3487887/IT+Sicherheit/Cybersecurity+Tools/v3.4.9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487887/IT+Sicherheit/Cybersecurity+Tools/v3.4.9/</guid>
<pubDate>Fri, 22 Aug 2025 17:09:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v3.4.10]]></title> 
<description><![CDATA[What&#039;s Changed
Other Changes

fix: segfault in template caching logic by @dwisiswant0 in #6421

Full Changelog: v3.4.9...v3.4.10 ]]></description>
<link>https://tsecurity.de/de/3487886/IT+Sicherheit/Cybersecurity+Tools/v3.4.10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487886/IT+Sicherheit/Cybersecurity+Tools/v3.4.10/</guid>
<pubDate>Sat, 23 Aug 2025 16:43:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[7.0.12]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/220
Download
https://www.openinfosecfoundation.org/download/suricata-7.0.12.tar.gz
https://www.openinfosecfoundation.org/download/suricata-7.0.12.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-7.0.12 ]]></description>
<link>https://tsecurity.de/de/3487885/IT+Sicherheit/Cybersecurity+Tools/7.0.12/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487885/IT+Sicherheit/Cybersecurity+Tools/7.0.12/</guid>
<pubDate>Tue, 16 Sep 2025 13:52:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[8.0.1]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/221
Download
https://www.openinfosecfoundation.org/download/suricata-8.0.1.tar.gz
https://www.openinfosecfoundation.org/download/suricata-8.0.1.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-8.0.1 ]]></description>
<link>https://tsecurity.de/de/3487884/IT+Sicherheit/Cybersecurity+Tools/8.0.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487884/IT+Sicherheit/Cybersecurity+Tools/8.0.1/</guid>
<pubDate>Tue, 16 Sep 2025 13:53:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2025.3]]></title> 
<description><![CDATA[Important changes
📛 Deprecated DirBuster wordlists
The dirbuster wordlists were made in 2007, and are now considered obsolete. Instead, these wordlists are recommended for testing modern web environments:

Discovery/Web-Content/combined_words.txt
Discovery/Web-Content/combined_directories.txt

Both of these wordlists are composed of various other wordlists in that same directory, and are automatically updated whenever one of their components is modified. For more information see the README.md for Discovery/Web-Content.
The dirbuster wordlists will remain contained in SecLists, but they now have the DirBuster-2007 prefix to highlight their age.

📛 Dangerous SQLi payloads
The SQL Injection wordlists contained in Fuzzing/Databases/SQLi are not safe to use on production environments. Many of those wordlists contain potentially destructive queries which may permanently delete data on any databases they&#039;re used on. A warning has been added to the README.md for that directory. For more information see issue #1011

New content

✨ feat(wordlist): Created Active Directory wordlist (PR #1224)
✨ feat(docs): Added &quot;GENOVEVA&quot; tool to readme (PR #1200)
✨ feat(docs): Added alternative reference to docs
✨ feat(docs): Added documentation for the &#039;cirt-net_collection.txt&#039; wordlist
✨ feat(docs): Added documentation for the &#039;Java-Spring-Boot.txt&#039; wordlist
✨ feat(docs): Added documentation for the &#039;xato-net-10-million-passwords&#039; wordlists
✨ feat(wordlist): Added &#039;encryptionkeys&#039; directory to &#039;common_directories.txt&#039;
✨ feat(wordlist): Added /etc/apache2/.htpasswd to LFI fuzzing lists (PR #1223)
✨ feat(wordlist): Added a dictionary for Model Context Protocol server discovery. (PR #1216)
✨ feat(wordlist): Added common Spanish names and words (PR #1199)
✨ feat(wordlist): Added default SSH password &quot;padmin:padmin&quot; for IBM Power Systems (PR #1211)
✨ feat(wordlist): Added IANA mime-types to &quot;web-all-content-types.txt&quot; (PR #1204)
✨ feat(wordlist): Added mcp-server.txt entries to common.txt
✨ feat(wordlist): Added more OBEX common filenames and cleaned OBEX wordlists (PR #1249)
✨ feat(wordlist): Added more permutations to &#039;common_directories.txt&#039;
✨ feat(wordlist): Added more swagger endpoints (PR #1219)
✨ feat(wordlist): Added new payload to &#039;SAP&#039; wordlist (PR #1196)
✨ feat(wordlist): Added prefixes to deal with Java-Spring-Boot being behind spring-cloud-gateway (PR #1220)
✨ feat(wordlist): Added Quectel to default-passwords.csv + updated default-passwords.txt (PR #1208)
✨ feat(wordlist): Added readme.md to &quot;Discovery/Web-Content/big.txt&quot; (PR #1248)
✨ feat(wordlist): Added YYYY-MM-DD dates wordlists (PR #1217)

Other changes

🐛 fix(wordlist): Added &#039;DirBuster-2007&#039; prefix to all DirBuster wordlists
🐛 fix(cicd): Removed trailing spaces from wordlist-updater_default-passwords.yml (PR #1243)
🐛 fix(cicd): Updated paths in the &#039;Wordlist Updater - Combined directories&#039; pipeline
🐛 fix(docs): Updated filenames that compose &#039;combined_directories.txt&#039;
🐛 fix(wordlist): Cleaned up &#039;100k-most-used-passwords-NCSC.txt&#039; (PR #1235)
🐛 fix(wordlist): Fixed encoding in &quot;100k-most-used-passwords-NCSC.txt&quot; (PR #1226)
🐛 fix(wordlist): Updated curl-protocols wordlist (PR #1237)
🔧 chore(wordlist): Moved &#039;curl-protocols.txt&#039; wordlist to the &#039;Fuzzing&#039; directory

New Contributors

@GoombaProgrammer made their first contribution in #1198
@joseaguardia made their first contribution in #1199
@theclayton made their first contribution in #1204
@rtfmkiesel made their first contribution in #1208
@DaddyBigFish made their first contribution in #1217
@psytester made their first contribution in #1219
@Jhayrolandero made their first contribution in #1223
@kennystrawnmusic made their first contribution in #1224
@liamjones made their first contribution in #1226
@evilgensec made their first contribution in #1235
@robinkarlberg made their first contribution in #1237
@Sh3b0 made their first contribution in #1243
@totobarbar made their first contribution in #1248

Full Changelog: 2025.2...2025.3 ]]></description>
<link>https://tsecurity.de/de/3487883/IT+Sicherheit/Cybersecurity+Tools/2025.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487883/IT+Sicherheit/Cybersecurity+Tools/2025.3/</guid>
<pubDate>Fri, 19 Sep 2025 07:50:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v4.13.1]]></title> 
<description><![CDATA[There are no changes in this release. ]]></description>
<link>https://tsecurity.de/de/3487882/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.13.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487882/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.13.1/</guid>
<pubDate>Thu, 25 Sep 2025 17:43:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.67.1]]></title> 
<description><![CDATA[release: v0.67.1 [release/v0.67] (#9614) ]]></description>
<link>https://tsecurity.de/de/3487881/IT+Sicherheit/Cybersecurity+Tools/v0.67.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487881/IT+Sicherheit/Cybersecurity+Tools/v0.67.1/</guid>
<pubDate>Thu, 09 Oct 2025 12:55:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v0.67.2]]></title> 
<description><![CDATA[release: v0.67.2 [release/v0.67] (#9639) ]]></description>
<link>https://tsecurity.de/de/3487880/IT+Sicherheit/Cybersecurity+Tools/v0.67.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487880/IT+Sicherheit/Cybersecurity+Tools/v0.67.2/</guid>
<pubDate>Fri, 10 Oct 2025 14:53:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.42.0-rc3]]></title> 
<description><![CDATA[chore(build): update falco libs dependency to 0.22.1

Signed-off-by: Iacopo Rozzo  ]]></description>
<link>https://tsecurity.de/de/3487879/IT+Sicherheit/Cybersecurity+Tools/0.42.0-rc3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487879/IT+Sicherheit/Cybersecurity+Tools/0.42.0-rc3/</guid>
<pubDate>Mon, 20 Oct 2025 15:27:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.42.0-rc4]]></title> 
<description><![CDATA[fix(userspace/falco): correct default duration calculation

Signed-off-by: Leonardo Grasso  ]]></description>
<link>https://tsecurity.de/de/3487878/IT+Sicherheit/Cybersecurity+Tools/0.42.0-rc4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487878/IT+Sicherheit/Cybersecurity+Tools/0.42.0-rc4/</guid>
<pubDate>Wed, 22 Oct 2025 11:16:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[0.42.0]]></title> 
<description><![CDATA[




Packages
Download




rpm-x86_64



deb-x86_64



tgz-x86_64



tgz-static-x86_64



rpm-aarch64



deb-aarch64



tgz-aarch64







Images




docker pull docker.io/falcosecurity/falco:0.42.0


docker pull public.ecr.aws/falcosecurity/falco:0.42.0


docker pull docker.io/falcosecurity/falco-driver-loader:0.42.0


docker pull docker.io/falcosecurity/falco-driver-loader:0.42.0-buster


docker pull docker.io/falcosecurity/falco:0.42.0-debian



v0.42.0
Released on 2025-10-22
Major Changes

feat: add falco_libs.thread_table_auto_purging_interval_s and thread_table_auto_purging_thread_timeout_s configuration options [#3670] - @ekoops
feat: log plugin version info at loading time [#3657] - @FedeDP
feat: ability to add statically defined fields via static_fields configuration [#3557] - @FedeDP
feat(engine): emit warning when a rule containing the evt.dir field in output is encountered [#3697] - @irozzo-1A
feat(engine): emit warning when a rule containing a condition on the deprecated evt.dir field is encountered [#3690] - @irozzo-1A
new: ability to record .scap files (capture feature) [#3645] - @leogr
new(docker): includes sha on the image labels [#3658] - @jcchavezs
new(cmake,userspace,ci): add mimalloc support [#3616] - @FedeDP

Minor Changes

docs(falco.yaml): refactor config documentation [#3685] - @leogr
build: fix debian:buster apt debian repo URL in :driver-loader-buster container image [#3644] - @ekoops
build: updagrade libs to version 0.22.1 [#3705] - @irozzo-1A
build: upgrade drivers to v9.0.0+driver [#3701] - @irozzo-1A
build: upgrade cpp-httplib to v0.23.1 [#3647] - @FedeDP
update: upgrade default ruleset to v5.0.0 [#3700] - @leogr
build: upgrade falcoctl to v0.11.4 [#3694] - @leogr
chore(prometheus): deprecate enter events drop stats [#3675] - @irozzo-1A

Bug Fixes

fix(cmake): correct abseil-cpp for alpine build [#3598] - @RomanenkoDenys
fix: enable handling of multiple actions configured with syscall_event_drops.actions [#3676] - @terror96
fix: disable dry-run restarts when Falco runs with config-watching disabled [#3640] - @Proximyst

Non user-facing changes

fix(userspace/falco): correct default duration calculation [#3715] - @leogr
chore(falcoctl): update falco rules to version 5 [#3712] - @irozzo-1A
doc(OWNERS): move incertum (Melissa Kilby) to emeritus_approvers [#3605] - @incertum
update(cmake): update libs and driver to latest master [#3689] - @github-actions[bot]
chore(docker): use new ENV syntax in place of deprecated one [#3696] - @ekoops
chore(cmake/modules): update rules to 5.0.0-rc1 [#3698] - @leogr
fix(userspace/engine): fix logger date format [#3672] - @ekoops
docs(OWNERS): add ekoops(Leonardo Di Giovanna) as approver [#3688] - @ekoops
update(cmake): update libs and driver to latest master [#3665] - @github-actions[bot]
Refactor: cppcheck cleanups [#3649] - @sgaist
update(userspace/engine): update falco engine version and checksum [#3648] - @ekoops
update(cmake): update libs and driver to latest master [#3662] - @github-actions[bot]
update(cmake): update libs and driver to latest master [#3661] - @github-actions[bot]
update(cmake): update libs and driver to latest master [#3653] - @github-actions[bot]
chore(ci): disable mimalloc for master builds. [#3655] - @FedeDP
chore(deps): Bump submodules/falcosecurity-rules from 1208816 to be38001 [#3651] - @dependabot[bot]
docs(falco.yaml): avoid out-of-sync config options for container pl&hellip; [#3650] - @leogr
update(cmake): update libs and driver to latest master [#3636] - @github-actions[bot]
update(CHANGELOG.md): release 0.41.3 (cherry-pick) [#3634] - @ekoops
update(cmake): update libs and driver to latest master [#3628] - @github-actions[bot]
update(CHANGELOG.md): release 0.41.2 (cherry-pick) [#3623] - @ekoops
update(cmake): update libs and driver to latest master [#3618] - @github-actions[bot]
update(cmake): update libs and driver to latest master [#3602] - @github-actions[bot]
chore(falco.yaml): clean up plugins config leftover [#3596] - @leogr
chore(deps): Bump submodules/falcosecurity-rules from b4437c4 to 4d51b18 [#3607] - @dependabot[bot]
update(docs): cherry pick CHANGELOG. [#3600] - @FedeDP
update(cmake): update libs and driver to latest master [#3592] - @github-actions[bot]
update(docs): bumped changelog for release 0.41.0, master sync [#3586] - @FedeDP
chore(deps): Bump submodules/falcosecurity-rules from cb17833 to b4437c4 [#3578] - @dependabot[bot]

Statistics



MERGED PRS
NUMBER




Not user-facing
29


Release note
23


Total
52



Release Manager @ekoops ]]></description>
<link>https://tsecurity.de/de/3487877/IT+Sicherheit/Cybersecurity+Tools/0.42.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487877/IT+Sicherheit/Cybersecurity+Tools/0.42.0/</guid>
<pubDate>Wed, 22 Oct 2025 13:37:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v4.14.0]]></title> 
<description><![CDATA[Manager
Added

Added system users and groups to the inventory data. (#30848)
Added browser extensions and services to the inventory data. (#31614)
Added IPv6 support to Maltiverse integration. (#31731)

Fixed

Fixed internal decoder RC startup. (#29663)
Fixed queue stats RC over wazuh-analysisd. (#29673)
Fixed race condition in the event queue. (#29672)
Fixed regexCompile race condition. (#29699)
Fixed malformed alerts in alerts.log when  contains newline characters. (#30653)
Fixed and improved dpkg version comparison algorithm in Vulnerability Detector. (#31599)

Changed

Improved databaseFeedManagerTesttool. (#30192)
Adapted wazuh-maild to RFC5322 standard. (#30793)
Enhanced the active response endpoint performance. (#31218)

Agent
Added

Added support for parquet version 2 in AWS Wodle. (#30235)
Added capability to do a hot configuration reload in Linux agents. (#30797)
Added support for Amazon Inspector v2. (#31163)
Added system users and groups to the inventory data. (#30369)
Added browser extensions to the inventory data. (#805)
Added services to the inventory data. (#807)
Added missing AWS regions us-gov-west-1 and us-gov-east-1 to AWS wodle. (#31418)
Included Windows kernel version information to IT Hygiene. (#32413)

Fixed

Fixed errors with Azure Graph event fields. (#30831)
Added the missing &quot;provider&quot; field to the whodata section in syscheckd JSON configuration. (#30877)
Fixed journald disabled filters when both blocks have no filters. (#31700)
Fixed whodata FIM compatibility with latest audit versions. (#30215)
Fixed mismatch between MTU values in database and indexer for Windows agents. (#31875)

Changed

Improved rootkit error messages to warnings due to future deprecation. (#31640)

RESTful API
Added

Added syscollector users and groups endpoints. (#30913)
Added syscollector services and browser_extension endpoints. (#31513)

Fixed

Fixed secure headers. (#31046)
Fixed the display of sensitive information for non-privileged users. (#31315)

Ruleset
Added

Added SCA content for Rocky Linux 10. (#30745)
Added SCA content for Debian 13. (#31747)

Fixed

Fixed multiple Rocky Linux SCA checks generating incorrect results. (#29976)
Fixed missing Check (2.3.7.6) in Windows Server 2019 v2.0.0. (#30173)
Fixed camel casing in ownCloud ruleset header. (#30276)
Fixed false positive in check 2.3.3.2 of macOS 13, 14, and 15 SCA. (#30489)
Fixed bug in rule 92657. (#30529)
Fixed field names in Office 365 rules. (#30528)
Fixed action field in Fortigate rules. (#30515)
Fixed Auditd EXECVE sibling Decoders. (#30612)
Fixed problems with other Windows OS languages except English. (#31227)
Reworked SCA Policy for Debian Linux 12. (#30717)
Fixed missing comma in 0393-fortiauth_rules.xml. (#32025)
Fixed Windows sca user account checks. (#32102)
Fixed inaccuracies in Ubuntu 2404 sca policy. (#32106)
Fixed incorrect service name in Ubuntu firewall service check. (#32143)

Other
Changed

Updated packaging dependency to 25.0. (#31272)
Updated requests to version 2.32.4. (#30536)
Updated urllib3 to version 2.5.0 and protobuf to version 5.29.5. (#30624)
Upgraded Python embedded interpreter to 3.10.18. (#30916)
Updated OpenSSL to 3.0.15 and cpp-httplib to v0.25.0. (#31779)
Updated SQLite dependency to version 3.50.4. (#29586)
 ]]></description>
<link>https://tsecurity.de/de/3487876/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487876/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.0/</guid>
<pubDate>Thu, 23 Oct 2025 19:45:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.3-rc2]]></title> 
<description><![CDATA[Changes

move hubupdate.sh to libexec (#4000) @mmetc
rpm: install hubupdate with full path (#4002) @mmetc

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3487875/IT+Sicherheit/Cybersecurity+Tools/v1.7.3-rc2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487875/IT+Sicherheit/Cybersecurity+Tools/v1.7.3-rc2/</guid>
<pubDate>Fri, 24 Oct 2025 12:12:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.3]]></title> 
<description><![CDATA[Changes

move hubupdate.sh to libexec (#4000) @mmetc
rpm: install hubupdate with full path (#4002) @mmetc

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3487874/IT+Sicherheit/Cybersecurity+Tools/v1.7.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487874/IT+Sicherheit/Cybersecurity+Tools/v1.7.3/</guid>
<pubDate>Fri, 24 Oct 2025 15:41:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[7.0.13]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-8-0-2-and-7-0-13-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/224
Download
https://www.openinfosecfoundation.org/download/suricata-7.0.13.tar.gz
https://www.openinfosecfoundation.org/download/suricata-7.0.13.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-7.0.13 ]]></description>
<link>https://tsecurity.de/de/3487873/IT+Sicherheit/Cybersecurity+Tools/7.0.13/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487873/IT+Sicherheit/Cybersecurity+Tools/7.0.13/</guid>
<pubDate>Thu, 06 Nov 2025 09:56:15 +0100</pubDate>
</item>
<item> 
<title><![CDATA[8.0.2]]></title> 
<description><![CDATA[Release Notes
https://forum.suricata.io/t/suricata-8-0-2-and-7-0-13-released/
Redmine Tracker
https://redmine.openinfosecfoundation.org/versions/225
Download
https://www.openinfosecfoundation.org/download/suricata-8.0.2.tar.gz
https://www.openinfosecfoundation.org/download/suricata-8.0.2.tar.gz.sig
Documentation
https://docs.suricata.io/en/suricata-8.0.2 ]]></description>
<link>https://tsecurity.de/de/3487872/IT+Sicherheit/Cybersecurity+Tools/8.0.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487872/IT+Sicherheit/Cybersecurity+Tools/8.0.2/</guid>
<pubDate>Thu, 06 Nov 2025 09:58:17 +0100</pubDate>
</item>
<item> 
<title><![CDATA[0.42.1]]></title> 
<description><![CDATA[




Packages
Download




rpm-x86_64



deb-x86_64



tgz-x86_64



tgz-static-x86_64



rpm-aarch64



deb-aarch64



tgz-aarch64







Images




docker pull docker.io/falcosecurity/falco:0.42.1


docker pull public.ecr.aws/falcosecurity/falco:0.42.1


docker pull docker.io/falcosecurity/falco-driver-loader:0.42.1


docker pull docker.io/falcosecurity/falco-driver-loader:0.42.1-buster


docker pull docker.io/falcosecurity/falco:0.42.1-debian



v0.42.1
Released on 2025-11-06
Non user-facing changes

docs(CHANGELOG.md): update changelog for 0.42.0 release [#3730] - @leogr

Statistics



MERGED PRS
NUMBER




Not user-facing
1


Release note
0


Total
1



Release Manager @leogr ]]></description>
<link>https://tsecurity.de/de/3487871/IT+Sicherheit/Cybersecurity+Tools/0.42.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487871/IT+Sicherheit/Cybersecurity+Tools/0.42.1/</guid>
<pubDate>Thu, 06 Nov 2025 12:14:29 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Wazuh v4.14.1]]></title> 
<description><![CDATA[Manager
Added

Added IAM role support for VPC flow logs in the AWS wodle. (#32009)
Added support for static and temporary AWS credentials in the Amazon Security Lake subscriber. (#32514)

Changed

Optimized wazuh-db startup by executing agent schema creation in a single transaction. (#32401)
Improved vulnerabilities index upgrade with hash-based mapping validation, automatic safe reindex, and backup cleanup. (#32463)
Improved C++ logging mechanism to avoid unnecessary heap allocations. (#32069)
Improved IndexerConnector error handling and response parsing to provide structured logging of 4xx/5xx errors. (#32521)
Reduced default verbosity of wazuh-authd when handling invalid connections. (#32525)
Remoted now reads internal options at process startup. (#32697)

Fixed

Fixed manager vulnerability scan not triggering due to incorrect syscollector event provider topic name. (#32045)
Fixed IndexerConnector abuse control to prevent data loss on failed syncs. (#32787)
Fixed user tag handling by adding &#039;user&#039; as an alias for the &#039;dstuser&#039; static field. (#32107)
Fixed JSON validation issues in Analysisd and SCA components. (#32057)
Fixed a bug in Vulnerability Scanner where the DB offset was updated even in error cases. (#32829)

Agent
Added

Added support for Homebrew 2.0+ in IT Hygiene for macOS. (#32746)

Changed

Changed how the fim_check_ignore function works in case of negative regex cases. (#31080)
Changed how null values for hotfixes are handled in the Windows agent. (#31375)
Improved service shutdown procedure. (#32874)

Fixed

Fixed indefinite waiting in FIM whodata health check. (#32383)
Fixed graceful shutdown in FIM. (#31241)
SHA256 of commands is now verified on every execution. (#32049)
Fixed duplicate  configuration block during RPM package upgrades. (#32528)
Fixed a bug that prevented overwriting  or  options from remote configuration. (#31144)
Fixed a bug in Logcollector that prevented following symlinks when resolving wildcarded files. (#29853)
Unified detection logs for wildcarded files in Logcollector. (#31222)
Fixed a bug in FIM that did not recognize Registry keys unless they were UTF-8. (#32027)
Fixed a bug in Logcollector that ignored all files with  filter on Windows. (#32731)
Reverted IT Hygiene package vendor format on Debian: now includes name and email again. (#32812)
Fixed a bug in IT Hygiene that reported duplicated Edge browser extensions. (#32785)
Fixed reload of the  block via remote configuration. (#32838)
Fixed Windows installer to deploy SCA policies for Windows 2022 instead of Windows Server 2025. (#32836)

Ruleset
Changed

Reworked SCA Policy for Microsoft Windows 10 Enterprise. (#31449)
Fixed bug in Windows SCA. (#31349)
Fixed mistaken alert due to expected regex. (#31102)
Fixed SCA checks in Oracle Linux 9. (#31886)
Fixed bugs in Windows Server 2016 SCA. (#32509)
Fixed bugs in PAM decoder. (#32523)
Fixed MacOS Sequoia SCA scans with errors. (#32480)
Windows Server 2016 SCA policy not configured correctly. (#32802)

Other
Changed

Upgraded the starlette dependency to 0.47.2. (#31422)
Upgraded Python embedded interpreter to 3.10.19. (#32782)
Updated curl dependency to 8.12.1. (#32900)
Updated LUA to version 5.4.6. (#32294)
Updated libarchive to version 3.8.0. (#32294)
 ]]></description>
<link>https://tsecurity.de/de/3487870/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487870/IT+Sicherheit/Cybersecurity+Tools/Wazuh+v4.14.1/</guid>
<pubDate>Wed, 12 Nov 2025 19:11:43 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.5.0]]></title> 
<description><![CDATA[What&#039;s Changed
🎉 New Features

Adding json + xpath headless extractors by @Mzack9999 in #6559
Adding VNC auth by @Mzack9999 in #6413
Feat(templating): add vars templating into yaml inputs (ytt) by @alban-stourbe-wmx in #6261
Feat: added new text/template syntax to jira custom fields by @Ice3man543 in #6464
Feat(fuzz): enhance MultiPartForm with metadata APIs by @dwisiswant0 in #6486
Feat: http(s) probing optimization by @matejsmycka in #6511
Add option to control number of concurrent templates loaded on startup by @mielverkerken in #6373
CheckRDPEncryption function by @pussycat0x in #6204
SSH keyboard-interactive by @chovanecadam in #6508
Feat(templates): add file metadata fields to parsedTemplate by @dwisiswant0 in #6534
Add env variable for nuclei templates dir by @dogancanbakir in #6588
Adding support for execution in docker by @Mzack9999 in #6549

🐞 Bug Fixes

Clean up pools after 24hours inactivity by @Mzack9999 in #6545
Using clone options for auth store by @Mzack9999 in #6572
Path-based fuzzing SQL fix by @tarunKoyalwar in #6400
Fix(fuzz): handles duplicate multipart form field names by @dwisiswant0 in #6404
Don&#039;t load templates with the same ID by @dogancanbakir in #6465
Remove the stack trace when the nuclei-ignore file does not exist by @nu11zy in #6455
Fix: update go jira deps by @knakul853 in #6475
Jira: hotfix for Cloud to use /rest/api/3/search/jql by @knakul853 in #6489
Fix: improve cleanup in parallel execution by @knakul853 in #6490
Fix headless template loading logic when -dast option is enabled by @dogancanbakir in #6495
Fix: suppress warn code flag not found &amp; excludes known misc dir by @dwisiswant0 in #6500
Fix(variable): global variable not same between two request in flow mode by @iuliu8899 in #6395
Log failed expr compilations by @dogancanbakir in #6528
Fixing failing integration tests by @Mzack9999 in #6544
Fix: populate req_url_pattern before event creation by @Ice3man543 in #6547
Fix(headless): fixed memory leak issue during page initialization by @Deamhan in #6569
Fix(templates): mem leaks in parser cache by @dwisiswant0 in #6584
Fix(http): resolve timeout config issues by @dwisiswant0 in #6562
Fix(charts): fixed out of bounds read by @Deamhan in #6607
Feat 6231 deadlock by @Mzack9999 in #6469

⚡ Performance Improvements

Perf(loader): reuse cached parsed templates by @dwisiswant0 in #6504
Http probing optimizations high ports by @matejsmycka in #6538
Cache, goroutine and unbounded workers management by @knakul853 in #6420
Centralizing ratelimiter logic by @Mzack9999 in #6472

🔧 Refactoring

Refactor to use reflect.TypeFor by @cuiweixie in #6428
Refactored header-based auth scans not to normalize the header names by @halcyondream in #6479
Refactor(disk): templates catalog by @dwisiswant0 in #5914

📦 Other Changes

Test(reporting/exporters/mongo): add mongo integration test with test&hellip; by @loresuso in #6237
Bump httpx version by @dogancanbakir in #6425
Reporting validation by @mkrs2404 in #6456
Code from #6427 by @Mzack9999 in #6471
No changes message for github custom template update to INF from ERR for better logging by @zy9ard3 in #6422
Update Go version requirement in README by @DFwJZ in #6529
Chore(typos): fix typos by @pstoeckle in #6521
Chore: add typos check into tests CI by @dwisiswant0 in #6533
Revert &quot;chore: add typos check into tests CI&quot; by @dwisiswant0 in #6535
Chore: preserve issue report w/ issue form by @dwisiswant0 in #6531
Update go version in logo by @DFwJZ in #6530
Update -tl flag by @matejsmycka in #6536

New Contributors

@loresuso made their first contribution in #6237
@cuiweixie made their first contribution in #6428
@mkrs2404 made their first contribution in #6456
@nu11zy made their first contribution in #6455
@zy9ard3 made their first contribution in #6422
@halcyondream made their first contribution in #6479
@matejsmycka made their first contribution in #6511
@mielverkerken made their first contribution in #6373
@DFwJZ made their first contribution in #6529
@pstoeckle made their first contribution in #6521
@Deamhan made their first contribution in #6569
@chovanecadam made their first contribution in #6508

Full Changelog: v3.4.10...v3.5.0 ]]></description>
<link>https://tsecurity.de/de/3487869/IT+Sicherheit/Cybersecurity+Tools/v3.5.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487869/IT+Sicherheit/Cybersecurity+Tools/v3.5.0/</guid>
<pubDate>Fri, 14 Nov 2025 17:54:13 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.5.1]]></title> 
<description><![CDATA[What&#039;s Changed

Remove genproto replace directives from go.mod by @ehsandeep in #6608

Full Changelog: v3.5.0...v3.5.1 ]]></description>
<link>https://tsecurity.de/de/3487868/IT+Sicherheit/Cybersecurity+Tools/v3.5.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487868/IT+Sicherheit/Cybersecurity+Tools/v3.5.1/</guid>
<pubDate>Fri, 14 Nov 2025 19:25:19 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.4-rc1]]></title> 
<description><![CDATA[Changes

docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc
refact cscli: define csconfig.Getter once (#4091) @mmetc
refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc
pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc
refact pkg/database batching (#3906) @mmetc
refact pkg/acquisition: split appsec.go (#4043) @mmetc
refact pkg/acquisition: journalctl configuration (#4057) @mmetc
lint revive: lower complexity threshold (#4056) @mmetc
lint: unused parameters / 2 (#4055) @mmetc
lint: unused parameters (#4049) @mmetc
refact pkg/acquisition: split loki.go (#4034) @mmetc
refact pkg/acquisition: split victorialogs.go (#4037) @mmetc
refact pkg/acquisition: split wineventlog.go (#4036) @mmetc
refact pkg/acquisition: split s3.go (#4035) @mmetc
refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc
refact pkg/acquisition: split kinesis.go (#4032) @mmetc
refact pkg/acquisition: split kafka.go (#4031) @mmetc
refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc
refact pkg/acquisition: split http.go (#4030) @mmetc
refactg pkg/acquisition: split file.go (#4038) @mmetc
refact pkg/acquisition: split syslog.go (#4028) @mmetc
papi: explicit context (#3973) @mmetc
pkg/csplugin: remove unused function (#4019) @mmetc
pkg/types -&gt; new imports pt 4 (#4012) @mmetc
pkg/types -&gt; new imports pt 3 (#4014) @mmetc
pkg/types -&gt; new imports pt 2 (#4013) @mmetc
pkg/types -&gt; new imports pt 1 (#4011) @mmetc
pkg/types -&gt; pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc
CI: enable linter &quot;protogetter&quot; (#3995) @mmetc
enable linters: unnecessary-format, unused-receiver (#4001) @mmetc
refact: remove unused struct fields and params / 3; enable linter &quot;unused&quot; (#3334) @mmetc

New Features

WAF: Add DropRequest helper to block request in hooks (#4016) @blotus

Improvements

pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc
refact logging configuration; add log_media=&quot;syslog&quot; (#4045) @mmetc
cscli hubtest: better report docker/nuclei errors (#4052) @mmetc
build: check make version before running Makefile (#4054) @mmetc
pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc
option api.server.disable_usage_metrics_export (#4021) @mmetc
build: optional pure-go sqlite driver (#3908) @mmetc

Bug Fixes

docker acquisition: prevent data races (#3956) @mmetc
Fix avoidable prometheus metrics cardinality (#4080) @g00g1
loki acquisition: remove forgotten debug print (#4062) @mmetc
fix 2808: show certificate path in &quot;lapi status&quot; (#4053) @mmetc
decisionStream: only select required fields from the DB (#4024) @blotus

Documentation

docs: add public roadmap section to README.md (#4039) @mazzma12

Chore / Deps

Update go-re2 to 1.10.0 (#4020) @blotus
waf: remove custom raw body processor and use the upstream one (#4092) @blotus
build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @dependabot[bot]
update go-cs-lib (#4084) @mmetc
update coraza (#4047) @blotus
build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @dependabot[bot]
replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc
build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @dependabot[bot]
build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4069) @dependabot[bot]
build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4064) @dependabot[bot]
update docker/docker to moby/moby (version docker-v29.0.0) (#4048) @mmetc
build(deps): bump github/codeql-action from 4.31.0 to 4.31.3 (#4051) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.2 to 7.1.3 (#4042) @dependabot[bot]
build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#4041) @dependabot[bot]
build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0 (#4025) @dependabot[bot]
CI: update golangci-lint to 2.6.1 (#4026) @mmetc
waf: extract temp state from AppsecRuntimeConfig (#3952) @blotus
build(deps): bump astral-sh/setup-uv from 7.1.1 to 7.1.2 (#4009) @dependabot[bot]
build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#4008) @dependabot[bot]
build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#4010) @dependabot[bot]

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3487867/IT+Sicherheit/Cybersecurity+Tools/v1.7.4-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487867/IT+Sicherheit/Cybersecurity+Tools/v1.7.4-rc1/</guid>
<pubDate>Thu, 27 Nov 2025 11:15:41 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.68.0]]></title> 
<description><![CDATA[release: v0.68.0 [main] (#9549) ]]></description>
<link>https://tsecurity.de/de/3487866/IT+Sicherheit/Cybersecurity+Tools/v0.68.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487866/IT+Sicherheit/Cybersecurity+Tools/v0.68.0/</guid>
<pubDate>Tue, 02 Dec 2025 07:48:31 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.68.1]]></title> 
<description><![CDATA[release: v0.68.1 [main] (#9867) ]]></description>
<link>https://tsecurity.de/de/3487865/IT+Sicherheit/Cybersecurity+Tools/v0.68.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487865/IT+Sicherheit/Cybersecurity+Tools/v0.68.1/</guid>
<pubDate>Wed, 03 Dec 2025 09:50:26 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.4-rc2]]></title> 
<description><![CDATA[Changes

docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc
refact cscli: define csconfig.Getter once (#4091) @mmetc
refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc
pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc
refact pkg/database batching (#3906) @mmetc
refact pkg/acquisition: split appsec.go (#4043) @mmetc
refact pkg/acquisition: journalctl configuration (#4057) @mmetc
lint revive: lower complexity threshold (#4056) @mmetc
lint: unused parameters / 2 (#4055) @mmetc
lint: unused parameters (#4049) @mmetc
refact pkg/acquisition: split loki.go (#4034) @mmetc
refact pkg/acquisition: split victorialogs.go (#4037) @mmetc
refact pkg/acquisition: split wineventlog.go (#4036) @mmetc
refact pkg/acquisition: split s3.go (#4035) @mmetc
refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc
refact pkg/acquisition: split kinesis.go (#4032) @mmetc
refact pkg/acquisition: split kafka.go (#4031) @mmetc
refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc
refact pkg/acquisition: split http.go (#4030) @mmetc
refactg pkg/acquisition: split file.go (#4038) @mmetc
refact pkg/acquisition: split syslog.go (#4028) @mmetc
papi: explicit context (#3973) @mmetc
pkg/csplugin: remove unused function (#4019) @mmetc
pkg/types -&gt; new imports pt 4 (#4012) @mmetc
pkg/types -&gt; new imports pt 3 (#4014) @mmetc
pkg/types -&gt; new imports pt 2 (#4013) @mmetc
pkg/types -&gt; new imports pt 1 (#4011) @mmetc
pkg/types -&gt; pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc
CI: enable linter &quot;protogetter&quot; (#3995) @mmetc
enable linters: unnecessary-format, unused-receiver (#4001) @mmetc
refact: remove unused struct fields and params / 3; enable linter &quot;unused&quot; (#3334) @mmetc

New Features

WAF: Add DropRequest helper to block request in hooks (#4016) @blotus

Improvements

pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc
refact logging configuration; add log_media=&quot;syslog&quot; (#4045) @mmetc
cscli hubtest: better report docker/nuclei errors (#4052) @mmetc
build: check make version before running Makefile (#4054) @mmetc
pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc
option api.server.disable_usage_metrics_export (#4021) @mmetc
build: optional pure-go sqlite driver (#3908) @mmetc

Bug Fixes

fix accessLogger setup to separate file (#4103) @mmetc
docker acquisition: prevent data races (#3956) @mmetc
Fix avoidable prometheus metrics cardinality (#4080) @g00g1
loki acquisition: remove forgotten debug print (#4062) @mmetc
fix 2808: show certificate path in &quot;lapi status&quot; (#4053) @mmetc
decisionStream: only select required fields from the DB (#4024) @blotus

Documentation

docs: add public roadmap section to README.md (#4039) @mazzma12

Chore / Deps

build(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4101) @dependabot[bot]
build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#4083) @dependabot[bot]
Update go-re2 to 1.10.0 (#4020) @blotus
waf: remove custom raw body processor and use the upstream one (#4092) @blotus
build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @dependabot[bot]
update go-cs-lib (#4084) @mmetc
update coraza (#4047) @blotus
build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @dependabot[bot]
replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc
build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @dependabot[bot]
build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4069) @dependabot[bot]
build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4064) @dependabot[bot]
update docker/docker to moby/moby (version docker-v29.0.0) (#4048) @mmetc
build(deps): bump github/codeql-action from 4.31.0 to 4.31.3 (#4051) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.2 to 7.1.3 (#4042) @dependabot[bot]
build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#4041) @dependabot[bot]
build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0 (#4025) @dependabot[bot]
CI: update golangci-lint to 2.6.1 (#4026) @mmetc
waf: extract temp state from AppsecRuntimeConfig (#3952) @blotus
build(deps): bump astral-sh/setup-uv from 7.1.1 to 7.1.2 (#4009) @dependabot[bot]
build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#4008) @dependabot[bot]
build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#4010) @dependabot[bot]

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3487864/IT+Sicherheit/Cybersecurity+Tools/v1.7.4-rc2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487864/IT+Sicherheit/Cybersecurity+Tools/v1.7.4-rc2/</guid>
<pubDate>Wed, 03 Dec 2025 14:25:32 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v1.7.4]]></title> 
<description><![CDATA[Changes

docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc
refact cscli: define csconfig.Getter once (#4091) @mmetc
refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc
pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc
refact pkg/database batching (#3906) @mmetc
refact pkg/acquisition: split appsec.go (#4043) @mmetc
refact pkg/acquisition: journalctl configuration (#4057) @mmetc
lint revive: lower complexity threshold (#4056) @mmetc
lint: unused parameters / 2 (#4055) @mmetc
lint: unused parameters (#4049) @mmetc
refact pkg/acquisition: split loki.go (#4034) @mmetc
refact pkg/acquisition: split victorialogs.go (#4037) @mmetc
refact pkg/acquisition: split wineventlog.go (#4036) @mmetc
refact pkg/acquisition: split s3.go (#4035) @mmetc
refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc
refact pkg/acquisition: split kinesis.go (#4032) @mmetc
refact pkg/acquisition: split kafka.go (#4031) @mmetc
refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc
refact pkg/acquisition: split http.go (#4030) @mmetc
refactg pkg/acquisition: split file.go (#4038) @mmetc
refact pkg/acquisition: split syslog.go (#4028) @mmetc
papi: explicit context (#3973) @mmetc
pkg/csplugin: remove unused function (#4019) @mmetc
pkg/types -&gt; new imports pt 4 (#4012) @mmetc
pkg/types -&gt; new imports pt 3 (#4014) @mmetc
pkg/types -&gt; new imports pt 2 (#4013) @mmetc
pkg/types -&gt; new imports pt 1 (#4011) @mmetc
pkg/types -&gt; pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc
CI: enable linter &quot;protogetter&quot; (#3995) @mmetc
enable linters: unnecessary-format, unused-receiver (#4001) @mmetc
refact: remove unused struct fields and params / 3; enable linter &quot;unused&quot; (#3334) @mmetc

New Features

WAF: Add DropRequest helper to block request in hooks (#4016) @blotus

Improvements

pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc
refact logging configuration; add log_media=&quot;syslog&quot; (#4045) @mmetc
cscli hubtest: better report docker/nuclei errors (#4052) @mmetc
build: check make version before running Makefile (#4054) @mmetc
pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc
option api.server.disable_usage_metrics_export (#4021) @mmetc
build: optional pure-go sqlite driver (#3908) @mmetc

Bug Fixes

LAPI metrics: don&#039;t use empty path as label for LAPI hits metrics (#4106) @blotus
fix accessLogger setup to separate file (#4103) @mmetc
docker acquisition: prevent data races (#3956) @mmetc
Fix avoidable prometheus metrics cardinality (#4080) @g00g1
loki acquisition: remove forgotten debug print (#4062) @mmetc
fix 2808: show certificate path in &quot;lapi status&quot; (#4053) @mmetc
decisionStream: only select required fields from the DB (#4024) @blotus

Documentation

docs: add public roadmap section to README.md (#4039) @mazzma12

Chore / Deps

build(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4101) @dependabot[bot]
build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#4083) @dependabot[bot]
Update go-re2 to 1.10.0 (#4020) @blotus
waf: remove custom raw body processor and use the upstream one (#4092) @blotus
build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @dependabot[bot]
update go-cs-lib (#4084) @mmetc
update coraza (#4047) @blotus
build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @dependabot[bot]
replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc
build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @dependabot[bot]
build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4069) @dependabot[bot]
build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4064) @dependabot[bot]
update docker/docker to moby/moby (version docker-v29.0.0) (#4048) @mmetc
build(deps): bump github/codeql-action from 4.31.0 to 4.31.3 (#4051) @dependabot[bot]
build(deps): bump astral-sh/setup-uv from 7.1.2 to 7.1.3 (#4042) @dependabot[bot]
build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#4041) @dependabot[bot]
build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0 (#4025) @dependabot[bot]
CI: update golangci-lint to 2.6.1 (#4026) @mmetc
waf: extract temp state from AppsecRuntimeConfig (#3952) @blotus
build(deps): bump astral-sh/setup-uv from 7.1.1 to 7.1.2 (#4009) @dependabot[bot]
build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#4008) @dependabot[bot]
build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#4010) @dependabot[bot]

Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions. ]]></description>
<link>https://tsecurity.de/de/3487863/IT+Sicherheit/Cybersecurity+Tools/v1.7.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487863/IT+Sicherheit/Cybersecurity+Tools/v1.7.4/</guid>
<pubDate>Thu, 04 Dec 2025 16:23:59 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.6.0]]></title> 
<description><![CDATA[What&#039;s Changed
✨ New Features

Write resume file specified by flag by @circleous (#6616)
Javascript Multi-Port Support by @pussycat0x (#6501)
Direct fuzzing using target URL for OpenAPI/Swagger by @roiswd (#6542)
Bump DSL with .NET deserialization helpers by @Ice3man543 (#6625)
Implement persistent metadata cache in loader by @dwisiswant0 (#6630)
Check for undefined params for lazy evaluation in variables by @dwisiswant0 (#6618)

🐛 Fixed

Configure tmpDir for SDK by @AuditeMarlow (#6596)
Skip DNS lookups on Interactsh domains by @dwisiswant0 (#6614)
Restore parallel processing in file protocol by @dwisiswant0 (#6493)

⚙️ Changed / Improvements

Enable BenchmarkRunEnumeration/Default benchmark by @dwisiswant0 (#6603)
Cache Go-rod browser in CI by @dwisiswant0 (#6640)
Apply free-disk-space check on tests by @dwisiswant0 (#6642)
Disable stale workflow for enhancements by @dogancanbakir (#6637)
Omit unnecessary reassignment by @ledigang (#6622)

🧹 Maintenance / Dependencies

Bump the modules group with 6 updates by @dependabot[bot] (#6615)
Bump actions/checkout from 5 to 6 in workflows by @dependabot[bot] (#6628)
Bump PD modules &amp; update httputil calls by @dependabot[bot] (#6629)
Bump the modules group with 11 updates by @dependabot[bot] (#6646)
Bump golang.org/x/crypto from 0.43.0 to 0.45.0 by @dependabot[bot] (#6621)
Bump github.com/projectdiscovery/fastdialer@v0.4.16 by @dwisiswant0 (#6624)

🌱 New Contributors

@AuditeMarlow (#6596)
@roiswd (#6542)
@ledigang (#6622)

Full Changelog: v3.5.1 &rarr; v3.6.0 ]]></description>
<link>https://tsecurity.de/de/3487862/IT+Sicherheit/Cybersecurity+Tools/v3.6.0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487862/IT+Sicherheit/Cybersecurity+Tools/v3.6.0/</guid>
<pubDate>Thu, 04 Dec 2025 22:20:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v3.6.1]]></title> 
<description><![CDATA[What&rsquo;s Changed
🐞 Bug Fixes

fix(config): template exclusion logic for paths with reserved names by @dwisiswant0 in #6663
fix(http): lost request body on retries &amp; redirects by @dwisiswant0 in #6666
fix(http): pass dynamicValues to EvaluateWithInteractsh by @dwisiswant0 in #6685
fix(lib): segfault when initializing the engine with EnableHeadlessWithOpts by @dwisiswant0 in #6602
build: fix compilation on loong64 architecture by @dwisiswant0 in #6667
fix: enable all template types for template list and display by @dwisiswant0 in #6668
fix(http): cache response strings to reduce memory allocations by @dwisiswant0 in #6679
fix: body loss on retries/redirects in remaining paths by @dwisiswant0 in #6693
fix(headless): data race when reading page history by @dwisiswant0 in #6687
fix(update): handle empty folder edge case during template updates by @Mzack9999 in #6573

🔨 Maintenance

chore: run goimports to format the codebase by @stringscut in #6691
chore(deps): bump fastdialer to v0.4.20 to fix &gt;10s delays by @dwisiswant0 in #6688
chore(deps): bump Go modules (10 updates) by @dependabot[bot] in #6675
chore(deps): bump Go modules (7 updates) by @dependabot[bot] in #6698
chore(deps): bump GitHub workflows (2 updates) by @dependabot[bot] in #6699

📚 Documentation

docs: fix typos in multiple files by @didier-durand in #6653
docs: fix additional typos across various files by @didier-durand in #6661
docs: typos and minor improvements by @AaryanBansal-dev in #6669

New Contributors

@didier-durand made their first contribution in #6653
@AaryanBansal-dev made their first contribution in #6669
@stringscut made their first contribution in #6691

Full Changelog: v3.6.0...v3.6.1 ]]></description>
<link>https://tsecurity.de/de/3487861/IT+Sicherheit/Cybersecurity+Tools/v3.6.1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487861/IT+Sicherheit/Cybersecurity+Tools/v3.6.1/</guid>
<pubDate>Tue, 16 Dec 2025 10:05:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[v0.68.2]]></title> 
<description><![CDATA[release: v0.68.2 [release/v0.68] (#9950) ]]></description>
<link>https://tsecurity.de/de/3487860/IT+Sicherheit/Cybersecurity+Tools/v0.68.2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487860/IT+Sicherheit/Cybersecurity+Tools/v0.68.2/</guid>
<pubDate>Wed, 17 Dec 2025 06:57:32 +0100</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,22ms -->