Skip to main content

Free 30-min security demo Book Now

Offensive360 Offensive360
PRODUCT UPDATES

What's new in Offensive360

Dated release notes across the platform — SAST, DAST, MAST, Attack Surface Management, Autonomous Red Teaming, the AI Pentester, and the on-premise appliance. Newest first.

Last updated: 8 September 2026

September 2026

Website

Product updates page and full DAST coverage documentation

  • This product-updates page is live and linked from every page footer.
  • The DAST product page now lists every active and passive check class the engine runs.
  • llms.txt and the new llms-full.txt describe all six products, their FAQs and this update log for AI assistants and search engines.
DAST

Access-control and business-logic testing hardened

  • Mass-assignment checks now probe an 18-field dictionary of privileged attributes (role, isAdmin, verified, balance, owner_id, tenant_id, price and more) in form and JSON bodies — up from 3.
  • Price and quantity tampering in AI-driven engagements is confirmed against the server-computed outcome, not an echoed value.
  • A multi-identity authorization differ — IDOR/BOLA and function-level BFLA across high, low and anonymous identities — is wired into the engagement engine.
  • Security-header and clickjacking checks no longer report on responses that were never captured, removing a class of false positives.
  • The Vulnerabilities view shows human-readable finding types, and the CVSS column appears only when scores exist.
  • The dashboard separates the findings-weighted Scan Risk Index from the ASM-derived External Exposure Risk, and its counts match the Scans list.
DAST · Red Teaming · ASM · Appliance

AI Pentester and AI Red Teaming become separate workspaces

  • AI Red Teaming operations get their own sidebar tab, list and creation flow, distinct from approval-gated AI Pentester engagements.
  • ASM monitor creation accepts full URLs (reduced to hostnames) and named monitors.
  • Azure VHD appliance images validated end to end alongside the OVA — SAST, DAST and MAST, online and fully air-gapped.
ASM

Organization risk roll-up and tighter egress controls

  • Per-exposure risk scores roll up into an organization-level exposure score on the dashboard.
  • Tighter egress controls for OSINT collection, and an AI-assisted triage pass that marks likely false positives.
DAST · Red Teaming

Wider discovery and offline fallback

  • Subdomain enumeration expanded and active port discovery added ahead of crawling.
  • AI-assisted false-positive triage on scan findings.
  • Red-team operations fall back to offline reasoning automatically when no cloud AI service is reachable.

August 2026

SAST · Red Teaming · Appliance

Full offline analysis parity on air-gapped appliances

  • All core language engines now analyze fully offline — verified by scanning the same vulnerable code with the network disconnected.
  • The Autonomous Red Teaming engine ships with an enforced scope guard, safe mode by default, denial-of-service force-disabled and a kill switch.
  • The appliance engine self-heals after an interrupted first boot.
Appliance

Encrypted Azure payload and SIEM forwarding

  • Azure images carry an encrypted (LUKS) payload with key release through the licensing relay, so a cloud tenant cannot read the engine at rest.
  • Syslog forwarding to SIEM platforms validated end to end with FortiSIEM.
SAST

Free for Open Source, GitHub Action and MCP server

  • Public repositories on GitHub, GitLab, Bitbucket and Codeberg can request a free 30-day SAST scan token.
  • offensive360/sast-scan-action runs a full scan in GitHub Actions and uploads SARIF to the code-scanning tab; a GitLab CI template is included.
  • An open-source MCP server lets AI coding assistants scan a local directory and read findings with file, line, severity and fix.
MAST

Mobile engine overhaul

  • New mobile analysis engine for Android APK/AAB and iOS IPA binaries.
  • AI-assisted false-positive triage and a detailed PDF report mapped to the OWASP Mobile Top 10 (2024).
  • Chunked upload for large binaries.

July 2026

AI Pentester · DAST

Authorization-gated AI penetration testing

  • PTES-structured engagements on the DAST engine: reconnaissance, vulnerability analysis, human-approved exploitation and reporting.
  • Signed in-product authorization record with eight attestations, a visible kill switch and denial-of-service force-disabled.
  • OWASP WSTG and MITRE ATT&CK mapped reports.
  • LLM application probes for the OWASP Top 10 for LLM Applications (2025).

Earlier history and the full capability reference live in llms-full.txt and on each product page. Customers on the on-premise appliance receive these updates through the signed over-the-air channel.

See the latest release on your own code

Book a demo and we'll walk through the newest DAST, ASM and red-teaming capabilities against a target you choose.