What's new with Fluid Attacks ✨
Implemented
🗃️ More filters for vulnerability prioritization: In the weaknesses table, you now have a filter to immediately see the Top 20 vulnerabilities to be remediated according to your prioritization algorithm settings. Additionally, we offer filters for Exploit Prediction Scoring System (EPSS), Known Exploited Vulnerabilities (KEV), and reachability, among others.
🩺 Vulnerability treatments record: For all vulnerabilities that your team has already remediated, you can see the label "Treated" in the Treatment column. Those that appear as "Untreated" are those that have yet to be defined as either accepted or remediated, which you can also see in one of the pie charts in the Analytics section.
📱 Better asset management experience: To evaluate your mobile applications, in addition to uploading binary files (.ipa or .apk), you can give us access to the applications through TestFlight, Firebase, App Store Connect, or Google Play Store. This new option means you don't have to manually modify binaries on the platform every time there is an update; we will always be checking and testing the latest versions.
📉 New condition for plan downgrade: Now, when you switch from the Advanced to the Essential plan, not only will you no longer be able to reattack vulnerabilities that we detected manually (i.e., through PTaaS, secure code review, or reverse engineering), but those vulnerabilities will also automatically disappear from your records on our platform.
Deprecations
- We removed CVSS 3.1 from our API.
- We removed our scanners' old Docker images.
Upcoming
🗄️ Improvements to the asset management: We will continue to enhance the usability of the Scope section of our platform.
🧩 Enhancements to our IDE integrations: Soon, you will be able to use general Autofix and reattacks from IntelliJ. In addition, for both this extension and the VS Code plugin, you will be able to use Autofix for vulnerabilities detected through SCA.
⚠️Fluid Attacks call notice⚠️
Recently, our sales team may have called your team members to offer them onboarding and adoption of new features on our platform. This is a reliable procedure in which we will never seek to discuss your software's vulnerabilities. However, if you have any questions, please contact us at help@fluidattacks.com.
✨Have 10-15 minutes to spare?✨
Share your opinions on our AppSec solution on Gartner Peer Insights and earn a $25 gift card! Your feedback helps others make informed decisions and shapes the future of application security. Just follow this link! Now, you can also do it in Spanish: