What's new with Fluid Attacks 🚀
Implemented
🦀 Rust and Elixir are here: We said they were coming, and they shipped. Rust now has 37 new SAST rules (injection, path traversal, SSRF, weak crypto, session and header misconfigurations), and Elixir now has 19 more alongside reachability analysis for Hex packages. Your Rust and Elixir services are now covered by the same detection depth as the rest of your stack.
🌿 Multi-branch testing: The same repository can now be registered in more than one group, each tracking a different branch with its own findings and testing scope. Teams running long-lived and short-term branches can finally test them in parallel instead of choosing one. See the registration rules.
🚁 Peer Reviewer Assistant, now on GitHub, plus secrets scanning: The assistant runs SAST, SCA and the Secrets Scanner on pull request diffs across GitLab, GitHub and Azure DevOps. Hardcoded credentials and many other types of weaknesses get caught in review, before they reach your default branch. Available for Advanced plan groups on cloud-hosted repositories.
🎯 Sharper prioritization: Every vulnerability in our Database now carries a VLAI severity rating (Critical to Low), a dynamic score generated by a machine-learning algorithm that reads each vulnerability's details. You can filter by it alongside CVSS and EPSS when prioritizing fixes. Real-world exploitation activity is now surfaced as Signals, and the filter panel supports include and exclude modes for CWE and weakness, so you can scope a view to what your team actually owns.
⏱️ Stronger service commitments: Our maximum initial support response time went from 16 to 8 business hours, and the availability SLA now explicitly covers the platform API, not just the web application.
Upcoming
🕵️ A view for fraud teams: Fraud teams will be able to see which of the vulnerabilities reported in their organization are fraud enablers, and request priority attention on them.
🗺️ Discovery: An organization-level map of every asset you have, such as repositories and environments, both inside and outside Fluid Attacks' testing scope. Available as a paid add-on feature.
🧠 More AI SAST coverage: Expanding to weakness types where automation previously meant false positives.
⚠️Fluid Attacks call notice⚠️
Our education specialists may call your team members to provide onboarding and adoption support for new platform features. This is a reliable procedure in which we will never seek to discuss your software's vulnerabilities. However, if you have any questions, please contact us at help@fluidattacks.com.
✨Have 10-15 minutes to spare?✨
Share your opinions on our AppSec solution on Gartner Peer Insights and earn a $25 gift card! Your feedback helps others make informed decisions and shapes the future of application security. Just follow this link! Remember, you can write your review in whichever language you prefer.