ASL Scan: an attacker's-eye-view testing tier
ASL Scan substantially expanded its active adversary-emulation tier — the part that tests a system the way an attacker would. New technique categories include server-side request forgery, token and session confusion, cache poisoning, request smuggling, CORS and security-header posture, open-redirect, mass-assignment, and tenant-isolation checks.
Crucially it added the guardrails that make active testing safe to run: a mutation-control policy, a reversible-mutation harness, a behavior-only reverse-shell emulation, and an operator console to run and audit every technique.
Customer-facing outcome
- Many new attacker's-eye-view technique categories
- Reversible-mutation harness and mutation-control policy
- Behavior-only reverse-shell emulation
- Operator console to run and audit techniques (self-hosted purple team)
Three products debut
SignalLab spun off into its own RF signal-lab product — RF manifest lifecycle, integrity hashing, test sessions, link-budget tooling, and a fixture-class policy with countersignatures. BandSight debuted for RF band planning with survey sessions, import/merge, receiver support and instrument proof.
Aegis, a new host-security product, shipped its first release.
Customer-facing outcome
- SignalLab: RF manifests, integrity hashing, link-budget tooling
- BandSight: band planning, survey sessions, receiver support
- Aegis: first host-security release
AI Hub governance
AI Hub added encrypted multi-account provider routing, encrypted organization-policy controls, project-workspace governance, two-phase route approval, and workflow restart and recovery — plus assisted setup for connecting coding assistants.
Customer-facing outcome
- Encrypted multi-account routing and org-policy controls
- Two-phase route approval and workflow recovery
- Assisted connection setup for coding assistants