What's new in AppScan on Cloud

Discover upcoming and recently added features.

Updates: AppScan on Cloud announcements, including advance notice of planned changes and scheduled maintenance that might affect your workflow, can be found on AppScan News. To be notified when there is an announcement, you can subscribe to AppScan News.
Translations: If you are reading this page in translation, please be aware that it may not include the latest additions. To see the latest version of this page, switch to the English version, using the "Change Language" option at the top right of the menu bar.

New on November 25, 2025

  • DAST engine update: Dynamic analysis engine updated to version 10.10.0. This update includes:
    • Automatic login improvements: AppScan now crawls Angular applications more reliably, fixes rare login recording failures, and adds a delay between actions on the second attempt after a playback failure, improving overall success rates.
    • Masking improvements: Enhanced masking across AppScan for more consistent protection of sensitive information.
    • Improved support for Single Page Applications (SPA) scans that use AngularJS framework.
    • New and updated security rules.

New on November 20, 2025

  • SCA malware scanning
    • AppScan's new SCA engine now includes integrated malware detection capabilities. This enhancement automatically scans open-source and third-party components for known malicious or compromised packages, helping teams identify and mitigate potential supply-chain risks early in the development process.

New on November 16, 2025

  • Dynamic analysis (DAST)
    • Template management: Manage DAST templates in ASoC to control and expedite DAST configurations. Templates can be customized and assigned to asset groups as needed.
    • Create scan from an uploaded template: After you upload a template to ASoC, you can review and edit its configuration before running the scan.
  • Compliance reports and policies
    • New compliance reports:
      • OWASP Top 10 for LLM Applications 2025
      • [Canada] IT security risk management: A lifecycle approach (ITSG-33)
    • Updated compliance reports:
      • International Standard - ISO 27001:2022
      • International Standard - ISO 27002:2022
      • The Payment Card Industry Data Security Standard (PCI DSS) - V4.0.1
      • NIST Special Publication 800-53 - 5.2.0
      • [EU] General Data Protection Regulation (GDPR)
      • [US] Health Insurance Portability and Accountability Act (HIPAA)
  • Custom application fields enhancements
    • Custom application fields are now available in a CSV exported file along with application details and are displayed in generated security reports.
  • Plugins
    • New plugins and integrations are now available and can be accessed from the integration page:
      • Slack: Receive AppScan on Cloud security alerts and scan notifications in your Slack channels.
      • Splunk: Connect AppScan on Cloud with Splunk to gain centralised visibility into scan data through analytics and dashboards.
      • Cursor AI: Integrate with AppScan CodeSweep to identify and remediate vulnerabilities during AI-assisted coding.

New on November 6, 2025

  • Static analysis (SAST)
    • Static analysis client updated to 8.0.1663.
    • When generating a report, users can now specify whether to include the "Table of Contents" and "Summary" sections in the report.
    • Static analysis can now process .mjs files as part of JavaScript support.
    • Updates to rules.

New on October 26, 2025

  • User experience improvements
    • SAST: You can now search in the GitHub repository and branch dropdown.
    • Faster page load times.
    • Improved breadcrumb navigation accuracy.
    • Updated colors and graphics to support accessibility.

New on October 17, 2025

  • Interactive application security testing (IAST)
    • New IAST Java agent (1.21.1)
      • Updated dependencies for better compatibility and security.
    • New IAST .NET agent (1.15.2)
      • Dependency refresh, improved result accuracy.
    • New IAST PHP agent (1.2.1)
      • Performance optimizations and bug fixes.

New on October 7, 2025

  • Static analysis (SAST)
    • Static analysis client updated to 8.0.1655.
    • Updates to rules.

New on September 14, 2025

  • Dynamic analysis (DAST)
    • Resume scan: In some scenarios, you can now resume failed or partially completed scans. This feature enhances the scanning process by allowing you to continue from where the scan stopped once previous limitations are resolved, thereby saving time and resources.
  • Software Composition Analysis (SCA)
    • The Audit Trail tab for open source libraries provides clarity into all actions and changes related to each library, helping teams track history, maintain compliance, and improve accountability.
    • EPSS (Exploit Prediction Scoring System) is available in the new SCA engine for new scans, enabling smarter prioritization of vulnerabilities based on real-world exploit likelihood. EPSS score and percentile are listed on the Details pane for SCA issues. For more information, see EPSS.
  • Platform improvements
    • The Fix group interface is redesigned for better usability. The new interface makes it easier to understand grouped issues, navigate resolutions, and manage fixes efficiently.

New on September 10, 2025

  • SAST
    • Static analysis client updated to 8.0.1653.
    • Fixed an issue where Git information may be incorrectly collected if an Azure DevOps repository is in a detached head state.
    • Updates to rules.

New on August 27, 2025

  • Interactive application security testing (IAST ):
    • New IAST Java agent (1.20.2)
      • Improved support for customers using org.springframework.core.io.UrlResource.
    • New IAST .NET agent (1.14.3)
      • Support for IAST analyzer for microservices.
      • Log file name and path for IAST can now be configured via the secagent.log environment variable.
      • Improved support for customers using System.Net.WebClient.
    • New IAST PHP agent (1.1.4)
      • Performance improvements and bug fixes for Magento framework users.
    • IAST for Kubernetes (1.0.8)
      • Security updates

New on August 25, 2025

  • Dynamic analysis (DAST)
    • DAST configuration editing: You can now edit the scan configuration for completed or failed DAST scans, allowing you to rescan with a modified configuration.
    • Exclude paths: When scanning APIs, you can configure AppScan to ignore certain paths in the application, just like when scanning web applications.
  • General updates:
    • Export scan data: The export option, which was previously only for administrators, is now available to everyone.
    • Reports customization: Support for SVG file format for report logos is discontinued.

New on August 12, 2025

  • SAST
    • Static analysis client updated to 8.0.1651.
    • Foundation for upcoming Yarn package manager support by Software Composition Analysis (SCA). Full support to be announced.

New on July 30, 2025

  • SAST
    • Static analysis client updated to 8.0.1650.
    • Fixed an issue where Maven/Gradle failures cause AppScan Go! to fail “Path 2”.
    • Clarified Failed in IAssemblyInfo call messages printed in console output.
    • Fixed an issue where Git relative path fails for files at root of repository on Linux.

New on July 22, 2025

  • AppScan Go!
    • AppScan Go! updated to version 2.3.0.
    • New installation procedure allows for smarter service detection.
    • AppScan Go! now automatically detects and fills in the correct service URL at login.
    • Users can now allow intervention from our scan enablement team within AppScan Go!.
    • Software Composition Analysis (SCA) files specified for scanning no longer show absolute paths.
    • User interface improvements.

New on July 18, 2025

  • Software Composition Analysis (SCA)

    Over the next several weeks, the AppScan team will be migrating accounts to use the new and improved SCA engine.

    • Software Composition Analysis (SCA) engine updated to version 3.
    • Cleaner and more reliable scanning results.

      The new engine enhances our already strong detection capabilities, further improving accuracy by minimizing noise and refining result precision.

    • Expanded vulnerability database.

      Faster and more precise identification of known risks.

    • Dependency graph view now available.

      When dependency data is available in a scan, you’ll see a visual graph view—making it easier to understand package relationships and impact.

    • Extended config file scanning support.

      C/C++, PHP, and Java configuration files. Static analysis client version 8.0.1646 required.

If you are not yet able to access these new SCA engine features, contact your AppScan representative.

New on July 15, 2025

  • Static analysis (SAST)
    • Static analysis client updated to 8.0.1646.
    • Fixes an issue in the Java parallel processing cache for locally generated .irx files.

New on July 15, 2025

  • Static analysis (SAST)
    • Static analysis client updated to 8.0.1645.
    • Updates to rules.
    • Improved IRGen performance during Git discovery.
    • Secrets scanning now properly enabled using the Organization setting.

New on July 13, 2025

  • Dynamic analysis (DAST)
    • AppScan For Dev - DAST Issue Verifier: Added the option to download a python script and run it in the IDE.
    • Download scan file for failed scans: You can now download the scan file even if the scan fails for further troubleshooting in AppScan Standard. The file can be downloaded only if the scan actually started running.
  • Software Composition Analysis (SCA):
    • Added “Removed” status to library view: By default, the library view does not display information about libraries that have been removed from the application. You can now apply a filter to view libraries that have been removed, and these libraries are clearly noted with the status "Removed."
  • Platform improvements:
    • Report customization updates
      • Set a custom title for your reports using the report layout.
      • The report type is displayed in the generated reports.
  • User experience improvements:
    • Subscription page redesign: The subscription page has been revamped to enhance user experience.
    • Tables:
      • Column selection: Column selection is organized by category to improve usability.
      • Copy from grid: Right-click any table cell to easily copy its content.

New on June 18, 2025

  • DAST engine update: Dynamic analysis engine updated to version 10.9.0. This update includes:
    • Automatic login improvements: Perform automatic logins more accurately, which improves the overall success rate.
    • Support for WebSocket protocol that uses JSON or XML messages for data exchange.

New on June 16, 2025

  • Static analysis (SAST)
    • Updates to C/C++ scanning.

New on June 15, 2025

  • Software Composition Analysis (SCA):
    • SCA scan details include library status: SCA now indicates whether a library is still present in the latest scan, helping track remediation progress.
  • Static analysis (SAST):
    • JavaScript scanner: New hybrid scanning for improved accuracy when scanning JavaScript source-code, including taint-flow analysis.
    • ICA 2.0 for Java: Major enhancements to Intelligent Code Analytics (ICA) for Java, our AI/ML auto-security descriptor, include more precise findings and reduced false negatives.
  • Interactive application security testing (IAST ):
    • IAST analyzer for Microservices (Node.js)
      • Full Service Graph View: Provides a comprehensive visualization of how your microservices interact, offering better insight into their relationships.
      • Reduced False Positives: Improves the accuracy of vulnerability detection by leveraging the service graph, leading to fewer irrelevant alerts and more focused security efforts.
  • Compliance Reports and Policies:
    • Updated compliance reports:
      • [US] DISA's Application Security and Development STIG. V6R3
      • CWE Top 25 Most Dangerous Software Weaknesses 2024

New on June 13, 2025

  • Static analysis (SAST)
    • Static analysis client updated to 8.0.1640.
    • Updates to rules.

New on May 27, 2025

  • Dynamic analysis (DAST):
    • AppScan For Dev - DAST Issue Verifier: This approach allows developers to simulate DAST vulnerabilities that AppScan reports directly within the IDE or browser. Developers can run an AppScan-generated script to replicate the issue, debug it, and validate the fix—all without needing a rescan and before checking in the code.
    • Multiple domains on a traffic file: When uploading a traffic file with multiple domains, ASoC automatically adds these domains to the 'Domains to test' list, and mark those verified to be included in the scan.

  • Interactive analysis (IAST):
    • IAST for Microservices now offers enhanced support for Kubernetes Node.js environments, providing a non-intrusive solution for deploying the IAST agent automatically within Kubernetes pods. AppScan automates the integration of agents using a deployment script. This new feature facilitates the management of numerous containers and enables testing and production environments to use the original application image without alteration. This allows for a full visibility graph view for your microservice and helps to identify and address security issues early in the development lifecycle.
  • Integration updates:
    • A new Centraleyezer plugin lets you seamlessly import and manage HCL AppScan on Cloud vulnerability data, including both DAST and SAST scans, within the Centraleyezer Vulnerability Management platform, allowing you to identify, prioritize, track, and remediate security vulnerabilities.
    • Integration with CMD+CTRL Security providing hands-on, immersive secure code training.

New on May 26, 2025

  • DAST engine update: Dynamic analysis engine updated to version 10.8.1.28522.
    • Engine bug fixes

New on May 25, 2025

  • Licensing updates: AppScan on Cloud now uses the MyHCLSoftware (MHS) licensing system for all new and existing customers. When a license is purchased or renewed, a new license file is sent by email. Uploading this file to ASoC adds a new subscription to the organization. Existing licenses in ASoC remain unaffected.

New on May 13, 2025

  • DAST engine update: Dynamic analysis engine updated to version 10.8.1.28519. This update includes fixes for the zero-day vulnerability CVE-2025-2783.

New on May 11, 2025

  • New IAST .NET agent (1.14.1)
    • Fixed a bug affecting customers using the .NET Framework.

  • New IAST PHP agent (1.1.1)
    • Added support for customers using Red Hat 8 with PHP 8.2.
    • Fixed installation issues on Windows.
    • Improved performance and made various optimizations.
    • General bug fixes.

New on May 07, 2025

  • Static Analyzer Command Line Utility updated to 8.0.1634.
  • Updates to rules.
  • Custom application fields: Streamline application management in AppScan on Cloud with custom application fields. This new feature offers greater flexibility in how you categorize, filter, and analyze application data. Whether you manage risk, track security progress, or organize large inventories, custom fields provide a more granular and tailored view to support your workflows and decision-making. To learn more about how to configure and use custom fields, refer to Custom application fields.

New in version 8.0.1634 (May 7, 2025)

  • Static Analyzer Command Line Utility updated to 8.0.1634.
  • Updates to rules.

New on April 22, 2025

  • Static analysis (SAST) and Software Composition Analysis (SCA):
  • Plugins:
    • ThreadFix plugin was removed.

New on April 1, 2025

SAST updates:

New on March 30, 2025

  • Dynamic analysis (DAST):
    • Test Policies tab is now added under Organization. Here, you can manage your test policies and upload a custom policy that you created in AppScan Standard or AppScan Enterprise.
    • Policies tab under Organization is now renamed as Compliance policies.

New on March 27, 2025

  • IAST for Kubernetes (1.0.5)
    • Dependencies update
    • Fix container privileges
    • Fix Windows installation
    • Install script can get registry name as a parameter, for customers using private registry.

New on March 17, 2025

  • Dynamic analysis (DAST):
  • Software Composition Analysis (SCA):
  • Platform improvements:
    • Report customization: Personalize your reports with your brand identity by easily adding your company logo and creating custom headers and footers.
    • Custom policies: Issues can now be filtered based on technology, along with the other filtering options that were already available.

New on March 11, 2025

SAST updates:
  • Static analysis client updated to 8.0.1628.
  • Bug fix from version 8.0.1623: File paths for files at the root of a Git repository are now relative file paths.

New on March 05, 2025

  • New IAST .NET agent (1.13.1)
    • Performance improvements.
    • Reduced frequency of heartbeat communication to AppScan on Cloud when the agent is disabled.
    • Enhanced algorithm for merging similar issues.

New on March 3, 2025

  • Static analysis client updated to 8.0.1623.
  • Support for .NET 9.

New on February 28, 2025

New on February 02, 2025

  • Dynamic analysis (DAST):
    • API testing: AppScan on Cloud provides a native workflow for automatic scanning based on the OpenAPI specification file, with improved configuration capabilities and enhanced coverage.
    • Compliance Reports and Policies:
      • New compliance reports:
        • [EU] Digital Operational Resilience Act (DORA)
        • OWASP Application Security Verification Standard
      • Updated compliance reports:
        • [US] DISA's Application Security and Development STIG. V6R1
    • Support for EXD file: When you upload a traffic recording for "Explore with Guidance", you can now import the EXD file generated by AppScan Standard or AppScan Dynamic Analysis Client (ADAC).
    • Support to import scan files, including the results, without running the scan in AppScan on Cloud. This option is only available through the API.
  • Integrations updates
    • A new JetBrains Android Studio plugin lets you secure your Android apps early through seamless code analysis.

New on January 20, 2025

  • Static analysis client updated to 8.0.1616.
  • Client-only update.
  • Removed stage in the path for SCA Java archives.

New on January 10, 2025

  • Static analysis client updated to 8.0.1612.
  • Client-only update.
  • Java archives now properly extracted for Software Composition Analysis (SCA) in source code-only mode.

Previous updates 2023-2024

Previous updates 2021-2022

Previous updates 2019-2020

Previous updates 2016-2018