Every change to Security Tools, newest first. New features, bug fixes, and improvements to the security agent and web UI.
Three rounds of adversarial testing against the PhishGuard API and its clients, and the fixes for everything they turned up. Admin access is now per-organization with optional TOTP, the verdict cache can no longer be poisoned across readers, and every dependency with a published advisory has been patched.
PhishGuard now reasons about the thing invoice fraud actually depends on: a message that changes where money goes. Organizations can register the vendors they pay, and a request to change payment details from anywhere else is treated as a high signal on its own.
The same detection engine, applied to what an AI coding agent reads and writes. PhishGuard Gate installs into Claude Code as a plugin and scans the content arriving through the agent's delivery channels before it is acted on.
PhishGuard now ships as a native Outlook add-in alongside the Chrome extension, and the engine keeps a running account of its own accuracy rather than waiting for someone to notice it drifting.
Masking now happens before anything is sent, and it covers the fields that matter most in payment fraud. What reaches the server is a redacted shape of the email, not its contents.
The PhishGuard Chrome extension now auto-scans emails the moment they're opened — no manual click required. A new OAuth consent phishing detector identifies Microsoft OAuth URLs in email links and scores each requested permission scope. A silent background inbox scanner adds colored risk dots to inbox rows without opening any emails.
URL enrichment (following URL shortener redirects + fetching OneDrive/SharePoint/GDrive documents server-side) has been disabled after it caused Microsoft and Google sign-in pages to open in the user's browser. Government domains are now permanently whitelisted. The AI hallucination safety cap is now bypassed by concrete high/critical AI signals.
The Windows Python agent was silently crashing with a UnicodeEncodeError when writing box-drawing characters (─, —) to Windows CMD stdout. The scan appeared to start (browser opened, init event received) but logged nothing and stayed at '0/~40 checks'. Three layered fixes make the agent reliable.
New tool at /subdomain-takeover. Scan 60+ common subdomains for dangling CNAME records pointing to unclaimed cloud services — with HTTP body fingerprint confirmation.
New tool at /headers-check. Fetch any site's HTTP response headers and get an A–F grade covering 10 security policies — with copy-ready recommended values for missing headers.
New tool at /tls-check. Enter any domain for an instant A–F grade covering certificate expiry, TLS version, cipher suite strength, HSTS configuration, and CAA DNS records.
New tool at /bec-scanner for MSSP triage. Enter any domain and instantly see which typosquatting lookalikes attackers have registered, with real-time DNS probing for active email capability.
New tool at /email-security. Enter any domain and get an instant A–F grade across SPF, DKIM, DMARC, BIMI, MTA-STS, and TLS-RPT. Built for MSSP client onboarding and domain audits.
New tool at /phish-kit for detecting phishing infrastructure. Paste a suspicious URL and get a fingerprint verdict: Bluekit, Evilginx2/3, GoPhish, or Modlishka. Designed for MSSP triage workflows.
TapIn is now listed as a tool on the platform. The /tapin route is an App Store landing page for the iOS app — proximity-based ephemeral chat within 300m.
New tool at /worksecure. Assign every worker a unique alias email per SaaS app — containing blast radius if any vendor is breached. Instant offboarding revokes all access in one click.
New tool at /oauth-scanner for supply chain OAuth risk. Analyzes any authorized OAuth app using a three-layer engine: deterministic scope rules (primary, no AI), a Supabase RAG knowledge base of 18 known vendor breaches, and Claude as a fallback only when both layers return low confidence.
The security agent now runs 27 deterministic CIS checks on Linux machines — covering firewall, SSH, kernel parameters, auditd, mandatory access control (AppArmor/SELinux), file permissions, and more.
New tool at /ai-photo-detector. Upload any image to instantly detect whether it was generated by AI tools like Midjourney, DALL-E, Stable Diffusion, or Adobe Firefly — with detailed per-signal analysis.
New tool at /video-ai-detector. Upload any video to detect AI-generated content from Sora, Runway, Kling, or deepfake tools — with frame-level artifact analysis and temporal coherence checks.
Security findings are now grouped into 9 security domains (OS & System, Encryption, Network & Firewall, SSH, Logging, Auth, File System, Privacy) with one-click domain filter pills.
The SSH check now generates a complete, copy-pasteable sshd_config hardening block instead of a vague 'add hardening directives' message.
New tool at /audio-deepfake. Upload any audio file to detect AI-generated or cloned voices. Powered by Whisper transcription and GPT-4o acoustic analysis.
New tool at /live-call-detector. Put your phone on speaker and detect AI-generated voices mid-call in real time — using acoustic heuristics with no data stored or sent externally.
systemsetup -getusingnetworktime requires admin on macOS Ventura and later. The agent now falls back to pgrep -x timed, correctly detecting whether the system time daemon is running without requiring elevated privileges.
The Re-Analyze button now copies the curl command to clipboard instead of downloading a .command file that macOS Gatekeeper blocks. The command panel is always visible.
New tool at /apk-scanner. Deep static analysis for mobile and desktop binaries. Extracts metadata, maps permissions, detects CVEs, and generates an SBOM — all locally in the browser, no file upload to servers.
New tool at /graphql-pentest. Automated offensive security for GraphQL APIs — tests injection, auth bypass, IDOR, DoS, and business logic flaws with AI-powered attack generation.
New tool at /cyber-sense. Not sure if something is a scam? Find your situation and get a plain-English answer — designed for non-technical staff and SMBs.
The security agent runs 38 deterministic CIS Level 1 & 2 checks on macOS covering all major security domains. Each check has a stable canonical fingerprint to prevent duplicate findings across re-scans.
New checks, features, and improvements ship weekly. Join the Pro waitlist to get release notes in your inbox.
Open Security Monitor