Back to Blog

What we've shipped lately: September 2026

Eamon Carroll
Eamon Carroll
Marketing Coordinator

Key Points

Another busy month for the engineering team. Here's what's new and live in Intruder.

TL;DR

  • AI pentest results in the portal: Manage pentest findings in the same place as everything else
  • Bitbucket and Azure repos for AI Pentesting: Connect Bitbucket or Azure repos and run AI pentests against your code
  • Retest pentest findings: Unlimited retests to check whether your fixes worked, without re-running the full pentest
  • Cross-domain scanning: One authenticated scan across your app, its APIs, and its auth provider
  • Improved Azure DevOps integration: Control which targets and tags create work items
  • Auto AI SQL injection validation: SQL injection findings are now automatically validated during the scan, so false positives are suppressed before they reach you
  • Monitor cyber hygiene: See how your score is trending over time

Your pentest findings have joined the rest of your workflows

Your AI pentest findings now live in the portal alongside your regular scan issues. Same layout, remediation guidance, and ability to comment. Managing pentest results becomes part of your normal security workflow, right alongside everything else.

Connect Bitbucket and Azure repos for AI pentesting

Bitbucket and Azure Repos now sit alongside GitHub and GitLab as supported code repositories for AI Pentesting. If your team hosts code in either, you can connect your repos and run AI-powered penetration tests directly against your codebase.

Spot-check your pentest fixes 

Found and fixed an AI pentest issue? Select the finding(s) in the portal, hit retest, and get a check on whether they've actually been resolved. Retests only check the findings you select, and results are captured in a dedicated retest report alongside the originals, giving you a clear record of what's been fixed. The best bit? Retests are unlimited and free.

Authenticated scanning that follows your app across domains

We’ve introduced the ability to scan across subdomains, so your frontend and its API backend could be covered in one authenticated scan. Cross-domain scanning takes that further. If your app relies on entirely separate domains for authentication, APIs, or external services, you can now add up to three cross-domains alongside your primary application target. The scanner follows the real application flows across domain boundaries, so a single scan covers more of how your app actually works.

Available on: Cloud, Pro, and Enterprise

Route Azure DevOps work items to the right teams

You can now scope which vulnerabilities auto-create Azure DevOps work items by target and tag, combining asset scope with existing severity rules. That way only the issues that matter reach each project, and the right teams get the right tickets.

Available on: Cloud, Pro, and Enterprise

Less noise from SQL injection checks

Intruder now deploys AI agents to validate SQL injection findings before they reach you. Confirmed false positives are automatically suppressed, while genuine and inconclusive results continue to surface as normal. Less time triaging noise, more time on the issues that actually matter.

Available on: Enterprise

Understand how your security posture is changing over time

You can now see how your Cyber Hygiene Score is trending over time, with a configurable range from four weeks up to a full year. That means you can answer "are we getting better or worse, and how quickly?" at a glance. Useful when you need to demonstrate progress to leadership or show an auditor that things are moving in the right direction.

Don't take our word for it, try it for yourself

All of it's live now. Log in to take a look, or if you're new here, start a free trial and see what's exposed across your attack surface. Interested in AI pentesting? Take a look at pricing, or book a call.

Got feedback or something you'd like to see next? Send it our way.

Get our free

Ultimate Guide to Vulnerability Scanning

Learn everything you need to get started with vulnerability scanning and how to get the most out of your chosen product with our free PDF guide.