Every second, organizations face an evolving battlefield in cybersecurity. APIs and cloud environments—the backbone of modern businesses—are prime targets for attackers exploiting overlooked vulnerabilities. A single breach can now cost organizations an average of $4.88 million.
For businesses, this means heightened risks across critical systems, compounded by the struggle to identify vulnerabilities quickly enough. It’s not just about avoiding breaches; it’s about staying resilient in the face of them. Yet, while companies are adopting cloud-first strategies at unprecedented rates, 95% of them are underprepared to secure their digital assets, exposing themselves to costly incidents and reputational damage.
At Astra Security, we recognize the urgency of these challenges. However, we also see an opportunity to arm businesses with tools that turn this complexity into clarity. That’s why our focus remains on proactive, automated security solutions that allow organizations to discover and address risks at their core—before they escalate.
Our latest updates are more than features—from analyzing industry trends to understanding our customers’ pain points. This winter, we’re introducing solutions that tackle today’s most pressing problems in API and cloud security, empowering organizations to stay ahead. Here’s what we’ve built and why it matters:
1. API security platform (Beta launch)

The Problem: APIs are the backbone of modern applications, but they’re also becoming a favorite target for attackers.
- Last year, an exposed Trello API compromised data of over 15 million users by linking private email addresses to Trello accounts.
- Hackers used the Microsoft Graph API to establish covert malware communication channels, leveraging a trusted cloud service to evade detection.
What’s common in these attacks? Lack of visibility and security for APIs.
The Solution: Introducing the Astra API Security Platform, which is now live in beta! This tool is built to help you manage, scan, and secure your entire API inventory seamlessly.
Key Features:
- Automated Mapping: It automatically discovers and visualizes the connections between your APIs and their associated systems, ensuring you have a clear, up-to-date map of your entire API network. Without manual intervention, this feature helps you track all endpoints, including their dependencies, permissions, and potential attack vectors.
- API Inventory Visualization: View all your APIs in one centralized place, keeping track of endpoints effortlessly.
- Security Vulnerability Detection: Advanced risk-scoring algorithm to identify vulnerabilities, including common flaws and advanced risks like data leakage.
- OpenAPI Risk Classification: Classifies APIs into Shadow, Zombie, and Orphan categories, highlighting hidden or outdated APIs.
- PII Detection: Flags endpoints that handle Personally Identifiable Information (PII), ensuring sensitive data protection.
The Impact:
- Catch vulnerabilities early: Identify and address security issues before they escalate into bigger problems.
- Faster development: Shift your security testing earlier in the development lifecycle, making your development process more secure and efficient.
- Comprehensive API security: Stay on top of your entire API ecosystem with an easy-to-manage inventory and automated risk detection.
2. Pentester dashboard

The Problem:
Pentesters face a fragmented security landscape today, with disjointed tools, manual processes, and siloed data, making it difficult to deliver accurate, comprehensive results efficiently. The growing volume of vulnerabilities and the demand for faster turnarounds leave teams overwhelmed and prone to errors. A major challenge is the lack of a centralized system that fails to provide the insights, automation, and prioritization needed to address high-risk vulnerabilities quickly and effectively. This inefficiency disrupts workflows, hinders proactive security, and prevents real-time collaboration.
The Solution:
The Pentester Dashboard is a centralized hub to manage your entire pentesting workflow. It simplifies tasks like credential verification, vulnerability tracking, and team collaboration.
The Impact:
- Streamlined Workflow: A single dashboard consolidates your tasks and tools for greater efficiency.
- Enhanced Productivity: Save time and effort by having everything you need in one place.
- Improved Collaboration: Assign and easily manage tasks, ensuring better team alignment.
3. Sticky notes feature

The Problem:
Pentesting is fast-paced and detail-oriented, requiring constant note-taking for to-dos, observations, and key findings. Yet, capturing these insights is often chaotic. Many pentesters resort to scattered tools—spreadsheets, third-party apps, or even sticky notes on their desks—leading to disorganized workflows and missed details.
This fragmentation doesn’t just waste time; it risks critical observations slipping through the cracks, potentially impacting test quality. When working across multiple environments or collaborating with teammates, the lack of a centralized and searchable solution only compounds the challenge.
The Solution:
The Sticky Notes Feature provides a straightforward way to jot down and organize notes directly within your workspace, ensuring seamless access and synchronization across all platforms.
The Impact:
- Better Organization: Keep reminders and to-dos in one place, reducing clutter.
- Increased Efficiency: Quickly find and manage notes with built-in search and infinite scrolling.
- Cross-Platform Convenience: Access your notes anywhere, ensuring consistency across workspaces.
4. Dark theme for user interface

The Problem: Long hours in bright, white interfaces or working in dimly lit environments can lead to eye strain, fatigue, and reduced focus—hindering productivity. For cybersecurity professionals who spend hours combing through complex data, an uncomfortable interface isn’t just a nuisance; it’s a drain on physical well-being and efficiency.
The Solution: We’ve rolled out the Dark Theme for Astra Security, offering you a customizable and more comfortable experience.
Key Features:
- Reduced Eye Strain: Ideal for long hours or dimly lit environments.
- Customizable Experience: Easily switch between dark and light modes according to your preference.
- Improved Focus: A distraction-free interface to help you focus on what matters most.
The Impact:
- Better user experience: Customize your interface to suit your comfort.
- Enhanced productivity: A sleek, dark interface helps you focus better without the distractions of a bright screen.
- Less eye strain: Work longer without feeling fatigued.
What’s new in Astra’s OrbitX platform?
Improvements
- Optimized Scheduling & Compliance Workflow: We’ve enhanced the scheduling algorithm to improve resource allocation, ensuring timely and reliable scans. Plus, the compliance page loads faster, with added filters for a more efficient analysis of timeframes.
- Consistent User Experience Across Platforms: To streamline navigation, we’ve unified time formats across the dashboard for better consistency. Additionally, we’ve improved role flexibility in the Android apps, enabling user roles to support usernames, emails, or phone numbers.
Key bug fixes
- Enhanced Scan Accuracy & Efficiency: Fixed issues with API target configuration, ensuring comments and notes were saved correctly. We’ve also improved scan reliability, guaranteeing that scheduled scans run precisely on time.
- Simplified Setup & Access: IPA file uploads have been fixed for smoother iOS target setup, and we’ve resolved issues with programmatic access for targets that don’t have cloud providers. Additionally, errors related to renaming scans in the dashboard have been addressed, ensuring better consistency in your workflow.
- Improved Data Integrity: We’ve resolved issues related to risk score sorting and fixed duplicate headers during web target setup to ensure smoother, more accurate scanning results.
Summing up
As we continue our journey towards strengthening your cybersecurity defenses, the Winter updates mark just the beginning of a series of innovations to simplify and enhance your security workflows. We’re focused on delivering proactive, automated solutions that give you the power to stay one step ahead of evolving threats.
But this is just the start. As we look towards our Spring update, we’re excited to unveil features that will further elevate your security operations. Among these are advanced tools like a Trust Center for deeper visibility, automated rescanning of individual vulnerabilities to ensure nothing slips through the cracks, and enhanced API security capabilities with new integrations.
Stay tuned—the best is yet to come.
Lock down your security with our 10,000+ AI-powered test cases.
Discuss your security needs
& get started today!
