{"id":39727,"date":"2025-07-11T14:11:16","date_gmt":"2025-07-11T08:41:16","guid":{"rendered":"https:\/\/www.getastra.com\/blog\/?p=39727"},"modified":"2026-01-12T23:59:28","modified_gmt":"2026-01-12T18:29:28","slug":"summer-2026-product-updates-whats-new-at-astra-security","status":"publish","type":"post","link":"https:\/\/www.getastra.com\/blog\/astra-product\/summer-2026-product-updates-whats-new-at-astra-security\/","title":{"rendered":"Summer 2025 Product Updates: What\u2019s New at Astra Security"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Security teams don\u2019t need another dashboard screaming about low-priority bugs. They need to know what\u2019s important, what\u2019s already fixed, and what\u2019s still a ticking time bomb.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s where we\u2019re headed at Astra.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This summer, we\u2019ve made several updates that do exactly that. Delta scans that stop pointing at the same issues. MFA protection where it actually matters. Cloud rescans that are faster and smarter. Reports that don\u2019t require a Sunday afternoon to clean up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everything is designed to save time, reduce noise, and help you move quickly without breaking things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re building security that works with your workflow, not against it. And this is just the start.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s walk you through what\u2019s new.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Incremental_Delta_Scanning_for_Web_Apps_and_API\"><\/span><strong>1. Incremental (Delta) Scanning for Web Apps and API<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcI6nlFIssVKbRAfpNKwmX3SEVWBJge7vJN2-XPqcEuxVhcF9ap8eJnRcMgM8hMXnBedVzGjzX6WmRbjJ3Z0KA-ejJzmvR9-9ZDbTBkgWtgRUcADGF_Bq8_2Bopn6MjLBbawzw6?key=bftTh7YkNXGaxK57TOTcFQ\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<br><\/strong>Full scans were too slow. Lightning scans were fast but lacked depth. There was no middle ground for teams that just wanted to test what changed<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<br><\/strong>We introduced Delta Scanning. Astra now detects new or modified endpoints and runs full test coverage only on those parts of your app or API.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Scan times are reduced up to 80%<\/li>\n\n\n\n<li>You still get the depth of a full scan where it matters<\/li>\n\n\n\n<li>Ideal for agile CI\/CD pipelines<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_JSON_Export_for_Vulnerability_Reports\"><\/span><strong>2. JSON Export for Vulnerability Reports<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdOhRTj4bwHNilLTQItpjQci_ubZAh-vFmAmXWx76YiGQkvBU_3Ms59ylQbVeNWnmaG0V4FyO25jfZMs5v3zTf0CUgB6bflQiBG3jLSWTQJdst4sAD5reh1xNYgtccVaTUwi6Hz?key=bftTh7YkNXGaxK57TOTcFQ\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>Teams wanted more than a PDF. They needed vulnerability data in a machine-readable format that could plug into their own systems, dashboards, or workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>You can now export vulnerability reports in JSON format directly from the Astra platform. It&#8217;s structured, clean, and ready to be used wherever you need it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You can integrate scan data into SIEM tools, ticketing systems, or internal dashboards.<br><\/li>\n\n\n\n<li>Enterprise workflows can automate triage and reporting more easily.<br><\/li>\n\n\n\n<li>Your team gets full flexibility in how vulnerability data is consumed and acted on.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Unique_Vulnerabilities_in_Pentest_Reports\"><\/span><strong>3. Unique Vulnerabilities in Pentest Reports<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>Reports were cluttered with duplicate vulnerabilities across scans. This made it harder to focus on what truly mattered and often led to wasted effort during triage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>You can now toggle \u201cShow only unique vulnerabilities\u201d when generating Full or Management reports. This filters out repetition and gives you a streamlined view of the real issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Reports are cleaner and easier to digest.<\/li>\n\n\n\n<li>You\u2019ll see around a 20 percent reduction in report size.<\/li>\n\n\n\n<li>It becomes simpler to focus on root causes rather than repeated symptoms.<br><\/li>\n\n\n\n<li>20% reduction in report size<br><\/li>\n\n\n\n<li>Better visibility into root issues<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"4_MFA_Support_for_Web_App_Scanning\"><\/span><strong>4. MFA Support for Web App Scanning<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>Apps with mandatory two-factor authentication (like TOTP-based 2FA) couldn\u2019t be scanned end-to-end without manual workarounds. That meant important sections were left untested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>Astra now supports scanning of TOTP-protected web apps. You can provide MFA secrets and login recordings during setup, allowing secure and automated access throughout the scan.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You get full scanning coverage for 2FA-enabled targets.<br><\/li>\n\n\n\n<li>Access is handled securely and stays under your control.<br><\/li>\n\n\n\n<li>Your team is better prepared for compliance checks and audit requirements.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"5_Findings_Response_Body_in_UI\"><\/span><strong>5. Findings Response Body in UI<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>ome vulnerabilities were hard to interpret without seeing the full picture. Without the actual HTTP response that triggered the issue, teams had to guess what went wrong or replicate it manually.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>Each vulnerability now includes a \u201cResponse\u201d section in the UI. It shows the full response headers and body from the triggering HTTP request, giving you complete visibility right where you need it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Easier root cause analysis<\/li>\n\n\n\n<li>More transparent and informative findings<\/li>\n\n\n\n<li>Findings are clearer and more actionable.<\/li>\n\n\n\n<li>Your team can make faster decisions during triage and remediation.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"6_Support_for_Larger_Mobile_Uploads_APKIPA\"><\/span><strong>6. Support for Larger Mobile Uploads (APK\/IPA)<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXccfFOhAQYXi8hnWEt28uzbreqgU9E77TXnAJBk2Ym-x0tWfrLR3Zzc6YcW8e63SjXy4_4iZxyeNItxqm82utZ09nOLZwhV80wD3tB3aaEJfJDgd__cibnySUzqOorPF7kn4EAeCQ?key=bftTh7YkNXGaxK57TOTcFQ\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>Uploads for mobile app files were capped at 100MB. That limit, set by a third-party tool, forced users to rely on workarounds or share files externally, not ideal for security or speed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>Users can now upload files up to 300MB directly within the platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Seamless onboarding for mobile assets<br><\/li>\n\n\n\n<li>Elimination of upload-related friction<br><\/li>\n\n\n\n<li>Faster test setup for mobile app pentests<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"7_Scanner_Agency_Plan_for_MSSPs\"><\/span><strong>7. Scanner Agency Plan for MSSPs<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeqcvqMvspITQrwMQ87Ryio28lAJ3PSANJDPZUfujTzFMMSbA3bl65Uw6y7w7ztXdCPHzrjnAbVUXnKHi3-kLDgNd-06Cy3yzem9xoqiryLHSIo7XDPqaDpdZTP88f16d1veikE?key=bftTh7YkNXGaxK57TOTcFQ\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>Agencies and MSSPs often struggled with rigid licensing. Managing scans across multiple clients meant buying a separate license for each one, even when only a few were active at a time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>The new Scanner Agency Plan solves that. You get a flexible pool of targets, for example, 5 at a time, and can rotate them across clients after a 30-day cooldown. It\u2019s built for how agencies actually work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You get cost-effective coverage across multiple clients.<\/li>\n\n\n\n<li>Target rotation gives you flexibility without extra licenses.<\/li>\n\n\n\n<li>License management becomes simpler and more predictable.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"8_Trust_Center_Redesign\"><\/span><strong>8. Trust Center Redesign<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Problem<\/strong><strong><br><\/strong>The earlier Trust Center took too much manual effort to set up. Customizing it for different stakeholders was clunky, and publishing updates felt more like a chore than a win.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Solution<\/strong><strong><br><\/strong>The new Trust Center is faster, smarter, and built for scale. You get AI-powered content suggestions, a drag-and-drop editor, and a clean layout that\u2019s ready for customers out of the box.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Impact<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You can launch a trust portal in just a few minutes.<\/li>\n\n\n\n<li>Sharing your security posture with customers is now effortless.<\/li>\n\n\n\n<li>You build credibility without getting stuck in the weeds.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"9_Platform-Wide_Improvements\"><\/span><strong>9. Platform-Wide Improvements<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the major features, we\u2019ve implemented several quality-of-life enhancements across the platform. These are the small but mighty changes that make security work feel less like work.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Test Connectivity Before Scan Launch<\/strong><strong><br><\/strong>Now you can check if a target is reachable before starting a scan. No more surprises from misconfigured endpoints.<br><\/li>\n\n\n\n<li><strong>Delta Scan Toggle for All Users<\/strong><strong><br><\/strong>You can now choose between Full or Incremental scans depending on your scope and urgency. More control, less waiting.<br><\/li>\n\n\n\n<li><strong>Revamped Tables<\/strong><strong><br><\/strong>API, Subscription, Target, and Compliance tables have been redesigned for faster load times and better visibility.<br><\/li>\n\n\n\n<li><strong>Session Duration Control<\/strong><strong><br><\/strong>Authenticated session durations can now be extended up to 48 hours. Perfect for scanning apps with complex login flows.<br><\/li>\n\n\n\n<li><strong>Improved Vulnerability Navigation<\/strong><strong><br><\/strong>Keyboard shortcuts, bulk actions, and advanced filters make triage faster and smoother.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>More Accurate Reporting<\/strong><strong><br><\/strong>Scan states, risk scores, and vulnerability data are now more consistent across the platform and in downloaded reports.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Whats_Next_at_Astra_The_Future_Is_Closer_Than_You_Think\"><\/span><strong>What\u2019s Next at Astra: The Future Is Closer Than You Think<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What\u2019s Coming Next: The Future of AppSec at Astra<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This summer, we focused on making security faster, smarter, and easier to work with. But we\u2019re just getting started.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In <strong>DAST<\/strong>, we\u2019re pushing for deeper API coverage and smarter scans that adapt to your app\u2019s architecture. Threat model testing is becoming more precise with test cases tailored to the specific structure of your application. A redesigned dashboard is also on the way, built to quickly surface the right insights, allowing your team to take action faster.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In <strong>API Security<\/strong>, self-serve onboarding is coming soon, so you can activate protection in minutes without waiting for manual setup. Detection for critical risks, such as broken access control, is being upgraded, and new compliance mappings are on the way, including PCI, DORA, and NIST 2. These will help you align your APIs with evolving regulations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For <strong>Pentesting and Compliance<\/strong>, we\u2019re streamlining everything from planning to reporting. Expect compliance-ready reports for SOC 2, HIPAA, and ISO 27001, along with broader vulnerability mappings, to help you close audits faster and with less friction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And then there\u2019s our <strong>AI roadmap<\/strong>. Soon, AI-powered suggestions will help developers fix issues directly inside their IDEs. AI agents will simulate complex attack paths to uncover deeper flaws. You\u2019ll also see smarter crawling, issue enrichment, and logic-aware detection to catch vulnerabilities that used to fly under the radar.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At every step, the goal remains the same: to build security that fits your stack, integrates seamlessly into your workflow, and grows with you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The next version of Astra is already in motion. You\u2019ll be seeing it soon.<\/p>\n\n\n<style>\n\n.testCaseWrap{\n  padding:35px;\n  border: 6px;\n  background-image: url('https:\/\/cdn-blog.getastra.com\/2024\/08\/838dc804-smallimgicbg.png');\n  background-size: cover;\n  background-repeat: no-repeat;\n  position: relative;\n  background-position: right;\n  height: 100%;\n  border-radius: 10px;\n  margin: 20px 0px; \n}\n\n.pentestHeading{\n  color: #575757;\n  font-size: 24px;\n  font-weight: 600;\n  color: #575757;\n  max-width: 450px;\n}\n\n.testCaseHead {\n    display: flex;\n    align-items: center;\n    grid-gap: 1rem;\n}\n\n.ctaOne {\n    text-decoration: none;\n    background-color: #2F76F8;\n    color: #ffffff !important;\n    padding: 10px 25px;\n    border-radius: 6px;\n    font-weight: 600;\n}\n\n.ctaTwo {\n    text-decoration: none;\n    background-color: #24BC94;\n    color: #ffffff !important;\n    padding: 10px 25px;\n    border-radius: 6px;\n    font-weight: 600;\n}\n\n.spanBoldBlue {\n    color: #3078FE;\n    font-weight: 700;\n}\n\n.testCaseImg{\n  position: absolute;\n  bottom: 0px;\n  right: -20px;\n  height: 250px;\n  width: 240px;\n}\n\n@media(max-width: 768px){\n\n}\n\n@media(max-width: 576px){\n    .testCaseHead {\n      flex-direction: column;\n      align-items: start;\n    }\n\n   .pentestHeading{\n      font-size: 28px;\n    }\n\n   .testCaseImg{\n    display: none;\n  }\n}\n\n<\/style>\n\n<div class=\"testCaseWrap\">\n  <p class=\"pentestHeading\">Lock down your security with our <span class=\"spanBoldBlue\">10,000+ AI-powered test cases.<\/span><\/p>\n  <p >Discuss your security needs <br \/> &#038; get started today!<\/p>\n<br \/>\n  <div class=\"testCaseHead \">\n    <a href=\"https:\/\/www.getastra.com\/pentest\/pricing\" class=\"ctaOne\" target=\"_blank\" rel=\"noopener\">View Pricing<\/a>\n    <a href=\"https:\/\/www.getastra.com\/contact-us\" class=\"ctaTwo\" target=\"_blank\" rel=\"noopener\">Schedule a call<\/a>\n  <\/div>\n\n  <img decoding=\"async\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/09\/34b4861d-boy1.png\" alt=\"character\" class=\"testCaseImg\" \/>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Security teams don\u2019t need another dashboard screaming about low-priority bugs. They need to know what\u2019s important, what\u2019s already fixed, and what\u2019s still a ticking time bomb. That\u2019s where we\u2019re headed at Astra. This summer, we\u2019ve made several updates that do exactly that. Delta scans that stop pointing at the same issues. MFA protection where it &#8230; <a title=\"Summer 2025 Product Updates: What\u2019s New at Astra Security\" class=\"read-more\" href=\"https:\/\/www.getastra.com\/blog\/astra-product\/summer-2026-product-updates-whats-new-at-astra-security\/\" aria-label=\"Read more about Summer 2025 Product Updates: What\u2019s New at Astra Security\">Read more<\/a><\/p>\n","protected":false},"author":124,"featured_media":39728,"comment_status":"open","ping_status":"0","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[],"class_list":["post-39727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-astra-product"],"_links":{"self":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/39727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/users\/124"}],"replies":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/comments?post=39727"}],"version-history":[{"count":7,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/39727\/revisions"}],"predecessor-version":[{"id":44783,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/39727\/revisions\/44783"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media\/39728"}],"wp:attachment":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media?parent=39727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/categories?post=39727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/tags?post=39727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}