Product Updates

Discover the latest feature releases, improvements and updates.
All updates
Asset Management
User Roles
Targets
October 19, 2025

Release Notes October 19th

Introducing: Asset Appendix

This release introduces the new Asset Appendix, a dedicated section in Asset Details that surfaces extra technical data collected by our scanners, including CORS configurations, input reflections, and JavaScript files. It provides security teams and researchers with deeper context for triage, investigation, and validation.We’ve also refined user roles, target cards, and the API to deliver smoother, more efficient workflows.

Asset Appendix

Our scanners collect valuable technical details beyond vulnerabilities. With this release, we’re giving you access to more of that data through the new Asset Appendix, a place where all those “extra but interesting” findings now live.


The Asset Appendix gives you visibility into three new types of asset data collected during scans:

Input Reflections

See where the platform detected reflected input that could indicate injection points like HTML Injection or XSS. These aren’t vulnerabilities by themselves, but they can help identify areas worth a closer look.

CORS Configurations

Review detected CORS settings and possible misconfigurations that might expose sensitive tokens or cookies.

JavaScript Analysis

View JavaScript files discovered during scans - including their URLs, filenames, and content types -to understand how scripts interact with your application.

You’ll find the new Appendix tab inside the Asset Details overlay. Like everything in ULTRA RED, this data is refreshed according to your scan schedule, and items not seen again within three days are automatically removed to keep things clean and relevant.

More Updates in This Release


User Roles

Operators and above can now adjust the scan Rate Limit (RPM), a small change that gives you finer control over scan behavior.

Target Prioritization

Each target card now highlights the highest Threat Score and EPSS Score across its assets, making it easy to spot which environments need your attention first.

Sidebar Reorder

The Targets sidebar has been reorganized to flow more naturally, putting the most-used sections right where you expect them.

API Enhancements

  • Added EPSS score to vector-related endpoints.
  • Added support for filtering vectors by status to streamline queries.

General Improvements

  • Added a new Asset Management filter for "Dead" Assets - assets with no active IPs, ports, technologies, or vectors.
    • Note: Assets not being actively scanned may lead to inaccurate results.
  • Added a new Timeline event when a scan is manually stopped, improving auditability and traceability.
  • Added a new Enrichment when a DNS service was identified on port 53 TCP or UDP