2026

June 1, 2026

Syhunt Hybrid 7.2 introduces Authenticator 2.0 and major platform enhancements - Syhunt Hybrid 7.2 is a major platform update that introduces Authenticator 2.0, a complete redesign of the authentication framework that unifies authentication management and simplifies authenticated security testing. The release delivers significant improvements across the web interface, scan management, authenticated scanning, AJAX crawling, API and code scanning workflows, and cross-platform support for Windows, Linux, and macOS. New capabilities include login sequence recorder, browser-assisted authentication through the Sandcat extension, real-time scan monitoring via web UI, scan comparison, expanded archive scanning support, simplified HTTPS deployment, and enhanced integration with issue trackers and private repositories. The release also updates security coverage to align with OWASP Top 10 2025 and CWE Top 25 2025, migrates all CLI applications to Rust, removes legacy dependencies, and completes the transition toward a modern web-based platform, making it one of the most significant Syhunt releases in the last decade. Read more

May 15, 2026

Syhunt Hybrid is NOT affected by CVE-2026-42945 - Yesterday, Syhunt completed an internal security analysis of CVE-2026-42945, a vulnerability affecting NGINX’s ngx_http_rewrite_module under highly specific configuration conditions involving vulnerable rewrite rule patterns. Successful exploitation may trigger a heap buffer overflow in the NGINX worker process, potentially causing denial of service through worker crashes or restarts. Under standard modern operating system security protections, this would generally be limited to service disruption. Remote code execution (RCE) is considered significantly more difficult and would typically require Address Space Layout Randomization (ASLR) to be disabled or otherwise bypassed, which is uncommon in properly secured modern Linux and Windows deployments.

While NGINX is included with Syhunt, it is not enabled by default, and Syhunt’s official reverse proxy deployment documentation does not use rewrite rules matching the vulnerable pattern. Internal review of Syhunt’s back-end NGINX/OpenResty configurations also confirmed that existing rewrite rules do not satisfy the exploitation requirements described in public advisories. To further validate this, Syhunt tested the public proof-of-concept (PoC) exploit, along with customized variants, against its own environment. In all cases, exploitation was unsuccessful. Based on this analysis, Syhunt environments are not vulnerable to CVE-2026-42945 under supported configurations. As a precautionary best practice, customers are still encouraged to upgrade externally deployed NGINX reverse proxies to the latest patched release (NGINX 1.31.0 or later), particularly in custom deployments. Customers can verify their installed version by running the command: nginx -version.

Syhunt’s bundled pre-configured back-end NGINX/OpenResty will also be proactively updated in the upcoming major release scheduled for next week. Additionally, as an application security platform, Syhunt will include dedicated detection rules for CVE-2026-42945 in its vulnerability scanning engine, enabling customers to proactively identify potentially vulnerable NGINX configurations across their own environments.

February 16, 2026

Strategic Distribution Opportunity in Australia with Syhunt - As part of its continued global growth strategy, Syhunt is looking to appoint a dedicated distribution partner in Australia to strengthen its footprint in the region. Recognized for its proprietary, in-house developed assessment technology, Syhunt has built a strong reputation in application security, supporting organizations of all sizes - from emerging businesses to large enterprises - in protecting their web and mobile applications against increasingly complex threats.

With cyber risks evolving rapidly, Syhunt’s solutions are engineered to identify and mitigate vulnerabilities across the full application layer spectrum. The company’s approach combines depth, precision, and innovation, enabling security teams to stay ahead of modern attack vectors. This initiative presents a strategic opportunity for an Australian distributor to represent a mature, globally trusted security brand while helping local organizations enhance their resilience against web and mobile application attacks. Organizations interested in becoming part of Syhunt’s expanding international partner network are encouraged to get in touch to discuss this opportunity further.

February 2, 2026

Introducing Cross-Model Scripting (XMS) vulnerabilities - Syhunt published today a new cybersecurity paper that introduces the term Cross-Model Scripting (XMS) to describe AI-mediated injection scenarios and explores the cross-site scripting (XSS) risks arising from unsanitized LLM-generated output. It also examines how Unicode-based transformations implemented in CrossSpeak - a tool released alongside this paper - can challenge ASCII-bound defenses when model output is not properly revalidated and contextually encoded. Read the paper

Contact