Loading...
New detection for adversary-in-the-middle (AiTM) phishing — "Evilginx"-style attacks that present Microsoft's real sign-in page from a look-alike, non-Microsoft web address to steal both your password and your multi-factor (MFA) session, even when the page looks and behaves exactly like the genuine one. Scanned pages that serve the Microsoft sign-in flow from a non-Microsoft address are now flagged as dangerous. Genuine Microsoft sign-in — including government (sovereign cloud) and Azure AD B2C / Entra business sign-in — is unaffected.
Loading...
Improved detection of cryptocurrency scam apps that appear blank to automated scanners but load a fake investment or "earn money" app in a real browser. These are now flagged as dangerous and tracked as they reappear on new web addresses. Reputable services are unaffected.
Loading...
Improved the JavaScript analysis pages — the Security tab now reliably lists the malware and obfuscation patterns detected in each script, and the Similar Scripts tab shows full details and working links. Previously this information could load slowly or be missing.
Loading...
Further reduced Security Verdict false positives on legitimate sites — content-delivery and shared-hosting infrastructure addresses that merely contain a well-known brand name, and sign-in pages on new or lesser-known domains, are no longer flagged as brand impersonation without concrete evidence of credential theft. Genuine phishing and brand-impersonation pages continue to be flagged.
Loading...
Improved detection of a stealthy phishing technique that shows security scanners a blank page and only assembles its fake Microsoft sign-in and "device code" authorisation prompt inside the visitor's browser from encrypted content. These pages are now recognised by their structure and flagged as a known malicious kit on the scan result.
Loading...
New detection for "ClickFix" scams — fake CAPTCHA or error pages that try to trick you into copying and pasting a command into your computer to run malware. When a scanned page attempts this clipboard trick, it is now captured and flagged as dangerous.
Loading...
Improved detection of cryptocurrency scams — pages that try to steal wallet recovery ("seed") phrases or trick you into connecting a wallet so it can be drained are now more reliably flagged, and scans are checked against an additional continuously-updated list of known crypto-phishing and wallet-drainer sites.
Loading...
Community reports now help flag threats — when visitors mark a scanned page as malicious, those reports contribute to the Security Verdict and trigger a fresh analysis, so threats reported by the community surface faster. A flood of false reports will not flag a page on its own.
Loading...
Improved detection of phishing pages that hide their trap — including multi-step "sign in with [brand]" lures that only reveal the credential form after a fake verification or CAPTCHA step, and pages that serve scanners a harmless decoy while showing their real content to ordinary visitors.
Loading...
Reduced Security Verdict false positives on many kinds of legitimate sites — self-hosted software dashboards and their sign-in pages on your own domain, corporate single sign-on and identity providers, cloud-platform default and error pages, official sites that simply link to a well-known brand, and country-specific domains are no longer flagged as phishing without concrete evidence of credential theft. Genuine phishing and brand impersonation continue to be flagged.
Loading...
Faster "Known malicious kit" warnings on scan results — when a scanned site matches one of the phishing or malware kits tracked in our hunt catalog, the warning banner now appears on the result page automatically within moments of the analysis finishing. Previously it could take up to 15 minutes to be detected and only showed after reloading the page. Hunt pages pick up newly matching scans just as quickly - Visit /hunts
Loading...
New Page Load Speed rating on scan results — the HTTP tab now shows how a site's page-load time compares with every other site we've scanned, as a simple Very Fast / Fast / Medium / Slow rating along with the percentage of scanned sites it loaded faster than.
Loading...
Improved Security Verdict accuracy on Microsoft phishing-simulation test pages — links from Microsoft's Attack Simulation Training (the harmless phishing-awareness tests organisations send their own staff) are no longer flagged as Microsoft brand-impersonation. These Microsoft-operated test domains are now identified and treated as benign, while genuine Microsoft-impersonation phishing continues to be flagged.
Loading...
Security Verdict reliability — the brand-impersonation and network-level threat checks are now applied consistently on every scan, so a dangerous page is flagged the first time it is scanned rather than only on a later re-analysis.
Loading...
Improved detection of brand-impersonation phishing — the Security Verdict now more reliably flags pages that impersonate a well-known brand's sign-in flow (including "device code" login scams that try to trick you into authorising an attacker's access) and pages that display a trusted brand's logo on a look-alike domain. Threat alerts raised at the network level during a scan are now reflected in the Security Verdict as well.
Loading...
Improved AI Security Verdict accuracy on legitimate sign-in pages — government, municipal, university and other official login portals are no longer flagged as phishing merely for showing a login form on a low-traffic or unfamiliar domain. A high-risk verdict for these now requires concrete evidence of credential theft, while genuine phishing and brand-impersonation pages continue to be flagged.
Loading...
Improved detection of fake login pages hosted on cloud storage and app-hosting platforms — credential-harvesting pages placed on free file-storage and hosting services are now more reliably flagged as dangerous in the Security Verdict, including ones that don't impersonate a well-known brand.
Loading...
Reduced Security Verdict false positives from overly-broad threat data — a website is no longer flagged as dangerous just because it shares a server address with many unrelated sites, or because of an outdated entry in a discontinued threat list. Genuine, corroborated threats are unaffected.
Loading...
Improved AI Security Verdict accuracy on new and lesser-known websites — a site is no longer rated a likely scam based only on a recently-registered domain or a lack of established reputation. An elevated verdict now requires concrete evidence of malicious behaviour, reducing false positives on legitimate new sites.
Loading...
New account dashboard — logged-in users now have an account page showing their submitted scans, recent logins, and API keys. API keys can be created with scopes and expiration dates, revoked at any time (individually or all at once), and used to submit scans and read results programmatically via the X-API-Key header — see the API documentation. Private scans are now available: results are visible only to you when logged in or using your API key.
Loading...
Fixed the image hashes shown on scan results — in some cases they were stored as blank values that no longer matched the screenshot on the page. The perceptual image hashes now correctly reflect the captured screenshot, so visual similarity searches between scans work as expected.
Loading...
Improved phishing detection for sites that hide from automated scanners — pages that show security tools a harmless decoy while serving their real content to ordinary visitors are now more reliably flagged as dangerous.
Loading...
Improved scan submission reliability — resolved an intermittent issue that caused some recent scans to time out without producing a result. Affected scans can be re-submitted.
Loading...
Newly-reported threats now appear in scan results faster.
Loading...
Improved AI Security Verdict accuracy on niche and regional sites — fewer false positives where a login form alone was triggering a high-risk verdict.
Loading...
Improved AI Security Verdict accuracy on sites hosted on common developer platforms and on sites that use in-browser file handling — these are no longer treated as inherently suspicious.
Loading...
Improved AI Security Verdict accuracy — better-corroborated threat reports are weighted more heavily, reducing false positives on widely-used third-party services.
Loading...
Made the search loading indicator more noticeable — the progress bar shown while results load is now more prominent and stays on screen long enough to see, even on fast searches.
Loading...
Search results now show a clear loading state when you change the search type — a progress bar at the top of the page and a placeholder table appear while the new results load, instead of the page appearing to pause with no feedback.
Loading...
Expanded threat-intelligence coverage — scanned URLs are now matched against an additional continuously-updated database of known malware-hosting and phishing URLs, refreshed throughout the day so newly reported threats are caught quickly.
Loading...
Improved the accuracy of network threat alerts on scan results — a class of technical false positives produced by the way encrypted traffic is captured no longer appears, so the alerts shown now reflect genuine findings.
Loading...
Corrected the JavaScript analysis statistics on scan results — the script count, number of static analyses and code-entropy figures were overstated on some scans and now report accurately.
Loading...
Improved malware-pattern coverage on JavaScript code-analysis pages — script-detail pages now show their full set of pattern matches.
Loading...
Improved JavaScript fingerprinting — per-function code segments that drive cross-scan code-similarity, library detection, and pattern matching are now recorded for every new scan.
Loading...
Improved Certificate Transparency and reverse DNS lookup reliability — the certificate history, similar-domain, and rDNS endpoints under /api/v1/ct/ are serving normally.
Loading...
Search and scan-result pages are now noticeably faster after migrating the search backend onto faster storage — full-cluster searches drop from seconds to under 100 ms, scan-result page loads feel snappier on cold-cache requests
Loading...
Fixed multi-segment crop-resistant screenshot hash search — the endpoint was rejecting legitimate hash values produced by the imagehash library and now accepts the comma-joined format correctly
Loading...
Reduced false-positive "Compromised WordPress" flags on legitimate WordPress sites — the detector is more selective about what counts as a compromise indicator.
Loading...
Improved AI Security Verdict coverage on JavaScript-driven pages — pages whose content is rendered by scripts now reliably receive a full verdict.
Loading...
Fixed IP geolocation (ASN, country, city) showing "Unknown" for some bot-protected scans — when the fallback browser refreshed the IP list, geolocation data now stays in sync with the captured IPs
Loading...
Long redirect URLs in scan result headers no longer wrap across multiple lines — collapsed to a single line with a click-to-expand button
Loading...
Improved JavaScript library detection accuracy — bundler chunk filenames are no longer mistaken for libraries with spurious version numbers
Loading...
Fixed intermittent 500 errors on several API endpoints (OCR, favicon search, scan summary, high-risk search, analyzer stats) that occurred after the first cached request
Loading...
Improved AI Security Verdict accuracy — reduced false positives on corporate sites, news/media, and small business websites.
Loading...
API: Renamed several response fields for consistency across scan results, nameserver lookups, and PCAP endpoints
Loading...
Further improved AI brand impersonation detection with contextual awareness for venue names, geographic locations, and corroborating signal requirements
Loading...
Improved AI security verdict accuracy for brand impersonation detection, reducing false positives on sites that use third-party services
Loading...
Fixed missing ASN organization names for some IPs in the Domain & IP Information table
Loading...
New Advanced Search (SMQL) with 120+ filters, boolean logic, and sorting - Browse /search-advanced
Loading...
Added multi-signal phishing detection for Microsoft 365 credential phishing (AiTM proxies, static clones, obfuscated kits)
Loading...
Added stable behavioral signatures and behavior vectors for JavaScript similarity clustering - Browse /blog/stable-behavioral-signatures
Loading...
Improved database query performance and search responsiveness
Loading...
Fixed "Find Similar" links for behavioral code fingerprints on scan results
Loading...
Improved scan submission responsiveness and URL validation performance
Loading...
Improved threat intelligence coverage with additional feed sources and freshness monitoring
Loading...
Improved YARA malware detection accuracy and updated threat intelligence feeds
Loading...
Improved JavaScript analysis for external scripts with enhanced hybrid analysis pipeline
Loading...
Added crypto wallet drainer detection with blockchain RPC monitoring and brand impersonation checks
Loading...
Improved AI security analysis accuracy and network traffic analysis coverage
Loading...
Show full certificate hashes in Certificate Transparency Intelligence section
Loading...
Fixed Certificate Transparency API endpoints to correctly return DNS records and IP addresses for domains
Loading...
Infrastructure: Resolved search cluster issue and performed disk space optimization
Loading...
Published blog post: Detecting Coruna, the nation-state iOS exploit kit targeting Safari, with 16 new YARA detection rules - Visit /blog/coruna-ios-exploit-kit-detection
Loading...
Cleaner RDAP display — IP descriptions no longer include cloud-provider internal metadata.
Loading...
Improved how domain registration age is interpreted across cross-domain redirects.
Loading...
Security hardening across scan result rendering.
Loading...
Skip AI analysis for error pages to reduce false alerts
Loading...
Reduced AI verdict false positives for news and article sites writing about brands
Loading...
Added title-domain mismatch detection to AI security analysis
Loading...
Fixed AI verdict false positive for gambling sites misclassified as phishing
Loading...
Added Content Security Policy header to frontend pages
Loading...
Fixed search query timeouts for faster hash and fingerprint lookups
Loading...
Improved accuracy: hosting platform false positive prevention, domain age scoring, and scam taxonomy
Loading...
Integrated network intrusion-detection alerts into AI Security Verdict for deeper threat detection.
Loading...
Improved AI security analysis with enhanced phishing detection and reduced false positives for legitimate websites
Loading...
Scanning performance improved 34x with optimized parallelization
Loading...
Improved credential exfiltration detection accuracy with reduced false positives
Loading...
Published blog post analyzing ShinyHunters phishing kit campaign with 21,090 domains scanned - Visit /blog/shinyhunters-phishing-kit-analysis
Loading...
Added malware warning indicators to script analysis pages
Loading...
Refined malware detection patterns achieving under 5% false positive rate
Loading...
Fixed AI analyzer to correctly identify critical malware patterns
Loading...
Added Meta/Facebook brand detection to security analysis
Loading...
Fixed AI classification thresholds for more accurate risk scoring
Loading...
Added trusted domain badge to individual script analysis pages
Loading...
Improved scan processing reliability with optimized timeout settings for better resource management
Loading...
Enhanced logging infrastructure for improved performance monitoring across distributed systems
Loading...
Improved network traffic capture quality by preventing empty packet captures from being stored
Loading...
Infrastructure: Optimized internal data management for better system performance
Loading...
Enhanced system health monitoring with TLS certificate analysis status tracking
Loading...
Enhanced scan pipeline reliability analysis for better error detection and automatic recovery
Loading...
Improved code analysis accuracy by reducing false positive detections in fingerprint matching
Loading...
Expand API documentation with 10 new endpoints: YARA malware detection (4 endpoints), registrar search, tracking keys analysis (3 endpoints), Chrome network debug logs, and nameserver domain lookups - Visit /api-docs
Loading...
Add confidence level indicators when identifying code libraries in scan results
Loading...
Improved accuracy in library identification by reducing false matches for generic filenames
Loading...
Launch Model Context Protocol (MCP) server for AI integration - enables Claude Desktop and other AI tools to directly access ScanMalware security scanning capabilities - Visit https://mcp.scanmalware.com
Loading...
Enhanced library detection accuracy for inline and embedded code blocks
Loading...
Substantially reduced threat-intelligence false positives on widely-used third-party content delivery services.
Loading...
Improved library version detection accuracy with better validation logic
Loading...
Add detection for programming interfaces and system calls used in JavaScript code
Loading...
Improved reliability of network traffic capture and analysis during scans
Loading...
Expand library detection capabilities by 355% with 47 new identification signatures
Loading...
Expanded threat-intelligence coverage to millions of indicators across network, file-hash, and structured-threat data.
Loading...
Fix scan result page error when analyzing forms with unusual field configurations
Loading...
Improved tracking of URL redirects to preserve fragment identifiers in destination URLs
Loading...
Improve code analysis reliability to 100% success rate, eliminating processing errors
Loading...
Launch automated copyright and licensing detection with 119% improvement in accuracy
Loading...
Add detection for JavaScript-based navigation and blob URLs for better tracking of client-side URL changes
Loading...
Add automatic URL preprocessing to unwrap redirect links from social media platforms and URL shorteners
Loading...
Enhanced IP geolocation display with full country names in Network tab
Loading...
Performance: Database query optimizations for faster domain search and tracking key lookups
Loading...
Add WAF and CDN identification to TLS fingerprint analysis across major providers.
Loading...
Add page-level JavaScript behavioral risk analysis on Scripts tab
Loading...
Add MD5 and SHA-1 hash search support to JavaScript search with direct links to script detail pages
Loading...
Improved domain registration (RDAP/WHOIS) caching with smart expiration-based refresh
Loading...
Improved JavaScript malware analysis with better code segment extraction and pattern matching
Loading...
Fix technology detection service - improved reliability for website fingerprinting
Loading...
Infrastructure: Improved network reliability for DNS lookups and domain intelligence
Loading...
Reduced false positives for legitimate country-specific variants of major brand websites.
Loading...
Improved form analysis to reduce false positive password field detections
Loading...
Add business legitimacy assessment for positive trust signals in security analysis
Loading...
Enhanced form classification to recognize legitimate booking forms and third-party services
Loading...
Add industry-aware brand detection to reduce false positives for legitimate businesses
Loading...
Improved scan reliability for sites protected by bot-detection systems.
Loading...
Add scan visibility selector UI with public, unlisted, and private options (coming soon)
Loading...
Fix malware scanning service and improve intrusion detection reliability
Loading...
Performance: Increased search database memory and extended Certificate Transparency query timeout for large searches
Loading...
Add dual search cluster monitoring to health checks for improved reliability
Loading...
Enhanced Certificate Transparency search performance and reliability
Loading...
Improved infrastructure monitoring with enhanced health checks for all services
Loading...
Refactored internal architecture for better scalability and maintainability
Loading...
Add dark mode support for YARA malware pattern detection results
Loading...
Launch YARA malware pattern detection with visual indicators on scan results
Loading...
Expand YARA malware detection capabilities by 23% (1,250 → 1,540 detection patterns)
Loading...
Add YARA malware pattern matching to JavaScript analysis for enhanced threat detection
Loading...
Add automated daily updates for YARA malware detection rules
Loading...
Launch unified search page with tabs for text, visual, and JavaScript code search
Loading...
Launch JavaScript Malware Analysis v2.0 with YARA patterns, fuzzy hashing (TLSH), webpack de-bundling, and ML-based code similarity detection
Loading...
Add library fingerprinting system to identify known JavaScript libraries and isolate suspicious code
Loading...
Infrastructure improvements: Updated to latest platform versions for better performance and security
Loading...
Add domain registration and nameserver information to scan results with DNS fallback support
Loading...
Launch JavaScript obfuscation detection to identify malicious code hiding techniques
Loading...
Improve scan reliability with automated retry logic, reducing error rate to under 6%
Loading...
Fix critical scanning issues and enhance error handling for improved stability
Loading...
Launch hybrid JavaScript fingerprinting with 19x coverage increase for better malware detection
Loading...
Fix GeoIP data enrichment for network analysis and IP geolocation
Loading...
Add trusted CDN whitelist badges to Scripts tab for better security transparency
Loading...
Fix screenshot loading issue on Visual Search page
Loading...
Add TLS Certificate Analysis API endpoint with CAA validation and Certificate Transparency data - Visit https://scanmalware.com/api-docs#tls
Loading...
Launch public changelog page with timezone-aware timestamps and clickable links - Visit /changelog
Loading...
Add RSS feed for changelog updates - Subscribe at /changelog.xml
Loading...
Launch security blog with articles on TLS certificates, CAA validation, and Certificate Transparency - Visit /blog
Loading...
Add RSS feed for blog posts - Subscribe at /rss.xml
Loading...
Add tag filtering for blog posts - Browse posts by topic
Loading...
Performance improvement: Database optimizations
Loading...
Add daily automated browser profile warmup for better bot detection evasion
Loading...
Expand browser profile warmup from 5 to 10 popular websites
Loading...
Security: Browser workers now run as non-root user for improved security
Loading...
Add CAA validation and certificate validity period checks to TLS analyzer
Loading...
Add hostname validation and certificate chain validation to TLS analyzer
Loading...
Add comprehensive security certificate test validation
Loading...
Fix TLS analyzer ECDSA key size false positive
Loading...
Implement TLS Certificate Analyzer with Certificate Transparency enrichment
Loading...
Optimize JavaScript fingerprinting performance
Loading...
Add CJK script detection and language code normalization
Loading...
Implement improved multi-signal language detection
Loading...
Implement multi-signal phishing clone detection
Loading...
Remove white background from favicons, make transparent
Loading...
Fix URL manipulation false positive for hash fragments in single-page apps
Loading...
Fix browser error URL exposure and improve AI analysis continuation logic
Loading...
Improved JavaScript fingerprinting processing speed with parallel workers
Loading...
Fix HTML upload race condition with inline data storage
Loading...
Enhanced reliability for JavaScript file downloads and analysis
Loading...
Fix null checks in expanded fingerprint metrics section
Loading...
Fix null handling for function count in JavaScript fingerprints
Loading...
Add obfuscated JavaScript detection for improved malware identification
Loading...
Add expanded JavaScript fingerprint metrics view
Loading...
Implement JavaScript fingerprinting feature for malware detection
Loading...
Faster JavaScript fingerprinting results for newly submitted scans
Showing recent updates and improvements