<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Nsasoft Press Releases</title>
    <link>https://www.nsauditor.com/ai/</link>
    <description>Press releases, product announcements, and security advisories from Nsasoft US LLC</description>
    <language>en-us</language>
    <image>
      <url>https://www.nsauditor.com/ai/images/avatar-option-1-shield-neural.png</url>
      <title>Nsasoft Press Releases</title>
      <link>https://www.nsauditor.com/ai/</link>
      <width>144</width>
      <height>144</height>
    </image>
    <item>
      <title>NSAuditor AI Pro &amp; Enterprise Edition v0.2.3 Released — Enhanced Compliance Mapping, Smarter Agent Verification, and Stability Improvements</title>
      <link>https://www.nsauditor.com/ai/</link>
      <guid isPermaLink="false">e3a7c291-5f84-4b12-9d63-1a0f82e45c08</guid>
      <pubDate>Thu, 01 May 2026 12:00:00 GMT</pubDate>
      <content:encoded><![CDATA[<p><strong>FOR IMMEDIATE RELEASE</strong></p>

<p><strong>Las Vegas, NV — May 1, 2026</strong> — Nsasoft US LLC today announced the release of <strong>NSAuditor AI — Pro &amp; Enterprise Edition v0.2.3</strong>, a maintenance and enhancement release built on the v0.2.x parallel-agent analysis pipeline. This update ships with improved compliance gap reporting, more accurate agent verification logic, and several stability and compatibility fixes across Windows, Linux, and macOS environments.</p>

<blockquote><p>"Version 0.2.3 is about hardening the foundation we laid in 0.2.1. Customers running large-scale enterprise audits asked for more precise compliance evidence references and faster verification cycles — both land in this release. The parallel agent model stays intact; we've just made it more reliable under real-world load." — Nsasoft US LLC</p></blockquote>

<h2>What's New in v0.2.3</h2>

<h3>Improved Compliance Mapping (Enterprise)</h3>
<p>The Compliance Engine now produces tighter evidence references when mapping findings to <strong>NIST CSF</strong>, <strong>CIS Controls</strong>, <strong>HIPAA Security Rule</strong>, <strong>GDPR Article 32</strong>, and <strong>PCI DSS</strong>. Each control mapping now includes the source finding ID, verification status, and the specific scan probe that produced the evidence — making gap reports fully auditable by compliance teams.</p>

<h3>Faster Verification Engine (Pro)</h3>
<p>The non-destructive verification engine has been refactored to reduce per-host round-trip overhead. Probe batching across the Auth, Crypto, and Config agents cuts average verification time by up to 30% on subnets with 50+ hosts, while maintaining the existing 2s/host rate limit and full audit logging.</p>

<h3>Risk Score Calibration (Pro)</h3>
<p>Composite risk scoring has been recalibrated based on real-world audit feedback. POTENTIAL findings with corroborating indirect evidence are now scored at 0.75× (up from 0.6×), reducing under-reporting of likely vulnerabilities in environments where direct probes are filtered by internal firewalls.</p>

<h3>Cloud Scanner Fixes (Enterprise)</h3>
<p>Resolved an intermittent credential resolution issue affecting AWS STS-based role assumption chains. GCP firewall rule parsing now correctly handles hierarchical policy inheritance across shared VPC configurations. Azure RBAC scanner updated for the April 2026 Microsoft Graph API schema changes.</p>

<h3>CE Peer Dependency</h3>
<p>Peer dependency aligned to <code>^0.1.26</code>, picking up all stability fixes and the updated MCP server detection signatures shipped in the Community Edition 0.1.26 release.</p>

<h2>Availability</h2>
<p>NSAuditor AI — Pro &amp; Enterprise Edition v0.2.3 is available immediately on npm:</p>
<pre><code>npm install -g @nsasoft/nsauditor-ai-ee</code></pre>
<p>A valid Pro or Enterprise license key is required to activate EE features. Pricing and licensing: <a href="https://nsauditor.com/ai/pricing">https://nsauditor.com/ai/pricing</a><br/>
System requirements: Node.js 20+, NSAuditor AI CE v0.1.26 or later.</p>

<h2>About Nsasoft US LLC</h2>
<p>Nsasoft US LLC builds network security and audit tooling for IT teams, MSPs, and enterprise security organizations. For more information, visit <a href="https://nsauditor.com">https://nsauditor.com</a></p>

<p><strong>Media Contact:</strong><br/>
Nsasoft US LLC<br/>
732 S 6th St, Ste R<br/>
Las Vegas, NV 89101<br/>
Phone: +1 (702) 625-0401<br/>
<a href="mailto:info@nsasoft.us">info@nsasoft.us</a><br/>
<a href="https://nsauditor.com">https://nsauditor.com</a></p>]]></content:encoded>
      <author>Nsasoft US LLC</author>
      <category>NSAuditor AI</category>
      <category>Pro Edition</category>
      <category>Enterprise Edition</category>
      <category>AI Agents</category>
      <category>Network Security</category>
      <category>Compliance</category>
      <category>MITRE ATT&amp;CK</category>
      <category>press-release</category>
      <enclosure url="https://www.nsauditor.com/ai/images/77311966-6faf-45ee-ac92-760e7a2db4a7.jpg" type="image/jpeg" length="100641"/>
      <media:content url="https://www.nsauditor.com/ai/images/77311966-6faf-45ee-ac92-760e7a2db4a7.jpg" medium="image" width="1200" height="630"/>
    </item>
    <item>
      <title>nsauditor-ai v0.1.26 Released — Expanded MCP Server Detection, Stability Fixes, and Improved Scan Reporting</title>
      <link>https://www.nsauditor.com/ai/</link>
      <guid isPermaLink="false">f9d2b847-3e51-4c90-a127-6b5e73d01f94</guid>
      <pubDate>Thu, 01 May 2026 11:00:00 GMT</pubDate>
      <content:encoded><![CDATA[<p><strong>FOR IMMEDIATE RELEASE</strong></p>

<p><strong>Las Vegas, NV — May 1, 2026</strong> — Nsasoft US LLC today announced the release of <strong>nsauditor-ai v0.1.26</strong>, the latest update to the open-source network security audit platform. This release expands MCP server detection coverage, improves scan report output quality, and ships a set of stability fixes addressing edge cases reported by the community since v0.1.24.</p>

<h2>What's New in v0.1.26</h2>

<h3>Expanded MCP Server Detection</h3>
<p>Building on the MCP server scanner plugin introduced in v0.1.24, this release adds detection for two additional vulnerability categories:</p>
<ul>
  <li>&#x1F534; <strong>Insecure CORS Configuration</strong> — Identifies MCP servers that accept cross-origin requests from wildcard or overly permissive origins, enabling unauthorized cross-site tool invocation</li>
  <li>&#x1F534; <strong>Missing Rate Limiting on Tool Endpoints</strong> — Detects MCP servers that expose tool endpoints without request throttling, leaving them vulnerable to enumeration and abuse</li>
</ul>
<p>Port candidate coverage has been extended with three additional commonly observed MCP deployment ports: <strong>4000, 7860, and 9000</strong>.</p>

<h3>Improved Scan Report Output</h3>
<p>The CLI report renderer now groups findings by severity tier (CRITICAL → HIGH → MEDIUM → LOW → INFO) and includes a one-line remediation hint for each finding category. JSON output mode adds a <code>scan_meta</code> block with scan duration, plugin versions, and host reachability summary — making automated ingestion into SIEM and ticketing systems more reliable.</p>

<h3>save_finding MCP Tool Enhancement</h3>
<p>The <code>save_finding</code> MCP tool now accepts an optional <code>remediation</code> field, allowing AI agents and MCP-aware IDE assistants to attach structured fix guidance directly to persisted findings. Compatible with NSAuditor AI EE v0.2.3 and later.</p>

<h3>Stability Fixes</h3>
<ul>
  <li>Fixed a hang condition on hosts that return partial TLS handshake responses during the Crypto agent probe sequence</li>
  <li>Resolved incorrect MITRE ATT&amp;CK technique assignment for SNMP community string findings (was T1046, corrected to T1602.001)</li>
  <li>STDIO transport detection no longer emits false-positive MCP Inspector findings on localhost loopback addresses</li>
  <li>Improved IPv6 target handling in the port scanner module</li>
</ul>

<h2>Resources</h2>
<ul>
  <li>&#x1F4E6; npm Package: <a href="https://npmjs.com/package/nsauditor-ai">npmjs.com/package/nsauditor-ai</a></li>
  <li>&#x1F4BB; GitHub: <a href="https://github.com/nsasoft/nsauditor-ai">github.com/nsasoft/nsauditor-ai</a></li>
</ul>

<h2>Availability</h2>
<p>nsauditor-ai v0.1.26 is MIT-licensed and available immediately via npm:</p>
<pre><code>npm install -g nsauditor-ai</code></pre>

<h2>About Nsasoft US LLC</h2>
<p>Nsasoft US LLC is a Las Vegas-based network security software company specializing in privacy-first, AI-assisted security tooling. The company develops open-core security scanners and infrastructure auditing tools for enterprise and developer audiences.</p>

<p><strong>Media Contact:</strong><br/>
Nsasoft US LLC<br/>
732 S 6th St, Ste R<br/>
Las Vegas, NV 89101<br/>
Phone: +1 (702) 625-0401<br/>
Email: info@nsasoft.us<br/>
Web: https://www.nsauditor.com</p>]]></content:encoded>
      <author>Nsasoft US LLC</author>
      <category>NSAuditor AI</category>
      <category>MCP Security</category>
      <category>AI Security</category>
      <category>Network Security</category>
      <category>Open Source</category>
      <category>Infosec</category>
      <category>press-release</category>
      <enclosure url="https://www.nsauditor.com/ai/images/322211d0-76ab-4b5a-aee9-75432aa51df0.jpg" type="image/jpeg" length="149802"/>
      <media:content url="https://www.nsauditor.com/ai/images/322211d0-76ab-4b5a-aee9-75432aa51df0.jpg" medium="image" width="1200" height="630"/>
    </item>
    <item>
      <title>NSAuditor AI Pro &amp; Enterprise Edition v0.2.1 Released — Parallel Analysis Agents and Verified Findings Bring Senior-Analyst Triage to Network Security Audits</title>
      <link>https://www.nsauditor.com/ai/</link>
      <guid isPermaLink="false">b1e4f920-3c7a-4d88-a561-8f2e01c94b37</guid>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <content:encoded><![CDATA[<p><strong>FOR IMMEDIATE RELEASE</strong></p>

<p><strong>Las Vegas, NV — April 27, 2026</strong> — Nsasoft US LLC today announced the release of <strong>NSAuditor AI — Pro &amp; Enterprise Edition v0.2.1</strong>, the commercial extension to the open-source <a href="https://github.com/nsasoft/nsauditor-ai">NSAuditor AI</a> network security audit platform. The release pairs the v0.2.x parallel-agent analysis pipeline with full compatibility against Community Edition v0.1.24, which now ships with the MCP server scanner plugin and the <code>save_finding</code> MCP tool.</p>

<p>The 0.2.x line is the largest functionality jump since the product's launch. Five specialized analysis agents — Auth, Crypto, Config, Service, and Exposure — now run in parallel on every scan, each producing structured findings within its category. Results flow into a non-destructive verification engine that confirms whether each finding is real before it reaches a report.</p>

<blockquote><p>"A scanner that says 'TLS 1.0 might be enabled' is just adding to the analyst's queue. We wanted a system that says 'TLS 1.0 is enabled — here is the handshake response, here is the matching CVE, here is the MITRE technique, here is the risk score.' That's what 0.2 ships. And it does it without sending customer data anywhere — same API call, vastly better output, customer keeps the keys." — Nsasoft US LLC</p></blockquote>

<h2>What's New in v0.2.x</h2>

<h3>Parallel Analysis Agents (Pro)</h3>
<p>Five concurrent agents triage scan output by category: weak auth and default credentials; TLS and certificate weaknesses; configuration mistakes (default SNMP communities, debug modes, exposed .env files); service-level CVEs and end-of-life software; and internet-facing exposure paths. Agents execute via <code>Promise.allSettled</code> — categories with no relevant services are skipped automatically.</p>

<h3>Verification Engine (Pro)</h3>
<p>Findings are confirmed with safe, non-destructive probes — a TLSv1.0 handshake attempt, an SNMP sysDescr GET, a banner grab — and labeled <strong>VERIFIED</strong>, <strong>POTENTIAL</strong>, or <strong>FALSE_POSITIVE</strong>. Probes are rate-limited (2s/host), carry no exploit payloads, write no data, and are individually audit-logged.</p>

<h3>Intelligence-Enriched AI Reports (Pro)</h3>
<p>AI providers (OpenAI, Claude, Ollama) work in every tier; the difference is what enters the prompt. Pro injects CVE matches, MITRE ATT&amp;CK techniques, risk scores, and verification status — producing executive-ready summaries and remediation plans. Customers supply their own API keys. No scan data transits Nsasoft infrastructure (<strong>Zero Data Egress</strong> preserved).</p>

<h3>Risk Scoring Engine (Pro)</h3>
<p>Composite scoring combines severity, exploitability, impact, and exposure. VERIFIED findings score at 1.0×; POTENTIAL findings at 0.6× — so unconfirmed signal cannot inflate a report's headline numbers.</p>

<h3>Cloud and Compliance (Enterprise)</h3>
<p>AWS, GCP, and Azure cloud scanners audit security groups, IAM policy, firewall rules, NSG rules, and RBAC bindings using the customer's own cloud credentials. The Compliance Engine maps findings to <strong>NIST CSF</strong>, <strong>CIS Controls</strong>, <strong>HIPAA Security Rule</strong>, <strong>GDPR Article 32</strong>, and <strong>PCI DSS</strong>, producing gap reports with evidence references.</p>

<h3>Pro &amp; Enterprise MCP Tools</h3>
<p><code>get_vulnerabilities</code>, <code>risk_summary</code>, <code>scan_compare</code>, <code>save_finding</code> (Pro) and <code>start_assessment</code>, <code>prioritize_risks</code>, <code>compliance_check</code>, <code>export_report</code> (Enterprise) make EE intelligence available to MCP-aware agents and IDE assistants.</p>

<h2>What's Specifically New in v0.2.1</h2>
<ul>
  <li>CE peer dependency aligned to <code>^0.1.24</code>, picking up the MCP server scanner plugin (CE plugin 070) and the shared <code>save_finding</code> MCP tool</li>
  <li>Documentation updated across README and architecture references to reflect the unified CE+EE plugin surface</li>
  <li>Repository hygiene: <code>tasks/</code> directory excluded from publication</li>
</ul>

<h2>Availability and Pricing</h2>
<p>NSAuditor AI — Pro &amp; Enterprise Edition v0.2.1 is available immediately on npm:</p>
<pre><code>npm install -g @nsasoft/nsauditor-ai-ee</code></pre>
<p>A valid Pro or Enterprise license key is required to activate EE features. Pricing and licensing: <a href="https://nsauditor.com/ai/pricing">https://nsauditor.com/ai/pricing</a><br/>
System requirements: Node.js 20+, NSAuditor AI CE v0.1.24 or later.</p>

<h2>About Nsasoft US LLC</h2>
<p>Nsasoft US LLC builds network security and audit tooling for IT teams, MSPs, and enterprise security organizations. For more information, visit <a href="https://nsauditor.com">https://nsauditor.com</a></p>

<p><strong>Media Contact:</strong><br/>
Nsasoft US LLC<br/>
<a href="mailto:info@nsasoft.com">info@nsasoft.com</a><br/>
<a href="https://nsauditor.com">https://nsauditor.com</a></p>]]></content:encoded>
      <author>Nsasoft US LLC</author>
      <category>NSAuditor AI</category>
      <category>Pro Edition</category>
      <category>Enterprise Edition</category>
      <category>AI Agents</category>
      <category>Network Security</category>
      <category>Compliance</category>
      <category>MITRE ATT&amp;CK</category>
      <category>press-release</category>
      <enclosure url="https://www.nsauditor.com/ai/images/77311966-6faf-45ee-ac92-760e7a2db4a7.jpg" type="image/jpeg" length="100641"/>
      <media:content url="https://www.nsauditor.com/ai/images/77311966-6faf-45ee-ac92-760e7a2db4a7.jpg" medium="image" width="1200" height="630"/>
    </item>
    <item>
      <title>nsauditor-ai v0.1.24 Introduces Open-Source MCP Server Detection for AI Infrastructure Security Auditing</title>
      <link>https://www.nsauditor.com/ai/</link>
      <guid isPermaLink="false">ca2fc382-672a-4587-b34d-57ea4d5052ff</guid>
      <pubDate>Mon, 27 Apr 2026 01:25:14 GMT</pubDate>
      <content:encoded><![CDATA[<strong>Las Vegas, NV — April 27, 2026</strong> — Nsasoft US LLC today announced the release of <strong>nsauditor-ai v0.1.24</strong>, an open-source network security scanner that introduces native detection of <strong>MCP (Model Context Protocol) servers</strong> — making it the first open-source network auditing tool to address this emerging AI infrastructure attack surface.

<h2>The MCP Security Gap</h2>
<p>As AI agents and LLM-powered applications proliferate, MCP servers are rapidly becoming the connective tissue of enterprise AI infrastructure. Yet unlike traditional web services, MCP deployments often lack standardized security hardening guidance — leaving organizations exposed to risks that conventional scanners are not equipped to detect.</p>

<p>nsauditor-ai v0.1.24 closes that gap with a dedicated plugin suite that audits HTTP/SSE-transport MCP servers across four critical vulnerability categories:</p>

<ul>
  <li>&#x1F534; <strong>Cleartext Bearer Token Exposure</strong> — Detects authentication tokens transmitted without TLS or proper header protection</li>
  <li>&#x1F534; <strong>Anonymous Authentication + Tool Enumeration</strong> — Identifies MCP endpoints that allow unauthenticated tool discovery, enabling attackers to map available capabilities</li>
  <li>&#x1F534; <strong>Deprecated Protocol Versions</strong> — Flags servers running outdated MCP protocol revisions with known weaknesses</li>
  <li>&#x1F534; <strong>MCP Inspector Interface Exposure</strong> — Detects inadvertently exposed developer inspection interfaces on production hosts</li>
</ul>

<h2>Safe, Read-Only Detection Methodology</h2>
<p>The scanner operates exclusively through safe, read-only JSON-RPC <code>initialize</code> probes sent to eight commonly used MCP port candidates: <strong>1967, 3000, 3005, 5173, 6274, 6277, 8000, and 8090</strong>. No tool invocation occurs. No exploitation is performed. All findings are automatically mapped to <strong>CWE, OWASP Top 10, and MITRE ATT&amp;CK</strong> framework identifiers, enabling direct integration into enterprise risk and compliance workflows.</p>

<h2>Architecture &amp; Availability</h2>
<p>nsauditor-ai v0.1.24 ships as both a <strong>command-line interface (CLI)</strong> and a <strong>native MCP server itself</strong>, allowing it to be composed directly into AI agent pipelines for automated, continuous security posture assessment. The tool is MIT-licensed and available immediately via npm:</p>

<pre><code>npm install -g nsauditor-ai
nsauditor-ai scan --host &lt;target&gt; --plugins all</code></pre>

<p>The current release covers HTTP/SSE-transport MCP servers — the network-exposed attack surface. Audit support for STDIO-transport MCP (the default for Claude Desktop and similar local deployments) is planned for a future release.</p>

<h2>Resources</h2>
<ul>
  <li>&#x1F4E6; npm Package: <a href="https://npmjs.com/package/nsauditor-ai">npmjs.com/package/nsauditor-ai</a></li>
  <li>&#x1F4BB; GitHub: <a href="https://github.com/nsasoft/nsauditor-ai">github.com/nsasoft/nsauditor-ai</a></li>
</ul>

<h2>About Nsasoft US LLC</h2>
<p>Nsasoft US LLC is a Las Vegas-based network security software company specializing in privacy-first, AI-assisted security tooling. The company develops open-core security scanners and infrastructure auditing tools for enterprise and developer audiences.</p>

<p><strong>Media Contact:</strong><br>
Nsasoft US LLC<br>
732 S 6th St, Ste R<br>
Las Vegas, NV 89101<br>
Phone: +1 (702) 625-0401<br>
Email: info@nsasoft.us<br>
Web: https://www.nsauditor.com</p>]]></content:encoded>
      <author>Nsasoft US LLC</author>
      <category>MCP Security</category>
      <category>AI Security</category>
      <category>Network Security</category>
      <category>Open Source</category>
      <category>Infosec</category>
      <enclosure url="https://www.nsauditor.com/ai/images/322211d0-76ab-4b5a-aee9-75432aa51df0.jpg" type="image/jpeg" length="149802"/>
      <media:content url="https://www.nsauditor.com/ai/images/322211d0-76ab-4b5a-aee9-75432aa51df0.jpg" medium="image" width="1200" height="630"/>
    </item>
    <item>
      <title>Nsasoft US LLC Releases Nsauditor Network Security Auditor 3.2.7 — Critical Security Update Fixes Four CVE Vulnerabilities</title>
      <link>https://www.nsauditor.com/network_security/network_security_auditor.html</link>
      <guid isPermaLink="false">ccbb0974-f3a7-48af-9357-54b9537b51af</guid>
      <pubDate>Mon, 13 Apr 2026 01:00:09 GMT</pubDate>
      <content:encoded><![CDATA[<strong>LAS VEGAS, NV — April 12, 2026</strong> — Nsasoft US LLC, a leading provider of network security and audit software, today announced the release of Nsauditor Network Security Auditor version 3.2.7, a critical security update that resolves four reported Common Vulnerabilities and Exposures (CVE) affecting previous versions of the software.

<h3>Security Fixes</h3>
<p>Version 3.2.7 addresses the following vulnerabilities:</p>
<ul>
<li><strong>CVE-2018-25213</strong> — DNS Lookup DNS Query field SEH buffer overflow (Fixed)</li>
<li><strong>CVE-2019-25597</strong> — SNMP Auditor Community field buffer overflow (Fixed)</li>
<li><strong>CVE-2020-37130</strong> — Registration Name field buffer overflow (Fixed)</li>
<li><strong>CVE-2021-47815</strong> — Registration Key field buffer overflow (Fixed)</li>
</ul>
<p>In addition, the vulnerability detection and network databases have been updated to reflect the latest known threats and security signatures.</p>

<h3>About Nsauditor Network Security Auditor</h3>
<p>Nsauditor Network Security Auditor is a comprehensive network security scanner for auditing and monitoring network computers for possible vulnerabilities. The software checks network computers using all potential methods that a hacker might use to attack them. Nsauditor includes over 45 network tools including intrusion detection, firewall, packet analyzer, port scanner, SNMP auditor, DNS tools, and more. The product supports Windows XP through Windows 11.</p>

<h3>Availability and Pricing</h3>
<p>Nsauditor Network Security Auditor 3.2.7 is available for immediate download at <a href="https://www.nsauditor.com/downloads/nsauditor_setup.exe">https://www.nsauditor.com/downloads/nsauditor_setup.exe</a>. The software is priced at $69.00 USD with a 15-day free trial. All existing customers are strongly encouraged to update immediately.</p>

<h3>About Nsasoft US LLC</h3>
<p>Nsasoft US LLC, based in Las Vegas, Nevada, develops network security audit software, internet tools, network monitoring software, and password recovery products. For more information, visit <a href="https://www.nsauditor.com">https://www.nsauditor.com</a> or contact <a href="mailto:info@nsasoft.us">info@nsasoft.us</a>.</p>

<p><strong>Media Contact:</strong><br>
Nsasoft US LLC<br>
732 S 6th St, Ste R<br>
Las Vegas, NV 89101<br>
Phone: +1 (702) 625-0401<br>
Email: info@nsasoft.us<br>
Web: https://www.nsauditor.com</p>]]></content:encoded>
      <author>Nsasoft US LLC</author>
      <category>security</category>
      <category>software-update</category>
      <category>CVE</category>
      <category>network-security</category>
      <category>vulnerability-fix</category>
      <category>press-release</category>
    </item>
    <lastBuildDate>Thu, 01 May 2026 12:00:00 GMT</lastBuildDate>
  </channel>
</rss>