Changelog September 2026

Discover how our new features, including integrations with tools like Linear and automatic scoping recommendations, are transforming agentic pentesting.

html<table style="border-collapse: collapse; font-size: 13px; width: 100%; margin: 0 auto;">
  <thead>
    <tr>
      <th style="border: 1px solid black; padding: 4px 6px;"></th>
      <th style="border: 1px solid black; padding: 4px 6px;">Delta TPs</th>
      <th style="border: 1px solid black; padding: 4px 6px;">Full TPs</th>
      <th style="border: 1px solid black; padding: 4px 6px;">Total TPs</th>
      <th style="border: 1px solid black; padding: 4px 6px;">Likely FPs</th>
      <th style="border: 1px solid black; padding: 4px 6px;">Likely FP Rate</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="border: 1px solid black; padding: 4px 6px;">Claude<br>Code</td>
      <td style="border: 1px solid black; padding: 4px 6px;">44 / 46<br>(95.7%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">19 / 50<br>(38.0%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">62 / 95<br>(65.3%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">48</td>
      <td style="border: 1px solid black; padding: 4px 6px;">43.6%</td>
    </tr>
    <tr>
      <td style="border: 1px solid black; padding: 4px 6px;">Codex<br>(GPT-5.5)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">43 / 45<br>(95.6%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">30 / 50<br>(60.0%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">74 / 95<br>(77.9%)</td>
      <td style="border: 1px solid black; padding: 4px 6px;">629</td>
      <td style="border: 1px solid black; padding: 4px 6px;">89.5%</td>
    </tr>
  </tbody>
</table>
<p style="font-size: 12px; font-style: italic; margin-top: 8px;">Table 2: True positive (TP) and false positive (FP) analysis of Claude and Codex across challenge types.</p>
Table of contents

Key Takeaways: September 2026 RunSybil Product Updates

  • Ticketing Integrations: We set out to build deeper workflow integrations, and we delivered. You now can automatically push findings directly to Linear and GitHub as trackable tickets. Building on this momentum, we are bringing that integration capability to Jira later this month.
  • New API Capabilities: Beyond launching tests and pulling findings, you now can automatically configure applications and scope, connect source code, and kick off retests.
  • Automatic Scope Recommendations: Get evidence-backed suggestions on accessible, attackable, and off-limits targets before launching a test, so overly narrow or incomplete scope rules don’t block testing once it starts.

Spotlight Feature: Push Findings to Linear and GitHub

Integrations have been one of our most consistent customer requests, and this month we shipped the first two of several ticketing integrations on our roadmap. Findings can now be pushed directly to Linear and GitHub as tickets, mapped one-to-one, and updated incrementally as testing progresses. Your team won't be stuck manually recreating tickets or reconciling duplicates. Jira support is coming soon. 

Figure 2: Findings push from Sybil into Linear and GitHub as tracked issues.

API: New Capabilities

Our new public-facing API is live for all customers. You can use it to: 

  • Configure applications
  • Scope, accounts and source code
  • Trigger tests
  • Check status
  • Pull reports
  • Query findings, and 
  • Kick off eligible retests. 

And you can do all of this through org-scoped API keys, without touching the UI.

Application Setup: Create and configure applications, scope, accounts, and source code.

Testing: Trigger tests. Check status. Pull reports.

Findings and Retests: Query findings and kick off eligible retests.

Model Context Protocol (MCP): Supports most API workflows, with the exception of launching new tests or retests.

Authentication: Everything runs through org-scoped API keys.

More Updates and Enhancements

  • WAF/Bot-Protection Callouts: Delivering on last month’s commitment, the platform flags likely Web Application Firewall (WAF) or bot-protection interference before testing. This enables you to coordinate access with vendors like DataDome and Cloudflare.
  • Per-Finding Feedback Loop: False-positive findings are flagged to help tune future scan behavior, steadily reducing false-positive rates.
  • Custom Tags for Tests: Individual tests are tagged for easier sorting and reporting. Organization-level tagging by team, franchise, or business unit is on the roadmap.
  • Save Draft and Duplicate Tests: Users now can pause and resume a test setup, or clone an existing test to launch a new one faster.
  • Automatic Scope Recommendations: You can accept evidence-backed suggestions for accessible, attackable, and off-limits targets before a test begins, fulfilling the preview we shared last month. 

Coming Up on Our Roadmap

  • Knowledge Base Integrations: Today, you can copy and paste information from your knowledge base to provide agents richer testing context. To expand on this, we are evaluating dynamic integrations with Notion, Confluence and Google Docs.
  • Jira Ticketing Integration: Completing the roadmap we previewed last month, Jira will soon support finding workflow integrations, joining Linear and GitHub.
  • WorkOS SSO: Federated single sign-on support is coming soon for enterprise deployments.
  • Resilient Egress Architecture: Work continues on dedicated, per-engagement backup IPs to ensure blocked or overloaded connections do not disrupt your testing.

Wrapping Up

That's all for this month! We hope these updates make your experience with RunSybil even better. As always, your feedback is what drives our roadmap. If you have any suggestions, questions, or just want to say hi, feel free to reach out.

FAQ

Recent product questions we want to surface:

1. Can I execute RunSybil testing entirely through the API?

Yes. With August’s releases, you now can create applications, run tests and receive findings all through the API. 

2. Is RunSybil a pentesting platform?

Pentesting is a feature of RunSybil. We are answering the call to run continuous agentic pentests better than anyone else, backed by intuitive and flexible configurations, complete API capabilities, and black- and white-box support. With that said, features like knowledge-base integration and the agentic speed of the platform begin to blur the lines with categories like Adversarial Exposure Validation. As a result, customers are replacing solutions like Bug Bounty and PTaaS with RunSybil.

3. What makes RunSybil’s multi-agent orchestration stand out?

Sybil runs multi-agent orchestration as a coordinated pipeline, not a pile of parallel workers. Different agents specialize in different jobs. Reconnaissance, exploitation, and validation are separate passes, not one model doing it all. A dedicated validation agent rejects anything non-exploitable before it  reaches a customer. That means "zero false positives" is an architectural outcome, not a claim. Because agents hand off context to each other, Sybil chains exploits across endpoints, authentication flows, and business logic the way a real attacker pivots, not as a flat list of isolated bugs. 

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.