CIO Influence
CIO Influence News Security

NewNormal Security Launches NewScan, a Free All-in-One Local Penetration Testing Scanner That Minimizes False Positives by Design

NewNormal Security Launches NewScan, a Free All-in-One Local Penetration Testing Scanner That Minimizes False Positives by Design

NewScan sweeps five attack surfaces โ€” APIs, web apps, network and infrastructure, Wi-Fi, and segmentation โ€” in one local scan, re-running and confirming every finding before it’s reported. Free to download. No account required to run.

NewNormal Security, a cybersecurity company focused on high frequency and fidelity Penetration Testing and API Security testing solutions, launched NewScan, a free, self-hosted, all-in-one local scanner for penetration testers and application security teams.

The Problem:ย Agentic software development ships code, including APIs, faster than humans can review, while attackers deploy their own agents to intensify attacks year-round. Security teams meanwhile juggle costly, disconnected tools that generate more false positives than insight, and weren’t built for an agentic coding world.

The Solution:ย NewsScan is a self-hosted, multi-surface scanner. Companies can run it manually, via CI/CD or MCP. It validates all findings; never inflating severity. AI can be applied for use cases it best handles. BYOK or use an AI optionally furnished by NewScan Pro. NewScan covers protocols and attack vectors others donโ€™t attempt, while putting control in the hands of analyst and developers.

Also Read:ย CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX

Key capabilities:

NewScan,

  • Correlated five-surface coverage;
  • Automatic API and endpoint discovery;
  • Verified findings with honest severity;
  • Local-first privacy with no account needed to run;
  • AI-optional BYOK support (OpenAI, Anthropic, Gemini, Ollama);
  • CI/CD-ready output.
  • Supports REST, SOAP, GRPC, Websockets, Graphql, MCP

NewScan Pro,

  • Adds over 20 out-of-band (OOB) detections for blind vulnerabilities,
  • Integrations with Jira and GitHub,
  • Compliance-formatted reports (SOC2, PCI, ISO 27001),
  • Optional in-line AI.

Catch more CIO Insights:ย What Does โ€œJob-Readyโ€ Really Mean in IT and Cybersecurity?

[To share your insights with us, please write toย psen@itechseries.com ]

Related posts

Precision-Guided RAG: Transforming Customer Support for the Modern Enterprise

Karan Sood

Europeโ€™s Leading Information Security Analyst Firm Recognizes OneSpan as an Overall Leader for Fraud Reduction Technologies

BARR Advisory Releases Exclusive Resources on Healthcare Compliance

PR Newswire