CIO Influence
CIO Influence News Security

NewNormal Security Launches NewScan, a Free All-in-One Local Penetration Testing Scanner That Minimizes False Positives by Design

NewNormal Security Launches NewScan, a Free All-in-One Local Penetration Testing Scanner That Minimizes False Positives by Design

NewScan sweeps five attack surfaces โ€” APIs, web apps, network and infrastructure, Wi-Fi, and segmentation โ€” in one local scan, re-running and confirming every finding before it’s reported. Free to download. No account required to run.

NewNormal Security, a cybersecurity company focused on high frequency and fidelity Penetration Testing and API Security testing solutions, launched NewScan, a free, self-hosted, all-in-one local scanner for penetration testers and application security teams.

The Problem:ย Agentic software development ships code, including APIs, faster than humans can review, while attackers deploy their own agents to intensify attacks year-round. Security teams meanwhile juggle costly, disconnected tools that generate more false positives than insight, and weren’t built for an agentic coding world.

The Solution:ย NewsScan is a self-hosted, multi-surface scanner. Companies can run it manually, via CI/CD or MCP. It validates all findings; never inflating severity. AI can be applied for use cases it best handles. BYOK or use an AI optionally furnished by NewScan Pro. NewScan covers protocols and attack vectors others donโ€™t attempt, while putting control in the hands of analyst and developers.

Also Read:ย CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX

Key capabilities:

NewScan,

  • Correlated five-surface coverage;
  • Automatic API and endpoint discovery;
  • Verified findings with honest severity;
  • Local-first privacy with no account needed to run;
  • AI-optional BYOK support (OpenAI, Anthropic, Gemini, Ollama);
  • CI/CD-ready output.
  • Supports REST, SOAP, GRPC, Websockets, Graphql, MCP

NewScan Pro,

  • Adds over 20 out-of-band (OOB) detections for blind vulnerabilities,
  • Integrations with Jira and GitHub,
  • Compliance-formatted reports (SOC2, PCI, ISO 27001),
  • Optional in-line AI.

Catch more CIO Insights:ย What Does โ€œJob-Readyโ€ Really Mean in IT and Cybersecurity?

[To share your insights with us, please write toย psen@itechseries.com ]

Related posts

Demandbase Hires Sean Malone as Chief Information Security Officer

CIO Influence News Desk

Kyyba Tech Inc. Strengthens Partnership with Commonwealth of Massachusetts at IT Leadership Summit 2026

PR Newswire

PagerDuty Appoints Jeff Hausman as Chief Product Development Officer

Business Wire