<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://docs.bugcrowd.com/changelog.xml" rel="self" type="application/atom+xml" /><link href="https://docs.bugcrowd.com/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-08-07T16:39:39+00:00</updated><id>https://docs.bugcrowd.com/changelog.xml</id><title type="html">Bugcrowd Docs | Changelogs</title><subtitle>Bugcrowd user documentation</subtitle><entry><title type="html">Savant Vista Public Beta (1.0)</title><link href="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/" rel="alternate" type="text/html" title="Savant Vista Public Beta (1.0)" /><published>2026-07-14T00:00:00+00:00</published><updated>2026-07-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/">&lt;p&gt;Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="asset-management" /><summary type="html">Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.</summary></entry><entry><title type="html">VRT Update (1.19.1)</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/" rel="alternate" type="text/html" title="VRT Update (1.19.1)" /><published>2026-07-08T00:00:00+00:00</published><updated>2026-07-08T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-update-119</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/">&lt;p&gt;Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.</summary></entry><entry><title type="html">Verifying Your Identity</title><link href="https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity/" rel="alternate" type="text/html" title="Verifying Your Identity" /><published>2026-05-18T00:00:00+00:00</published><updated>2026-05-18T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity/">&lt;p&gt;Identity verification (IDV) is now required for all researchers prior to submitting reports to Managed Bug Bounty (MBB) programs — both public and private (excluding on-demand MBBs). This change strengthens platform integrity by reducing high volumes of low-quality submissions originating from newly created or rotating accounts. Verification requires researchers to complete a live selfie capture via webcam and upload a valid government-issued ID (passport, identity card, or driver’s license) through an embedded portal accessible directly from Account Settings under the Identity Verification tab. Researchers who have previously completed IDV — including those verified for payments or background checks — do not need to re-verify. The process supports multi-nationality verification and allows up to five attempts before a support ticket is required. For more information, visit &lt;a href=&quot;https://docs.bugcrowd.com/researchers/managing-account/account-settings/verifying-your-identity/&quot;&gt;Verifying Your Identity&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="researcher" /><summary type="html">Identity verification (IDV) is now required for all researchers prior to submitting reports to Managed Bug Bounty (MBB) programs — both public and private (excluding on-demand MBBs). This change strengthens platform integrity by reducing high volumes of low-quality submissions originating from newly created or rotating accounts. Verification requires researchers to complete a live selfie capture via webcam and upload a valid government-issued ID (passport, identity card, or driver’s license) through an embedded portal accessible directly from Account Settings under the Identity Verification tab. Researchers who have previously completed IDV — including those verified for payments or background checks — do not need to re-verify. The process supports multi-nationality verification and allows up to five attempts before a support ticket is required. For more information, visit Verifying Your Identity.</summary></entry><entry><title type="html">IP Restrictions</title><link href="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/" rel="alternate" type="text/html" title="IP Restrictions" /><published>2026-05-14T00:00:00+00:00</published><updated>2026-05-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/ip-restrictions</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/">&lt;p&gt;The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.&lt;/p&gt;

&lt;p&gt;This setting is configured at the organization level and applies to all admin users associated with that organization.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.</summary></entry><entry><title type="html">New API version released V1.1.0</title><link href="https://docs.bugcrowd.com/changelog/api/api-version-1.1.0/" rel="alternate" type="text/html" title="New API version released V1.1.0" /><published>2026-05-05T00:00:00+00:00</published><updated>2026-05-05T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/api/api-version-1.1.0</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/api/api-version-1.1.0/">&lt;p&gt;See the full &lt;a href=&quot;https://docs.bugcrowd.com/api/1.1.0/&quot;&gt;API Version 1.1.0 reference&lt;/a&gt; for request/response details.&lt;/p&gt;

&lt;h2 id=&quot;funding_pool-include-on-monetary-rewards&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;funding_pool&lt;/code&gt; include on monetary rewards&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;funding_pool&lt;/code&gt; as an includable relationship on the monetary reward endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=funding_pool&lt;/code&gt; to retrieve the funding pool associated with a monetary reward in a single request.&lt;/p&gt;

&lt;h2 id=&quot;last_activity_feed_item_created_at-filter-on-the-submissions-index&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;last_activity_feed_item_created_at&lt;/code&gt; filter on the submissions index&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;filter[last_activity_feed_item_created_at]&lt;/code&gt; query parameter to the submissions index endpoint.
This allows filtering submissions by the timestamp of their last activity feed item.&lt;/p&gt;

&lt;h2 id=&quot;active_blocker-include-on-submissions&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_blocker&lt;/code&gt; include on submissions&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_blocker&lt;/code&gt; as an includable relationship on the submission endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=active_blocker&lt;/code&gt; to retrieve the active blocker for a submission in a single request.&lt;/p&gt;

&lt;h2 id=&quot;active_researcher_request_response-include-on-submissions&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_researcher_request_response&lt;/code&gt; include on submissions&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_researcher_request_response&lt;/code&gt; as an includable relationship on the submission endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=active_researcher_request_response&lt;/code&gt; to retrieve the active researcher request response for a submission in a single request.&lt;/p&gt;

&lt;h2 id=&quot;credential-bucket-endpoints&quot;&gt;Credential bucket endpoints&lt;/h2&gt;

&lt;p&gt;Added credential bucket endpoints.
Credential buckets allow programs to manage pools of credentials for researchers to use during testing.&lt;/p&gt;

&lt;h2 id=&quot;credential-endpoints&quot;&gt;Credential endpoints&lt;/h2&gt;

&lt;p&gt;Added credential endpoints.
Credentials represent individual login credentials within a credential bucket that can be assigned to researchers.&lt;/p&gt;

&lt;h2 id=&quot;post-submissionssearch-endpoint&quot;&gt;POST &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/submissions/search&lt;/code&gt; endpoint&lt;/h2&gt;

&lt;p&gt;Added a POST endpoint for searching submissions with a JSON request body.
Accepts filter, sort, page, include, and fields parameters in the body, avoiding URL length limitations for complex queries.&lt;/p&gt;</content><author><name></name></author><category term="api_webhook" /><summary type="html">See the full API Version 1.1.0 reference for request/response details.</summary></entry><entry><title type="html">Submission Limits for MBB Programs</title><link href="https://docs.bugcrowd.com/changelog/researchers/submissions-throttling/" rel="alternate" type="text/html" title="Submission Limits for MBB Programs" /><published>2026-05-04T00:00:00+00:00</published><updated>2026-05-04T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/researchers/submissions-throttling</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/researchers/submissions-throttling/">&lt;p&gt;To reinforce platform accountability and ensure that high-quality, validated findings receive the attention and speed they deserve, Bugcrowd is introducing submission limits for Managed Bug Bounty (MBB) programs. Researchers will be limited to 5 simultaneous Open submissions (reports in the New or Triaged states), and submission limits will be restored as reports are moved out of Open states. Accounts with a proven track record of quality submissions and performance are exempt from these limits. For a complete breakdown of eligibility, substates, and tips for managing your account standing, please visit our &lt;a href=&quot;https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/submissions-limit/&quot;&gt;documentation&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="researcher" /><summary type="html">To reinforce platform accountability and ensure that high-quality, validated findings receive the attention and speed they deserve, Bugcrowd is introducing submission limits for Managed Bug Bounty (MBB) programs. Researchers will be limited to 5 simultaneous Open submissions (reports in the New or Triaged states), and submission limits will be restored as reports are moved out of Open states. Accounts with a proven track record of quality submissions and performance are exempt from these limits. For a complete breakdown of eligibility, substates, and tips for managing your account standing, please visit our documentation.</summary></entry><entry><title type="html">VRT Scope Rules Added</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules/" rel="alternate" type="text/html" title="VRT Scope Rules Added" /><published>2026-05-01T00:00:00+00:00</published><updated>2026-05-01T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules/">&lt;p&gt;Engagement Briefs, the Submission form, and Security Inbox now support &lt;strong&gt;VRT Scope Rules&lt;/strong&gt;. These rules allow you to set reminders and out-of-scope exclusions for VRT items on all or some of your targets or target groups.&lt;/p&gt;

&lt;p&gt;VRT Scope Rules are intended to set expectations with researchers at or before time of submission. Used judiciously, should reduce noise and triage times across your engagements.&lt;/p&gt;

&lt;p&gt;For full details, see the &lt;a href=&quot;/customers/engagement-management/engagement-vrt-scope-rules/&quot;&gt;VRT Scope Rules&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="engagement-management" /><summary type="html">Engagement Briefs, the Submission form, and Security Inbox now support VRT Scope Rules. These rules allow you to set reminders and out-of-scope exclusions for VRT items on all or some of your targets or target groups.</summary></entry><entry><title type="html">CVSS v4.0 Support Added</title><link href="https://docs.bugcrowd.com/changelog/customers/cvss-v4/" rel="alternate" type="text/html" title="CVSS v4.0 Support Added" /><published>2026-04-29T00:00:00+00:00</published><updated>2026-04-29T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/cvss-v4</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/cvss-v4/">&lt;p&gt;The CVSS Calculator now supports CVSS 4.0 alongside CVSS 3.1. Program administrators can enable CVSS 4.0 under Program Settings &amp;gt; Submissions, after which all new submissions will default to the new version.
Switching versions does not automatically update existing submissions. These must be reviewed manually via the Security Inbox, or updated in bulk through the API.&lt;/p&gt;

&lt;p&gt;For full details, see the &lt;a href=&quot;https://docs.bugcrowd.com/customers/submission-management/cvss/&quot;&gt;CVSS documentation&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="submission-management" /><summary type="html">The CVSS Calculator now supports CVSS 4.0 alongside CVSS 3.1. Program administrators can enable CVSS 4.0 under Program Settings &amp;gt; Submissions, after which all new submissions will default to the new version. Switching versions does not automatically update existing submissions. These must be reviewed manually via the Security Inbox, or updated in bulk through the API.</summary></entry><entry><title type="html">VRT Update (1.18)</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-update-118/" rel="alternate" type="text/html" title="VRT Update (1.18)" /><published>2026-03-09T00:00:00+00:00</published><updated>2026-03-09T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-update-118</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-update-118/">&lt;p&gt;Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been enhanced to support mappings to auto-suggest CVSS vectors for opt-in customers.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been enhanced to support mappings to auto-suggest CVSS vectors for opt-in customers.</summary></entry><entry><title type="html">New Security Inbox- Speed, Automation, and AI</title><link href="https://docs.bugcrowd.com/changelog/customers/the-security-inbox/" rel="alternate" type="text/html" title="New Security Inbox- Speed, Automation, and AI" /><published>2026-02-02T00:00:00+00:00</published><updated>2026-02-02T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/the-security-inbox</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/the-security-inbox/">&lt;p&gt;We are excited to announce the launch of the new Security Inbox. Designed as a high-performance command center, it offers streamlined triage workflows, powerful customization features, and deeper platform efficiencies to accelerate your time to remediation.&lt;/p&gt;

&lt;h2 id=&quot;whats-new&quot;&gt;What’s New&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Saved Views &amp;amp; Pinning:&lt;/strong&gt; Design your perfect workflow. Create, share, and pin custom filter sets as tabs for one-click access to your most critical work queues.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Focused View Layout:&lt;/strong&gt; Maximize productivity with a split-screen interface. View full technical details side-by-side without losing your place (activities, brief, disclosures, etc.)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;AI Triage Assistant:&lt;/strong&gt; Leverage our secure, in-platform AI operational assistant to summarize complex findings, suggest remediation steps, and even generate Nuclei retest templates using natural language.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Automated Integration Triggers:&lt;/strong&gt; Turn filters into actions. Link your Saved Views directly to Jira or other integrations to automate ticket creation based on your specific criteria.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;improved-capabilities&quot;&gt;Improved Capabilities&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Advanced Search &amp;amp; Filtering:&lt;/strong&gt; Find what you need in seconds. Search by Submission ID, Researcher, or Target with an enhanced filtering engine designed to help you focus on the vulnerabilities that matter most.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Modernized UI:&lt;/strong&gt; Experience a refreshed, scannable design across the entire Inbox, specifically engineered to reduce cognitive load during high-volume triage sessions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;ready-to-dive-in&quot;&gt;Ready to dive in?&lt;/h2&gt;

&lt;p&gt;To take full advantage of these new features and explore the updated workflows, please visit our &lt;a href=&quot;https://docs.bugcrowd.com/customers/security-inbox/the-security-inbox/&quot;&gt;Security Inbox Documentation.&lt;/a&gt;&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">We are excited to announce the launch of the new Security Inbox. Designed as a high-performance command center, it offers streamlined triage workflows, powerful customization features, and deeper platform efficiencies to accelerate your time to remediation.</summary></entry></feed>