ShadowTrackr

RSS feed

Parked assets and website security score

24 August 2026
Last week’s update had two unforeseen effects.

The first is that the discovery algorithm update caused ShadowTrackr to discover a lot more assets in some cases. We expected to find a little more, and that happened on most accounts. However, some accounts have public IP ranges where DNS records have been enumerated for every IP address. These were all added as assets. For two multi-tenant accounts, this resulted in tens of thousands of extra assets that only added noise. These extra assets are rarely accessible from the internet (or are not even up). ShadowTrackr now recognizes these types of assets and puts them under “parked URLs” and “parked hosts”. Parked assets do not count towards your total assets, so you are not paying for them. They are checked randomly every 10–20 days, and if they are found to be up, they are moved to your regular monitored assets.

The second effect was that the new, faster website security checks also included a change in scoring. This was done to keep the scoring in line with the Mozilla Observatory scores. The scoring has become stricter, so some sites that had a decent score before now have lower scores. As usual, the website pages show a breakdown of the scoring and provide tips on how to improve your grade.

This week, we’ll be doing a major refactor of the events index. Our goal is to provide you with more useful events and alerts, but to get there and be able to scale up further, we need to go through this first. You should not notice anything during the migration, as it will run in the background.

NCSC NL vulnerabilities report

17 August 2026
This week's update is actually a big update on a lot of scanner node modules. This is a quality improvement, but not one that will stand out particularly if you are using the GUI. You'll just have better quality results.

What does stand out to end users is the new $ncsc_vulnerabilities_report. Since we track all advisories from the Dutch NCSC now, we can provide reports on the CVE numbers in those reports that are relevant for the software we have detected on your assets. Will the most pressure to resolve these CVEs is on government and public organizations, it is a good idea for everyone to prioritise these. These vulnerabilities have been picked out of the bulk for a good reason.

Single Sign-On (SSO) now available

10 August 2026
Short post today, but one with impact. ShadowTrackr now supports Single Sign-On from Microsoft Azure AD/Entra ID, Okta and any generic OIDC (like Keycloak).

The option is available for enterprise accounts and up under Settings->Security.
Older posts >