Loading...

Spring 2026 Update: CV Processor, Web Pentest Labs & Security

2026-05-11

The past few months have been incredibly productive for the Cyber Proficiency Center team. From an entirely new CV processing module to hands-on Web Pentest Labs and a comprehensive security overhaul, this release delivers meaningful improvements across every layer of the platform. Here's everything that's new.

New Module: CV Processor

We are excited to introduce the CV Processor — a brand-new module that automates resume handling within your recruitment workflow. You can now upload CVs in PDF or DOCX format, and the platform will automatically parse their contents and generate standardized documents based on your company templates. The module supports both Polish and English and is designed to save hours of manual formatting work for recruitment teams.

CV Processor main page showing side menu with My CVs, Templates and Generated Files buttons. The main screen shows Upload CV button, list of already uploaded CVs and details of one of them.
CV Processor main page

Web Pentest Labs: a new way to assess security skills

We've launched Web Pentest Labs — a completely new assessment format where candidates identify and report real vulnerabilities in live web applications. Instead of answering theoretical questions, candidates interact with intentionally vulnerable apps, locate security flaws, and submit structured reports. The platform automatically evaluates their findings and generates detailed PDF summaries, making it possible to assess practical offensive security skills at scale.

Stronger security across the board

Security has always been at the heart of our platform, and this release raises the bar significantly:

  • OAuth 2.0 Single Sign-On (SSO) with Microsoft Azure AD, including a dedicated admin panel for managing SSO configurations.
  • Login rate limiting to protect against brute-force attacks.
  • Admin audit log that records all security-relevant actions performed on the platform.
  • Automated weekly security scanning powered by Snyk to catch vulnerabilities early.
  • RFC 9116 security.txt endpoint for responsible disclosure.
  • Hardened Content Security Policies and improved sandbox isolation for coding tasks.
  • URL-safe tokens replacing base64 tokens for password reset and registration flows.
  • Email Delivery via Microsoft Graph API replacing traditional SMTP with modern enterprise email standard.
Web App Live Pentest Lab tasks running on MS Azure. At the top lab instructions are present with link to instructions in form of PDF file. Below there is Lab status sections with additional buttons such as Update status, Get OppenVPN Config, Get WireguardVPN Config and Stop lab environment. At the bottom there is section that allows to report vulnerabilities found during assessment.
Web App Live Pentest Lab tasks running on MS Azure

Faster code evaluation and better performance

Code task evaluation now runs asynchronously via Symfony Messenger, which keeps the platform responsive even during peak usage. Under the hood, we achieved a 400% throughput improvement in the sandbox supervisor and resolved execution issues for C#, Scala, and Go tasks. On the frontend, we optimized PageSpeed Insights scores with responsive images, lazy loading, improved caching, and eliminated N+1 database queries in critical endpoints.

Modern PDF reports with Gotenberg

We replaced the legacy Dompdf engine with Gotenberg for generating assessment report PDFs. The new engine produces higher-quality documents with proper icon rendering and better overall layout — giving recruiters polished, professional reports they can share with confidence.

Azure infrastructure upgrades

Our lab provisioning backend received major upgrades:

  • Migration to Azure Container Instances with simplified VPN configuration.
  • A new intelligent Pulumi queue system with automatic error recovery and conflict handling.
  • Automated cleanup of zombie stacks and orphaned cloud resources.
  • Support for public containers that don't require VPN — perfect for demo and introductory labs.

Admin Panel and reporting improvements

Administrators now benefit from server-side pagination for questions and assigned assessments, making large datasets easy to navigate. We also added simplified CSV and XLSX report exports, a new Manager role with limited admin access, and country flags next to IP addresses in the audit log for quick geographic context.

Accessibility, SEO, and internationalization

We improved WCAG 2.1 accessibility across key UI components and added structured data (JSON-LD), hreflang tags, and canonical URLs for better search engine visibility. We published interactive OpenAPI/Swagger documentation for our public API for our Enterprise customers to make any custom integration much easier. The platform also received a fresh Security & Trust Center page and a dedicated cybersecurity services page.

Stability and continuous integration

Behind the scenes, we expanded our automated test suite with new E2E (Playwright), unit (Jest, PHPUnit), and integration (pytest) tests. Post-deployment smoke tests now run automatically, CI/CD pipelines execute builds in parallel for faster delivery, and we migrated to Node.js 24 LTS.

We sincerely thank all our customers, partners, and candidates for their continued trust and invaluable feedback. Every suggestion you share helps us build a better platform. We are committed to delivering even more features, practical labs, and usability improvements in the coming months — stay tuned for what's next!


7 min read
Share this post:

Related Posts

All posts

Get your three regular assessments for free now!

  • All available job profiles included
  • Start assessing your candidates' skills right away
  • No time restrictions - register now, use your free assessments later
Create free account
  • All available job profiles included
  • Start assessing your candidates' skills right away
  • No time restrictions - register now, use your free assessments later
Top Scroll to top