diff --git a/docs/changelog.mdx b/docs/changelog.mdx
index 4304d79bfa..2233ee1077 100644
--- a/docs/changelog.mdx
+++ b/docs/changelog.mdx
@@ -4,6 +4,81 @@ description: "New features and improvements in each Prowler release"
rss: true
---
+
+ ### π Compliance Watchlist
+
+
+ This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
+
+
+ Compliance Watchlist keeps the frameworks an organization tracks in one shared list. Pin frameworks from any compliance view, manage several at once through a searchable catalog, and filter the Compliance section to show only the pinned frameworks.
+
+ The Overview page now reports the latest score for every pinned framework, while finding details highlight the watched frameworks associated with each check. Universal frameworks remain a single watchlist entry across provider views, keeping the organization's priorities consistent everywhere.
+
+ 
+
+ Read more in the [Compliance Watchlist documentation](https://docs.prowler.com/user-guide/compliance/tutorials/compliance#tracking-frameworks-with-the-compliance-watchlist).
+
+ ### π SAML SSO - Multiple Email Domains
+
+
+ This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
+
+
+ One SAML configuration can now authorize a primary email domain and up to 19 additional domains through the same Identity Provider. Every domain shares one stable Assertion Consumer Service (ACS) URL based on the primary domain, so subsidiaries, acquired companies, regional domains, and multiple brands no longer require separate tenants or duplicated SAML applications.
+
+ Domain ownership remains tenant-bound throughout the authentication flow. During service provider-initiated sign-in, the discovery domain and the domain asserted by the Identity Provider must resolve to the same tenant before provisioning continues.
+
+ 
+
+ Read more in the [SAML SSO documentation](https://docs.prowler.com/user-guide/tutorials/prowler-app-sso#add-multiple-saml-domains).
+
+ ### π₯ User Sign-In Methods
+
+
+ This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
+
+
+ The Users table now shows each account's sign-in methods as tags, including email/password, Google, GitHub, SAML with linked domains, and Partner SSO. Accounts without a reported method display a placeholder.
+
+ 
+
+ ### πΈοΈ Attack Paths - Expanded AWS Privilege-Escalation Coverage
+
+ Attack Paths adds 20 AWS privilege-escalation queries from [pathfinding.cloud](https://pathfinding.cloud), while `iam_policy_allows_privilege_escalation` gains 22 additional escalation combinations.
+
+ The new coverage includes service `iam:PassRole` paths across AWS Batch, Braket, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, Systems Manager, and Step Functions. It also covers existing-resource abuse, permissions-boundary removal, role assumption, and IAM Identity Center permission-set policy injection.
+
+ The query catalog now exposes each AWS query's outcome category, distinguishing code execution, privilege escalation, public exposure, and resource inventory.
+
+ Explore the full Attack Paths query catalog at [Prowler Hub](https://hub.prowler.com/attack-paths).
+
+ Read more in the [Attack Paths documentation](https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths).
+
+ ### π Checks
+
+ #### Microsoft 365
+
+ Twelve new checks expand the coverage of CIS Microsoft 365 Foundations Benchmark v7.0.0:
+
+ - **Admin Center:** Shared Bookings is disabled.
+ - **Defender:** Priority account protection and strict preset security policies are enabled.
+ - **Entra ID:** Six checks cover device registration restrictions, local administrator behavior, device limits, LAPS, and BitLocker key visibility.
+ - **Exchange Online:** Personal accounts in Outlook on the web are disabled and Direct Send is rejected.
+ - **Microsoft Teams:** External access from trial-only tenants is blocked.
+
+ Explore all Microsoft 365 checks at [Prowler Hub](https://hub.prowler.com/check?provider=m365).
+
+ ### π Security
+
+ - Prowler API, UI, SDK, and MCP container images now publish per-architecture Software Bills of Materials (SBOMs) and build-provenance attestations. Prowler Cloud production and Prowler Private Cloud images carry the same attestations.
+ - SDK and API container builds verify the checksums of downloaded PowerShell, Trivy, and zizmor binaries before installation.
+ - Grype now complements Trivy across the container-image security gates, detecting components and vulnerabilities that manifest-based scanners can miss and blocking fixable high and critical findings.
+ - `aiohttp` was upgraded to 3.14.3 to address CVE-2026-69244. `cryptography` was upgraded to 50.0.0 to address CVE-2026-69247 and CVE-2026-69249.
+
+ See the [full release notes on GitHub](https://github.com/prowler-cloud/prowler/releases/tag/5.38.0) for the complete list of changes.
+
+
### π¬ Lighthouse AI β Context-Aware Chat and a Bigger Toolbox
diff --git a/docs/images/changelog/v5.38.0-user-sign-in-methods.png b/docs/images/changelog/v5.38.0-user-sign-in-methods.png
new file mode 100644
index 0000000000..f03682b14a
Binary files /dev/null and b/docs/images/changelog/v5.38.0-user-sign-in-methods.png differ