Neu 2025.3.10

Plexicus 2025.3.10: Elevating Security & Efficiency: New Features You’ll Love!

Partner Collection — We've introduced a new feature to manage and organize partner data.

🚀 New Features

  • Partner Collection: We’ve introduced a new feature to manage and organize partner data.
  • OCSF Field: A new OCSF field has been added to enhance how findings are tracked.
  • Customizable Reasoning Effort: Now you can customize the reasoning effort settings across the platform.
  • Prowler Integration: We’ve fully integrated Prowler, a new tool to improve security scanning.
  • DAST Integration: DAST (Dynamic Application Security Testing) is now part of the platform, allowing more detailed security analysis.
  • Account Setup Reminder: A helpful email reminder is now sent to users who haven’t set up their accounts yet.
  • GitLab Self-Hosted Support: You can now integrate GitLab self-hosted repositories for security scanning.
  • Websocket Support for Pipelines: We’ve improved the pipeline setup process by adding websocket support.
  • Enhanced Partnership Management: New improvements have been made to manage and configure partnerships more easily.

🛠 Enhancements

  • Better Organization for IaC scanner & IaC scanner: We’ve broken down IaC scanner and IaC scanner into smaller, more manageable categories for easier navigation.
  • Increased Timeout for Workers: Workers now have more time to process tasks, ensuring smoother operations.
  • Schedule Reminder: Cronjob for reminder have been enhanced for better reliability in scheduled tasks.
  • Improved Gitea Connector: Gitea connector has been upgraded to include additional features.
  • Updated Pricing Flow: We’ve made changes to the subscription payment process, including updates to the Stripe integration.

📋 Compliance & Customization

  • Partner: Added a new way to manage different partner types, including commercial and free options.
  • Prevention of Duplicate Reminders: We’ve added safeguards to stop the same reminder email from being sent multiple times.
  • Cloud Connector Improvements: Cloud deployment connectors have been enhanced for more reliable integration.

🔧 Integrations

  • OpenAI Connection Fixes: We’ve improved the OpenAI integration and resolved connection issues to ensure seamless functionality.
  • DAST & DAST engine Security Scans: Added support for DAST and DAST engine for more thorough security testing.
  • GitLab Action Integration: GitLab actions are now integrated for automated security checks and workflows.
  • Bitbucket Fixes: Fixed issues with Bitbucket, ensuring smoother operation.
Qualifizierung

Prüfen Sie, ob AI Swarm Pentest zu Ihrer Umgebung passt.

Teilen Sie den wichtigsten Kontext. Wir prüfen den Umfang und nennen den nächsten kommerziellen Schritt.

Vor dem Absenden — prüfen Sie, ob Sie passen

0 / 280

Keine Verpflichtung. Wenn Sie nicht passen, sagen wir es Ihnen.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Private Runde Für Investoren