Neu 2025.3.26

Plexicus 2025.3.26: Streamlining Workflows & Strengthening Compliance

GitLab Self-Hosted Enhancements

🚀 New Features

  • GitLab Self-Hosted Enhancements
  • Gitea Connector Enhancements
  • Prowler Integration (Initial & Full Implementation)
  • DAST Connector Implementation
  • Email Reminder for Not Setup Accounts

🛠 Enhancements

  • Bitbucket Workflow Action Setup Functions
  • IaC scanner & IaC scanner Category Division
  • Partnership Enhancements
  • Flow WebSocket on Setup Pipeline
  • Enhancement for OpenAI Connection

📋 Compliance & Customization

  • Remediation & Workflow Execution Fixes
  • Security & Dependabot Vulnerabilities Resolved
  • DAST engine Tool Exclusion for Default Users

🔧 Integrations

  • Fixes for Findings & Validation Tools
  • Token Refresh & API Issues (GitLab, OpenAI, Workers, Repository Management)
  • Worker Timeout & API Stability Improvements
  • Cronjob Fixes & Logging Enhancements
Qualifizierung

Prüfen Sie, ob AI Swarm Pentest zu Ihrer Umgebung passt.

Teilen Sie den wichtigsten Kontext. Wir prüfen den Umfang und nennen den nächsten kommerziellen Schritt.

Vor dem Absenden — prüfen Sie, ob Sie passen

0 / 280

Keine Verpflichtung. Wenn Sie nicht passen, sagen wir es Ihnen.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Private Runde Für Investoren