Neu v2025.14.11

Plexicus v2025.14.11: Next-Level Integration and Performance Upgrade

Onboarding Revamp — Completely revamped the setup process with guided collection for company information and initial configuration.

🚀 New Features

  • Onboarding Revamp: Completely revamped the setup process with guided collection for company information and initial configuration.
  • Language-Based Security Insights: You can now filter and view security findings broken down by programming language and severity level.
  • Advanced Dashboard Visualizations: Introduced new chart types, including heatmaps, risk quadrants, and language distribution charts, for deeper insights.

🛠 Enhancements

  • UI/UX Overhaul: Complete refresh of the interface, including streamlined navigation, redesigned sidebar, and smooth loading states throughout the application.
  • Faster Performance: Optimized table rendering, reduced API calls, and enhanced overall data loading speed across the platform.
  • Security & Auth Improvements: Strengthened two-factor authentication (using email verification), improved API security layers, and better user session management.
  • AI-Powered Remediation: Upgraded AI assistance for security issue resolution and enhanced automatic classification of findings.
  • Reporting & Analytics: Improved data export, reporting capabilities, and enhanced tracking of user workflows and feature usage.
  • Team Management: Enhanced controls for team invitation and user management.
  • Error Handling: Improved system stability with better error tracking, reporting, and recovery mechanisms.

📋 Compliance & Customization

  • Enhanced Compliance Tracking: Better monitoring and visibility into security compliance requirements.
  • Audit Trail: Improved tracking of security activities and changes within the platform.
  • Data Privacy: Enhanced protection against unauthorized access to sensitive information.
  • Custom Tool Configuration: Added ability to customize security tool parameters and settings.

🔧 Integrations

  • Dedicated CodeQL Connector: Replaced our generic GitHub SAST with a dedicated CodeQL connector for deeper security analysis.
  • Expanded Tool Coverage: Added support for external scans from Burpsuite and Kiuwan, alongside other new security scanners.
  • Scan Import Capabilities: Added ability to import security scans from multiple third-party tools.
  • SCM & Sync Improvements: Enhanced integrations and synchronization handling for all major Source Code Management platforms (GitHub, GitLab, Bitbucket, Gitea).
  • Analytics Overhaul: Integrated Google Tag Manager for a complete analytics system upgrade.
  • Automated Issue Tracking: Improved integration with external ticketing systems for automated issue synchronization.
Qualifizierung

Prüfen Sie, ob AI Swarm Pentest zu Ihrer Umgebung passt.

Teilen Sie den wichtigsten Kontext. Wir prüfen den Umfang und nennen den nächsten kommerziellen Schritt.

Vor dem Absenden — prüfen Sie, ob Sie passen

0 / 280

Keine Verpflichtung. Wenn Sie nicht passen, sagen wir es Ihnen.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Private Runde Für Investoren