Neu 2026.5.25

Plexicus 2026.5.25: Smarter Filters, AI Remediation & Reliability Improvements

Try AI remediation without a connected SCM, enjoy smarter filters, and experience a faster, more reliable platform across the board.

🚀 What’s New

  • Azure DevOps Support: You can now connect Azure DevOps repositories to Plexicus — scan, triage, and remediate findings directly alongside your GitHub, GitLab, and Bitbucket projects.
  • AI Remediation in Sandbox: Explore AI-powered fix suggestions in sandbox mode without needing to connect a repository first. Great for evaluating Plexicus before going live.
  • All Integrations in One Place: We’ve unified all third-party integrations under a single Settings page so you spend less time hunting for configuration options.
  • Smarter Login Experience: OAuth sign-in options now appear only when they’re relevant to your account setup, keeping the login screen clean and uncluttered.

🛠 Improvements

  • Access Control: We’ve rolled out the foundations of a more flexible, fine-grained permissions model — giving your team better control over who can see and do what inside Plexicus.
  • Compliance Readiness: Ongoing groundwork to support additional compliance frameworks — more details coming in future releases.
  • Upgrade Flow: Clicking the upgrade button now opens pricing in a new tab so you never lose your place in the app.

🔧 Fixes

  • Faster Startup for Large Organizations: Some organizations with a large number of users were experiencing significant delays — or outright failures — when the platform started up. The platform now becomes available in seconds, regardless of your organization’s size. All your access permissions remain fully enforced throughout.
  • Applying filters or hitting Refresh now reliably reloads the correct results — no more stale data appearing after a search.
  • Downloading your repository list as a CSV no longer returns an error.
  • The close button on finding details now correctly takes you back to the findings list, even when accessed via a direct link.
  • Starting a bulk repository scan during onboarding no longer fails unexpectedly.
  • Fixed cases where the AI remediation panel could show an incorrect status or fail to load altogether.
  • OAuth error messages are now clearer when something goes wrong during sign-in.
  • Added security protections to prevent the platform from being embedded in unauthorized third-party pages.
Qualifizierung

Prüfen Sie, ob AI Swarm Pentest zu Ihrer Umgebung passt.

Teilen Sie den wichtigsten Kontext. Wir prüfen den Umfang und nennen den nächsten kommerziellen Schritt.

Vor dem Absenden — prüfen Sie, ob Sie passen

0 / 280

Keine Verpflichtung. Wenn Sie nicht passen, sagen wir es Ihnen.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Private Runde Für Investoren