Novo 2025.3.10

Plexicus 2025.3.10: Elevating Security & Efficiency: New Features You’ll Love!

Partner Collection — We've introduced a new feature to manage and organize partner data.

🚀 New Features

  • Partner Collection: We’ve introduced a new feature to manage and organize partner data.
  • OCSF Field: A new OCSF field has been added to enhance how findings are tracked.
  • Customizable Reasoning Effort: Now you can customize the reasoning effort settings across the platform.
  • Prowler Integration: We’ve fully integrated Prowler, a new tool to improve security scanning.
  • DAST Integration: DAST (Dynamic Application Security Testing) is now part of the platform, allowing more detailed security analysis.
  • Account Setup Reminder: A helpful email reminder is now sent to users who haven’t set up their accounts yet.
  • GitLab Self-Hosted Support: You can now integrate GitLab self-hosted repositories for security scanning.
  • Websocket Support for Pipelines: We’ve improved the pipeline setup process by adding websocket support.
  • Enhanced Partnership Management: New improvements have been made to manage and configure partnerships more easily.

🛠 Enhancements

  • Better Organization for IaC scanner & IaC scanner: We’ve broken down IaC scanner and IaC scanner into smaller, more manageable categories for easier navigation.
  • Increased Timeout for Workers: Workers now have more time to process tasks, ensuring smoother operations.
  • Schedule Reminder: Cronjob for reminder have been enhanced for better reliability in scheduled tasks.
  • Improved Gitea Connector: Gitea connector has been upgraded to include additional features.
  • Updated Pricing Flow: We’ve made changes to the subscription payment process, including updates to the Stripe integration.

📋 Compliance & Customization

  • Partner: Added a new way to manage different partner types, including commercial and free options.
  • Prevention of Duplicate Reminders: We’ve added safeguards to stop the same reminder email from being sent multiple times.
  • Cloud Connector Improvements: Cloud deployment connectors have been enhanced for more reliable integration.

🔧 Integrations

  • OpenAI Connection Fixes: We’ve improved the OpenAI integration and resolved connection issues to ensure seamless functionality.
  • DAST & DAST engine Security Scans: Added support for DAST and DAST engine for more thorough security testing.
  • GitLab Action Integration: GitLab actions are now integrated for automated security checks and workflows.
  • Bitbucket Fixes: Fixed issues with Bitbucket, ensuring smoother operation.
Qualificação

Verifique se o AI Swarm Pentest se adequa ao seu ambiente.

Partilhe o contexto mínimo. Vamos rever o escopo e indicar o próximo passo comercial.

Antes de enviar — verifique se se encaixa

0 / 280

Sem compromisso. Se não se encaixa, dizemos.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Ronda privada Para investidores