Plexicus 上市:AI 驱动的漏洞修复现已推出

Plexicus 推出 AI 驱动的安全平台,实现实时漏洞修复。自主代理即时检测、优先处理并修复威胁。

José Palanco José Palanco
Last Updated:
1 min read
Share
Plexicus 上市:AI 驱动的漏洞修复现已推出

Beyond ASPM

Proof-Driven AppSec for teams building with AI

Plexicus uses AI Swarm Pentest to explore authorised application paths, validate what is exploitable, and give teams evidence they can use to prioritise remediation.

Explore AI Swarm Pentest

圣克拉拉,加利福尼亚州 – 2025年2月13日 – 今天,Plexicus宣布其突破性的AI驱动安全平台正式上线。在经过密集的私人测试阶段后,我们的解决方案现已面向所有准备迎接漏洞挑战的安全和开发团队开放,使用真正的自主AI代理。

“我们的平台不是空头承诺。我们建立了一个系统,AI代理会主动巡查您的代码,识别弱点,并立即部署有针对性的修复措施,”Plexicus创始人Jose Ramon Palanco说道。“在一个网络威胁每分钟都在演变的世界里,拥有一个像您一样努力工作的解决方案是一场真正的革命。”

Plexicus平台的主要功能包括:

  • 实时修复:自主AI代理根据最新的威胁情报提供即时的数据驱动补丁建议和自动化修复。
  • 全面覆盖:持续扫描和深入的漏洞评估涵盖软件开发生命周期的每个阶段。
  • 无缝集成:轻松集成到流行的开发工具和CI/CD管道中,确保您的工作流程保持高效和安全。
  • 可操作的见解:详细的分析和报告提供关于风险区域的清晰指导,支持主动和明智的安全决策。

Plexicus 设计旨在从灵活的初创公司扩展到全球企业,提供灵活的定价和专门的支持网络——包括个性化的入职培训和24/7的技术支持。

展望未来,Plexicus 致力于进一步创新。我们正在扩展我们的 AI 能力,通过增强的威胁预测模型和更深入的生态系统集成,以在不断变化的网络安全领域保持领先。

关于 Plexicus

Plexicus 成立于加利福尼亚州圣克拉拉,致力于通过自主的、AI 驱动的解决方案来改变网络安全。通过自动化漏洞检测和修复,我们使组织能够专注于创新和增长,同时我们的 AI 代理保持对新兴威胁的警惕和适应性防御。

Written by
José Palanco
José Palanco
José Ramón Palanco is the CEO/CTO of Plexicus, a pioneering company in ASPM (Application Security Posture Management) launched in 2024, offering AI-powered remediation capabilities. Previously, he founded Dinoflux in 2014, a Threat Intelligence startup that was acquired by Telefonica, and has been working with 11paths since 2018. His experience includes roles at Ericsson`s R&D department and Optenet (Allot). He holds a Telecommunications Engineering degree from the University of Alcala de Henares and a Master`s in IT Governance from the University of Deusto. As a recognized cybersecurity expert, he has been a speaker at various prestigious conferences including OWASP, ROOTEDCON, ROOTCON, MALCON, and FAQin. His contributions to the cybersecurity field include multiple CVE publications and the development of various open source tools such as nmap-scada, ProtocolDetector, escan, pma, EKanalyzer, SCADA IDS, and more.
Read More from José
More to read

Related posts

SAST 与 DAST:有什么区别及为何应同时使用
Cybersecurity

SAST 与 DAST:有什么区别及为何应同时使用

SAST 和 DAST 是用于保护应用程序免受攻击的安全测试方法。为了了解每种方法如何帮助应用程序安全性,我们来看看它们的区别以及它们在工作流程中的位置

José Palanco José Palanco ·
Web 应用程序安全:2026 年的最佳实践、测试和评估
Cybersecurity

Web 应用程序安全:2026 年的最佳实践、测试和评估

Web 应用程序安全对于保护您的应用免受针对敏感数据和破坏操作的网络攻击至关重要。本指南涵盖了 Web 应用程序安全的重要性、常见漏洞、最佳实践和测试方法,帮助您保护应用程序、确保合规性并维护用户信任

José Palanco José Palanco ·
Ready to validate what matters?

Ready to validate what matters?

Plexicus is Proof-Driven AppSec: validated findings, contextual understanding, and reviewed remediation — anchored in evidence, scoped with you.

Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

Teams with fewer than 50 developers: start a 14-day Trial instead of booking a demo. Start a 14-day Trial →

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorised target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)