Register and share your invite link to earn from video plays and referrals.

Semgrep
@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
205 Following    4.7K Followers
Many malicious packages get caught within a few days or even a few hours. Your org rarely needs a dependency version released that recently. A one week cooldown offers a strong security ROI with minimal developer friction.
Show more
Same four repos, same revisions. Semgrep Multimodal found 63 confirmed IDORs that Mythos didn't report, at 59.9% recall against 13.9%. Mythos was the more precise of the two. For bugs that hide behind an authenticated endpoint, we'd still take the recall. Read the research:
Show more
We benchmarked Mythos against other models we have. Our analysis runs 23 configurations evaluated against 275 human-reviewed IDOR labels. Mythos did not take the top spot, and as others have reported the harness matters more than the model. See our results:
Show more
GLM-5.3 API is now live. - Built for coding, defensive cybersecurity, and long-horizon agentic tasks - Priced the same as GLM-5.2 - Available via the official API and partner model gateways Get started:
Show more
0
189
3.8K
327
Forward to community
* BLACK & WHITE. Blind shadows. A dark figure sits at a desk lit by a single monitor. Rain sounds in the background but with careful listening you realise someone is typing * The city was drowning in AI. Everyone was using it. Or at least... everyone said they were. The demo was beautiful. Too beautiful. The kind of demo that walks into your office, finds every vulnerability, and leaves before production opens its mouth. Forty agents. One intern overseeing them. Somethin' didn't add up... The token bill. * He turns to a cork board, you can't make out the exact words of the article, but you clearly see a long bill and you make out the Anthropic logo at the top * Every case is the same. It works... IF. If you've got one very specific setup. If you've got the time. If you never, ever look behind the curtain. If you have a usage based pricing enabled. * A phone rings in the background and the dark figure turns to answer it* Turns out two informants had the goods. Mehdi and Katie. Real intel — customer calls, hallway confessions, their own experiments. What works. What's a party trick. How to tell the difference before the budget's a chalk outline. *Stubs out cigarette.* That's the tip-off, kid. Link's below. Be there.
Show more
Coffee's for Coders / Brews are for Builders ☕ We’re hosting a virtual coffee tasting experience across EMEA on Thursday 10 September! Sample some of London’s finest roasts in your own home, see Semgrep in action, and enjoy an energising mid-morning break on us. ⚡ Save your spot by 25 August latest:
Show more
Exposed third-party infrastructure will likely become a recurring theme because the internet is awash in weak software. As models become more capable, they’ll have more opportunities to find and exploit those weaknesses.
Show more
Malicious Python and JavaScript deps have dominated this year's supply chain news cycle, but how many of y'all still have pinning GitHub Actions on your to do list? Here’s how I did this org-wide at Semgrep.
Show more
Millions of developers build on Replit - many with AI agents writing the code. Speed like that needs security that keeps pace. Semgrep Guardian's secrets detection is now built directly into Replit, catching vulnerabilities the moment code is generated. Every scan completes in under 5 seconds and is deterministic on every run, so it doesn't slow developers down or add unpredictable cost to your agent. Paired with Replit's reasoning layer, it filters out >93% of false positives, so developers see high-confidence results, not noise. Live now, no setup required. Read the full announcement:  #AppSec# #AI# #DevSecOps#
Show more
Black Hat's in the books. Now the vibe shifts: DEF CON is where hacker culture takes over, and where theory meets practical exploitation. Today, 4:30 PM, Crypto & Privacy Village: Diptendu Kar on "Crypto Is Fine. The Code Is Not." Crypto failures rarely come from bad math, they come from the gap between cryptographic theory and secure implementation. This weekend, Bug Bounty Village, Saturday 2:30 PM: @insiderphd and @hackfidgetcube on "Slop Spotting." As AI reshapes how code gets written (and how bug reports get filed), the challenge shifts from finding bugs to finding the right ones. Their talk digs into using SAST rule generation to separate genuine risk from AI-generated noise. IoT Village, Saturday 3:15 PM: Katie's back solo with "Beyond Your Bookshelf: Hackable eReaders." Bring your Kindle. She might jailbreak it on the spot. See you in the villages.
Show more
Gotta collect them all! If you missed our sticker drops at BSidesLV come meet us at "It's All Fun and Games" for a scavenger hunt for all 22 designs. See you tonight
Another day at Black Hat, another set of real-world AppSec challenges. Yesterday was about the grind: finding vulns, fixing them, and pushing security upstream. Today, we're staring down the barrel of AI-generated code. It ships fast, but human review? Still moves at human speed. and Pablo Estrada are tackling this gap at 9:30 AM in the Business Hall – a critical discussion on how not to turn review into a rubber stamp. Then at 3:15 PM on Pulse Stage 4, @drewdennison is talking 'Using SAST + Mythos to Shift Right.' For anyone who thinks 'SAST + LLMs' is just marketing fluff, he's demonstrating how this pairing can actually surface novel, long-buried vulnerabilities at scale. This isn't about shiny new tech; it's about practical strategies to keep pace without burning out our teams. Come share your war stories at booth #4943#.
Show more
We asked security pros at BSides Las Vegas for their hottest takes, and now we're sharing ours! 🔥 Our Head of Product Daghan Altas predicts that automated tools will soon take the reins on most PR code reviews, leaving humans to handle only the essential exceptions, so in a thousand PRs a human only reviews 1 or 2.
Show more
Another solid day at Hacker Summer Camp connecting with AppSec folks in the trenches. The recurring theme isn't just finding vulns, it's getting them fixed—and more importantly, preventing them upstream. That means working *with* developers, understanding their pain points, and making security less of a roadblock. It's about pragmatic wins and continuous improvement, not just tool deployment. If you're at Black Hat, swing by booth #4943# to share war stories and strategies for effective developer collaboration. Also, don't miss Katie Paxton-Fear and Milan Williams today at 1:30 PM at our booth, talking about 'Overcoming the Fear of Security Risk with AI-Assisted Development'—a critical topic for practitioner success.
Show more
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog:
Show more
🔍 We've been pointing fingers at AI, but are we missing the bigger picture? 🤔 Our Security Advocate Cris Thomas, aka Space Rogue, shares his thoughts on why regulation isn't the answer and that we might already know the answer to the AI problem all along... it's people, stupid.
Show more