注册并分享邀请链接,可获得视频播放与邀请奖励。

Semgrep
@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
加入 May 2019
205 正在关注    4.7K 粉丝
Another day at Black Hat, another set of real-world AppSec challenges. Yesterday was about the grind: finding vulns, fixing them, and pushing security upstream. Today, we're staring down the barrel of AI-generated code. It ships fast, but human review? Still moves at human speed. and Pablo Estrada are tackling this gap at 9:30 AM in the Business Hall – a critical discussion on how not to turn review into a rubber stamp. Then at 3:15 PM on Pulse Stage 4, @drewdennison is talking 'Using SAST + Mythos to Shift Right.' For anyone who thinks 'SAST + LLMs' is just marketing fluff, he's demonstrating how this pairing can actually surface novel, long-buried vulnerabilities at scale. This isn't about shiny new tech; it's about practical strategies to keep pace without burning out our teams. Come share your war stories at booth #4943#.
显示更多