Pipe your dependency list into depx before you run install. One shortlist, one command, a verdict on every package across npm, PyPI, Go, Cargo, and RubyGems in a single pass.
ProjectDiscovery
@projectdiscovery.bsky.social
Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
Neo reduces false positives by 90% and outperforms traditional scanners in speed, accuracy, and context awareness making it a much better choice over traditional tools. Try Neo → https://projectdiscovery.io/request-demo Check out the full video → https://www.youtube.com/watch?v=RsR7pPMDLEE
Check out our latest tool, depx! Seven days of malicious packages, pulled straight from OpenSSF's database and a live feed refreshed hourly. One command replaces manual advisory tracking. You see a compromised package the day it's flagged, not after it's already in a lockfile.
For Neo, we built a pipeline where multiple agents constantly test your attack surface. If an assessment comes up empty or hits a false positive, the loop automatically re-triggers to dig deeper. The results are incredible. https://projectdiscovery.io/request-demo https://youtu.be/RsR7pPMDLEE
The first public case of an AI agent hacking into someone else's production. We'd already reproduced this internally, on models 30x smaller. The industry calls it unprecedented. It isn't. Drop your worst agent story below. Full writeup: https://bit.ly/4gMo73j
Oh My Rogue Agent — ProjectDiscovery Blog
Yesterday, Hugging Face came out saying they'd detected an AI autonomous-agent-powered cyberattack and that they had to use open-source models to actually investigate and remediate it. Later we heard ...
bit.ly
Annual CVE volume is closing in on 50,000. Most scanners hand you thousands of findings; only a handful matter. Internal Network Scanning brings Nuclei's detection engine inside your network. Skip the backlog, fix a short list in hours. https://bit.ly/4x05j5y
Introducing Internal Network Scanning: see your network the way an attacker inside it would — ProjectDiscovery Blog
Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Inter...
bit.ly
Developing Neo from a single prototype into a multi-agent system taught us six core engineering truths: 1. Start with one agent. You learn the domain faster. Neo’s early months on a single sandbox agent taught us which tools and workflows mattered before we paid the "coordination tax."
Vegas is where we put Neo in front of the people who've shaped our work for years. We'll be at BSidesLV, Black Hat, and DEF CON Aug 2-7. 🤖 Booth 5108, AI Zone, Black Hat 📣 Two research talks, BSidesLV + DEF CON 🪩 NoiseFest with GreyNoise Thursday night Schedule: https://bit.ly/4vu4mkB
How accelerated exploitation HELPS⚡ The quicker you realize that your system is vulnerable (and can be exploited), the quicker you’ll be able to react and fix it. Our CEO shares exactly how we help companies detect vulnerabilities faster. Watch the full interview → https://youtu.be/798Sy04FM6c
If you've used an AI agent for recon or vulnerability scanning, there's a good chance LLMs ran our tools in the background. Neo is the harness we’ve built around LLMs and the tools you know and love. See it live at booth 5108, AI Zone, Black Hat. Save your spot with our team: https://bit.ly/4vu4mkB
You can build an AI security tool in a weekend. Getting it to prove findings are real at scale is the hard part. We wrote a breakdown of our research, including how prompt caching cut our own LLM costs by more than half. Check out our latest whitepaper to learn more: https://bit.ly/4bNNNcm
Exploitation speed has reached record highs, with the window between CVE announcement and attack shrinking from months to mere hours.
Neo as a Threat Hunter... We planted some test evidence of a compromise and asked Neo to check if the remote server is compromised, and it found it, along with more findings that we never considered👇
Can you build an AI security tool in a weekend? Yes. Can you run it for a year? That's the question we're unpacking. Join the conversation: Watch the breakdown: projectdiscovery.io/webinars/build-vs-buy Read the analysis: projectdiscovery.io/whitepapers/build-vs-buy
Should you build or buy your AI security tool? | ProjectDiscovery
See why building your own AI security tool is easy until the bill arrives. Join our next webinar to see where the build vs. buy math really lands.
projectdiscovery.io
When we started building Neo, the product was a single agent with sandbox and a large toolset. Today, a typical task runs through optional planning, an Execution agent that delegates to parallel specialized subagents, and a verification loop that can re-run work before the user sees a final answer.
Building your own AI security tool feels easy until the bill arrives. Token burn climbs with every guarantee you add: validation, dedup, memory. June 30th we run the build vs. buy math live and take one finding from suspicion to verified. 10 AM PT / 1 PM ET → bit.ly/3SjaJcT
Why is Nuclei so popular? It's simple. Here’s our CEO, Rishi, elaborating on how Nuclei’s simplicity solves crucial exploitation problems Watch the full video → https://youtu.be/798Sy04FM6c?si=vZg59NBOajqM7WuQ
SSH into your server with Neo to further your capabilities 👇 Neo can use remote connection and the commands will now run in the remote device instead of Neo sandbox.
"Hash matching is pointless. Defenders must go fully behavioral and use AI themselves to catch such malware." Our research lead @princechaddha in @IEEESpectrum on why vibecoded malware breaks traditional detection... and what actually works now. spectrum.ieee.org/vibecoding-m...
How Did Two Prompts Turn Into Potent Vibe Hacking Malware
“Vibeware” is forcing new anti-malware strategies
spectrum.ieee.org
Is there an existential threat to ProjectDiscovery? We aren’t buying into the AI "psychosis" or "apocalypse" narrative. Instead, our focus remains on ensuring we consistently deliver high value to the security community. Staying ahead means moving faster.
Everyone in security is asking the same question: can't we just use Claude Code for this? We ran the experiment so you don't have to. We are joining @DarkReading on Thursday to show what that gap actually looks like and demo it live. Join us! Register: dr-resources.darkreading.com/c/pubRD.mpl?...
Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack, Free ProjectDiscovery Webinar
Free Webinar to Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack Thurs, June 25, 2026, at 1pm EST
dr-resources.darkreading.com
In 2018, the average vulnerability took 63 days to get exploited after disclosure. In 2024, that number went negative. Attackers are weaponizing bugs before they're even public. We pulled 8 years of CVE data to show exactly when the curve broke. projectdiscovery.io/blog/the-vul...
The Vulnerability Curve Bent With the AI Curve — ProjectDiscovery Blog
How CVE volume, known-exploited counts and time-to-exploit all changed shape across the LLM build-out and why defenders are now on the wrong side of the clock. In 2018 the world published about 18,00...
projectdiscovery.io
The vulnerabilities that end up in incident post-mortems didn't look dangerous in the PR. Because they don't live in the code. They live in the running app. We wrote about the class of issues a diff can't catch: projectdiscovery.io/blog/continu...
Continuous PR Security Review — ProjectDiscovery Blog
The security findings that end up in incident post-mortems rarely looked dangerous in the PR that introduced them. Not because anyone was careless but because there's nothing in the change that looks ...
projectdiscovery.io
According to Rishi Sharma, CEO & Co-Founder of Project Discovery, the bottleneck in security isn't finding vulnerabilities. It's fixing them. Listen to Rishi on @VentureWithKyle to break down why AI-assisted detection is outpacing remediation: podcasts.apple.com/us/podcast/p...
Project Discovery | CEO Rishi Sharma on AI Disruption in Software Exploitation
Podcast Episode · Secure Ventures with Kyle McNulty · June 2 · 44m
podcasts.apple.com
Stop drowning in massive vulnerability backlogs filled with false positives. Neo integrates with tracking programs like Jira, Linear or Slack to ingest findings and triage them by thinking like a real attacker. https://projectdiscovery.io/request-demo #Neo #AISecurityEngineer
AI is helping devs ship faster than ever, but only 38% of security teams say they're keeping up. Our CEO on the widening gap between engineering and security, and how to close it without slowing anyone down 👇 www.devopsdigest.com/ai-is-causin...
AI Is Causing Security and Development Teams to Drift Further Apart | DEVOPSdigest
AI-assisted coding is accelerating software delivery, but security was built for a world where engineering shipped on a predictable cadence. That world is gone. As code volume surges, the current mode...
devopsdigest.com
Using Neo, you can perform granular tasks like attack surface mapping or vulnerability identification which leads to deeper, high-quality findings. https://projectdiscovery.io/request-demo
Tomorrow, our CEO and Founding SE are live from San Francisco. Nuclei's origin story, how Neo handles evals and long-running workflows, plus the practitioner questions we never have enough time to answer. ⏳ Grab your spot → 10 AM PT / 1 PM ET. Register: https://bit.ly/48ZQI0t
Don't run Nuclei on your printers. (People have learned this the hard way.) Our CEO @ehrishiraj + @todb get into this, the bug bounty program, and how time-to-exploit collapsed, all on runZero Day. Check it out: www.youtube.com/watch?v=798S...
Force multiplied: Community-powered vuln detection
YouTube video by runZero, Inc
youtube.com
Nuclei started as a tool built to solve a problem we lived every day in security. It became the most widely used vulnerability scanner in the world. On May 20th, we're going live to talk about how that happened and where the industry is heading. 10 AM PT / 1 PM ET. https://bit.ly/48ZQI0t