Semgrep

@semgrep.com

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

Will AI replace AppSec teams? 👀 In the latest episode of Security Rulez, our Security Advocate Dr. Katie Paxton-Fear (@InsiderPhD) sat down with Anshuman Bhartiya (Tech Lead at Lyft) to tackle this exact question. 👇

"AI agents are writing code so fast, we can't keep up with the security debt." 🫠 We have the solution: A plugin that lives in your IDE, detecting and resolving the vulnerabilities, malicious packages, and hardcoded secrets before a PR is ever opened.

Bild

mbt@1.2.48 and @cap-js/sqlite@2.2.2 are malicious. preinstall hook → fetches Bun runtime → executes obfuscated payload → exfils GitHub/npm/AWS/Azure/GCP/k8s secrets → writes to attacker-controlled GitHub repos with description "A Mini Shai-Hulud Has Appeared" we pushed rules for customers

Bild

This hack week some of us are building new features, others are writing talks, and some people are doing gods work. That big rock? Verified commits.

Rule writing: Whenever possible, avoid leading ellipsis patterns (These patterns cause the engine to perform exhaustive searches and are quite slow, we have rules for this) BAD ... <- VERY BAD DO NOT DO THIS $X = someFunc(...) ... GOOD someOtherFunc($X) ...

Bild

Here at Semgrep HQ our engineers are all in SF for our annual HackWeek so this is the Semgrep #EngineeringTakeover we've hacked the social accounts, we've locked out the marketing team and all posts going forward will be by engineers sorry, not sorry

Bild

Why are so many organizations still hesitant to truly experiment with AI security? Our Security Advocate, Dr. Katie Paxton-Fear, has the answer👇

Detect hard-coded JWT secrets in your Express.js codebase! Run: semgrep scan --config express-jwt-hardcoded-secret.yml ./src This rule catches risky credential patterns that could expose your authentication.

Bild

Want to better understand the Semgrep Multimodal approach? Rick Harp, Senior Solutions Engineer, explains what it is and how it’s different from other static analysis tools. 👇

Is your AppSec team scaling at the speed of AI, or are they still running on human-only hours? 🛡️ The timing is critical for two reasons.👇

If your team is leaning into "vibe coding" or heavy LLM usage, you need a strategy to ensure that speed doesn't turn into a liability. Here are four essential principles for securing AI-generated code👇

Bild

Want to scan your entire codebase without touching a single CI/CD file? 🛡️ In this quick walkthrough, we show you how to scale security across your repos in minutes using Semgrep Managed Scans. No manual config, just results.👇 #AppSec #SecureCode

Imagine an AI that reasons like a security engineer with the context of your lead developer.  Semgrep’s retrieval systems give any LLM the repo-specific nuance it needs to be reliable.👇 #AppSec

We provide secure coding feedback where it matters most: on the dev's screen. Faster feedback = less exploitable software, less frustration from devs and less time wasted.

If a vulnerable function in your supply chain isn’t reachable, it shouldn’t derail your sprint. If it *is* reachable, you need it at the top of the queue. Semgrep helps teams figure this out quickly so that remediation is efficient.

$ semgrep init --year 2026 [INFO] Initializing Future... [OK] [INFO] Deploying: Secure_Code.v2026 [SUCCESS] [WARN] Challenges: Loading...  Welcome to 2026❇️

Leave false positives in 2025. Imagine 2026: An AppSec world with zero noise and 100% developer trust. By leveraging the Semgrep platform, you can silence the friction of irrelevant alerts and focus on what actually matters ➡️ shipping secure code. 🌀Learn how we’re doing it: https://semgrep.dev/

59% of developers still don’t trust AI tools to handle security. With "vibe-coding" skyrocketing, even a small error rate creates a massive wave of new vulnerabilities. At Semgrep, we’re bridging that trust gap. #AppSec #AI #DevSecOps

In the world of "vibe coding," agents are powerful but they aren’t secure. Semgrep x Cursor Hooks changes that. Using Cursor Hooks allows AI agents to run and test code safely in their own environment, identifying vulnerabilities and applying fixes before you ever see the code.

Bild

That’s a wrap on Black Hat Europe 🇬🇧 Huge thank you to everyone who stopped by Booth #816 and to everyone who joined us at our events! We’re heading home feeling genuinely grateful for this community. Thanks for the great conversations, thoughtful questions, and good energy. Until next time! 👋

BildBildBildBild