Will AI replace AppSec teams? 👀 In the latest episode of Security Rulez, our Security Advocate Dr. Katie Paxton-Fear (@InsiderPhD) sat down with Anshuman Bhartiya (Tech Lead at Lyft) to tackle this exact question. 👇
Semgrep
@semgrep.com
Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.
"AI agents are writing code so fast, we can't keep up with the security debt." 🫠 We have the solution: A plugin that lives in your IDE, detecting and resolving the vulnerabilities, malicious packages, and hardcoded secrets before a PR is ever opened.
mbt@1.2.48 and @cap-js/sqlite@2.2.2 are malicious. preinstall hook → fetches Bun runtime → executes obfuscated payload → exfils GitHub/npm/AWS/Azure/GCP/k8s secrets → writes to attacker-controlled GitHub repos with description "A Mini Shai-Hulud Has Appeared" we pushed rules for customers
PLEASE DON'T enable subcategory: - audit rules if you only want confirmed vulnerabilities, these are noisy by design! #EngineeringTakeover
This hack week some of us are building new features, others are writing talks, and some people are doing gods work. That big rock? Verified commits.
For years engineers wanted, and now they have it, everyone rejoices. Semgrep has a mobile rules editor #EngineeringTakeover
Rule writing: Whenever possible, avoid leading ellipsis patterns (These patterns cause the engine to perform exhaustive searches and are quite slow, we have rules for this) BAD ... <- VERY BAD DO NOT DO THIS $X = someFunc(...) ... GOOD someOtherFunc($X) ...
Here at Semgrep HQ our engineers are all in SF for our annual HackWeek so this is the Semgrep #EngineeringTakeover we've hacked the social accounts, we've locked out the marketing team and all posts going forward will be by engineers sorry, not sorry
Why are so many organizations still hesitant to truly experiment with AI security? Our Security Advocate, Dr. Katie Paxton-Fear, has the answer👇
Detect hard-coded JWT secrets in your Express.js codebase! Run: semgrep scan --config express-jwt-hardcoded-secret.yml ./src This rule catches risky credential patterns that could expose your authentication.
Want to better understand the Semgrep Multimodal approach? Rick Harp, Senior Solutions Engineer, explains what it is and how it’s different from other static analysis tools. 👇
Is your AppSec team scaling at the speed of AI, or are they still running on human-only hours? 🛡️ The timing is critical for two reasons.👇
AI-native assistants don't automatically understand your unique security practices during code development. Custom Guardrails bridge that gap.👇 #AppSec #SecureCode
If your team is leaning into "vibe coding" or heavy LLM usage, you need a strategy to ensure that speed doesn't turn into a liability. Here are four essential principles for securing AI-generated code👇
Want to scan your entire codebase without touching a single CI/CD file? 🛡️ In this quick walkthrough, we show you how to scale security across your repos in minutes using Semgrep Managed Scans. No manual config, just results.👇 #AppSec #SecureCode
Imagine an AI that reasons like a security engineer with the context of your lead developer. Semgrep’s retrieval systems give any LLM the repo-specific nuance it needs to be reliable.👇 #AppSec
We provide secure coding feedback where it matters most: on the dev's screen. Faster feedback = less exploitable software, less frustration from devs and less time wasted.
If a vulnerable function in your supply chain isn’t reachable, it shouldn’t derail your sprint. If it *is* reachable, you need it at the top of the queue. Semgrep helps teams figure this out quickly so that remediation is efficient.
🟢 Semgrep version 1.147.0 is live! Check out all the details here👇 https://github.com/semgrep/semgrep/releases/tag/v1.147.0
We’re just 3 days away from our exclusive boot fitting event at the San Francisco Sports Basement. Attendance is limited and subject to confirmation. RSVP today to get on the list 👇 https://semgrep.dev/events/step-into-ski-season-with-semgrep/
$ semgrep init --year 2026 [INFO] Initializing Future... [OK] [INFO] Deploying: Secure_Code.v2026 [SUCCESS] [WARN] Challenges: Loading... Welcome to 2026❇️
Leave false positives in 2025. Imagine 2026: An AppSec world with zero noise and 100% developer trust. By leveraging the Semgrep platform, you can silence the friction of irrelevant alerts and focus on what actually matters ➡️ shipping secure code. 🌀Learn how we’re doing it: https://semgrep.dev/
59% of developers still don’t trust AI tools to handle security. With "vibe-coding" skyrocketing, even a small error rate creates a massive wave of new vulnerabilities. At Semgrep, we’re bridging that trust gap. #AppSec #AI #DevSecOps
In the world of "vibe coding," agents are powerful but they aren’t secure. Semgrep x Cursor Hooks changes that. Using Cursor Hooks allows AI agents to run and test code safely in their own environment, identifying vulnerabilities and applying fixes before you ever see the code.
Last chance to join us! ⏰ Tomorrow at 9:00 AM PT, @insider.phd (Semgrep) and Aubrey King (F5) will go head-to-head on the industry’s biggest hot takes, from whether AI is actually helping security teams to why developers might not care about security 🔗 semgrep.dev/events/unfil...
That’s a wrap on Black Hat Europe 🇬🇧 Huge thank you to everyone who stopped by Booth #816 and to everyone who joined us at our events! We’re heading home feeling genuinely grateful for this community. Thanks for the great conversations, thoughtful questions, and good energy. Until next time! 👋
On December 16th at 9:00 AM PT, join @insider.phd (Semgrep) and Aubrey King (F5) for a live, unscripted session where they tackle the hot takes practitioners are actually debating. No slides. No scripts. Just two experts digging into the issues shaping 2026. 👉 semgrep.dev/events/unfil...
Huge thank you to everyone who joined us for Security Sundowners on the Sunborn Yacht last night 🛥️🍸 And a big shoutout to our partners who helped make it happen: Tines, Cyera, Sublime Security, and Zenity 🙌 #BlackHatEU #BHEU #AppSec #Cybersecurity #Semgrep
Ready to shape the future of AppSec? We are hiring across Engineering, Sales, and Marketing! Come build with us. 🌀See our open roles: https://semgrep.dev/about/careers/