Sign in

ProjectDiscovery

@projectdiscovery.bsky.social
47 followers 20 following 177 posts

Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.

PostsRepliesMedia
ProjectDiscovery @projectdiscovery.bsky.social · 24/09/2026
🚨 CVE-2026-87902: WordPress remote code execution. Discover every WordPress site you run and see which ones are exploitable. Try for free with Neo: neo.projectdiscovery.io/sign-up?utm_... "Find my WordPress sites and test them for CVE-2026-87902. Ask me for my domains, CIDRs, or ASNs."
000
ProjectDiscovery @projectdiscovery.bsky.social · 15/09/2026
Factorial's cloud footprint grew faster than their security team could track by hand. Neo now scans their full external surface daily, and their researchers spend time on novel findings instead of toil. New case study on how they got there → bit.ly/3SQydqq
000
ProjectDiscovery @projectdiscovery.bsky.social · 09/09/2026
Every other week, we host 30-minute episodes of our Neo webinar series, Plugged In. Register once and you're set for the whole series. Tomorrow, September 9th at 10 AM PT / 1 PM ET, we're covering how to spend your credits wisely. Hope you can join us: bit.ly/4qY5DzQ
000
ProjectDiscovery @projectdiscovery.bsky.social · 03/09/2026
Confirmed findings with a working proof of concept. That's what a good night's rest looks like for Emma Sleep's security team 😴
000
ProjectDiscovery @projectdiscovery.bsky.social · 02/09/2026
There's an emerging gap between the amount of AI-generated code and security team capacity. Check out our co-founder's latest interview for his take on how we close the gap → bit.ly/4yg0DJe
bit.ly
Code Smells and Verification Gaps – Communications of the ACM
000
ProjectDiscovery @projectdiscovery.bsky.social · 31/08/2026
Benchmark scores are a false flag. We ran open and closed models against 54 black-box web targets with no hints or source code, then read every run by hand. We'll uncover findings live on Tuesday, September 8th at 10 AM PT / 1 PM ET. Register: bit.ly/3SCK6QC
000
ProjectDiscovery @projectdiscovery.bsky.social · 06/08/2026
Nuclei, httpx, and subfinder got you this far. Neo takes it further, same tools, same team, running at scale. For the hackers of the world. Try it yourself → neo.projectdiscovery.io/sign-up
000
ProjectDiscovery @projectdiscovery.bsky.social · 27/07/2026
Pipe your dependency list into depx before you run install. One shortlist, one command, a verdict on every package across npm, PyPI, Go, Cargo, and RubyGems in a single pass.
110
ProjectDiscovery @projectdiscovery.bsky.social · 25/07/2026
Neo reduces false positives by 90% and outperforms traditional scanners in speed, accuracy, and context awareness making it a much better choice over traditional tools. Try Neo → projectdiscovery.io/request-demo Check out the full video → www.youtube.com/watch?v=RsR7pPMDLEE
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/07/2026
Check out our latest tool, depx! Seven days of malicious packages, pulled straight from OpenSSF's database and a live feed refreshed hourly. One command replaces manual advisory tracking. You see a compromised package the day it's flagged, not after it's already in a lockfile.
100
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
For Neo, we built a pipeline where multiple agents constantly test your attack surface. If an assessment comes up empty or hits a false positive, the loop automatically re-triggers to dig deeper. The results are incredible. projectdiscovery.io/request-demo youtu.be/RsR7pPMDLEE
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
The first public case of an AI agent hacking into someone else's production. We'd already reproduced this internally, on models 30x smaller. The industry calls it unprecedented. It isn't. Drop your worst agent story below. Full writeup: bit.ly/4gMo73j
bit.ly
Oh My Rogue Agent — ProjectDiscovery Blog
Yesterday, Hugging Face came out saying they'd detected an AI autonomous-agent-powered cyberattack and that they had to use open-source models to actually investigate and remediate it. Later we heard ...
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
Annual CVE volume is closing in on 50,000. Most scanners hand you thousands of findings; only a handful matter. Internal Network Scanning brings Nuclei's detection engine inside your network. Skip the backlog, fix a short list in hours. bit.ly/4x05j5y
bit.ly
Introducing Internal Network Scanning: see your network the way an attacker inside it would — ProjectDiscovery Blog
Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Inter...
000
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
Developing Neo from a single prototype into a multi-agent system taught us six core engineering truths: 1. Start with one agent. You learn the domain faster. Neo’s early months on a single sandbox agent taught us which tools and workflows mattered before we paid the "coordination tax."
100
ProjectDiscovery @projectdiscovery.bsky.social · 20/07/2026
Vegas is where we put Neo in front of the people who've shaped our work for years. We'll be at BSidesLV, Black Hat, and DEF CON Aug 2-7. 🤖 Booth 5108, AI Zone, Black Hat 📣 Two research talks, BSidesLV + DEF CON 🪩 NoiseFest with GreyNoise Thursday night Schedule: bit.ly/4vu4mkB
000
ProjectDiscovery @projectdiscovery.bsky.social · 17/07/2026
How accelerated exploitation HELPS⚡  The quicker you realize that your system is vulnerable (and can be exploited), the quicker you’ll be able to react and fix it. Our CEO shares exactly how we help companies detect vulnerabilities faster. Watch the full interview → youtu.be/798Sy04FM6c
000
ProjectDiscovery @projectdiscovery.bsky.social · 17/07/2026
If you've used an AI agent for recon or vulnerability scanning, there's a good chance LLMs ran our tools in the background. Neo is the harness we’ve built around LLMs and the tools you know and love. See it live at booth 5108, AI Zone, Black Hat. Save your spot with our team: bit.ly/4vu4mkB
100
ProjectDiscovery @projectdiscovery.bsky.social · 16/07/2026
You can build an AI security tool in a weekend. Getting it to prove findings are real at scale is the hard part. We wrote a breakdown of our research, including how prompt caching cut our own LLM costs by more than half. Check out our latest whitepaper to learn more: bit.ly/4bNNNcm
010
ProjectDiscovery @projectdiscovery.bsky.social · 15/07/2026
Exploitation speed has reached record highs, with the window between CVE announcement and attack shrinking from months to mere hours.
100
ProjectDiscovery @projectdiscovery.bsky.social · 04/07/2026
Neo as a Threat Hunter... We planted some test evidence of a compromise and asked Neo to check if the remote server is compromised, and it found it, along with more findings that we never considered👇
000
ProjectDiscovery @projectdiscovery.bsky.social · 29/06/2026
Can you build an AI security tool in a weekend? Yes. Can you run it for a year? That's the question we're unpacking. Join the conversation: Watch the breakdown: projectdiscovery.io/webinars/build-vs-buy Read the analysis: projectdiscovery.io/whitepapers/build-vs-buy
projectdiscovery.io
Should you build or buy your AI security tool? | ProjectDiscovery
See why building your own AI security tool is easy until the bill arrives. Join our next webinar to see where the build vs. buy math really lands.
000
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
When we started building Neo, the product was a single agent with sandbox and a large toolset. Today, a typical task runs through optional planning, an Execution agent that delegates to parallel specialized subagents, and a verification loop that can re-run work before the user sees a final answer.
100
ProjectDiscovery @projectdiscovery.bsky.social · 24/06/2026
Building your own AI security tool feels easy until the bill arrives. Token burn climbs with every guarantee you add: validation, dedup, memory. June 30th we run the build vs. buy math live and take one finding from suspicion to verified. 10 AM PT / 1 PM ET → bit.ly/3SjaJcT
000
ProjectDiscovery @projectdiscovery.bsky.social · 24/06/2026
Why is Nuclei so popular? It's simple. Here’s our CEO, Rishi, elaborating on how Nuclei’s simplicity solves crucial exploitation problems Watch the full video → youtu.be/798Sy04FM6c?si=vZg59NBOajq…
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/06/2026
SSH into your server with Neo to further your capabilities 👇 Neo can use remote connection and the commands will now run in the remote device instead of Neo sandbox.
010
ProjectDiscovery @projectdiscovery.bsky.social · 23/06/2026
"Hash matching is pointless. Defenders must go fully behavioral and use AI themselves to catch such malware." Our research lead @princechaddha in @IEEESpectrum on why vibecoded malware breaks traditional detection... and what actually works now. spectrum.ieee.org/vibecoding-m...
spectrum.ieee.org
How Did Two Prompts Turn Into Potent Vibe Hacking Malware
“Vibeware” is forcing new anti-malware strategies
053
ProjectDiscovery @projectdiscovery.bsky.social · 22/06/2026
Is there an existential threat to ProjectDiscovery? We aren’t buying into the AI "psychosis" or "apocalypse" narrative. Instead, our focus remains on ensuring we consistently deliver high value to the security community. Staying ahead means moving faster.
100
ProjectDiscovery @projectdiscovery.bsky.social · 22/06/2026
Everyone in security is asking the same question: can't we just use Claude Code for this? We ran the experiment so you don't have to. We are joining @DarkReading on Thursday to show what that gap actually looks like and demo it live. Join us! Register: dr-resources.darkreading.com/c/pubRD.mpl?...
dr-resources.darkreading.com
Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack, Free ProjectDiscovery Webinar
Free Webinar to Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack Thurs, June 25, 2026, at 1pm EST
000
ProjectDiscovery @projectdiscovery.bsky.social · 18/06/2026
In 2018, the average vulnerability took 63 days to get exploited after disclosure. In 2024, that number went negative. Attackers are weaponizing bugs before they're even public. We pulled 8 years of CVE data to show exactly when the curve broke. projectdiscovery.io/blog/the-vul...
projectdiscovery.io
The Vulnerability Curve Bent With the AI Curve — ProjectDiscovery Blog
How CVE volume, known-exploited counts and time-to-exploit all changed shape across the LLM build-out and why defenders are now on the wrong side of the clock. In 2018 the world published about 18,00...
000
ProjectDiscovery @projectdiscovery.bsky.social · 15/06/2026
The vulnerabilities that end up in incident post-mortems didn't look dangerous in the PR. Because they don't live in the code. They live in the running app. We wrote about the class of issues a diff can't catch: projectdiscovery.io/blog/continu...
projectdiscovery.io
Continuous PR Security Review — ProjectDiscovery Blog
The security findings that end up in incident post-mortems rarely looked dangerous in the PR that introduced them. Not because anyone was careless but because there's nothing in the change that looks ...
010
ProjectDiscovery @projectdiscovery.bsky.social · 05/06/2026
According to Rishi Sharma, CEO & Co-Founder of Project Discovery, the bottleneck in security isn't finding vulnerabilities. It's fixing them. Listen to Rishi on @VentureWithKyle to break down why AI-assisted detection is outpacing remediation: podcasts.apple.com/us/podcast/p...
podcasts.apple.com
Project Discovery | CEO Rishi Sharma on AI Disruption in Software Exploitation
Podcast Episode · Secure Ventures with Kyle McNulty · June 2 · 44m
010
ProjectDiscovery @projectdiscovery.bsky.social · 28/05/2026
Stop drowning in massive vulnerability backlogs filled with false positives. Neo integrates with tracking programs like Jira, Linear or Slack to ingest findings and triage them by thinking like a real attacker. projectdiscovery.io/request-demo #Neo #AISecurityEngineer
000
ProjectDiscovery @projectdiscovery.bsky.social · 28/05/2026
AI is helping devs ship faster than ever, but only 38% of security teams say they're keeping up. Our CEO on the widening gap between engineering and security, and how to close it without slowing anyone down 👇 www.devopsdigest.com/ai-is-causin...
devopsdigest.com
AI Is Causing Security and Development Teams to Drift Further Apart | DEVOPSdigest
AI-assisted coding is accelerating software delivery, but security was built for a world where engineering shipped on a predictable cadence. That world is gone. As code volume surges, the current mode...
010
ProjectDiscovery @projectdiscovery.bsky.social · 20/05/2026
Using Neo, you can perform granular tasks like attack surface mapping or vulnerability identification which leads to deeper, high-quality findings. projectdiscovery.io/request-demo
010
ProjectDiscovery @projectdiscovery.bsky.social · 19/05/2026
Tomorrow, our CEO and Founding SE are live from San Francisco. Nuclei's origin story, how Neo handles evals and long-running workflows, plus the practitioner questions we never have enough time to answer. ⏳ Grab your spot → 10 AM PT / 1 PM ET. Register: bit.ly/48ZQI0t
000
ProjectDiscovery @projectdiscovery.bsky.social · 19/05/2026
Don't run Nuclei on your printers. (People have learned this the hard way.) Our CEO @ehrishiraj + @todb get into this, the bug bounty program, and how time-to-exploit collapsed, all on runZero Day. Check it out: www.youtube.com/watch?v=798S...
youtube.com
Force multiplied: Community-powered vuln detection
YouTube video by runZero, Inc
010
ProjectDiscovery @projectdiscovery.bsky.social · 13/05/2026
Nuclei started as a tool built to solve a problem we lived every day in security. It became the most widely used vulnerability scanner in the world. On May 20th, we're going live to talk about how that happened and where the industry is heading. 10 AM PT / 1 PM ET. bit.ly/48ZQI0t
011
ProjectDiscovery @projectdiscovery.bsky.social · 12/05/2026
ProjectDiscovery has been named to @NotableCap's Rising in Cyber 2026 — 30 companies, voted by 150 CISOs. Humbled to stand alongside this year's honorees and the alumni who came before us. To our community: this one's yours. 🧡 www.notablecap.com/risingincyber
000
ProjectDiscovery @projectdiscovery.bsky.social · 27/04/2026
We surveyed 200 security practitioners and found that 66% spend the majority of their week validating findings rather than fixing them. AI is shipping code faster. Security is not keeping up. Full report here: projectdiscovery.io/research/ai-...
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/04/2026
66% of security practitioners spend more than half their week validating findings. Not fixing them. Validating them. Engineering is shipping faster. The tools aren't keeping up. The gap lands on the security team. Full findings: projectdiscovery.io/research/ai-...
projectdiscovery.io
ProjectDiscovery's 2026 AI Coding Impact Report
We surveyed 200 cybersecurity practitioners on AI-assisted coding. Engineering ships faster than ever — and security teams are feeling every bit of it.
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/04/2026
New research. 200 cybersecurity practitioners. North America and Western Europe. All using AI-assisted coding. 100% say engineering is shipping faster. 49% credit AI-assisted coding. Only 38% feel their security team is keeping up. Full findings: projectdiscovery.io/research/ai-...
010
ProjectDiscovery @projectdiscovery.bsky.social · 10/04/2026
We cut LLM costs by 59% with prompt caching on Neo. Key moves: → 3 breakpoints with deliberate TTLs → Moved dynamic content out of the prefix to the tail → Stable templates, byte-identical across all users 7% to 84% cache hit rate. Full breakdown: projectdiscovery.io/blog/how-we-...
projectdiscovery.io
How We Cut LLM Costs by 59% With Prompt Caching — ProjectDiscovery Blog
At ProjectDiscovery, we've been building Neo, an autonomous security testing platform that runs multi-agent, multi-step workflows, routinely executing 20-40+ LLM steps per task. Vulnerability assessments, code reviews, and security audits at scale, enabling continuous testing across the entire development lifecycle. When we launched, our LLM costs were staggering. A single complex task with Opus 4.5 could consume 60 million tokens. Then we implemented prompt caching. Here's what changed:
000
ProjectDiscovery @projectdiscovery.bsky.social · 08/04/2026
Everyone in security is asking, "Can't we just use Claude Code?" We tried so you don't have to. Join us April 16th at 1 PM EST to see where the execution gap shows up, and what it takes to close it. Register 👉 bit.ly/4cm1QFQ
000
ProjectDiscovery @projectdiscovery.bsky.social · 03/04/2026
Last month, we shipped: ▪️ Prompt Library with public, private, and team-scoped prompts ▪️ A community Showcase of popular security tasks ▪️ BYOK model gateway for Anthropic, OpenAI, Google, xAI, and Openrouter ▪️ New model support ▪️ Runtime skills discovery Try Neo here: bit.ly/4bZfhuO
000
ProjectDiscovery @projectdiscovery.bsky.social · 24/03/2026
We just launched Neo, a security testing platform that proves vulnerabilities, not just reports them. www.prnewswire.com/news-release... At #RSAC? Try it live at Booth #3131 → projectdiscovery.io/events/rsac-...
prnewswire.com
ProjectDiscovery Launches Neo, an Advanced Security Testing Platform That Finds and Proves Real Vulnerabilities
/PRNewswire/ -- ProjectDiscovery, winner of the 2025 RSAC Innovation Sandbox, today announced the commercial launch of Neo, an advanced security testing...
000
ProjectDiscovery @projectdiscovery.bsky.social · 20/03/2026
Finding vulns is getting easier. Proving them is still the hard part. We ran Neo against popular open source repos and got back 22 confirmed CVEs, each with working exploits and real evidence. New blog breaks down 5 of the most interesting findings 👉 projectdiscovery.io/blog/everyon...
projectdiscovery.io
Everyone is finding vulns. The hard part is proving them. — ProjectDiscovery Blog
LLMs are a genuine leap forward for vulnerability discovery. Anthropic reported 500+ zero-days from Opus 4.6 and OpenAI's Codex Security discovered 14 CVEs across projects like OpenSSH and GnuTLS. If ...
000
ProjectDiscovery @projectdiscovery.bsky.social · 19/03/2026
Rishi on Daniel Miessler's Unsupervised Learning: "False positives aren’t an AI problem. They’re a validation problem." www.youtube.com/watch?v=RsR7... Neo separates detection from validation to reduce false positives by 90+% At RSAC next week? Meet Rishi & try Neo hands-on at booth 3131.
youtube.com
A Conversation With Rishi Sharma
YouTube video by Unsupervised Learning
000
ProjectDiscovery @projectdiscovery.bsky.social · 16/03/2026
This is exactly the kind of content we love to see 🙌 Watching @nahamsec.bsky.social dig into AI hacking recon in real time is a masterclass. Honored that Neo has earned a spot in his pentest toolkit. If you're into AI security, this series is one to follow 👇 youtu.be/dG6NFXQOmsE?...
youtu.be
BECOMING AN AI HACKER (Episode 01)
YouTube video by NahamSec
001
ProjectDiscovery @projectdiscovery.bsky.social · 11/03/2026
We benchmarked Neo, Claude Code, Invicti, and Snyk against 3 AI-generated apps (banking, healthcare, insurance) — 74 confirmed vulns total. Full walkthroughs, results + open-source benchmark data 👇 projectdiscovery.io/blog/inside-...
000
ProjectDiscovery @projectdiscovery.bsky.social · 10/03/2026
Tired of dealing with duplicate results in your scans? 𝚑𝚝𝚝𝚙𝚡 has a feature for that: Filter Duplicates Tag!🌀 It allows you to filter duplicates as you scan, saving you time and giving you cleaner results. See how it works 👇
youtu.be
ProjectDiscovery Tips and Tricks - Filter Duplicates Tag!
As we get into 2025, we're back with another PD Tips and Tricks video to help improve your workflow. This time, we're focusing on a cool feature of httpx tha...
000