Sign in

ProjectDiscovery

@projectdiscovery.bsky.social
48 followers 20 following 177 posts

Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.

PostsRepliesMedia
ProjectDiscovery @projectdiscovery.bsky.social · 24/09/2026
🚨 CVE-2026-87902: WordPress remote code execution. Discover every WordPress site you run and see which ones are exploitable. Try for free with Neo: neo.projectdiscovery.io/sign-up?utm_... "Find my WordPress sites and test them for CVE-2026-87902. Ask me for my domains, CIDRs, or ASNs."
000
ProjectDiscovery @projectdiscovery.bsky.social · 15/09/2026
Factorial's cloud footprint grew faster than their security team could track by hand. Neo now scans their full external surface daily, and their researchers spend time on novel findings instead of toil. New case study on how they got there → bit.ly/3SQydqq
000
ProjectDiscovery @projectdiscovery.bsky.social · 09/09/2026
Every other week, we host 30-minute episodes of our Neo webinar series, Plugged In. Register once and you're set for the whole series. Tomorrow, September 9th at 10 AM PT / 1 PM ET, we're covering how to spend your credits wisely. Hope you can join us: bit.ly/4qY5DzQ
000
ProjectDiscovery @projectdiscovery.bsky.social · 03/09/2026
Confirmed findings with a working proof of concept. That's what a good night's rest looks like for Emma Sleep's security team 😴
000
ProjectDiscovery @projectdiscovery.bsky.social · 02/09/2026
There's an emerging gap between the amount of AI-generated code and security team capacity. Check out our co-founder's latest interview for his take on how we close the gap → bit.ly/4yg0DJe
bit.ly
Code Smells and Verification Gaps – Communications of the ACM
000
ProjectDiscovery @projectdiscovery.bsky.social · 31/08/2026
Benchmark scores are a false flag. We ran open and closed models against 54 black-box web targets with no hints or source code, then read every run by hand. We'll uncover findings live on Tuesday, September 8th at 10 AM PT / 1 PM ET. Register: bit.ly/3SCK6QC
000
ProjectDiscovery @projectdiscovery.bsky.social · 06/08/2026
Nuclei, httpx, and subfinder got you this far. Neo takes it further, same tools, same team, running at scale. For the hackers of the world. Try it yourself → neo.projectdiscovery.io/sign-up
000
ProjectDiscovery @projectdiscovery.bsky.social · 27/07/2026
Try it here 👇
github.com
GitHub - projectdiscovery/depx: Malicious package & supply-chain intelligence
Malicious package & supply-chain intelligence. Contribute to projectdiscovery/depx development by creating an account on GitHub.
000
ProjectDiscovery @projectdiscovery.bsky.social · 27/07/2026
Pipe your dependency list into depx before you run install. One shortlist, one command, a verdict on every package across npm, PyPI, Go, Cargo, and RubyGems in a single pass.
110
ProjectDiscovery @projectdiscovery.bsky.social · 25/07/2026
Neo reduces false positives by 90% and outperforms traditional scanners in speed, accuracy, and context awareness making it a much better choice over traditional tools. Try Neo → projectdiscovery.io/request-demo Check out the full video → www.youtube.com/watch?v=RsR7pPMDLEE
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/07/2026
Try it here 👇
github.com
GitHub - projectdiscovery/depx: Malicious package & supply-chain intelligence
Malicious package & supply-chain intelligence. Contribute to projectdiscovery/depx development by creating an account on GitHub.
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/07/2026
Check out our latest tool, depx! Seven days of malicious packages, pulled straight from OpenSSF's database and a live feed refreshed hourly. One command replaces manual advisory tracking. You see a compromised package the day it's flagged, not after it's already in a lockfile.
100
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
For Neo, we built a pipeline where multiple agents constantly test your attack surface. If an assessment comes up empty or hits a false positive, the loop automatically re-triggers to dig deeper. The results are incredible. projectdiscovery.io/request-demo youtu.be/RsR7pPMDLEE
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
The first public case of an AI agent hacking into someone else's production. We'd already reproduced this internally, on models 30x smaller. The industry calls it unprecedented. It isn't. Drop your worst agent story below. Full writeup: bit.ly/4gMo73j
bit.ly
Oh My Rogue Agent — ProjectDiscovery Blog
Yesterday, Hugging Face came out saying they'd detected an AI autonomous-agent-powered cyberattack and that they had to use open-source models to actually investigate and remediate it. Later we heard ...
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/07/2026
Annual CVE volume is closing in on 50,000. Most scanners hand you thousands of findings; only a handful matter. Internal Network Scanning brings Nuclei's detection engine inside your network. Skip the backlog, fix a short list in hours. bit.ly/4x05j5y
bit.ly
Introducing Internal Network Scanning: see your network the way an attacker inside it would — ProjectDiscovery Blog
Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Inter...
000
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
Learn more at:
docs.neo.projectdiscovery.io
Welcome to Neo - neo
000
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
6. Architecture and cost optimization are coupled. We could not have shipped a plan → execute → verify pipeline at scale without aggressive prompt caching. Design with token economics in mind from day one. We are not done.
100
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
5. Parallelism belongs at the worker layer. Multiple orchestrators making independent decisions will fight each other. One Execution agent dispatching parallel workers scales better.
100
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
4. Execution and verification are different jobs. An agent optimized to "keep going" is wrong for judging whether to stop. We needed separate prompts, tools, and step budgets for each phase.
210
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
3. Subagents trade context for coordination. Working memory, scoped persistence, handoff envelopes, and transient streaming are not optional polish—they are the glue that makes delegation work.
100
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
2. Split when context or duration breaks. Compaction and truncation are your signals to decouple. Parallelizing before the product explicitly demands it is premature complexity.
100
ProjectDiscovery @projectdiscovery.bsky.social · 21/07/2026
Developing Neo from a single prototype into a multi-agent system taught us six core engineering truths: 1. Start with one agent. You learn the domain faster. Neo’s early months on a single sandbox agent taught us which tools and workflows mattered before we paid the "coordination tax."
100
ProjectDiscovery @projectdiscovery.bsky.social · 20/07/2026
Vegas is where we put Neo in front of the people who've shaped our work for years. We'll be at BSidesLV, Black Hat, and DEF CON Aug 2-7. 🤖 Booth 5108, AI Zone, Black Hat 📣 Two research talks, BSidesLV + DEF CON 🪩 NoiseFest with GreyNoise Thursday night Schedule: bit.ly/4vu4mkB
000
ProjectDiscovery @projectdiscovery.bsky.social · 17/07/2026
How accelerated exploitation HELPS⚡  The quicker you realize that your system is vulnerable (and can be exploited), the quicker you’ll be able to react and fix it. Our CEO shares exactly how we help companies detect vulnerabilities faster. Watch the full interview → youtu.be/798Sy04FM6c
000
ProjectDiscovery @projectdiscovery.bsky.social · 17/07/2026
If you've used an AI agent for recon or vulnerability scanning, there's a good chance LLMs ran our tools in the background. Neo is the harness we’ve built around LLMs and the tools you know and love. See it live at booth 5108, AI Zone, Black Hat. Save your spot with our team: bit.ly/4vu4mkB
100
ProjectDiscovery @projectdiscovery.bsky.social · 16/07/2026
You can build an AI security tool in a weekend. Getting it to prove findings are real at scale is the hard part. We wrote a breakdown of our research, including how prompt caching cut our own LLM costs by more than half. Check out our latest whitepaper to learn more: bit.ly/4bNNNcm
010
ProjectDiscovery @projectdiscovery.bsky.social · 15/07/2026
Link to the full podcast:
podcasts.apple.com
Project Discovery | CEO Rishi Sharma on AI Disruption in Software Exploitation
Podcast Episode · Secure Ventures with Kyle McNulty · June 2 · 44m
000
ProjectDiscovery @projectdiscovery.bsky.social · 15/07/2026
Attackers are now reverse-engineering repositories to exploit vulnerabilities before they are even public, while AI agents are discovering and exploiting zero-days in a continuous loop.
100
ProjectDiscovery @projectdiscovery.bsky.social · 15/07/2026
Exploitation speed has reached record highs, with the window between CVE announcement and attack shrinking from months to mere hours.
100
ProjectDiscovery @projectdiscovery.bsky.social · 04/07/2026
Neo as a Threat Hunter... We planted some test evidence of a compromise and asked Neo to check if the remote server is compromised, and it found it, along with more findings that we never considered👇
000
ProjectDiscovery @projectdiscovery.bsky.social · 29/06/2026
Can you build an AI security tool in a weekend? Yes. Can you run it for a year? That's the question we're unpacking. Join the conversation: Watch the breakdown: projectdiscovery.io/webinars/build-vs-buy Read the analysis: projectdiscovery.io/whitepapers/build-vs-buy
projectdiscovery.io
Should you build or buy your AI security tool? | ProjectDiscovery
See why building your own AI security tool is easy until the bill arrives. Join our next webinar to see where the build vs. buy math really lands.
000
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
Read the full engineering breakdown here →
projectdiscovery.io
How Neo's Agent Architecture Evolved: From One Agent → Plan, Execute & Verify — ProjectDiscovery Blog
Our first engineering post covered prompt caching, the infrastructure change that made long-running agentic tasks economically viable. That post assumed a multi-step, multi-agent system already existed. It did not exist on day one. When we started building Neo, the product was a single agent with a sandbox and a large toolset. Today, a typical task runs through optional planning, an Execution agent that delegates to parallel specialized subagents, and a verification loop that can re-run w
000
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
3. Verification Phase: A dedicated vulnerability-verifier-agent validates findings, generates PoCs, and strips out false positives before writing results to the database.
100
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
2. Execution Phase: A central orchestrator ("the conductor") delegates hyper-focused tasks to parallel, specialized subagents (recon, sandbox, browser) using structured working memory.
100
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
Here is how the three-phase evolution works: 1. Planning Phase: Neo maps out the entire task, explores multiple paths, and resolves context gaps with the user upfront before executing a single command.
100
ProjectDiscovery @projectdiscovery.bsky.social · 26/06/2026
When we started building Neo, the product was a single agent with sandbox and a large toolset. Today, a typical task runs through optional planning, an Execution agent that delegates to parallel specialized subagents, and a verification loop that can re-run work before the user sees a final answer.
100
ProjectDiscovery @projectdiscovery.bsky.social · 24/06/2026
Building your own AI security tool feels easy until the bill arrives. Token burn climbs with every guarantee you add: validation, dedup, memory. June 30th we run the build vs. buy math live and take one finding from suspicion to verified. 10 AM PT / 1 PM ET → bit.ly/3SjaJcT
000
ProjectDiscovery @projectdiscovery.bsky.social · 24/06/2026
Why is Nuclei so popular? It's simple. Here’s our CEO, Rishi, elaborating on how Nuclei’s simplicity solves crucial exploitation problems Watch the full video → youtu.be/798Sy04FM6c?si=vZg59NBOajq…
000
ProjectDiscovery @projectdiscovery.bsky.social · 23/06/2026
SSH into your server with Neo to further your capabilities 👇 Neo can use remote connection and the commands will now run in the remote device instead of Neo sandbox.
010
ProjectDiscovery @projectdiscovery.bsky.social · 23/06/2026
"Hash matching is pointless. Defenders must go fully behavioral and use AI themselves to catch such malware." Our research lead @princechaddha in @IEEESpectrum on why vibecoded malware breaks traditional detection... and what actually works now. spectrum.ieee.org/vibecoding-m...
spectrum.ieee.org
How Did Two Prompts Turn Into Potent Vibe Hacking Malware
“Vibeware” is forcing new anti-malware strategies
053
ProjectDiscovery @projectdiscovery.bsky.social · 22/06/2026
Link to the full podcast:
podcasts.apple.com
Project Discovery | CEO Rishi Sharma on AI Disruption in Software Exploitation
Podcast Episode · Secure Ventures with Kyle McNulty · June 2 · 44m
000
ProjectDiscovery @projectdiscovery.bsky.social · 22/06/2026
Is there an existential threat to ProjectDiscovery? We aren’t buying into the AI "psychosis" or "apocalypse" narrative. Instead, our focus remains on ensuring we consistently deliver high value to the security community. Staying ahead means moving faster.
100
ProjectDiscovery @projectdiscovery.bsky.social · 22/06/2026
Everyone in security is asking the same question: can't we just use Claude Code for this? We ran the experiment so you don't have to. We are joining @DarkReading on Thursday to show what that gap actually looks like and demo it live. Join us! Register: dr-resources.darkreading.com/c/pubRD.mpl?...
dr-resources.darkreading.com
Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack, Free ProjectDiscovery Webinar
Free Webinar to Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack Thurs, June 25, 2026, at 1pm EST
000
ProjectDiscovery @projectdiscovery.bsky.social · 18/06/2026
In 2018, the average vulnerability took 63 days to get exploited after disclosure. In 2024, that number went negative. Attackers are weaponizing bugs before they're even public. We pulled 8 years of CVE data to show exactly when the curve broke. projectdiscovery.io/blog/the-vul...
projectdiscovery.io
The Vulnerability Curve Bent With the AI Curve — ProjectDiscovery Blog
How CVE volume, known-exploited counts and time-to-exploit all changed shape across the LLM build-out and why defenders are now on the wrong side of the clock. In 2018 the world published about 18,00...
000
ProjectDiscovery @projectdiscovery.bsky.social · 15/06/2026
The vulnerabilities that end up in incident post-mortems didn't look dangerous in the PR. Because they don't live in the code. They live in the running app. We wrote about the class of issues a diff can't catch: projectdiscovery.io/blog/continu...
projectdiscovery.io
Continuous PR Security Review — ProjectDiscovery Blog
The security findings that end up in incident post-mortems rarely looked dangerous in the PR that introduced them. Not because anyone was careless but because there's nothing in the change that looks ...
010
ProjectDiscovery @projectdiscovery.bsky.social · 05/06/2026
According to Rishi Sharma, CEO & Co-Founder of Project Discovery, the bottleneck in security isn't finding vulnerabilities. It's fixing them. Listen to Rishi on @VentureWithKyle to break down why AI-assisted detection is outpacing remediation: podcasts.apple.com/us/podcast/p...
podcasts.apple.com
Project Discovery | CEO Rishi Sharma on AI Disruption in Software Exploitation
Podcast Episode · Secure Ventures with Kyle McNulty · June 2 · 44m
010
ProjectDiscovery @projectdiscovery.bsky.social · 28/05/2026
Stop drowning in massive vulnerability backlogs filled with false positives. Neo integrates with tracking programs like Jira, Linear or Slack to ingest findings and triage them by thinking like a real attacker. projectdiscovery.io/request-demo #Neo #AISecurityEngineer
000
ProjectDiscovery @projectdiscovery.bsky.social · 28/05/2026
AI is helping devs ship faster than ever, but only 38% of security teams say they're keeping up. Our CEO on the widening gap between engineering and security, and how to close it without slowing anyone down 👇 www.devopsdigest.com/ai-is-causin...
devopsdigest.com
AI Is Causing Security and Development Teams to Drift Further Apart | DEVOPSdigest
AI-assisted coding is accelerating software delivery, but security was built for a world where engineering shipped on a predictable cadence. That world is gone. As code volume surges, the current mode...
010
ProjectDiscovery @projectdiscovery.bsky.social · 20/05/2026
Using Neo, you can perform granular tasks like attack surface mapping or vulnerability identification which leads to deeper, high-quality findings. projectdiscovery.io/request-demo
010
ProjectDiscovery @projectdiscovery.bsky.social · 19/05/2026
Tomorrow, our CEO and Founding SE are live from San Francisco. Nuclei's origin story, how Neo handles evals and long-running workflows, plus the practitioner questions we never have enough time to answer. ⏳ Grab your spot → 10 AM PT / 1 PM ET. Register: bit.ly/48ZQI0t
000