Sign in

Semgrep

@semgrep.com
248 followers 42 following 503 posts

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

PostsRepliesMedia
Semgrep @semgrep.com · 06/06/2026
Will AI replace AppSec teams? 👀 In the latest episode of Security Rulez, our Security Advocate Dr. Katie Paxton-Fear (@InsiderPhD) sat down with Anshuman Bhartiya (Tech Lead at Lyft) to tackle this exact question. 👇
000
Semgrep @semgrep.com · 05/06/2026
"AI agents are writing code so fast, we can't keep up with the security debt." 🫠 We have the solution: A plugin that lives in your IDE, detecting and resolving the vulnerabilities, malicious packages, and hardcoded secrets before a PR is ever opened.
000
Semgrep @semgrep.com · 29/04/2026
mbt@1.2.48 and @cap-js/sqlite@2.2.2 are malicious. preinstall hook → fetches Bun runtime → executes obfuscated payload → exfils GitHub/npm/AWS/Azure/GCP/k8s secrets → writes to attacker-controlled GitHub repos with description "A Mini Shai-Hulud Has Appeared" we pushed rules for customers
100
Semgrep @semgrep.com · 29/04/2026
PLEASE DON'T enable subcategory: - audit rules if you only want confirmed vulnerabilities, these are noisy by design! #EngineeringTakeover
000
Semgrep @semgrep.com · 29/04/2026
This hack week some of us are building new features, others are writing talks, and some people are doing gods work. That big rock? Verified commits.
000
Semgrep @semgrep.com · 28/04/2026
For years engineers wanted, and now they have it, everyone rejoices. Semgrep has a mobile rules editor #EngineeringTakeover
000
Semgrep @semgrep.com · 28/04/2026
Rule writing: Whenever possible, avoid leading ellipsis patterns (These patterns cause the engine to perform exhaustive searches and are quite slow, we have rules for this) BAD ... <- VERY BAD DO NOT DO THIS $X = someFunc(...) ... GOOD someOtherFunc($X) ...
010
Semgrep @semgrep.com · 28/04/2026
"Give the people what they want and they want Semgrepio" #EngineeringTakeover
000
Semgrep @semgrep.com · 27/04/2026
Here at Semgrep HQ our engineers are all in SF for our annual HackWeek so this is the Semgrep #EngineeringTakeover we've hacked the social accounts, we've locked out the marketing team and all posts going forward will be by engineers sorry, not sorry
010
Semgrep @semgrep.com · 05/04/2026
Why are so many organizations still hesitant to truly experiment with AI security? Our Security Advocate, Dr. Katie Paxton-Fear, has the answer👇
000
Semgrep @semgrep.com · 03/04/2026
Detect hard-coded JWT secrets in your Express.js codebase! Run: semgrep scan --config express-jwt-hardcoded-secret.yml ./src This rule catches risky credential patterns that could expose your authentication.
000
Semgrep @semgrep.com · 03/04/2026
Want to better understand the Semgrep Multimodal approach? Rick Harp, Senior Solutions Engineer, explains what it is and how it’s different from other static analysis tools. 👇
000
Semgrep @semgrep.com · 16/03/2026
Is your AppSec team scaling at the speed of AI, or are they still running on human-only hours? 🛡️ The timing is critical for two reasons.👇
010
Semgrep @semgrep.com · 09/03/2026
AI-native assistants don't automatically understand your unique security practices during code development. Custom Guardrails bridge that gap.👇 #AppSec #SecureCode
000
Semgrep @semgrep.com · 08/03/2026
If your team is leaning into "vibe coding" or heavy LLM usage, you need a strategy to ensure that speed doesn't turn into a liability. Here are four essential principles for securing AI-generated code👇
110
Semgrep @semgrep.com · 07/03/2026
Want to scan your entire codebase without touching a single CI/CD file? 🛡️ In this quick walkthrough, we show you how to scale security across your repos in minutes using Semgrep Managed Scans. No manual config, just results.👇 #AppSec #SecureCode
000
Semgrep @semgrep.com · 28/02/2026
Imagine an AI that reasons like a security engineer with the context of your lead developer.  Semgrep’s retrieval systems give any LLM the repo-specific nuance it needs to be reliable.👇 #AppSec
000
Semgrep @semgrep.com · 26/02/2026
We provide secure coding feedback where it matters most: on the dev's screen. Faster feedback = less exploitable software, less frustration from devs and less time wasted.
000
Semgrep @semgrep.com · 25/02/2026
If a vulnerable function in your supply chain isn’t reachable, it shouldn’t derail your sprint. If it *is* reachable, you need it at the top of the queue. Semgrep helps teams figure this out quickly so that remediation is efficient.
000
Semgrep @semgrep.com · 14/01/2026
🟢 Semgrep version 1.147.0 is live! Check out all the details here👇 github.com/semgrep/semgrep/releases…
021
Semgrep @semgrep.com · 11/01/2026
We’re just 3 days away from our exclusive boot fitting event at the San Francisco Sports Basement. Attendance is limited and subject to confirmation. RSVP today to get on the list 👇 semgrep.dev/events/step-into-ski-se…
000
Semgrep @semgrep.com · 31/12/2025
$ semgrep init --year 2026 [INFO] Initializing Future... [OK] [INFO] Deploying: Secure_Code.v2026 [SUCCESS] [WARN] Challenges: Loading...  Welcome to 2026❇️
000
Semgrep @semgrep.com · 30/12/2025
Leave false positives in 2025. Imagine 2026: An AppSec world with zero noise and 100% developer trust. By leveraging the Semgrep platform, you can silence the friction of irrelevant alerts and focus on what actually matters ➡️ shipping secure code. 🌀Learn how we’re doing it: semgrep.dev
000
Semgrep @semgrep.com · 29/12/2025
59% of developers still don’t trust AI tools to handle security. With "vibe-coding" skyrocketing, even a small error rate creates a massive wave of new vulnerabilities. At Semgrep, we’re bridging that trust gap. #AppSec #AI #DevSecOps
000
Semgrep @semgrep.com · 28/12/2025
In the world of "vibe coding," agents are powerful but they aren’t secure. Semgrep x Cursor Hooks changes that. Using Cursor Hooks allows AI agents to run and test code safely in their own environment, identifying vulnerabilities and applying fixes before you ever see the code.
110
Semgrep @semgrep.com · 15/12/2025
Last chance to join us! ⏰ Tomorrow at 9:00 AM PT, @insider.phd (Semgrep) and Aubrey King (F5) will go head-to-head on the industry’s biggest hot takes, from whether AI is actually helping security teams to why developers might not care about security 🔗 semgrep.dev/events/unfil...
000
Semgrep @semgrep.com · 12/12/2025
That’s a wrap on Black Hat Europe 🇬🇧 Huge thank you to everyone who stopped by Booth #816 and to everyone who joined us at our events! We’re heading home feeling genuinely grateful for this community. Thanks for the great conversations, thoughtful questions, and good energy. Until next time! 👋
000
Semgrep @semgrep.com · 11/12/2025
On December 16th at 9:00 AM PT, join @insider.phd (Semgrep) and Aubrey King (F5) for a live, unscripted session where they tackle the hot takes practitioners are actually debating. No slides. No scripts. Just two experts digging into the issues shaping 2026. 👉 semgrep.dev/events/unfil...
000
Semgrep @semgrep.com · 11/12/2025
Huge thank you to everyone who joined us for Security Sundowners on the Sunborn Yacht last night 🛥️🍸 And a big shoutout to our partners who helped make it happen: Tines, Cyera, Sublime Security, and Zenity 🙌 #BlackHatEU #BHEU #AppSec #Cybersecurity #Semgrep
100
Semgrep @semgrep.com · 11/12/2025
Ready to shape the future of AppSec? We are hiring across Engineering, Sales, and Marketing! Come build with us. 🌀See our open roles: semgrep.dev/about/careers
000
Semgrep @semgrep.com · 10/12/2025
Black Hat Europe is in full swing, and we’re live at booth #816 with great conversations happening all day 🙌 Come say hi to the Semgrep team to see how our AI-driven AppSec platform helps dev and security teams fix vulnerabilities earlier, reduce noise, and accelerate release velocity.
000
Semgrep @semgrep.com · 09/12/2025
The Semgrep team has touched down for Black Hat Europe! 🇬🇧 We’re set up and ready to see you tomorrow at Booth #816. Stop by to see how Semgrep’s AI-driven AppSec platform helps dev + security teams find and fix issues earlier, cut noise across SAST/SCA/Secrets, and ship faster.
000
Semgrep @semgrep.com · 08/12/2025
Semgrep is wrapping up Black Hat EU with something a little different this year. Join us at THE CUBE live in London right after the conference for a gameshow-style AppSec adventure! 🗓️ Thu, Dec 11, 2025 | ⏰ 17:00–20:30 GMT 👉 semgrep.dev/events/the-c... We hope to see you there! 👋
000
Semgrep @semgrep.com · 05/12/2025
It’s been a busy week for the Semgrep team! ⚡ 🎉 We’ve been out and about at AWS re:Invent, OWASP Benelux, the Colorado = Security Holiday Party, Merry & Mingling: Evolve's Holiday Mixer, and Hack the Halls! Curious where we’re heading next? Check out our events page: semgrep.dev/events/
000
Semgrep @semgrep.com · 04/12/2025
Yesterday was a blast! 🏁🔥 A huge thank you to everyone who joined us at the Accelerate to Innovate – Raceday at re:Invent event with Sysdig. Amazing conversations, big energy, and such a fun mid-week highlight, we loved sharing it with you! Stop by booth #486 today before the week wraps! 🙌
000
Semgrep @semgrep.com · 03/12/2025
What a night! 🌆✨ Huge thank you to everyone who joined us yesterday for Sip and Sync at the Sphere with Pellera Technologies and the AWS re:Invent Cocktail Reception with Felicis, Tableau, Supabase, Tines, and MotherDuck. Incredible conversations and such a fun way to kick off the week!
020
Semgrep @semgrep.com · 03/12/2025
Tomorrow (Dec 4 @ 9:00am PT), join a fireside chat with Mudita Khurana (Airbnb) and Chushi Li (Semgrep) on measurement + benchmarks for the next generation of AppSec agents, including the Closed-Loop Capability (CLC) score. 🔗 Register here: semgrep.dev/events/measu...
010
Semgrep @semgrep.com · 02/12/2025
Day 2 at AWS re:Invent is underway! If you're exploring the expo floor, come swing by Booth #486 to meet the team, check out live demos, and snag some exclusive Semgrep swag. #AWSreinvent #Semgrep #AppSec #DevSecOps #Cybersecurity
000
Semgrep @semgrep.com · 02/12/2025
With all eyes on Sha1-Hulud, it’s easy to forget this is just the latest in a series of attacks showing a new normal where malicious dependencies wreak havoc on organizations. That’s why Malicious Dependency Detection is now generally available for Semgrep Supply Chain. semgrep.dev/blog/2025/bl...
000
Semgrep @semgrep.com · 02/12/2025
Big news! 🎉 Semgrep has been named a 2025 Inc Best in Business honoree in the Best AI Implementation category. It's an honor to be recognized for how we're using AI to accelerate security and shape the future of cybersecurity. Learn more: www.prnewswire.com/news-release...
000
Semgrep @semgrep.com · 01/12/2025
The Semgrep team has officially landed in Las Vegas for AWS re:Invent! ✈️🎉 We’ll be at Booth #486 all week. Come meet the team, grab some great swag, and see how Semgrep helps engineering and security teams ship faster and stay secure. See you on the expo floor! 🙌
010
Semgrep @semgrep.com · 01/12/2025
🇧🇪OWASP Benelux Days – see you tomorrow! 🇧🇪 We’re excited to touch down in Mechelen, Belgium soon – for a day of AppSec talks, followed by our ‘Brews & Bytes’ evening event afterwards… Learn more: semgrep.dev/events/owasp... Hope to see you there! #AppSec #InfoSec #Cybersecurity
010
Semgrep @semgrep.com · 28/11/2025
Join us on December 4th at 9:00 AM PT for a fireside chat with Mudita Khurana to explore how next-generation AppSec agents think, learn, and improve on their own, and why evaluating how they make decisions is becoming just as important as what they do. 🔗 Save your spot: semgrep.dev/events/measu...
000
Semgrep @semgrep.com · 27/11/2025
Happy Thanksgiving from all of us at Semgrep! 🍂 We’re grateful for our community who push the boundaries of what’s possible in AppSec every day. Wishing everyone a joyful and restful holiday filled with good food, good company, and plenty to be thankful for. 💚
000
Semgrep @semgrep.com · 26/11/2025
On December 16 at 9:00 AM PT, join @insider.phd (Semgrep) and Aubrey King (F5) for a live, unscripted conversation diving into some of the most debated topics in security today — including whether AI is actually helping security teams or just adding more noise. 🔗 semgrep.dev/events/unfil...
000
Semgrep @semgrep.com · 26/11/2025
The Semgrep team has a packed week planned at AWS re:Invent, and we’d love for you to join us! 🎉 We’re teaming up with some of our incredible partners to bring you a lineup of great events and conversations you won’t want to miss. Check out our full schedule: 🔗 semgrep.dev/events/aws-r...
010
Semgrep @semgrep.com · 25/11/2025
Join Semgrep and @stackhawk.bsky.social on December 10 at 10 AM PT to see how combining SAST + DAST helps teams focus on what’s actually exploitable and fix faster, with unified visibility, runtime validation, and AI-powered triage. 👉 semgrep.dev/events/sast-...
010
Semgrep @semgrep.com · 25/11/2025
A new variant of the Shai-Hulud worm is now impacting 500+ npm packages, introducing not only large-scale secret exfiltration but a persistent GitHub Actions backdoor capable of executing code on self-hosted runners. 👉 Read the full analysis: semgrep.dev/blog/2025/di...
010
Semgrep @semgrep.com · 24/11/2025
The Semgrep team is heading to Las Vegas! ✈️✨ We’ll be at AWS re:Invent from December 1st - 4th, and we can’t wait to meet you there. Stop by Booth #486 to meet the team, grab some great swag, and see how Semgrep helps engineering and security teams ship faster and stay secure. #AWSreinvent
000
Semgrep @semgrep.com · 24/11/2025
We’ve launched the Private Beta of Semgrep’s AI-Powered Detection, which combines AI reasoning with the Semgrep Pro Engine for reliable detection of logic vulnerabilities. Early results: • 80% of teams found real IDORs • 3× higher precision than AI alone semgrep.dev/contact/prod...
000