1. X
  2. depthfirst
Log inSign up
depthfirst
88 posts
Image
user avatar
depthfirst
@depthfirstlabs
The Operating System for Modern Application Security
San Francisco
depthfirst.com
Joined April 2025
40
Following
1,436
Followers
1
Subscription
AffiliatesAffiliatesRepliesRepliesArticlesArticlesMediaMedia
  • user avatar
    depthfirst
    @depthfirstlabs
    Jul 30
    Introducing dfs-large1, our new cybersecurity model achieving best-in-class performance on vulnerability detection tasks. Only a handful of companies outside the frontier AI labs have achieved this in other domains, and we’re proud to be the first to do so in security. Thank you
    user avatar
    Andrea Michi
    depthfirst
    @andreamichi
    Jul 30
    Today we're announcing dfs-large1, our newest cybersecurity model that achieves best-in-class performance on vulnerability detection tasks. Besides frontier AI labs, only a handful of companies have built specialized models that reach the state of the art in their domain. We're
    Image
  • user avatar
    depthfirst
    @depthfirstlabs
    Jul 29
    Being able to evaluate model capabilities is fundamental when new models are released at this pace, and when the models you use impact outcomes and margins. Benchmarks tend to saturate as companies overfit their models and harnesses to them. When that happens, higher scores are
    user avatar
    Francesco Piccoli
    depthfirst
    @francescpicc
    Jul 29
    It is time for the security industry to graduate from CyberGym Level 1. CyberGym has been one of the most impactful cybersecurity benchmarks since its launch in June 2025. Compared to prior benchmarks, it represented a jump in scale and a step in the right direction for the
    Image
  • user avatar
    depthfirst
    @depthfirstlabs
    Jul 28
    Read about our investigation into the Ruby ecosystem which led to 105 vulnerabilities across 34 projects with 8.6B+ downloads and a GitLab RCE.
    Article cover image
    Article
    Behind the GitLab RCE: A depthfirst Journey into the Ruby Ecosystem
    TL;DR: The GitLab RCE in our previous post emerged from a much broader investigation into the Ruby ecosystem conducted through the Open Defense Initiative. The depthfirst platform was used to analyze...
  • user avatar
    depthfirst
    @depthfirstlabs
    Jul 27
    Follow up announcement to last week's GitLab RCE - we found 105 vulnerabilities across 34 projects in Ruby, with 8.6b combined downloads. Read the technical breakdown in the Zheng's post.
    user avatar
    Zheng Yu
    depthfirst
    @dataisland99
    Jul 27
    We discovered 105 vulnerabilities across 34 projects in Ruby, some of which had remained undetected for more than 15 years. Collectively, these projects have been downloaded more than 8.6 billion times. The GitLab Remote Code Execution announced by @depthfirstlabs last week
  • user avatar
    depthfirst
    @depthfirstlabs
    Jul 24
    Read our technical breakdown of GitLab OJ Spill, a GitLab RCE in its default configuration found by depthfirst.
    Article cover image
    Article
    Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities
    TL;DR: As part of the Open Defense Initiative, the depthfirst system analyzed Oj, a high-performance JSON parser with a substantial native C implementation, and produced a prioritized queue of...

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement