Log inSign up
Semgrep
2,523 posts
Semgrep profile banner
@semgrep

Semgrep

@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
only on your local machine
semgrep.dev
Joined May 2019
205
Following
4,782
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @semgrep
    Semgrep
    @semgrep
    Sep 4
    Eric Snyder, Director of Global Partnerships, on what building alongside AWS has changed for us, from co-selling to where Semgrep shows up for developers. From the AWS Startup Partner Summit this week.
    Image
    00:00
  • @semgrep
    Semgrep
    @semgrep
    Sep 3
    In May, a set of OpenAI research agents that were supposed to be isolated from each other found a workaround: they started writing files into Artifactory, the internal package manager. It became a message board. On July 5, a security incident was opened. It cleared the message
    Image
    1
  • @semgrep
    Semgrep
    @semgrep
    Aug 27
    Same four repos, same revisions. Semgrep Multimodal found 63 confirmed IDORs that Mythos didn't report, at 59.9% recall against 13.9%. Mythos was the more precise of the two. For bugs that hide behind an authenticated endpoint, we'd still take the recall. Read the research:
    Image
    How Semgrep Multimodal Finds the IDORs Other Tools Miss
    From semgrep.dev
    2
  • @semgrep
    Semgrep
    @semgrep
    Aug 25
    We benchmarked Mythos against other models we have. Our analysis runs 23 configurations evaluated against 275 human-reviewed IDOR labels. Mythos did not take the top spot, and as others have reported the harness matters more than the model. See our results:
    Image
    Mythos Benchmarked Against 22 Configs on 275 IDORs
    From semgrep.dev
  • @semgrep
    Semgrep
    @semgrep
    Aug 24
    In tomorrow's webinar, we share some lessons from the front lines of AI in AppSec: what's working, what isn't, and how to tell the difference before you've burned weeks of time & budget... Teams are genuinely getting value from AI, but the key to elevating a party trick into a
    Image
    1
Advertisement
Advertisement