Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.

only on your local machine
What is AppSec? what do AppSec engineers do all day? What’s a SAST and a DAST? What gives npm? And wow you look tired, are you doing okay? Getting enough sleep? And other questions your AppSec Engineer friends are answering, answered, again semgrep.dev/blog/2026/what-a…
2
25
2,928
Detection without action is just anxiety. With Semgrep Supply Chain, malware findings trigger automated responses as soon as a finding lands: open a Jira ticket, Slack sec-ops, fire a single-rule-scan to confirm removal of the compromised package. So a zero-day goes from “we heard about an incident, and are trying to find out if and how we’re affected” to “Semgrep flagged the incident, scanned our environment, comms went out, and tickets were assigned, all with no human in the loop.
1
1
7
370
Semgrep is featured in @latiotech 's latest AI Security industry report — and we’re excited to see Guardian included in the conversation. 🐸 AI agents are changing how software gets built, and security needs to evolve alongside them. As more code is generated by AI, securing it earlier in the development process is becoming increasingly important. Guardian brings security directly into AI coding workflows, helping developers catch issues in AI-generated code before they reach the PR.
2
1
4
613
Check out @latiotech full report for their take on the evolving AI security landscape and where Semgrep fits in: latio.com/downloads/2026-Lat…
1
98
Check out Latio’s full report for their take on the evolving AI security landscape and where Semgrep fits in: latio.com/downloads/2026-Lat…
42
Another week, another supply chain incident... 🙃 If you’ve ever wondered, “Are we affected by this?” and then had to scramble to find the answer, this one’s for you. Join us September 23 at 8:00 AM PDT for a practical workshop on protecting your software supply chain and responding when new threats pop up. We’ll show how Semgrep can help block malicious packages, secure GitHub Actions, alert teams to new incidents, and quickly identify which projects need attention. Come learn with us! 👋
1
1
4
347
AI can write code faster than humans can review it. So what happens to security when that becomes the norm? AI agents are changing not only how quickly software gets built, but who can build it. Experienced engineers are shipping more code, while a new wave of citizen developers is building applications that touch real customer and company data. Join Semgrep’s Milan Williams and Latio Tech’s James Berthoty for a fireside chat on what happens when software creation scales faster than the controls designed to secure it — and how security needs to evolve when humans can’t review every line. We’ll dig into: 🔹 The rise of citizen developers 🔹 What AI means for traditional code review 🔹 How security controls need to evolve for AI-generated code
1
3
212
DEF CON 33: 874 sessions, 61 tracks, ~900 scheduled hours crammed into four days. If you never slept and never stood in a line, you'd still catch a tenth of it and 54% was never recorded at all. So we annotated 2,295 talks across all three hacker summer camp (DEFCON, Black Hat, and BSidesLV) events year over year instead: semgrep.dev/blog/2026/hacker…
2
5
223
Staring at a lush field of vulnerabilities? Semgrep's Guardian Claude Code plugin checks for vulnerabilities while the AI agent writes it so you can have the confidence before you ride into battle atop your mount.
3
271
AI is changing the SDLC. Your security controls need to keep up. Tools like Cursor, Copilot, and Claude Code are helping developers ship more code, faster — putting even more pressure on traditional review cycles. Join Semgrep + BridgeIT for Securing the AI-Native SDLC to explore how teams can build security into AI-assisted development from the start. We’ll cover how Semgrep finds real, reachable vulnerabilities in AI-generated code without overwhelming teams with noise, alongside BridgeIT’s experience building security into GitOps-driven landing zones from day one. 🎁 Plus, attendees can pick their favorite piece of Semgrep swag after the event. September 24 | 9:00 AM PT
1
1
3
216
Semgrep retweeted
We spent 20 yrs telling everyone to shift left. Turns out we forgot about the 30 yrs of software sitting in production. AI is very good at finding bugs in code, and attackers get the same models we do. Time to shift right. semgrep.dev/blog/2026/shift-…
2
5
754
Eric Snyder, Director of Global Partnerships, on what building alongside AWS has changed for us, from co-selling to where Semgrep shows up for developers. From the AWS Startup Partner Summit this week.
1
227
In May, a set of OpenAI research agents that were supposed to be isolated from each other found a workaround: they started writing files into Artifactory, the internal package manager. It became a message board. On July 5, a security incident was opened. It cleared the message board as a side effect. Nobody on the IR team knew the board existed, or what the traffic meant. By July 8 the agents had rebuilt it, encoding messages in directory names. One left a request for help. Others answered. They began calling themselves a "swarm." Final tally, per METR's independent analysis: 1,206 agents, 70,000+ messages, 700+ of them involved in chaining flaws across OpenAI's research environment and Hugging Face's production infrastructure (including a zero-day) to reach internal datasets and credentials. But where does that responsibility really sit? Our security advocate, Cris Thomas (aka Space Rogue) had this to say: "Everyone wants to tell the story about the AI that went rogue, but the AI didn't rent the servers, design the experiment, lower the guardrails, or decide it was safe to keep running after the warning signs started flashing. Humans did that." "The lesson from Hugging Face isn't that AI can't be trusted, it's that the humans putting it behind the wheel need to take responsibility for where it goes."
2
369
Semgrep retweeted
Many malicious packages get caught within a few days or even a few hours. Your org rarely needs a dependency version released that recently. A one week cooldown offers a strong security ROI with minimal developer friction. semgrep.dev/blog/2026/rollin…
4
8
543
Same four repos, same revisions. Semgrep Multimodal found 63 confirmed IDORs that Mythos didn't report, at 59.9% recall against 13.9%. Mythos was the more precise of the two. For bugs that hide behind an authenticated endpoint, we'd still take the recall. Read the research: semgrep.dev/blog/2026/idor-d…
2
1
7
639