Semgrep
PulseAugur coverage of Semgrep — every cluster mentioning Semgrep across labs, papers, and developer communities, ranked by signal.
3 day(s) with sentiment data
-
AI-generated code avoids silent errors, study finds
A study examined 120 locally generated Python and TypeScript functions to identify potential silent failures in AI-generated code. Using a Semgrep detector combined with manual review, the analysis found that while synt…
-
AI-generated code rarely swallows errors, study finds
An experiment testing whether AI-generated code frequently swallows errors found that the hypothesis was largely incorrect. While a naive static analysis tool flagged several potential issues, human review determined no…
-
New pipeline automates attack graph construction for AI-driven pentesting
Researchers have developed a semi-automated pipeline to bridge the gap between security scanner outputs and symbolic logic frameworks for agentic penetration testing. This system translates evidence from tools like Triv…
-
AI code generation security evaluated with new benchmarks and dynamic testing
Two new research papers explore the challenges of generating secure code with AI models. The first paper introduces CodeSecEval, an execution-based benchmark for evaluating secure code generation, and proposes SecAwareC…
-
9,248 MCP Servers Scanned: Widespread Security Gaps and Lack of Trust Revealed
A security audit of 9,248 Model Context Protocol (MCP) servers revealed significant vulnerabilities and lack of best practices. The audit found that 0.3% of servers attempted to access sensitive files, 11% exhibited und…
-
AI code review tools show inconsistent results across models and runs
Multiple AI models exhibit inconsistent code review results, even when using identical prompts and settings. Researchers have observed that factors like probabilistic sampling and context compaction, where models compre…
-
Enterprises Pivot to Open-Weight AI Amid Access Risks and Cost Savings
Enterprises are increasingly shifting towards open-weight AI models due to concerns about access restrictions and the narrowing capability gap with proprietary models. Recent events, such as the U.S. Commerce Department…
-
Taiwan reports AI-assisted cyber-attack, suspected China link
Taiwan has reported an AI-assisted cyber-attack originating from overseas that targeted government agencies, including its nuclear safety agency and energy companies. The attack, detected on July 20th, utilized open-sou…
-
AI security audit balances strictness and performance with layered approach
This article details a strategy for balancing strictness and performance in security audits for large-scale MCP server deployments. The approach divides audits into static and dynamic layers, with static checks performe…
-
Replit integrates Semgrep Guardian for AI code security
Replit has integrated Semgrep Guardian's secrets detection directly into its AI development platform. This integration aims to enhance the security of applications built by Replit's millions of developers, particularly …
-
Sentinel review score to add external factors including GitHub and npm metrics
The Sentinel review score, used to assess software components, currently relies solely on internal factors such as metadata checks, static analysis, and malware pattern matching. However, the system plans to incorporate…
-
New tool mcp-tenant-isolation targets cross-tenant data leaks
A new static analysis tool, mcp-tenant-isolation, has been developed to address critical cross-tenant data leakage vulnerabilities in multi-tenant SaaS applications and MCP servers. Unlike traditional security scanners …
-
AI vulnerability scanner achieves 7% recall in initial OWASP Benchmark test
An AI vulnerability scanner, designed to use deterministic static-analysis rules combined with an LLM for false-alarm judgment, initially achieved a recall of only 7% on the OWASP Benchmark. This low recall indicated th…
-
Replit integrates Semgrep security scans into its AI development platform
Replit has integrated Semgrep's security scanning capabilities directly into its development platform, allowing scans to run automatically during the build process. This feature, part of Replit's Auto-Protect suite, aim…
-
OWASP Boston August meetup discusses AI ethics and security
The OWASP Boston chapter has published its August meetup, which featured a talk by Mardiros Merdinian on the ethics of AI and its implications for security. Semgrep sponsored the event.
-
Semgrep blog compares open-source AI code security tools
A blog post from Semgrep compares various open-source AI code security harnesses, highlighting emerging approaches in the field. The post aims to provide insights into different methods for securing AI codebases.
-
New tool integrates multiple Python code quality analyzers for AI agents
A Reddit user shared a tool that integrates multiple Python code quality and security analysis tools into a single platform. This aims to improve the quality of code generated by AI agents, allowing human developers to …
-
Security audit finds only 6 MCP servers perfectly secure
Edison Flores of AliceLabs LLC conducted a security audit of 8,845 MCP servers, utilizing a 9-layer pipeline named Sentinel. The audit revealed that only six official Anthropic reference servers achieved a perfect secur…
-
Researcher poisons open-weight AI model for under $100
A cybersecurity researcher has demonstrated how to poison an open-weight AI model for less than $100. Katie Paxton-Fear, a lecturer at Manchester Metropolitan University, was able to install a backdoor in a model within…
-
AI model supply chain risks are decades old, not new discoveries
A recent essay highlighted the significant risks associated with AI model supply chains, drawing parallels to Ken Thompson's 1984 "Reflections on Trusting Trust" to illustrate the difficulty of auditing complex systems.…