@GavinSBaker@GavinSBaker, thank you for articulating what I was thinking to myself earlier today (Monday). It's looking like that's exactly what will happen, as the alternatives seem a lot less likely.
You already knew Mythos-Class was marketing BUT what does Mythos class REALLY mean? Well nobody knows but here’s a graph showing them all together infer what you will
Millions of developers build on Replit - many with AI agents writing the code. Speed like that needs security that keeps pace.
Semgrep Guardian's secrets detection is now built directly into Replit, catching vulnerabilities the moment code is generated.
Every scan completes in under 5 seconds and is deterministic on every run, so it doesn't slow developers down or add unpredictable cost to your agent. Paired with Replit's reasoning layer, it filters out >93% of false positives, so developers see high-confidence results, not noise.
Live now, no setup required.
Read the full announcement: https://t.co/QyYfUhcHwZ
#AppSec #AI #DevSecOps
We heard you didn't want to wait until the end of a build to run Replit's security scans.
So we fixed it.
Replit now runs security scans while you build, in partnership with @semgrep
Stop by Veracode booth #435 to learn more about AI-Generated Code and to meet Chief Security Evangelist, Chris Wysopal, who will be leading a panel at the event on Monday, alongside speakers from #OpenAI, Fastly, and, Unsupervised Learning. https://t.co/t7Xy3vWnAZ
OpenClaw: AI innovation or security nightmare? Veracode Threat Research uncovers the risks of this fast-growing tool, from malware to misconfigurations. Stay informed.
🔗 Read more
#ClawdBot#Moltbot#OpenClaw https://t.co/uaPPyAuj4Z
Confidence requires evidence.
GigaOm has named Veracode a Leader in the Radar for Software Supply Chain Security. We give you the visibility and control to fix flaws faster and build secure software from the start.
Read the full release:
#SupplyChain https://t.co/UMWchSlWgc
AI code generation is changing how software gets built, but speed without guardrails creates security debt. By embedding the right controls into the SDLC, teams can validate AI-generated code early and protect the supply chain. 🔐
https://t.co/WDB2dofVKY
A bunch of very smart security nerds (and, along for the ride, me) are standing up a conference about AI/security (the intersection of those ideas, not just the security of AI).
https://t.co/R82QCfJZTe
Before bug bounties, before root shells, before the word hacker meant anything at all there was a blind kid who whistled 2600 Hz and bent Ma Bell to his will.
Joybubbles tells the story of Joe Engressi, the original phone phreak and a reminder that hacking started as curiosity, play, and defiance.
Sundance screening.
https://t.co/jTWpFngJzN
“Prompt injection” is a misleading label.
What we’re seeing in real LLM systems looks a lot more like malware campaigns than single-shot exploits.
This paper argues LLM attacks are a new malware class, Promptware, and maps them to a familiar 5-stage kill chain:
• Initial access (prompt injection)
• Priv esc (jailbreaks)
• Persistence (memory / RAG poisoning)
• Lateral movement (cross-agent / cross-user spread)
• Actions on objective (exfil, fraud, execution)
If you’ve ever thought: “why does this feel like 90s/2000s malware all over again?", that’s the point.
Read the paper ⬇️
https://t.co/LQraD7MAia
🏅 Veracode is wrapping up 2024 with a fantastic honor from PeerSpot, being recognized as the top leader in Application Security Posture Management (ASPM)!
ASPM is an invaluable tool for App and Cloud risk as it provides real prioritization and root cause fixes.
My Congressional testimony on how vulnerabilities are discovered by researchers, how patching doesn't solve our problems and the need for secure by design.
This was 9/11/2003. Are we making progress yet? https://t.co/YnCdrjxQBv
Supply Chain Industry Update: @Veracode, a leader in application risk management, has acquired key technology assets from @Phylum_IO, to enhance its ability to detect and block malicious code in open-source libraries. https://t.co/2hACbwTnZS
I am very excited about this upcoming episode of The Phillip Wylie Show! It features @Veracode cofounder and OG hacker Chris Wysopal, aka @WeldPond. This episode drops on 01/20/2025.
https://t.co/VK0i7moE2j