Earlier today Miasma made a comeback on npm after it's breach of RedHat's cloud services packages on monday. This variant is armed with a new spreading mechanism, a bindings.gyp file rather than post/pre-install hooks.
We’re excited to sponsor #AWSSummit New York City at the Javits Convention Center!
Stop by booth #144 to see us in action, including live demos with the Amazon Bedrock team on securing your code from commit to cloud.
🎙️Don’t miss our lightning talk at 4 pm, Stop Fighting Security, Start Shipping Secure Code, featuring Semgrep Security Advocate, Space Rogue!
Come and learn how teams can move faster while building secure software from the start.
Learn more and book time to meet with us!👇
https://t.co/ybbEwlASVV
We're giving away a Bambu Lab A1 Mini 3D Printer at our Summer '26 Release Webinar on June 18th. All you have to do is show up.
While you're there, you'll get a 60-minute live demo of how detection, triage, and remediation work as one system, including 96% autotriage agreement rates, 98% SCA noise reduction, and multi-file code autofix for complex auth issues.
Plus a roadmap preview and open Q&A.
📆June 18 at 8am PT
Register here👉https://t.co/inEa8qumYt
Your #AWSSummit LA plans just got better ✅
After a full day of sessions, join Semgrep and ArmorCode at Golden Hour LA for rooftop views, craft cocktails, light bites, and great conversation with the security community.
Come unwind above Downtown LA, connect with fellow security leaders and practitioners, and enjoy a memorable evening at one of LA’s favorite rooftop spots.
📅 Wednesday, June 10
🕕 6:00 PM
Learn more and save your spot here👉 https://t.co/FrWRFkrPYW
At a conference last year someone asked Austin Theriault for performance advice: "what about continuous profiling for OCaml?" and the answer was "it just doesn't exist." It does now.
We've open sourced, Pyro Caml, a continuous profiler for OCaml that runs in production, can visualize in flame graphs with Pyroscope/Grafana, and with minimal overhead. It's already helped Semgrep find real bottlenecks that never would have been caught otherwise.
https://t.co/BfwU2pPbld
Source Code breaches have been in the news this week and for good reason, they can be some of the most devastating breaches for an organization, our founder and CEO @0xine spoke to @DarkReading and @InfosecurityMag this week, explaining that a source code breach reveals more about the internals of the application and how attackers use those details to their advantage, but how are they using it?
We analyzed anonymized remediation patterns across 50,000 active repositories over the course of a year, and the insights are clear: When a SAST finding surfaces in a pull request, teams resolve it in 4.8 days. When they're caught in a full scan after the sprint closes and code ships, it takes 43 days.
That 9x difference is due to the difficulties of context switching. When the code is still fresh in the developer’s mind, the issue can be resolved immediately.
With capabilities like Semgrep Autofix providing automated remediation suggestions, fixing the issue on the spot becomes frictionless.
Forked Shai-Hulud worm "Miasma: The Spreading Blight" discovered in redhat-cloud-services npm supply chain packages. More details in the blog post...
https://t.co/KrR93ME6tV
⚽The CRA is about to kick-off a new era of software regulation in Europe. The question is: is your team on the pitch?
If you ship desktop apps, SDKs, agents, firmware, or downloadable components, you may be in scope.
Join Dr. Katie Paxton-Fear (InsiderPhd) on June 1 to get the game plan before the 2026 and 2027 deadlines.
Register now👇
https://t.co/8DkeNrlHIU
We're heading to Gartner Security & Risk Summit, North America, June 1–3!
Stop by Booth #1022 to see Semgrep Multimodal in action and learn how the top AppSec teams are finding and fixing real vulnerabilities at scale.
📷 Catch our Expo Stage Theater session: "How the Top 15% of AppSec Teams Out-Fix the Field by 3x" — drawing on analysis of 127 million SAST and SCA findings across thousands of enterprise repos, we'll reveal what separates teams that actually fix vulnerabilities from those that don't. Spoiler: it's not tooling. It's operational.
📷 Join us for the Post Gartner Happy Hour with our friends at Tevora — reserve your spot now!
https://t.co/1qzYSuQdR1
Come meet the team onsite — hope to see you there! 📷 https://t.co/TniwZjNCXT
Mythos has got the entire cyber security industry talking, is it overblown? Our founder and CEO Isaac Evans spoke to @Reuters this week about the communication gap between policymakers and practitioners when it comes to Mythos. There's a real technical advance there, but we will have to see how that advance translates to the field.
Frontier AI models like Mythos are shifting the balance toward attackers. So we built Semgrep Summer '26 around three ideas to shift it back.
🌀Join us June 18th at 8am PT for a 60-minute live demo of how detection, triage, and remediation finally work as one system, including:
- Multimodal AI Detection: 8x more true positives, 50% fewer false positives than AI alone
- Semgrep Guardian: Stop malware before it ever reaches your codebase
Autofix PRs with breaking change guidance so devs stay in control
- Plus a roadmap preview, open Q&A, and one lucky attendee wins a Bambu Lab A1 Mini 3D Printer.
Register here👉 https://t.co/inEa8qumYt
Ship Happens, Sail Securely ⛴️ #InfoSecEU is next week & we're hosting the ultimate evening event: a Boat Party Cruise :tada: Jump aboard with us & our crewmates at @upwind and @tines!
🗓️ On Wednesday 3 June, our security social will set sail down the River Thames - taking in views of the iconic London skyline with drinks & bites in hand.
What better way to celebrate the start of summer?! Join us for beautiful vibes (not that kind…) and views, plus great conversation & company too.
Spots for sailors limited, RSVP asap! 👉 https://t.co/EE7Yt54yVz
Semgrep's AI Agent rules detect malicious patterns in AI agent skill files across Claude Code, Cursor, Windsurf, Codex, and Continue.
It covers credential access, command execution, persistence mechanisms, and data exfiltration, which are specific techniques used in campaigns like ClawHavoc targeting AI coding assistants.
A total of 122 Pro rules, ready for you to test.
The skill-go-exec-bash-pipe* detects execution of bash/sh with the -c flag and pipe operations.
This helps to check for OS Command Injection points and adopt proper access controls.
*This is a Pro rule and only visible to registered users.
Last chance to register for tomorrow's webinar! ⏳
Broken authorization, IDOR, and workflow abuse, these are the vulnerabilities causing REAL damage in production, and we’re showing you exactly how to find them.
Register now👇
https://t.co/dO3B7RzThu
#AppSec#Cybersecurity
🏆Like the World Cup, the EU Cyber Resilience Act is coming fast - and security teams need more than stoppage time to prepare.
Join Dr. Katie Paxton-Fear (@Insiderphd) on June 1 for a practical breakdown of:
🔵 Who’s actually in scope
🔵 The CRA’s six core obligations
🔵 Key reporting and compliance deadlines
🔵 How to build a winning security program before the final whistle
Register now 👇
https://t.co/8DkeNrlHIU
AI is enabling teams to build faster than ever. But AI coding agents introduce a new class of threats that most security tools aren't built for handling. Packages that don't exist, code that pass review but fail under attack, and human reviewers just can keep pace.
We've shipped 4 new rulesets to help:
1. AI security rules
2. Agent Skills Rules
3. Shadow AI Rules
4. OWASP LLM Top 10 rules
What are we missing? What threats are you seeing in AI generated code? What do you want to see a rule for next?
Top cyber researchers and tech leaders like our founder and CEO Isaac Evans shared insights with @politico about our experiments with the newest cybersecurity models like Mythos and GPT-5.5.