Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.

only on your local machine
Semgrep retweeted
We’ve had 22 years of Cybersecurity Awareness Month. People are aware. People know phishing is bad, ransomware exists, and passwords shouldn’t be “password.” Mission Accomplished! Let's rename it Cybersecurity Readiness Month. semgrep.dev/blog/2026/rename…
1
4
14
742
⚠️ Your AI coding agent just found a new way around your security scanner. A recent Claude update changed how agents write files. Instead of Write and Edit, they now often go through Bash: cat > file <<EOF, sed -i, echo >>. Most scanners never see this code, and don’t think to check it for security issues, leaving a major gap in coverage. Guardian v2.2.0 now scans file changes Claude makes through Bash too. Your coverage stays the same, no matter how the agent writes code. The broader lesson for anyone securing agents: guard the outcome (a file changed), not the tool call. Agent behavior shifts with every model and prompt update. Update the plugin today. #AppSec #AIsecurity
6
2
26
2,172
"Shift left" assumed a human would review the code. Vibe coding doesn't. @0xine at @WeAreDev World Congress discussing what security looks like once that assumption breaks. If AI-generated code is anywhere near your software lifecycle you will want to watch the recording.
5
1
9
308
What is AppSec? what do AppSec engineers do all day? What’s a SAST and a DAST? What gives npm? And wow you look tired, are you doing okay? Getting enough sleep? And other questions your AppSec Engineer friends are answering, answered, again semgrep.dev/blog/2026/what-a…
2
26
3,197
Detection without action is just anxiety. With Semgrep Supply Chain, malware findings trigger automated responses as soon as a finding lands: open a Jira ticket, Slack sec-ops, fire a single-rule-scan to confirm removal of the compromised package. So a zero-day goes from “we heard about an incident, and are trying to find out if and how we’re affected” to “Semgrep flagged the incident, scanned our environment, comms went out, and tickets were assigned, all with no human in the loop.
1
1
7
444
Semgrep is featured in @latiotech 's latest AI Security industry report — and we’re excited to see Guardian included in the conversation. 🐸 AI agents are changing how software gets built, and security needs to evolve alongside them. As more code is generated by AI, securing it earlier in the development process is becoming increasingly important. Guardian brings security directly into AI coding workflows, helping developers catch issues in AI-generated code before they reach the PR.
2
1
4
641
Check out @latiotech full report for their take on the evolving AI security landscape and where Semgrep fits in: latio.com/downloads/2026-Lat…
1
106
Check out Latio’s full report for their take on the evolving AI security landscape and where Semgrep fits in: latio.com/downloads/2026-Lat…
42
Another week, another supply chain incident... 🙃 If you’ve ever wondered, “Are we affected by this?” and then had to scramble to find the answer, this one’s for you. Join us September 23 at 8:00 AM PDT for a practical workshop on protecting your software supply chain and responding when new threats pop up. We’ll show how Semgrep can help block malicious packages, secure GitHub Actions, alert teams to new incidents, and quickly identify which projects need attention. Come learn with us! 👋
1
1
4
378
AI can write code faster than humans can review it. So what happens to security when that becomes the norm? AI agents are changing not only how quickly software gets built, but who can build it. Experienced engineers are shipping more code, while a new wave of citizen developers is building applications that touch real customer and company data. Join Semgrep’s Milan Williams and Latio Tech’s James Berthoty for a fireside chat on what happens when software creation scales faster than the controls designed to secure it — and how security needs to evolve when humans can’t review every line. We’ll dig into: 🔹 The rise of citizen developers 🔹 What AI means for traditional code review 🔹 How security controls need to evolve for AI-generated code
1
3
216
DEF CON 33: 874 sessions, 61 tracks, ~900 scheduled hours crammed into four days. If you never slept and never stood in a line, you'd still catch a tenth of it and 54% was never recorded at all. So we annotated 2,295 talks across all three hacker summer camp (DEFCON, Black Hat, and BSidesLV) events year over year instead: semgrep.dev/blog/2026/hacker…
2
5
227
Staring at a lush field of vulnerabilities? Semgrep's Guardian Claude Code plugin checks for vulnerabilities while the AI agent writes it so you can have the confidence before you ride into battle atop your mount.
3
273
AI is changing the SDLC. Your security controls need to keep up. Tools like Cursor, Copilot, and Claude Code are helping developers ship more code, faster — putting even more pressure on traditional review cycles. Join Semgrep + BridgeIT for Securing the AI-Native SDLC to explore how teams can build security into AI-assisted development from the start. We’ll cover how Semgrep finds real, reachable vulnerabilities in AI-generated code without overwhelming teams with noise, alongside BridgeIT’s experience building security into GitOps-driven landing zones from day one. 🎁 Plus, attendees can pick their favorite piece of Semgrep swag after the event. September 24 | 9:00 AM PT
1
1
3
218