Semgrep @semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build. semgrep.dev only on your local machine Joined May 2019-
Tweets3K
-
Followers5K
-
Following205
-
Likes688
Exposed third-party infrastructure will likely become a recurring theme because the internet is awash in weak software. As models become more capable, they’ll have more opportunities to find and exploit those weaknesses.
Save your spot for the session now! 👉 semgrep.dev/events/where-i…
Everyone's using AI – and if you're not, the FOMO is real. But behind the LinkedIn posts and pitches, plenty of AI-in-AppSec use cases just... don't work. Join Dr Katie and Mehdi as they cut through the noise with what they've actually seen working. Pulling from conference conversations, customer calls, and their own experiments, they’ll share how teams are getting their tokens’ worth of AI.
Malicious Python and JavaScript deps have dominated this year's supply chain news cycle, but how many of y'all still have pinning GitHub Actions on your to do list? Here’s how I did this org-wide at Semgrep. semgrep.dev/blog/2026/sha-…
Millions of developers build on Replit - many with AI agents writing the code. Speed like that needs security that keeps pace. Semgrep Guardian's secrets detection is now built directly into Replit, catching vulnerabilities the moment code is generated. Every scan completes in under 5 seconds and is deterministic on every run, so it doesn't slow developers down or add unpredictable cost to your agent. Paired with Replit's reasoning layer, it filters out >93% of false positives, so developers see high-confidence results, not noise. Live now, no setup required. Read the full announcement: businesswire.com/news/home/2026… #AppSec #AI #DevSecOps
Black Hat's in the books. Now the vibe shifts: DEF CON is where hacker culture takes over, and where theory meets practical exploitation. Today, 4:30 PM, Crypto & Privacy Village: Diptendu Kar on "Crypto Is Fine. The Code Is Not." Crypto failures rarely come from bad math, they come from the gap between cryptographic theory and secure implementation. This weekend, Bug Bounty Village, Saturday 2:30 PM: @insiderphd and @hackfidgetcube on "Slop Spotting." As AI reshapes how code gets written (and how bug reports get filed), the challenge shifts from finding bugs to finding the right ones. Their talk digs into using SAST rule generation to separate genuine risk from AI-generated noise. IoT Village, Saturday 3:15 PM: Katie's back solo with "Beyond Your Bookshelf: Hackable eReaders." Bring your Kindle. She might jailbreak it on the spot. See you in the villages.
Gotta collect them all! If you missed our sticker drops at BSidesLV come meet us at "It's All Fun and Games" for a scavenger hunt for all 22 designs. See you tonight
Another day at Black Hat, another set of real-world AppSec challenges. Yesterday was about the grind: finding vulns, fixing them, and pushing security upstream. Today, we're staring down the barrel of AI-generated code. It ships fast, but human review? Still moves at human speed. linkedin.com/in/spacerogue/ and Pablo Estrada are tackling this gap at 9:30 AM in the Business Hall – a critical discussion on how not to turn review into a rubber stamp. Then at 3:15 PM on Pulse Stage 4, @drewdennison is talking 'Using SAST + Mythos to Shift Right.' For anyone who thinks 'SAST + LLMs' is just marketing fluff, he's demonstrating how this pairing can actually surface novel, long-buried vulnerabilities at scale. This isn't about shiny new tech; it's about practical strategies to keep pace without burning out our teams. Come share your war stories at booth #4943.
We asked security pros at BSides Las Vegas for their hottest takes, and now we're sharing ours! 🔥 Our Head of Product Daghan Altas predicts that automated tools will soon take the reins on most PR code reviews, leaving humans to handle only the essential exceptions, so in a thousand PRs a human only reviews 1 or 2.
Another solid day at Hacker Summer Camp connecting with AppSec folks in the trenches. The recurring theme isn't just finding vulns, it's getting them fixed—and more importantly, preventing them upstream. That means working *with* developers, understanding their pain points, and making security less of a roadblock. It's about pragmatic wins and continuous improvement, not just tool deployment. If you're at Black Hat, swing by booth #4943 to share war stories and strategies for effective developer collaboration. Also, don't miss Katie Paxton-Fear and Milan Williams today at 1:30 PM at our booth, talking about 'Overcoming the Fear of Security Risk with AI-Assisted Development'—a critical topic for practitioner success.
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog: semgrep.dev/blog/2026/its-…
🔍 We've been pointing fingers at AI, but are we missing the bigger picture? 🤔 Our Security Advocate Cris Thomas, aka Space Rogue, shares his thoughts on why regulation isn't the answer and that we might already know the answer to the AI problem all along... it's people, stupid.
Hacker Summer Camp starts today at BSides Las Vegas, and we can't wait to meet everyone! Swing by our booth to pick up your own custom clicker fidget, pick up some stickers, and share your hot take!
We’re excited to sponsor PBC Connect – Black Hat USA 2026 on August 4 at Mandalay Bay in Las Vegas. PBC Connect brings together CISOs, AppSec, infrastructure security, product security, AI security, and cyber resilience leaders for high-value discussion, networking, and community-building. This year’s Black Hat gathering will focus on the future of AI security, vulnerability remediation, product security, and frontier AI risk, including a featured fireside chat with Jason Clinton, Deputy CISO at Anthropic, and Phil Venables, Partner at Ballistic Ventures and former CISO of Google Cloud and Goldman Sachs. The agenda also includes a panel on Operationalizing Security for Mythos-Class Capabilities with Nathan Motyl, Kris Howitt, and Karthik Swarnam. Limited seats are available, register here: thepurplebook.club/pbc-connect-bl… #BlackHat #CyberSecurity #AISecurity #AppSec #ProductSecurity #PBCConnect
Traditional application security tools are great at finding known patterns. They're less effective at detecting subtle authentication flaws, business logic issues, complex injection vulnerabilities, and other weaknesses that require reasoning. Semgrep Agentic Workflows combines AI reasoning with proven static analysis - including Semgrep Pro Engine, Pro Rules, and other analysis tools - to detect the vulnerabilities that traditional tools miss. Because the most expensive vulnerabilities are often the ones that never get found.
Less than a week until Hacker Summer Camp. What's coming for AppSec in the next few years, and what needs to change about how we build security pipelines today? Find Semgrep at Black Hat Booth 4943 to talk it through, and catch our team on stage tackling AI-generated code review, shift-right security, and more. Full schedule: semgrep.dev/events/hacker-…
Read the full post: semgrep.dev/blog/2026/grou…
LLMs for AppSec are generating buzz, but how reliable are they? We audited our own IDOR benchmarks, asking: are models *reasoning* about vulnerabilities, or just getting lucky with pattern matching? F1 isn't enough to know the difference.
Clint Gibler @clintgibler
26K Followers 579 Following 🛡️ Leading Cyber at @OpenAI 📚 Creator of https://t.co/xwtIAI0CuJ newsletter
Jim Manico from Manic... @manicode
17K Followers 6K Following AI and AppSec Educator. Secure coding system prompts. https://t.co/gbW3ZLhURT
Christophe Tafani-Der... @christophetd
6K Followers 1K Following 302 Location: https://t.co/tP3JTD3HQp
Katie Paxton-Fear @InsiderPhD
99K Followers 2K Following Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her
Rohit @whorsehgal
23K Followers 1K Following Builder . Security engineer . Traveller Currently making agents gossip on https://t.co/jgwyzxqSnS
Daniel Cuthbert @dcuthbert
33K Followers 2K Following Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & Co_chair UK Gov Cyber Security Advisory Board
Md Ismail Šojal �... @0x0SojalSec
51K Followers 6K Following Cyber_Security_Re-searcher || Ai Re-searcher || AI-Sec|| Malware Analysis II iOS || Pwn || 0SINT || Project AI-StrikeSec || 0ldAccounts Suspended @0xSojalSec ||
Rana Khalil 🇵🇸 @rana__khalil
57K Followers 838 Following AppSec Team Lead | OSCP | CEO & Instructor of @ranakhalilacad
zeko @z3k0sec
30 Followers 127 Following Doing my own gigs now. I break prod so you don't have to. Paid to be paranoid.
0Zeta @0zSchnack
330 Followers 435 Following Machine Learning and Blockchain Security Enjoyer All-time top 10 on @HackenProof @kaggle Competitions Master
许忱 @hong_xu69853
15 Followers 2K Following
pwn2ooown @pwn2ooown
135 Followers 2K Following Pwn / ♥️Red Team / OSCP+ / Not affiliated with pwn2own competition / CTF with B33F 50μP & @thehackerscrew1 / opinions are on my own
Bean @sting8k_
62 Followers 544 Following
Ahmed Mahmoud @Aahmed646
440 Followers 811 Following Offensive Security | Bug Bounty Hunter @Hacker0x01
Nicolay Karnicov @NKarnicov33167
27 Followers 355 Following
Daily AI Insight @charliewdev
14 Followers 199 Following The signal in AI, daily. 🧠 Models · research · tools · trends — distilled into one tweet a day. No hype. 👇 Start with the pinned thread.
SHOGO 昇剛 ◓ @SHOGOx8
222 Followers 2K Following 𓆣 𓆤 𓆥 𓆦 𓆧 𓆨 𓆜 𓅁 𓅂 𓅐 🤌 🇦🇪🪐🚀 If I am alive. I must live. I must not merely exist as though I were dead.
Chris Isaias @_call_gate
209 Followers 4K Following Penetration Testing & Reverse Engineering. . . Phd(c), Msc (RHL), NATO, ESDC & RIPE fellow, IEEE snr, FIRST liaison, CISSP, CRTO, PNPT
Qodecheck @Qodecheck
0 Followers 51 Following AI-powered code security & static analysis. Catch vulnerabilities before they ship. Built for dev teams. #AppSec #DevSecOps
Go Digits @DigitsGo
8 Followers 467 Following
Innocent Michael Okaf... @Inno_MC_Okafor
41 Followers 472 Following Altar Knight ⛪️ Teaching & sharing my love for Tech & AI 🤖 Proudly Igbo 🇳🇬 | Main Character 99%
Nobody @p1m6_
6 Followers 228 Following
Rashid @Rashidmeta
1K Followers 146 Following
T @toposmd
5 Followers 314 Following
now.sh @n0wsh
32 Followers 1K Following
BGoodspeed @BGooodspeed987
247 Followers 550 Following I have worked as a Consultant , Now I concentrate my efforts, toward Modeling, Commercials, and Film.. while maintaining my Exclusive Private Poetry Collections
Golden Eagle @golden_eagle235
2 Followers 687 Following
Nico @venturewithnico
14 Followers 28 Following ⚔️ Former British Army PTI 👾Building business’s with AI 👊🏼 1% better every day 🏋🏻♂️ (Wannabe) Hybrid athlete
Joan Kelly EDd @ROARHealth
17K Followers 13K Following Designing Better Healthcare Experiences with AI | Founder at Caidir, RoarHX | Former CXO at Yale & NYU Langone | CX at Humana & Virgin Pulse
Víctor Alan Pérez G... @VPEREZG12
53 Followers 2K Following
Marc Torrents @Marctorrents
170 Followers 2K Following Founder & CEO at Axyom | Building Digital Resilience for Businesses ⚡️
George Ohan @Fresno_Famous
2K Followers 7K Following Intelligence is attractive #GeorgeOhan Husband, Father and Vibe Coding using @Replit "Whatever it takes!" #Veteran #UCLA
Khathutshelo Muvhango @K_Muvhango
1K Followers 5K Following 🇵🇸🇮🇷🇨🇺🇾🇪 @EFFSouthAfrica fightr. Fear fokol! @KaizerChiefs | From the river to the sea, Palestine will be free!
DomainHyve @DomainHyve
250 Followers 2K Following
Art Seabra @ifthis
135 Followers 1K Following Founder & computational neuro @aerrframe: research on cost of inquiry. Building ÆrrSpace, harness concerned with how durable states form, travel, get verified.
Jasonyeah | DeSpread @jasonyeah0503
3K Followers 4K Following Spread Your Own Narrative @DeSpreadteam CEO, Co-Founder | Member @safaryclub
Peter @PeterBuildsSec
4 Followers 82 Following DevSecOps builder creating practical security tools for solo founders and small teams shipping with AI—safer code, CI/CD and agent workflows.
Hck Crk @Hck_Crk
10 Followers 371 Following Here for learning bug bounty, hacking, and sharing my other tech hobbies!
Clint Gibler @clintgibler
26K Followers 579 Following 🛡️ Leading Cyber at @OpenAI 📚 Creator of https://t.co/xwtIAI0CuJ newsletter
Tanya Janca | Shehack... @shehackspurple
50K Followers 2K Following Secure Coding Trainer, Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her 🌻
Abhay Bhargav @abhaybhargav
7K Followers 677 Following AppSec & AI Sec Expert | Black Hat, DEF CON Trainer | Building the future of AI-Native Secure Design and AI Code Security @SecurityReviewAI
Jim Manico from Manic... @manicode
17K Followers 6K Following AI and AppSec Educator. Secure coding system prompts. https://t.co/gbW3ZLhURT
Louis Nyffenegger @snyff
21K Followers 613 Following Founder/CEO of @PentesterLab. Trainer, researcher, CVE archeologist. I like bugs, code review, and understanding why vulnerabilities exist.
Katie Paxton-Fear @InsiderPhD
99K Followers 2K Following Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her
Jayson DeLancey (j12y... @jaysondelancey
830 Followers 2K Following Head of Security Advocacy, Semgrep
AI Village @ DEF CON @aivillage_dc
6K Followers 499 Following Hackers, ML researchers, and data scientists focused on the use and abuse of AI; join us! Discord: https://t.co/XljmSXRZii Twitch: https://t.co/7OcrkYd5xM
Cathy Polinsky @cathy_polinsky
2K Followers 687 Following CTO at DataGrail (formerly Stitch Fix, Salesforce, Shopify, Yahoo!, Oracle, Amazon). Aetion Board. Swarthmore Board.
Alma R Cole @almacole
149 Followers 106 Following
eastside mccarty @eastsidemccarty
721 Followers 738 Following Founder of OpenSourceMalware. Researcher, startup founder, Software Supply Chain Threat Intel
Space Rogue @spacerog
24K Followers 324 Following I fight for the user. | L0pht Heavy Industries - ATStake - Whacked Mac Archives - Hacker News Network - Cyber Squirrel 1 | IBM X-Force
Leif Dreizler @leifdreizler
2K Followers 2K Following Eng Manager at @semgrep 💻 co-host of @404pod 🎙
Scott Helme @Scott_Helme
37K Followers 331 Following Hacker, researcher, builder of things. Founded @securityheaders/@reporturi, Pluralsight author, Microsoft MVP, award winning entrepreneur. Likes cars.
The Application Secur... @AppSecPodcast
3K Followers 1K Following Hosts dig into the stories of AppSec experts and the tools, tactics, and tricks that make them successful.
Codacy @codacy
5K Followers 338 Following Code Quality and Security for AI-Accelerated Coding. Add your repo and get your free scan report in minutes: https://t.co/NV099bie6E
Adam Berman @adamberman_13
182 Followers 415 Following Ultimate Frisbee, SF sports, and sometimes security/technical leadership. Eng director @ https://t.co/JiiqL4GQny
Anoushka Vaswani @anoushkavaswani
4K Followers 1K Following Partner @lightspeedvp investing in software and infrastructure
Will Kohler @wakohler
2K Followers 277 Following partner @Lightspeedvp | dad to 3 rock stars | founder | mom and dad immigrated to US to make it possible | philly sports
BSidesSF @BSidesSF
6K Followers 405 Following Security BSides San Francisco — Join us March 21-22, 2026!
r2c @r2cdev
89 Followers 1 Following We're the maintainers of @semgrep—a fast, open-source, static analysis tool for security and reliability. Follow our main account, @semgrep!
Lewis Ardern @LewisArdern
2K Followers 637 Following Security Researcher @Semgrep & Host of @SecuriTnC. Application Security is my 🍞 & 🧈.
Emily Fortuna @bouncingsheep
5K Followers 319 Following
Juan Zapata @theJuan1112
111 Followers 478 Following Product Security | Developing Secure Software 🇨🇴🍻🇩🇪
Jackie Singh @HackingButLegal
94K Followers 8K Following Investigative Journalist at Hacking, but Legal. Threat Researcher & Security Consultant. Secured @JoeBiden 2020. Cofounder @KinexisAI. Takes here, receipts ↓
Shashwat Sehgal @shashwatsehgal
158 Followers 555 Following Founder @P0Security. In the clouds, I build Security and IAM tools. Back on earth, I play chess
Felicis @felicis
17K Followers 988 Following We are the true believers in founders who have the imagination, courage, and discipline to defy the odds and build something extraordinary.
Pawan Khandavilli @khpawan
267 Followers 873 Following Product Manager for Azure Confidential Computing (ACC) #ConfidentialComputing Author of Amma's Kitchen Opinions are my own and not the views of my employer.
Brian Smith @BRIAN_____
3K Followers 556 Following
kingtoto @kingtot31410584
25 Followers 191 Following A little bit of this, a little bit of that and a lot of everyrhing else
Jurre van Bergen @DrWhax
5K Followers 2K Following I research surveillance and spyware systems. Secure contact: https://t.co/dR3wVwG083 - find me on other platforms.
Edgar @embarbosa
1K Followers 659 Following
Karan Chaudhary ⚽ @ckarany
58 Followers 65 Following Building and debugging distributed systems. Present-@demonware Past- @amazon, @freshworksinc and engineer in 3 startups.
Guy Flechter @Guy_Flechter
229 Followers 815 Following Changing things| Founder and CEO @SolaSecurity| Former Co-founder and CEO @Cider_sec (Now part of PANW))
Pradyumna Shome @PradyumnaShome
701 Followers 805 Following Ich geh mit dir wohin du willst. Geboren, um zu leben, mit den Wundern jener Zeit.
SidiMohamed Beillahi @SBeillahi
49 Followers 271 Following Postdoctoral researcher at @UofT PhD from @IRIF_Paris - @Univ_Paris
Achim D. Brucker @adbrucker
445 Followers 1K Following Cybersecurity Prof at @UniofExeter, former Security Testing Strategist at SAP SE. https://t.co/UOyCdkcxVK / @[email protected]
Sandesh Anand @JubbaOnJeans
2K Followers 641 Following AppSec since before it was cool. Building @seezo_io · BoringAppSec pod+newsletter. Currently overthinking Security in the AI SDLC. Bangalore.
Chang Xu @_changxu
4K Followers 3K Following Partner @BasisSet. Investing in and building AI agents. Former founder and operator.
Stefan Kraxberger @skraxberger
563 Followers 4K Following cyber security enthusiast, nature lover #cybersecurity, #infosec
Travis A. Everett (@a... @abathur
96 Followers 490 Following I code/write/edit. Fixing Shell w/ Nix + https://t.co/4p2invv1l0. Built @escarp literary review. MUD admin. Hopefully lazy-loading books into my wetw
0xdbe @0xdbe1
37 Followers 82 Following
Daniel Andion @dand_dev
19 Followers 122 Following Software Engineering :: AppSec :: Tech in general





























