Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungKI half beim Finden: iOS 27 schließt mehr als 100 Sicherheitslücken(21.09.2026 um 06:00 Uhr)
Sichere ProgrammierungWhat Is Rowhammer? How Can Repeated Memory Access Flip Bits in RAM?(21.09.2026 um 07:12 Uhr)
Sichere Programmierungnpm publish Ignores .gitignore: The .npmignore Override Rule(21.09.2026 um 07:15 Uhr)
Sichere ProgrammierungAphelion Editor - A free node-based video / VFX editor(21.09.2026 um 07:21 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: OKX(21.09.2026 um 07:31 Uhr)
Sichere ProgrammierungJSM Portal Request Create Property Panel Submit(21.09.2026 um 07:34 Uhr)
Reverse Engineeringsearch instructions assembly easy (X86,RISCV,AARCH64,etc)(20.09.2026 um 15:44 Uhr)
Sichere ProgrammierungKI half beim Finden: iOS 27 schließt mehr als 100 Sicherheitslücken(21.09.2026 um 06:00 Uhr)
Sichere ProgrammierungWhat Is Rowhammer? How Can Repeated Memory Access Flip Bits in RAM?(21.09.2026 um 07:12 Uhr)
Sichere Programmierungnpm publish Ignores .gitignore: The .npmignore Override Rule(21.09.2026 um 07:15 Uhr)
Sichere ProgrammierungAphelion Editor - A free node-based video / VFX editor(21.09.2026 um 07:21 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: OKX(21.09.2026 um 07:31 Uhr)
Sichere ProgrammierungJSM Portal Request Create Property Panel Submit(21.09.2026 um 07:34 Uhr)
Reverse Engineeringsearch instructions assembly easy (X86,RISCV,AARCH64,etc)(20.09.2026 um 15:44 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

AI Memories, PHP Reachability, CVE Policies, and Benchmarking

Reagiere als Erste:r — dein Feedback zählt!

I've rounded up some news and updates about Semgrep. We want to help developers to ship features, not vulnerabilities.

A Security Tool That Learns

Identify Memories using Semgrep Assistant and the AI model improves. The platform gets smarter about YOUR specific environment and policies. This effect compounds to make development teams more efficient by reducing false positives.

Read more in the blog post Is Zero False Positives a Reality?

PHP Reachability Analysis

Reachability analysis dramatically reduces the noise from SCA alerts, by up to 98%. We’re excited to introduce the industry’s first reachability analysis for PHP, marking the 11th language with this capability.

For additional coverage, see the docs about language support.

Vibe Coding and AI Security with MCP

"There's a viber born every minute."
-- P.T. Barnum (likely)

We can’t always trust the output of code generated by AI. When combined with security scanning, such as using the Semgrep MCP server, we can better manage risk with tools like Cursor – watch the demo.

Replit takes the security of their customers seriously and has integrated Semgrep into their Security Scanner.

Graduating to Semgrep AppSec Platform

We proudly sponsor continued support for Semgrep Community Edition which is why it continues to be a top performing free SAST tool used by:

  • Security researchers
  • Pentesters
  • Consultants
  • Open-source developers
  • Hobbyists

For Application Security Engineers and Development Teams that take security seriously, you may need more. The updated Semgrep Pricing page clarifies where to find the features you need.

Quarterly Release Summary

Our Quarterly Release page pulls together highlights from the past few months of releases to Code (SAST), Supply Chain (SCA), and Secrets (detection).

Use CVE as a Supply Chain Policy

Want to block or comment for a specific set of CVEs crucial to your product? Choose from a list of CVEs generated from findings, or input a known CVE ID -- dependency search is available by CVE ID or rule name.

Semgrep Supply Chain SCA Dependency Search

Benchmarking Source Code Scanning Speed

If source-code scanning and static analysis slows down development, engineering teams won’t adopt it. Is Semgrep fast? Yes it is.

Learn how we think about performance at Semgrep in this blog post: Benchmarking Semgrep Performance Improvements.

Find this update and more open-source improvements in 20+ releases so far this year.

Customizable PR / MR Comments

Many developers review security findings directly as comments left in merge or pull requests. In the Semgrep Platform settings tab, teams can customize these to add company-specific instructions, links to resources, or other helpful notes.

Semgrep Security Scan with PR and MR Comments

See the PR / MR Comments documentation for setting up Azue, GitHub, GitLab, or Bitbucket for examples of custom comments.

SoSafe Case Study

“We treat engineers as partners, not just stakeholders. Semgrep helps us meet them where they are.”
– Mubasher Chaudhary, Application Security Engineer, SoSafe

Learn more about how SoSafe evaluated tools for their security program in the SoSafe Case Study.

How to Get Started with Semgrep

If you've only just learned about Semgrep, here's some ways to get started:

The Semgrep Community Edition is free open-source software that powers many teams with basic functionality.

The Semgrep AppSec Platform capabilities are available to test on any project with fewer than ten (10) contributors for free. Just hop over to semgrep.dev, sign up, and follow the Quick Start.

If you have any questions or feedback, hop onto the Community Slack and let’s chat (I’m @j12y)! If you want to talk to us virtually or see us in-person, check out the events page to see where we’ll be.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten AI Memories, PHP Reachability, CVE Policies, and Benchmarking

Thematisch verwandte Begriffe: Memories, Reachability, Policies, Benchmarking · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick