Home / Companies / Semgrep / Blog / October 2025

October 2025 Summaries

5 posts from Semgrep

Filter
Month: Year:
Post Summaries Back to Blog
ENISA's analysis of 5,000 cybersecurity incidents across the European Union highlights the evolving threat landscape for 2025, emphasizing the increasing convergence, automation, and industrialization of cyber attacks. The report reveals that phishing remains the primary method for breaching corporate networks, with attackers using AI to enhance their tactics. State-sponsored groups, particularly from Russia, North Korea, and China, are increasingly adopting ransomware and hacktivist personas, blurring the lines between different threat actors. DDoS attacks account for the majority of incidents, especially in the public administration, transport, and digital infrastructure sectors, driven largely by hacktivism. The report underscores the importance of moving from reactive to proactive security measures, focusing on intelligence-driven resilience and strategic alignment with business objectives to anticipate and mitigate the evolving threat landscape. It calls for a collaborative approach to cybersecurity, emphasizing that awareness and shared responsibility across organizations are crucial in combating AI-enabled and human-centric threats.
Oct 29, 2025 896 words in the original blog post.
The integration of Semgrep's static analysis (SAST) with StackHawk's dynamic testing (DAST) aims to streamline application security workflows by providing a unified view of vulnerabilities, thereby reducing the noise and inefficiencies associated with disconnected testing tools. While static analysis identifies vulnerabilities early in the development process, dynamic testing evaluates their exploitability in a running environment. The integration addresses the challenges of duplicate findings and fragmented visibility by correlating code-level issues with runtime vulnerabilities, allowing AppSec teams to focus on actionable risks. This coordinated approach enhances remediation efficiency and strengthens the collaboration between development and security teams by offering a single source of truth regarding vulnerability risk. In an era of rapid software development accelerated by AI and automation, this integration is a significant advancement in application security maturity, ensuring that teams can prioritize real threats and improve remediation outcomes.
Oct 22, 2025 548 words in the original blog post.
Semgrep has been recognized in the 2025 Gartner Magic Quadrant for Application Security Testing, highlighting its innovative approach to modern application security challenges and its evolution from an open-source SAST tool to a comprehensive AI-enabled AppSec platform. The company has developed solutions like Semgrep Code, Semgrep Supply Chain, and Semgrep Secrets to address common issues such as false positives and developer engagement, incorporating advanced techniques like dataflow reachability and cross-file analysis. Semgrep Assistant's AI capabilities enhance precision by analyzing context beyond rule-based analysis, significantly reducing noise and improving developer workflows. This approach has led to a 96% agreement rate in classifying security findings, with AI Triage filtering out 60% of false positives, thereby decreasing the burden on AppSec teams and reducing developer remediation time. The company anticipates that as AI continues to transform software development, security strategies will need to adapt to address vulnerabilities in both human and machine-generated code.
Oct 14, 2025 949 words in the original blog post.
A recent discovery by Koi research revealed a subtle attack on npm involving a malicious MCP server named postmark-mcp, which added a BCC line to emails sent through an AI agent, allowing an attacker to receive copies. This incident raises questions about the security of Model-Context-Protocol (MCP) servers, which act as interfaces for AI agents interacting with traditional software. Although MCP is designed to be simple, this simplicity can create vulnerabilities, as seen in this attack where an attacker used typosquatting on npm to exploit the system. The incident emphasizes the need for robust security practices in MCP development, such as input validation, authentication, and supply chain security, as AI becomes more integrated into software systems. It also highlights the ongoing challenge of balancing AI advancements with security measures, suggesting a future shift towards trusted MCP marketplaces and potentially adopting zero trust principles for AI agents to prevent similar attacks.
Oct 02, 2025 1,509 words in the original blog post.
Semgrep Managed Scans (SMS) offers a streamlined solution for organizations to implement security tools like SAST, SCA, and secret detection without the need for complex infrastructure, enabling rapid deployment and modification of code scanning tools. By utilizing Semgrep's cloud infrastructure, SMS automates scan processes, providing a hands-free experience that has gained traction with over 40% of Semgrep customers, processing over one million scans weekly. The tool's architecture was shaped by real-world challenges from various companies, ensuring reliability, performance, and scalability, with features like enterprise-scale orchestration and AI-powered remediation. SMS delivers significant ROI by cutting operational overhead and infrastructure costs while enhancing the developer experience through fast scans and advanced noise reduction, as exemplified by Glasswall's success. The platform supports over 30 programming languages and offers features such as one-click deployment, configurable PR blocking, and comprehensive monorepo support, making it suitable for both small teams and large enterprises.
Oct 01, 2025 907 words in the original blog post.