Home / Companies / Semgrep / Blog / October 2026

October 2026 Summaries

5 posts from Semgrep

Filter
Month: Year:
Post Summaries Back to Blog
No summary generated yet.
Oct 09, 2026 1,718 words in the original blog post.
No summary generated yet.
Oct 08, 2026 1,551 words in the original blog post.
Engineering teams are increasingly adopting and switching among AI coding tools such as Codex, Claude Code, Cursor, IDEs, and command-line agents based less on formal organizational decisions than on individual developers’ perceptions of productivity and autonomy. Codex has gained traction because some engineers trust it to complete tasks with minimal supervision, including opening and merging pull requests, interacting with cloud services, and performing operational work, while its support for the shared AGENTS.md context format and comparatively favorable retry costs can make it practical in multi-tool environments. However, widespread autonomous use raises concerns about reduced human code review, usage limits, fragmented workflows, and the need for standardized configurations. The discussion argues that automated, deterministic security controls should replace some of the safeguards previously provided by manual review, highlighting lifecycle hooks in Codex, Claude Code, and Cursor that allow tools such as Semgrep Guardian to scan code immediately after AI agents modify files and to be deployed centrally through enterprise management systems.
Oct 06, 2026 1,101 words in the original blog post.
MCP and Hooks serve complementary roles in AI coding platforms: MCP standardizes how agents connect to external tools, repositories, APIs, and data sources, while Hooks provide platform-controlled moments to observe, modify, or block agent actions. Although an MCP security scanner can be available to an agent, its use remains optional because the model decides whether and when to invoke it; Hooks instead enforce checks independently of the model’s judgment. Grok Build’s Semgrep integration illustrates this approach by triggering code scans at defined points after agent changes, returning findings to the agent for remediation before work is completed. Hooks can also operate around MCP calls to inspect requests, monitor responses, and enforce organizational policies at tool boundaries. Together, MCP expands agent capabilities and Hooks establish reliable guardrails, enabling agents to access more systems without leaving critical security and compliance controls to prompts or model discretion.
Oct 05, 2026 1,227 words in the original blog post.
Cybersecurity Awareness Month began in 2004 as a U.S. government and industry initiative to teach newly connected individuals and organizations about basic online risks, but the author argues that widespread public recognition of threats such as phishing, ransomware, weak passwords, and software vulnerabilities has made awareness an insufficient goal. The piece contends that security campaigns should prioritize measurable readiness actions, including enabling multifactor authentication, patching systems, testing backups, fixing vulnerabilities, and exercising incident-response plans. It also notes that the common abbreviation CSAM conflicts with the established term for child sexual abuse material, creating an additional reason to change the branding. The author proposes “Cybersecurity Readiness Month” as a replacement and explains that CISA, the National Cybersecurity Alliance, presidential proclamations, and broader public adoption could facilitate the change, while recognizing that the original observance successfully helped make cybersecurity a mainstream concern.
Oct 02, 2026 1,316 words in the original blog post.