Shift Right? After 20 Years of Shift Left?
Blog post from Semgrep
Semgrep CTO Drew Dennison’s Black Hat 2026 talk argued that traditional “shift left” security practices remain necessary but must be complemented by “shifting right” to continuously analyze deployed and legacy software as AI expands both code production and attacker capabilities. Semgrep researchers, using early access to Anthropic’s Mythos model alongside static analysis, dynamic testing, and constrained agent skills, reported finding 100 runtime-verified vulnerabilities in major open-source projects, emphasizing that specialized analysis tools and testing harnesses can be as important as model capability. The company’s Mandoline project is designed to give AI agents structured program-analysis access across 47 languages, reducing repeated text searches and file reads by supplying code graphs, dataflow analysis, taint tracking, reachability information, and audit coverage. Its Context Engine aims to make recurring security analysis affordable by caching prior conclusions and retaining organizational knowledge, such as accepted risks and past triage decisions, so agents do not repeatedly flag known nonissues. The central argument is that defenders can offset attackers’ growing access to capable, cheaper AI models by combining continuous analysis with proprietary codebase, deployment, threat-model, and institutional context, while also applying security controls earlier in AI-assisted coding workflows.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.