Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Shift Right? After 20 Years of Shift Left?

Blog post from Semgrep

Post Details
Company
Date Published
Author
Cris Thomas (Space Rogue)
Word Count
1,580
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Semgrep CTO Drew Dennison’s Black Hat 2026 talk argued that traditional “shift left” security practices remain necessary but must be complemented by “shifting right” to continuously analyze deployed and legacy software as AI expands both code production and attacker capabilities. Semgrep researchers, using early access to Anthropic’s Mythos model alongside static analysis, dynamic testing, and constrained agent skills, reported finding 100 runtime-verified vulnerabilities in major open-source projects, emphasizing that specialized analysis tools and testing harnesses can be as important as model capability. The company’s Mandoline project is designed to give AI agents structured program-analysis access across 47 languages, reducing repeated text searches and file reads by supplying code graphs, dataflow analysis, taint tracking, reachability information, and audit coverage. Its Context Engine aims to make recurring security analysis affordable by caching prior conclusions and retaining organizational knowledge, such as accepted risks and past triage decisions, so agents do not repeatedly flag known nonissues. The central argument is that defenders can offset attackers’ growing access to capable, cheaper AI models by combining continuous analysis with proprietary codebase, deployment, threat-model, and institutional context, while also applying security controls earlier in AI-assisted coding workflows.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 2 No monthly metrics for this publish month.
MCP 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.