ZeroPath reposted this
Black Hat 2026: The Supply-Chain Trust Series by Dr. Arun Lakhotia explores Microsoft, ReversingLabs, NetRise, Chainguard, ActiveState, Magnitude & ZeroPath. Read the series: https://ow.ly/uZjk50ZAH1R
Founded by security engineers from Tesla and Google, ZeroPath empowers developers to ship secure code faster. Our LLM-powered security platform detects, verifies, and fixes conventional technical vulnerabilities and complex security issues like business logic flaws. Our intelligent analysis significantly reduces false positives and generates precise one-click patches that dramatically cut remediation time. ZeroPath transforms how teams approach application security with a truly developer-friendly solution. Visit ZeroPath.com to secure your code without sacrificing speed.
External link for ZeroPath
ZeroPath is an AI-driven AppSec platform that beats traditional tooling in coverage and accuracy by truly understanding your codebase. Rather than relying on static rules or signatures, it learns how repositories, services, and dependencies interact to detect issues that legacy tools miss, including business logic flaws, authentication bypasses, and chained vulnerabilities. We've replaced traditional SAST, SCA, Secrets, and IaC scanning stacks with a single engine that intelligently assesses exploitability and generates context-aware pull requests. For our customers, the ZeroPath scanner has helped close significant security gaps in end products and driven massive backlog reductions. In the wild, ZeroPath has been used to find bugs in curl, sudo, Next.js, and other major projects.
San Francisco, California, US
2261 Market St
STE 10797
San Francisco, California 94114, US
ZeroPath reposted this
Black Hat 2026: The Supply-Chain Trust Series by Dr. Arun Lakhotia explores Microsoft, ReversingLabs, NetRise, Chainguard, ActiveState, Magnitude & ZeroPath. Read the series: https://ow.ly/uZjk50ZAH1R
ZeroPath reposted this
ZeroPath reposted this
Fun first night at Black Hat! Always a good time hanging out with new and old friends in person. Ended day one with a crazy nightcap hunt courtesy of Rob Fuller. Worth it!! Excited for day two! SkillBit (formerly MetaCTF) + ZeroPath at the F1 Arcade tonight 👀
Our security team hacked five security vendors using their “Free Trial” signup. We submitted malicious repositories and discovered we could have modified customer code with the access we gained. I’m talking about this at BlackHat this week. I spoke with Dark Reading about how we did it and what we found. More details here: https://lnkd.in/gyVSUSCS
ZeroPath reposted this
Heading to Vegas with everyone else this week. If you want to catch us, here’s a list of where team SkillBit (formerly MetaCTF) will be. Hit me up if you want to say hello outside of our events! 🙌 🦉 🔶 Tuesday x SkillBit at Black Hat booth #5551 with The Ginger Hacker Initiative 🔶 Tuesday x Dinner with SkillBit (small group) 🔶 Wednesday x Roman and I at CISO Games 🔶 Wednesday x SkillBit at Black Hat booth #5551 with The Ginger Hacker Initiative 🔶 Wednesday x Race into Black Hat with SkillBit and ZeroPath at F1 Arcade 🔶 Wednesday x Dinner with SkillBit (small group) 🔶 Thursday x Attack / Defense CTF with US Cyber Games at HyperX Arena Las Vegas 🔶 Thursday x Hacking on the Higher Roller CTF hosted by us 🙂 🔶 Thursday x SkillBit at Black Hat booth #5551 with The Ginger Hacker Initiative 🔶 Friday x Roman‘s workshop on web security at Noob Village 🔶 Friday / Sat / Sun x CTF at Noob Village 🔶 Friday / Sat / Sun x CTF at Red Team Village 🔶 Friday / Sat / Sun x CTF at Blue Team Village Whew...with Hacker Summer Camp, back to school, and two of our kids’ birthdays, it’s going to be a busy August! 🙂 See y’all this week!
ZeroPath reposted this
Software supply chain attackers are increasingly turning their sights on how to abuse security tools in the development pipeline. I talked to ZeroPath's Raphael Karger for this piece in Dark Reading previewing his session next week at Black Hat USA. He'll show how simply feeding malicious repositories into security scanners can potentially give attackers a pivot into their customers' build environments. This is no academic exercise. The research was inspired by an attack his firm repelled from its own systems. Karger will drop a new tool to help orgs audit their security scanners for weakness to this attack path. https://lnkd.in/ekXHzw_g
ZeroPath reposted this
The tools we trusted to find vulnerabilities are now an attack surface. On July 29, Dark Reading reported on research from ZeroPath in which Raphael Karger's team tested 20 AppSec scanning vendors and found five with exploitable weaknesses including cloud credentials, production database access, and developer tokens that an attacker could use to turn a scanner into a supply chain foothold. This is a different attack model from the Trivy and KICS compromises where attackers breached the development environment itself. In this case, an attacker only needs to feed a scanner a malicious repository. When the scanner processes untrusted content without proper isolation, which many do, it becomes the attacker's proxy inside the pipeline. There is no breach and no stolen credentials, only a carefully crafted codebase and the assumption that scanners operate in read-only mode. At Black Hat next week, Karger will release Build Canaries as an open source tool with 349 validated payloads and a taxonomy of repository ingestion execution surfaces. It gives security teams a way to ask their AppSec vendors the same question they ask of any build tool: can you be turned against me? The uncomfortable truth is that AppSec is a hyper-competitive market where vendors often prioritize feature velocity over isolation architecture and the customer who trusts the scanner's output is rarely aware of the boundary between reading and executing. You can outsource the scanning but you cannot outsource the liability for what runs inside it. When was the last time you audited the tools that audit your code? https://lnkd.in/gQ4eWQWR