Viewing profile — asadeddin
asadeddin
HN member- Joined
- Tue, Oct 14, 2014, 2:39 PM UTC
- HN karma
- 163
- Public activity
- 68 items
- HN profile
- View on Hacker News ↗
About asadeddin
Recent public activity
- comment
- story
-
story
Show HN: Sighthound - open-source vulnerability scanner for source code
We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast…
- story
-
comment
Comment #48633682
OpenAI building security tooling is the natural next step after AI-powered code generation, if AI writes the code, AI will need to find and fix the bugs in it too. The interesting …
-
comment
Comment #48621980
Full disclosure, Ahmad, CEO at Corgea. Interesting approach, catching vulns at commit time before CI runs saves cycles. The challenge is always false positive rate at that stage an…
-
comment
Comment #48616649
Delaying vulnerability disclosure for political reasons undermines the entire coordinated disclosure model. If researchers learn that findings get buried when inconvenient, they st…
-
comment
Comment #48610760
[dead]
-
comment
Comment #48610752
[flagged]
-
comment
Comment #48602166
[dead]
-
comment
Comment #48574077
The Corgea team has found a High vulnerability in Axios using our security research agent. This 0-day affects millions of globally. The cost of finding this vulnerability was <$10 …
- story
- story
- story
- story
- story
-
comment
Comment #45456994
Hi there, I'm Ahmad, CEO at Corgea, and the author of the white paper. We do actually use LLMs to find the vulnerabilities AND triage findings. For the majority of our scanning, we…
-
comment
Comment #45168373
Very interesting. Thanks for sharing the insights! Would've it made more sense to separate this testing out to a different instance of your product? This would've probably helped d…
- story
- story
- story
-
comment
Comment #41569486
We completely agree. I would redefine it a bit. We combine static analysis + LLMs to do better detection, triaging and auto-fixing because static analysis alone is broken in many w…
-
comment
Comment #41569466
I would redefine it a bit. Reliable = deterministic Accurate? Not at all. Studies show that ~30% of findings are false positive. We've also seen that with the companies we work wit…
-
comment
Comment #41569398
Totally agree. We have a term for it "Dev confidence". Devs really don't want to touch something that's been working for a long time, especially in a codebase they're not familiar …
- comment