ZeroPath Blog & Research
Explore our team's latest research and stay up to date with ZeroPath's capabilities.

Product
•2026-06-12
•8 min read
Introducing Automated Application Threat Modeling
AI changed who writes code. ZeroPath keeps your application secure and true to your design, evaluating every change at the agent, the PR, and the repo.
ZeroPath Team

Product
•2026-05-11
•6 min read
Zero: AI Assistant For AppSec
We built an AI agent that runs your AppSec program. Here's what it actually does — from triaging bug bounty reports in about 10 minutes to building scheduled security sprints in plain English.
Peter Purcell

Product
•2024-11-01
•15 min read
How ZeroPath Works
Technical deep-dive into ZeroPath's SAST methodology: From AST generation to AI-powered vulnerability discovery and automated patch generation.
Raphael Karger

Product
•2026-08-20
•5 min read
Reachability-Aware SBOMs: VEX That Knows What's Actually Exploitable
ZeroPath builds CycloneDX, SPDX, VEX, and AI-BOM exports from your scan inventory, and marks every CVE reachable or not_affected so you fix what's exploitable first.
Gaurav Sarraf

Product
•2026-08-17
•5 min read
Posture-Safe Dependency Remediation: Upgrade PRs That Don't Make Your Security Worse
Dependabot bumps the version. ZeroPath makes sure the upgrade doesn't add a new CVE, proves transitive fixes in a sandbox, and flags which of your call sites might break.
Gaurav Sarraf

Product
•2026-08-13
•5 min read
Continuous CVE Alerting for the Dependencies You Already Ship
ZeroPath watches the OSV feed continuously and alerts you within minutes when a new CVE hits a dependency you already ship, triaged for reachability instead of waiting for your next scheduled scan.
Gaurav Sarraf

Product
•2026-08-10
•5 min read
Beyond CVSS: Contextual Vulnerability Intelligence for CVEs
CVSS rates worst-case severity, not real risk. ZeroPath layers four signals on every dependency CVE: the real advisory CVSS, CISA KEV, FIRST EPSS, and an AI-derived contextual severity for your repo, refreshed daily and kept honest.
Gaurav Sarraf

Product
•2026-08-03
•5 min read
Build-less Dependency Scanning: SCA Coverage You Can Actually Verify
SCA forces a bad trade: run a fragile build for full coverage, or scan manifests and miss the transitive majority. ZeroPath resolves the full graph build-lessly for npm, Maven, and pinned Python, and reports exactly how much of your supply chain each scan resolved.
Gaurav Sarraf

Product
•2026-05-19
•5 min read
How To Handle Bug Bounty Reports With ZERO
AI-assisted submission volume has inflated bug bounty inboxes while exploitation timelines have compressed to hours. ZERO drafts triage decisions (ticket or response) on the codebase context ZeroPath has already built, for a human to approve or override.
Ogulcan Gurcaglar

Product
•2026-05-11
•3 min read
ZeroPath Outperforms Mythos In Real World Test
When Anthropic's Mythos-powered Glasswing scanner re-analyzed curl, it surfaced one low-severity bug — months after ZeroPath helped Joshua Rogers ship fixes for nearly 170. The harness around the model matters more than the model itself.
John Walker

Product
•2025-08-12
•12 min read
Introducing ZeroPath: The Security Platform That Actually Understands Your Code
Announcing the official v1 launch of ZeroPath, an AI-powered application security platform trusted by 750+ companies and performing 125,000+ code scans monthly. Learn how ZeroPath combines LLMs with AST analysis to deliver contextual vulnerability detection and one-click patch generation.
ZeroPath Team

Product
•2025-03-27
•6 min read
Introducing ZeroPath’s Open-Source MCP Server
Query your product security findings with natural language. ZeroPath’s open-source MCP server integrates with Claude, Cursor, Windsurf, and other tools to surface SAST issues, secrets, and patches—right where developers work.
ZeroPath Security Research

Product
•2024-11-13
•5 min read
How ZeroPath Compares
ZeroPath compares its SAST performance against competitors using the XBOW benchmarks, in a manner thats reproducible.
ZeroPath Team