Automated Threat Modeling

ZeroPath Blog & Research

Explore our team's latest research and stay up to date with ZeroPath's capabilities.
Introducing CatastropheBench: A Tripwire for Autonomous Zero-Day Discovery
Research

2026-07-22

7 min read

Introducing CatastropheBench: A Tripwire for Autonomous Zero-Day Discovery

CatastropheBench gives AI agents current source code, with no CVE hints or internet access, and checks whether they get remote code execution. Zero is the only acceptable score.

Dean Valentine

Dean Valentine

CatastropheBench: A Benchmark for Autonomous Vulnerability Discovery in Frontier Models
Research

2026-07-21

9 min read

CatastropheBench: A Benchmark for Autonomous Vulnerability Discovery in Frontier Models

OpenAI's models broke out of an eval sandbox and autonomously compromised Hugging Face's production systems to cheat on a benchmark, chaining a novel zero-day, stolen credentials, and remote code execution. This is exactly the dangerous autonomous cyber capability CatastropheBench, our open-source latest-version zero-day canary, is designed to catch before it leaves the lab.

Etienne Lunetta

Etienne Lunetta, Raphael Karger, Dean Valentine

CVE-2026-30950 Allows Chat Session Hijacking In AutoGPT
Research

2026-05-20

7 min read

CVE-2026-30950 Allows Chat Session Hijacking In AutoGPT

ZeroPath Research discovered an authenticated IDOR in AutoGPT (CVE-2026-30950) that lets any logged-in user hijack any other user's chat session with a single PATCH request, exposing the full conversation history and locking out the original owner. Affects autogpt-platform-backend >= 0.6.36, < 0.6.51; patched in 0.6.51.

John Walker

John Walker

AI Coding Assistants Are Not a SAST Program
Insights

2026-05-19

10 min read

AI Coding Assistants Are Not a SAST Program

AI coding assistants can catch narrow, inner-loop security issues, but they do not replace full-codebase coverage, stable issue tracking, workflow integrations, and broader AppSec controls.

ZeroPath Team

ZeroPath Team

How To Handle Bug Bounty Reports With ZERO
Product

2026-05-19

5 min read

How To Handle Bug Bounty Reports With ZERO

AI-assisted submission volume has inflated bug bounty inboxes while exploitation timelines have compressed to hours. ZERO drafts triage decisions (ticket or response) on the codebase context ZeroPath has already built, for a human to approve or override.

Ogulcan Gurcaglar

Ogulcan Gurcaglar

ZeroPath Outperforms Mythos In Real World Test
Product

2026-05-11

3 min read

ZeroPath Outperforms Mythos In Real World Test

When Anthropic's Mythos-powered Glasswing scanner re-analyzed curl, it surfaced one low-severity bug — months after ZeroPath helped Joshua Rogers ship fixes for nearly 170. The harness around the model matters more than the model itself.

John Walker

John Walker

ZeroPath's 36 Sudo Bug Fixes Reduce CrackArmor's Impact
Research

2026-03-18

15 min read

ZeroPath's 36 Sudo Bug Fixes Reduce CrackArmor's Impact

One of ZeroPath's 36 sudo security fixes was rediscovered in Qualys' CrackArmor vulnerability. We share the full list of fixes, including POC for a previously-unpublished RCE targeting sudo's optional log server.

John Walker

John Walker

7 Best SAST Tools in 2026: Detailed Guide for AppSec Engineers and CISOs
Insights

2026-03-04

25 min read

7 Best SAST Tools in 2026: Detailed Guide for AppSec Engineers and CISOs

We compared the 7 best SAST tools of 2026 side-by-side. Pricing, features, false positive rates, enterprise readiness and more for AppSec engineers and CISOs.

ZeroPath Team

ZeroPath Team

Why Commenda Chose ZeroPath to Secure Their Global Tax Platform
Insights

2026-02-26

8 min read

Why Commenda Chose ZeroPath to Secure Their Global Tax Platform

How Commenda's CTO runs a complete security program, finding 4× more real vulnerabilities including business logic bugs no legacy scanner catches, in a couple hours per week without dedicated security headcount.

ZeroPath Team

ZeroPath Team

Malicious Websites Can Exploit Openclaw (aka Clawdbot) To Steal Credentials
Research

2026-02-02

5 min read

Malicious Websites Can Exploit Openclaw (aka Clawdbot) To Steal Credentials

Openclaw (aka Clawdbot) delivers impressive AI experiences but malicious websites can abuse it to steal your credentials

John Walker

John Walker

Autonomously Finding 7 FFmpeg Vulnerabilities With AI
Research

2025-12-02

15 min read

Autonomously Finding 7 FFmpeg Vulnerabilities With AI

ZeroPath's AI-assisted SAST analyzed FFmpeg and reported seven distinct memory safety flaws, including buffer overflows and invalid memory writes, missed by traditional tools.

ZeroPath Team

ZeroPath Team

Avahi Simple Protocol Server DoS (CVE-2025-59529)
Research

2025-11-18

8 min read

Avahi Simple Protocol Server DoS (CVE-2025-59529)

A logic flaw in Avahi Simple Protocol Server ignored the configured client limit, allowing any user to open unlimited connections and exhaust memory and file descriptors, causing a system-wide denial of service for mDNS and DNS-SD.

ZeroPath Team

ZeroPath Team

7 vulnerabilities in django-allauth enabling account impersonation and token abuse
Research

2025-11-05

5 min read

7 vulnerabilities in django-allauth enabling account impersonation and token abuse

Our audit of django-allauth uncovered seven vulnerabilities, including two that enable user impersonation and others affecting token handling, email verification, and HTTP configuration. We detail how our AI-assisted scanner exposed these logic-level issues, the patches applied, and what developers should do to secure their authentication flows.

ZeroPath Team

ZeroPath Team

How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports
Research

2025-10-21

10 min read

How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports

ZeroPath's AI-based static analyzer uncovered 170 verified issues in curl, from C footguns to logic and RFC compliance bugs across HTTP/3, SMTP, IMAP, TFTP, Telnet, and SSH/SFTP, with curl maintainer Daniel Stenberg praising the quality -- proof that AI source code analyzers can produce high-quality findings even in the curl project, not just AI slop.

ZeroPath Team

ZeroPath Team

Critical Account Takeover via Unauthenticated API Key Creation in better-auth (CVE-2025-61928)
Research

2025-10-19

9 min read

Critical Account Takeover via Unauthenticated API Key Creation in better-auth (CVE-2025-61928)

ZeroPath uncovered an unauthenticated API key creation flaw in better-auth's API keys plugin that enables attackers to mint privileged credentials for arbitrary users; this post details the bypass, exploitation path, and how we found it.

Etienne Lunetta

Etienne Lunetta

Introducing ZeroPath: The Security Platform That Actually Understands Your Code
Product

2025-08-12

12 min read

Introducing ZeroPath: The Security Platform That Actually Understands Your Code

Announcing the official v1 launch of ZeroPath, an AI-powered application security platform trusted by 750+ companies and performing 125,000+ code scans monthly. Learn how ZeroPath combines LLMs with AST analysis to deliver contextual vulnerability detection and one-click patch generation.

ZeroPath Team

ZeroPath Team

How to meet security requirements for PCI-DSS compliance?
Insights

2025-07-17

8 min read

How to meet security requirements for PCI-DSS compliance?

Of the 12 requirements of PCI DSS, the 6th one requires companies to maintain application security at all times and is one of the most critical and challenging to meet due to the dynamic nature of software development.

ZeroPath Security Research

ZeroPath Security Research

Authorization Bugs Are Having Their SQL Injection Moment
Research

2025-07-17

12 min read

Authorization Bugs Are Having Their SQL Injection Moment

GitLab patched critical auth bugs. McDonald's leaked 64M records through a basic IDOR. Authorization bugs aren't new but AI can now find them at scale. We turned LLMs loose on modern codebases and discovered why 2025 is the year IDORs go from manual pentest finding to automated epidemic.

ZeroPath Security Research

ZeroPath Security Research

What is PCI DSS? 12 Requirements to be PCI DSS Compliant
Insights

2025-07-16

6 min read

What is PCI DSS? 12 Requirements to be PCI DSS Compliant

PCI DSS is a set of 12 requirements designed to protect cardholder data. It covers security, network, and application layers. To be compliant, businesses must implement these requirements, which include data encryption, firewalls, regular security audits and more.

ZeroPath Security Research

ZeroPath Security Research

What is PCI Compliance? Does your business need PCI Compliance?
Insights

2025-07-15

5 min read

What is PCI Compliance? Does your business need PCI Compliance?

PCI compliance refers to security standards protecting cardholder data during transactions. It includes standards like PCI DSS for handling card data, PCI PTS for payment terminals, and PCI 3DS for online fraud prevention. Businesses must determine their specific needs, like whether they store card information or use physical readers.

ZeroPath Security Research

ZeroPath Security Research

Detect & fix
what others miss

Works with
  • GitHub
  • GitLab
  • Bitbucket
  • Azure DevOps Services
  • Gerrit
  • CVS
  • Jira
  • Linear
  • Slack
  • Security Compass
Explore integrations
Security magnifying glass visualization
Blog | ZeroPath - Security Research, CVE Analysis & Product Updates | Page 2 | ZeroPath