ai-security
6 posts on this topic. For the full archive, see the security blog. Comparison writes-ups live on Why Puaro and the methodology page.
Regex Finds Candidates. AI Decides What's Noise.
We ran Gitleaks, TruffleHog, GitGuardian, and Puaro on four open-source repos. Puaro's AI suppressed 334 candidate findings and left 33 real alerts for humans.
Innovation or Negligence? The Dark Side of the "Vibe Coding" Wave
Security researchers at RedAccess scanned hundreds of thousands of apps built on vibe coding platforms like Lovable, Replit, and Base44. What they found should worry anyone shipping software without a security review.
We Tested 4 Secret Scanners on 8 Real Repos. The Results Were Eye-Opening.
We scanned 2.2 million lines of code across 8 popular open-source repositories using Gitleaks, TruffleHog, GitGuardian, and Puaro. Here are the raw numbers and what they actually mean.
How AI-Powered Scanning Prevents the Next 'GlassWorm' Supply Chain Attack
The recent GlassWorm incident exposed critical vulnerabilities in the software supply chain when developers accidentally leaked VS Code extension tokens. Learn how AI-powered scanning provides proactive prevention beyond simple pattern matching.
Secret Scanning Is Becoming a $12 Billion Market by 2033
The source code secret scanning market is projected to reach up to $12 billion by 2033, and AI-powered detection tools are already hitting 97% accuracy in identifying real threats.
How AI and ML Improve Secret Detection Accuracy and Reduce False Positives
AI and machine learning models can adapt to new secret patterns and read surrounding code for context, cutting false positive rates from around 25-30% with traditional regex scanning to 3-7% with AI/ML-enhanced scanning.