Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Semgrep Multimodal brings AI reasoning and rule-based analysis to code security
    Cybersecurity

    Semgrep Multimodal brings AI reasoning and rule-based analysis to code security

    adminBy adminMarch 20, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Tosi Platform delivers unified connectivity, visibility, and security for OT at scale
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Semgrep announced Semgrep Multimodal, a system that combines AI reasoning with rule-based analysis for detection, triage, and remediation.

    Its detection finds up to 8x more true positives while cutting noise by 50% compared to foundation models alone, and has already discovered dozens of zero-days at customers.

    Multimodal is built on Semgrep Workflows, a framework for autonomous code security – using deterministic tools and AI so security teams can encode their processes once and scale them reliably across teams, repos, and the organization.

    Workflows can be run as-is from a pre-built library, customized for a team’s specific environment, or built from scratch. Semgrep’s managed infrastructure handles the production deployment, so teams can focus on defining their security logic, not maintaining the stack.

    The problem: AI code volume has outpaced security

    AI-generated code is outpacing the security practices built for human-speed development. Security teams fielding hundreds of pull requests a day know the math is unforgiving: a 95% fix rate still means hundreds of unresolved critical issues compounding across hundreds of repositories.

    Most are already reaching for LLMs to close the gap and hitting the same walls: demos that fall apart in production, outputs that vary between repositories, token costs that spiral, and hallucinations that erode trust. The jump from proof of concept to running reliably across the organization is where most efforts stall.

    Meanwhile, many of the largest and most costly breaches aren’t caused by the vulnerabilities traditional SAST scanners catch. Instead they’re caused by logic errors that escaped notice entirely.

    Semgrep Multimodal: Better than either approach alone

    Traditional rule-based SAST excels at catching known vulnerability patterns: SQL injection, SSRF, and secrets exposure. But it has always struggled with business logic flaws: IDORs, broken authorization, and authentication bypasses that require understanding context and developer intent. LLMs can reason about logic, but used alone they produce unacceptably high false positive rates and inconsistent results at scale.

    Semgrep Multimodal closes that gap. By pairing the Semgrep Pro engine’s precise program analysis with LLM reasoning, it covers both dimensions of vulnerability detection. And as underlying models improve, so does Semgrep Multimodal’s performance automatically.

    Semgrep Workflows: The framework underneath

    Semgrep Multimodal is built on Semgrep Workflows, which is now available to builders who want to go further than out-of-the-box AppSec. Workflows enables teams to encode their own security policies into automated pipelines covering detection, triage, remediation, compliance, and other AppSec work.

    Pre-built workflows cover common cases for the OWASP Top 10 and business logic vulnerabilities. Custom workflows are written in plain Python, can be easily extended with new tools, and are deployed at scale without building or maintaining infrastructure.

    Semgrep learns as teams build, incorporating feedback from security engineers and developers to improve accuracy over time. The result: customers are starting to report something the industry has long promised but rarely delivered.

    “Semgrep’s rule-based engine became the most widely deployed code scanner in the world by giving teams a way to encode their own security knowledge into precise, customizable rules. Semgrep Multimodal and Workflows are the next chapter of that same bet – that the teams closest to the code are best positioned to define what security means for their organization, and that our job is to give them the engine to automate it,” said Isaac Evans, CEO at Semgrep.

    Semgrep Multimodal is available now. Custom Workflows are available via private beta. Teams can join the waitlist.

    analysis brings Code Multimodal reasoning rulebased Security Semgrep
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleEx-data analyst stole company data in $2.5M extortion scheme
    Next Article 6 big changes as the luxury icon goes electric
    admin
    • Website

    Related Posts

    Google brings Preferred Sources to AI Overviews and AI Mode

    June 1, 2026

    How to do an SEO competitor analysis [+ template]

    May 29, 2026

    What is competitive analysis? How to do one (+ template)

    May 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    How a ‘client brain’ gives AI the context SEO work needs

    June 2, 2026

    Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

    June 2, 2026

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,337)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (324)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    How a ‘client brain’ gives AI the context SEO work needs

    June 2, 2026

    Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

    June 2, 2026

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026
    Most Popular
    • How a ‘client brain’ gives AI the context SEO work needs
    • Attackers exploit Palo Alto GlobalProtect flaw days after disclosure
    • MIT Research Shows The Shift Reshaping SEO Strategy
    • Commerce media expands beyond retail sites with Demand Gen integration
    • The 50 Most-Cited Websites in Perplexity (June 2026)
    • FTC broadens Microsoft probe to cloud, AI, and software bundling
    • Google expands Data Manager API with GMP event ingestion
    • The 50 Most-Cited Websites in Copilot (June 2026)
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.