Semgrep Threat Dex · The Year Since Black Hat 2025

GottaAvoidThem All

Professor Semgrep's field guide to the past year in cyber security — every creature a real story since Black Hat 2025. The supply-chain worm that wouldn't die, the AI-code gold rush, the vuln-hunting model kept out of public hands, and the funding cut that nearly took CVE with it. Register each entry to learn what happened, and why it matters for the code you ship.

21Entries
4Categories
10OWASP risks
0/21Avoided
Threat Dex v1
Professor Semgrep, your field guide
Prof. Semgrep
Your field guide
Seen 21Avoided 0
The canon, refreshed · 9 stickers

OWASP Top 10 — 2025

The 2025 list dropped this year and reshuffled the canon — Supply-Chain and Mishandling Exceptional Conditions muscled in. The risks every developer keeps meeting — led by the Big Three that do the most damage. (A03, Supply Chain, headlines its own series.)

The Big Three · the most dangerous vulnerabilities
No.001Big Three
Broken Access Control sticker
Broken Access Control
Enforcement that never runs
A01 · Holo Rare★★★
AVOIDED ✓
No.002Big Three
Injection sticker
Injection
Input the interpreter runs as code
A05 · Holo Rare★★★
AVOIDED ✓
No.003Big Three
Authentication Failures sticker
Authentication Failures
A lock that barely engages
A07 · Rare★★
AVOIDED ✓
Also in this series
No.004
Security Misconfiguration sticker
Security Misconfiguration
Shipped wide open
A02 · Common
AVOIDED ✓
No.005
Cryptographic Failures sticker
Cryptographic Failures
Security that only looks like security
A04 · Rare★★
AVOIDED ✓
No.006
Insecure Design sticker
Insecure Design
A flaw in the blueprint
A06 · Rare★★
AVOIDED ✓
No.007
Software or Data Integrity Failures sticker
Software or Data Integrity Failures
Trust without verification
A08 · Rare★★
AVOIDED ✓
No.008
Logging & Alerting Failures sticker
Logging & Alerting Failures
The breach nobody saw
A09 · Common
AVOIDED ✓
No.009
Mishandling of Exceptional Conditions sticker
Mishandling of Exceptional Conditions
How software behaves on its worst day
A10 · Common
AVOIDED ✓
The year it grew up · 5 stickers

AI

The year AI stopped being a demo and started writing the code, wielding the tools, and running up the bill — and, in one case, staying out of public hands because it was judged too dangerous to release.

Evolution line · how it escalates
No.010Stage 1/3
Vibe Coding sticker
Vibe Coding
Coding on feel
AI-01 · Common
AVOIDED ✓
No.011Stage 2/3
90% AI-Written Code sticker
90% AI-Written Code
Someone still secures the rest
AI-02 · Rare★★
AVOIDED ✓
No.012Stage 3/3
“We Can’t Afford Our AI Bill” sticker
“We Can’t Afford Our AI Bill”
The other side of the boom
AI-03 · Rare★★
AVOIDED ✓
Also in this series
No.013
Skills, MCP & Hooks sticker
Skills, MCP & Hooks
New powers, new attack surface
AI-04 · Holo Rare★★★
AVOIDED ✓
No.014
Claude Mythos sticker
Claude Mythos
The vuln-hunter kept under lock
AI-05 · Legendary★★★★
AVOIDED ✓
Policy made the headlines · 3 stickers

Governance & Resilience

The year policy and funding became security news: the EU CRA’s clock started ticking, a CISA cut nearly took the CVE program down with it, and the cloud proved how few hands hold the internet up.

Evolution line · the governance arc
No.015Stage 1/2
CISA Funding Cuts sticker
CISA Funding Cuts
The year CVE nearly went dark
GOV-01 · Rare★★
AVOIDED ✓
No.016Stage 2/2
EU Cyber Resilience Act sticker
EU Cyber Resilience Act
Security as a design requirement
GOV-02 · Holo Rare★★★
AVOIDED ✓
Also in this series
No.017
Cloud Outages sticker
Cloud Outages
When one region takes the internet with it
GOV-03 · Holo Rare★★★
AVOIDED ✓
The year of the worm · 4 stickers

Supply Chain

The year the supply chain became the story. Shai-Hulud turned “just a dependency” into a self-replicating nightmare — then did it again.

Evolution line · the worm keeps coming back
No.018Stage 1/3
Shai-Hulud sticker
Shai-Hulud
The worm that made it personal
SH-01 · Rare★★
AVOIDED ✓
No.019Stage 2/3
Shai-Hulud v2 sticker
Shai-Hulud v2
Bigger, quieter, faster
SH-02 · Holo Rare★★★
AVOIDED ✓
No.020Stage 3/3
Shai-Hulud, Open Source sticker
Shai-Hulud, Open Source
Cut one head, grow two
SH-03 · Legendary★★★★
AVOIDED ✓
Also in this series
No.021
Software Supply Chain Failures sticker
Software Supply Chain Failures
OWASP A03 — everything you shipped but didn’t write
A03 · Legendary★★★★
AVOIDED ✓
The 2025 shift

What changed in security this year

Step back from the individual creatures and a few big currents define the year since Black Hat 2025 — the forces that produced everything in this dex.

01 · AI

From autocomplete to author

AI stopped suggesting lines and started writing — and reviewing — whole features. Agents with skills, MCP, and hooks now read repos and run tools on their own. The bottleneck moved from writing code to checking it, faster than any manual review can keep up.

02 · Supply chain

Your dependencies are the attack surface

Shai-Hulud turned "just a dependency" into self-replicating malware that rode developer tokens across the ecosystem — twice. OWASP promoted Software Supply Chain Failures to a Top 10 category of its own. Trust in open source stopped being free.

03 · Policy

Security got legislated — and precarious

The EU Cyber Resilience Act wrote secure-by-default and vulnerability handling into law. Meanwhile a CISA funding cut left CVE and the NVD — the shared vocabulary the whole industry runs on — hours from going dark. The commons proved fragile.

04 · Capability

The tools cut both ways

Models like Claude Mythos found vulnerabilities at a scale that made governments nervous enough to restrict them. The same capability that hardens your code can hunt for weaknesses in it — so the gap between "bug shipped" and "bug found" has never mattered more.

That was the year

That was the year.
Here's to a shorter dex next time.

Plenty of these creatures start in your own code — the injections, the secrets, the shaky dependencies. Catching those before they ship is Semgrep's whole job.

Back to the collection Top ↑
No. 001

Dex entry

The design

Artist's note