Professor Semgrep's field guide to the past year in cyber security — every creature a real story since Black Hat 2025. The supply-chain worm that wouldn't die, the AI-code gold rush, the vuln-hunting model kept out of public hands, and the funding cut that nearly took CVE with it. Register each entry to learn what happened, and why it matters for the code you ship.
The 2025 list dropped this year and reshuffled the canon — Supply-Chain and Mishandling Exceptional Conditions muscled in. The risks every developer keeps meeting — led by the Big Three that do the most damage. (A03, Supply Chain, headlines its own series.)
The year AI stopped being a demo and started writing the code, wielding the tools, and running up the bill — and, in one case, staying out of public hands because it was judged too dangerous to release.
The year policy and funding became security news: the EU CRA’s clock started ticking, a CISA cut nearly took the CVE program down with it, and the cloud proved how few hands hold the internet up.
The year the supply chain became the story. Shai-Hulud turned “just a dependency” into a self-replicating nightmare — then did it again.
Step back from the individual creatures and a few big currents define the year since Black Hat 2025 — the forces that produced everything in this dex.
AI stopped suggesting lines and started writing — and reviewing — whole features. Agents with skills, MCP, and hooks now read repos and run tools on their own. The bottleneck moved from writing code to checking it, faster than any manual review can keep up.
Shai-Hulud turned "just a dependency" into self-replicating malware that rode developer tokens across the ecosystem — twice. OWASP promoted Software Supply Chain Failures to a Top 10 category of its own. Trust in open source stopped being free.
The EU Cyber Resilience Act wrote secure-by-default and vulnerability handling into law. Meanwhile a CISA funding cut left CVE and the NVD — the shared vocabulary the whole industry runs on — hours from going dark. The commons proved fragile.
Models like Claude Mythos found vulnerabilities at a scale that made governments nervous enough to restrict them. The same capability that hardens your code can hunt for weaknesses in it — so the gap between "bug shipped" and "bug found" has never mattered more.
Plenty of these creatures start in your own code — the injections, the secrets, the shaky dependencies. Catching those before they ship is Semgrep's whole job.