Yep, you read it right. 0 false positives. We scan the whole codebase for possible vulnerabilities, rank them, write the proof-of-concept for exploitation, spin up the software in a sandbox, and then attack. All of them happen autonomously without human involvement.
The end report? Only verified vulnerabilities are being reported without noise.
Already reported some unknown vulnerabilities in open source projects. The good thing is we're just getting started.
Thanks! But, I can't find any details on how you "intelligently adjust quantization for every possible layer" from that page. I assume this is a secret?
I am wondering about the possibility that different use cases might require different "intelligent quantization", i.e., quantization for LLM for financial analysis might be different from LLM for code generation. I am currently doing a postdoc in this. Interested in doing research together?
do any of you use LLM for code vulnerability detection? I see some big SAST players are shifting towards this (sonar is the most obvious one). Is it really better than the current SAST?
Tried it. It would save me a lot of time, I would say!
One suggestion: The back-and-forth chat in the beginning could be improved with a more extensive interaction. So, the final prompt could be more fine-grained into a specific area/context/anything one would aim for.
Avoiding all boeing planes altogether seems to be an overkill solution to me. An older version of 737 and 777 seems to be working pretty well. At least historically.
I have been intentionally avoiding Max since the Lion and Ethiopian (at least when I buy the ticket).
However, there were occasions when the airline rescheduled my flights (for many different reasons), which resulted in me being on a max flight. While I can change one of them, changes to most of them were not practical (time-wise, effort-wise, etc). So, at some point, I have to live with the fact that flying max is unavoidable. Any idea how we can practically circumvent this?
https://vyprsec.ai/
Yep, you read it right. 0 false positives. We scan the whole codebase for possible vulnerabilities, rank them, write the proof-of-concept for exploitation, spin up the software in a sandbox, and then attack. All of them happen autonomously without human involvement.
The end report? Only verified vulnerabilities are being reported without noise.
Already reported some unknown vulnerabilities in open source projects. The good thing is we're just getting started.