
attestd | CVE API for Machine-Readable Vulnerability Risk Signals
将CVE漏洞数据转换为机器可读风险信号的API,用于自动化。
robert_marshall5 · Product Hunt
attestd CVE and supply chain risk signals for autonomous AI agents.
完整作品展
技术栈
10 projects

将CVE漏洞数据转换为机器可读风险信号的API,用于自动化。
robert_marshall5 · Product Hunt
attestd CVE and supply chain risk signals for autonomous AI agents.

Vulnsy是为安全团队提供的渗透测试报告平台,可10倍快速交付客户报告。
@TurvSec · X

使用AI增强的安全分析扫描代码和应用漏洞。
u/swifi_ai · Reddit
After 10 years of keeping this idea alive, I finally launched my AI security platform to beta After more than 10 years of keeping this idea alive in one form or another, I finally pushed Swifi live to beta: https://swifi.ai Swifi is an AI-augmented application security platform. The goal: combine traditional security scanning with AI so teams can understand risk across code, vulnerabilities, and production context without stitching together a dozen disconnected tools. Why now? AI change

监控外部攻击面、检测子域名暴露、自动映射 CVE 威胁。
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform

探索2020年以来的CVE趋势和漏洞严重性,按报告组织分类。
u/Secret_Appeal6271 · Reddit
Agents are more capable, and susceptible to exploits, than ever. We're working to stop this from hurting users. AI agents are starting to get real access like GitHub tokens, cloud credentials, customer data, deploy permissions. Not coincidentally, the rate of major cybersecurity incidents is rising rapidly. See for yourself: https://epoch.ai/data/cve?view=graph https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/ My friend and I, both AI researchers, are working o

统一一个API接入200+个AI模型,包含Claude、GPT等,支持自动故障转移。
@MixRoute_ai · X

粘贴 GitHub 仓库扫描安全漏洞,自动修复代码问题。
u/Still_Amphibian545 · Reddit
almost launched a side project with my api keys sitting in the repo (a week free gpt 5.6 on us) was about a day from launching a small project when i noticed my openai key was just sitting in a committed file. it had been there for weeks. no idea how i missed it. made me wonder what else was wrong that i couldn't see. turns out for vibecoded stuff it's usually the same handful of things. secrets in the repo, endpoints with no auth, a database with no access rules, no limit on the ex

使用硬件认证和OTP保护GitHub拉取请求。
jallmann · HN
> want without a PR process that requires hardware authentication or proof of presence Just curious, what do you use for this? I built OTP Guard [1] a few years ago for exactly this problem, although I haven't seen any alternatives in the space. Does GitHub have something built-in now? The original framing was more "local malware compromising your GitHub account" ... it never occurred to me that the malware could be a LLM. I really should update the page. [1] https://otpguard.com

Jira原生测试管理,连接需求与测试执行,支持完整可追踪性。
@pakosteve · X
Improve your SaaS quality when scaling (by register requirements and test via MCP)

部署400+开源工具到9个云提供商中任意一个。
@Dil_Lynn · X