Blog

Get the latest news delivered to your inbox.

  1. James McLean

    Aug 13, 2026

    Product Release: Threat Model

    Introducing Threat Model, living security artifacts that capture each repository’s architecture, trust boundaries, and assumptions so vulnerability discovery and severity reflect how your application actually works.

  2. Francesco Piccoli

    Jul 28, 2026

    Graduating from CyberGym Level 1

    CyberGym Level 1 helped move cybersecurity evaluation forward, but its scores have compressed at the top and its task design captures only a narrow slice of real-world security work. The industry should graduate to harder, end-to-end benchmarks that test discovery, reachability, PoC generation, patching, and regression-free verification.

  3. James McLean

    Jul 22, 2026

    Product Release: Workflows

    Introducing Workflows, an automation layer that turns security events into repeatable actions, routing each finding to the right tool, team, and process so remediation never waits on a manual handoff.

  4. Qasim Mithani

    Jul 21, 2026

    2026: The Year Cyberattacks Became Autonomous

    2026 is the year cyberattacks became autonomous. The Hugging Face intrusion shows what machine-speed, multi-stage campaigns are now possible, and why defenders need systems that can respond at the same pace.

  5. Qasim Mithani

    Jun 26, 2026

    Almanax is joining depthfirst

    We're excited to welcome Francesco, Maxwell, and the Almanax team to depthfirst as we accelerate progress toward our mission of securing the world's software.

  6. Qasim Mithani

    Jun 19, 2026

    Why Defenders Can’t Bet on One Model

    Critical security capabilities cannot depend on infrastructure customers do not control. The next generation of AI security products needs to adapt across models, providers, policies, and access changes while preserving consistent enterprise outcomes.

  7. Qasim Mithani

    Jun 1, 2026

    Introducing Dependency Firewall

    Dependency Firewall reviews every open-source package being downloaded anywhere in your company and blocks malicious ones before they reach the person or system that asked for them.

  8. Daniele Perito

    Apr 15, 2026

    Cybersecurity's ChatGPT Moment

    The next phase of cybersecurity will be shaped by AI systems that can discover vulnerabilities at unprecedented scale, cheaper offensive capability through open-source models, and growing pressure on defenders to move faster. As attacks become more automated and sophisticated, security will turn into an arms race of intelligence, pushing organizations to invest more heavily in AI-native defense and accelerating consolidation across the security market.

  9. Qasim Mithani

    Apr 8, 2026

    Securing the World’s Software in the Age of AI

    AI is making attacks faster, cheaper, and more sophisticated. As software becomes the foundation of every critical system, securing it requires a new approach, one built on AI that can reason through and fix vulnerabilities in live environments.

  10. Mar 27, 2026

    Applied AI Lab depthfirst Announces $80 Million in Series B Funding

    Applied AI Lab depthfirst Announces $80 Million in Series B Funding Introduces first in-house security model dfs-mini1 demonstrating the power of domain specialized AI

  11. Jan 14, 2026

    depthfirst Announces $40M Series A to Secure the World’s Software

    depthfirst Announces $40M Series A to Secure the World’s Software Major spike in AI-driven exploits sees startup land fresh funding to deploy General Security Intelligence with custom AI agents that work 24/7 to secure businesses’ systems

  12. James McLean

    Jan 5, 2026

    Product Release: Secrets

    Introducing Secrets, a new approach to secret scanning that finds and verifies real leaked credentials so teams can fix what matters.