ProjectDiscovery Brings Open Source AI Testing to Vulnerability Discovery
ProjectDiscovery has made available an autonomous security testing platform that leverages an open source artificial intelligence (AI) testing framework to detect and validate vulnerabilities at a lower total cost. Company CEO Rishi Sharma said version 1.0 of the Neo platform is also available via a cloud service that makes it possible for DevSecOps teams to […]
ProjectDiscovery has launched an open-source AI-powered security testing platform called Neo, aiming to lower the cost of identifying and fixing vulnerabilities. CEO Rishi Sharma revealed that version 1.0 of Neo is accessible through a cloud service, enabling DevSecOps teams to run tests using a pay-as-you-go pricing model. Neo 1.0 also boasts integrations with popular DevOps tools such as GitHub, Jira, Confluence, Slack, Linear, APIs, webhooks, and the Model Context Protocol (MCP).
In addition to Neo, ProjectDiscovery provides access to Nuclei, an open-source vulnerability scanner driven by customizable YAML templates. Other tools integrated into the ecosystem include Subfinder for discovering subdomains, httpx for probing HTTP, Katana for web crawling, and Naabu as a port scanning tool. Together, these components form a robust open-source ecosystem supporting autonomous security testing and penetration.
Sharma emphasized that relying solely on code scanning tools is insufficient; a comprehensive tool chain is necessary to not only identify vulnerabilities but also determine which can be reached and abused. He stressed that DevSecOps teams must adopt new processes that extend beyond merely asking AI models to detect vulnerabilities in source code.
Mitch Ashley, a vice president and practice lead for software lifecycle engineering at the Futurum Group, pointed out that the market is inundated with vulnerability findings, overwhelming DevSecOps teams and consuming significant triage time trying to separate real threats from noise. Neo addresses this issue by validating findings and routing exploitable issues to the respective developers.
As AI models become increasingly advanced, the challenge for DevSecOps teams is to discover vulnerabilities before software is deployed in production. The cost of applying AI to test code has historically been prohibitive, but it is now essential to have processes in place to address the rapid emergence of more sophisticated cyber threats. DevSecOps teams must act swiftly to mitigate vulnerabilities in both existing applications and legacy systems to stay ahead of the rapidly evolving threat landscape.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.