Skip to content

Commit c4d61e5

Browse files
committed
Release v2025.09.10
1 parent 47b7a3f commit c4d61e5

2 files changed

Lines changed: 6 additions & 5 deletions

File tree

_posts/2025-07-29-Vulnerability-Disclosure-Challenges-in-Open-Source-Projects.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,14 @@
22
title: "Vulnerability Disclosure Challenges in Open Source Projects"
33
description: "An in-depth exploration of the challenges encountered during the security vulnerability disclosure process in the Formidable library, using CVE-2025-46653 as a case study, and reflections on the current state of open source ecosystem maintenance."
44
author: "Chris"
5-
date: 2025-09-10
5+
date: 2025-09-04
66
categories: [Security, Open Source, Vulnerability Disclosure]
77
tags: [CVE, Formidable, SBOM, Supply Chain Security, Responsible Disclosure, npm, GitHub]
88
---
99

1010
**Chris**,
1111
Co-founder, Zast.ai
12-
Sep. 10, 2025, Seattle
12+
Sep. 04, 2025, Toronto
1313

1414
---
1515
## Introduction: vulnerability in SBOM (open source)

_posts/2025-08-28-Finding-Zero-Day-Vulnerabilities-at-Scale.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,19 @@
22
title: "Finding Zero-Day Vulnerabilities at Scale: Our Journey with Zast.ai"
33
description: "Learn about our journey using Zast.ai to discover hundreds of zero-day vulnerabilities across the open-source ecosystem at scale, and the challenges we faced in responsibly disclosing them."
44
author: "Chris"
5-
date: 2025-09-04
5+
date: 2025-09-10
66
categories: [Security, AI, Open Source]
77
tags: [Zero-Day, Vulnerability Disclosure, Zast.ai, Log4Shell, Automation, CVE]
8+
hidden: true
89
---
910

1011
**Chris**,
1112
Co-founder, Zast.ai
12-
Sep. 04, 2025, Seattle
13+
Sep. 10, 2025, Toronto
1314

1415
---
1516

16-
In our previous blog post, we introduced [Zast.ai](https://zast.ai/), our AI agent for automated vulnerability discovery with zero false positives. Today, we're excited to share how we've put this technology to work in pursuit of a bold goal: assessing the entire open-source ecosystem to find the next Log4Shell.
17+
In our previous blog ***[Vulnerability Disclosure Challenges in Open Source Projects](https://blog.zast.ai/security/open%20source/vulnerability%20disclosure/Vulnerability-Disclosure-Challenges-in-Open-Source-Projects/)***, we used CVE-2025-46653 to discuss open source vulnerability disclosure hurdles and effort, aiming to boost collaboration. Today, were excited to share how weve put this technology to work in pursuit of a bold goal: assessing the entire open-source ecosystem to find the next Log4Shell.
1718

1819
## The Ambition: Assess the Entire Open Source Ecosystem
1920

0 commit comments

Comments
 (0)