Blog
Security That Ships
Security, strategy, and developer-first thinking for teams pushing open-source forward.
This is some text inside of a div block.

Hopper Launches Four AI-Powered AppSec Products for the Age of Modern Software
Traditional AppSec tools weren’t built for AI-powered development. Hopper’s new suite delivers visibility and control across open-source, embedded models, and AI-generated code.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
.png)
Reachability in AppSec: What Each Type Really Tells You
Not all reachability is equal. The post explains how package-level, function-level, internet, and runtime reachability each shape AppSec accuracy and prioritization, and how Hopper combines them with exploitability and business context to cut 93% of noise and focus teams on real risks.
Insights

Hopper Recognized for Innovation and Growth in 2025
Hopper has been recognized as Innovation of the Year at the Cybersecurity Awards and Finalist in the AWS & CrowdStrike Cybersecurity Accelerator. These milestones highlight Hopper’s role in redefining application security by cutting through noise, reducing risk, and enabling enterprises to secure innovation without slowing down.
Announcements

The Real ROI of Function-Level Reachability
With open-source vulnerabilities growing nearly 100% year over year, enterprises need precision. Function-level reachability delivers measurable ROI by eliminating more than 90% of false positives, accelerating remediation, and reducing wasted engineering hours.
Insights

FedRAMP RFC-0012 is Redefining Vulnerability Management Strategy
FedRAMP’s proposed RFC-0012 standard redefines vulnerability management by prioritizing exploitability and automation over traditional CVSS-driven compliance. Learn about major changes, industry reactions, and what executives need to do now to prepare.
Insights

Bringing Visibility to AI Model Usage with Hopper
Hopper’s new AI-BOM and Risk Analysis features give teams full visibility into how AI models and libraries are used across their applications. From embedded models to external APIs, Hopper pinpoints risks like insecure deserialization, data exposure, and compliance violations, delivering actionable insights with zero friction.
Product

Quieting the Noise from the Start, with Thoughtful Branding and Design
Hopper’s branding and product design are built around one principle: cutting through noise to create clarity in open-source security. From typography and color to product workflows and AI cues, every detail is designed to reduce distractions, build trust, and help teams focus on what truly matters.
Product
.png)
From 134 Vulnerabilities to 3 Real Risks: How Hopper Cuts Through the Noise
Hopper transforms vulnerability management by reducing noise and focusing teams on real risk. In this demo, a Python app with 134 vulnerabilities is distilled to just 3 critical issues worth fixing through function-level reachability and EPSS.
Insights

How Hopper Supports Evidence-Based Vulnerability Scanning for Spring Applications
Spring’s dynamic features break traditional static analysis. Hopper delivers the first and most accurate production-aware call graph analysis for Spring, modeling behaviors like reflection, proxies, and spring.factories for unmatched accuracy and fewer false positives.
Product

Introducing Vulnerability Insights: Cutting Through the Noise of Monorepos
Hopper cuts through the noise of monorepo dependencies by identifying and surfacing root causes, enabling security teams and developers to triage issues faster and more effectively.
Product
Newsroom
Hopper Press Mentions and Releases
Visit Publication Article

September 15, 2025
In Praise of Resilience: Why We Invested in Hopper Security
-Logo.wine.png)
Visit Publication Article

September 4, 2025
The ART of Taming Agents: A CISO’s Framework for Managing Enterprise Risk in the Age of Agentic AI

Visit Publication Article

April 25, 2025
Hopper Uncovers Over 2.5 Million Vulnerabilities Hidden in Java

Visit Publication Article

April 22, 2025
Hopper raises $7.6M to accelerate software development with streamlined risk management

Visit Publication Article

April 22, 2025
Open Source Security Firm Hopper Emerges From Stealth With $7.6M in Funding
