Lambda Security introduced Frame, a neuro-symbolic static application security testing (SAST) system that pairs a sound separation-logic analysis core with a verified, tiered large-language-model layer. The design aims to ground LLM-assisted vulnerability findings in symbolic reasoning while extending analysis to code patterns the core engine cannot resolve alone.
On Endor Labs’ real-world code corpus, Frame reportedly achieved 0.67 recall and 0.51 precision, compared with Semgrep’s reported 0.52 recall and 0.40 precision. The project also reported finding about 65 vulnerabilities across Java, JavaScript/TypeScript, and C# that were missed by both Frame’s symbolic engine and Semgrep.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
The neuro-symbolic SAST system Frame was evaluated on Endor Labs' real-world corpus, reporting 0.67 recall and 0.51 precision. In the stated comparison, it identified approximately 65 Java, JavaScript/TypeScript, and C# vulnerabilities missed by both its symbolic engine and Semgrep.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcelambdasec.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.