Aikido Security's Blog
https://www.aikido.dev
Detect, pentest, and block security threats across your entire stack - from one unified platform.
フィード

Software supply chain security requires decisions rather than defaults
Aikido Security's Blog
Most software runs on decisions nobody made. We talk about why gating, pinning, backporting, and SBOM upkeep only work if someone actually owns them.Category: News
4時間前

Aikido Security achieves ISO 42001:2023 certification for AI governance
Aikido Security's Blog
Aikido Security has achieved ISO 42001 certification, the global standard for AI governance, covering AI pentesting, Code Security Audit, and Deep PR Review.Category: Compliance
5時間前

Aikido launches agentic pentesting for Android apps
Aikido Security's Blog
Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue.Category: Product & Company Updates
5時間前

Could OpenClaw have actually hacked that Australian gym? We decided to test it.
Aikido Security's Blog
We recreated the viral AI gym hack in a controlled environment. Running Opus 4.6 on OpenClaw, the model exploited the booking flaw in nine of ten runs.Category: News
1日前

How Aikido finds more vulnerabilities than Mythos at half the cost
Aikido Security's Blog
Aikido AI Code Audit found 8 more vulnerabilities than Claude Security with Mythos at less than half the cost. How harness design drives coverage per dollar.Category: News
2日前

Shai-Hulud was the best thing to happen to supply chain security
Aikido Security's Blog
npm Trusted Publishing sat near-idle for two years. Then Shai-Hulud and 14 more supply chain attacks pushed adoption 3.4x. Charlie looks at the data behind it.Category: News
2日前

Top image hardening tools in 2026
1
Aikido Security's Blog
Image hardening tools compared for 2026: Aikido, Chainguard, Docker, RapidFort, Echo, Minimus, and WizCategory: DevSec Tools & Comparisons
5日前

Best enterprise AI pentesting tools for application security in 2026
Aikido Security's Blog
Compare the top enterprise AI pentesting tools of 2026: Aikido, XBOW, NodeZero, Pentera, Hadrian, and Cobalt.Category: DevSec Tools & Comparisons
5日前

What is CVE remediation in 2026?
Aikido Security's Blog
CVE remediation is fixing known flaws in the software you run. Why upgrading often fails, what remediation actually involves, and how backporting fixes it.Category: DevSec Tools & Comparisons
5日前

We burned 11.7bn tokens to find the best cyber AI model
Aikido Security's Blog
We tested 10 AI models on 32 fresh CVEs. DeepSeek V4 Pro found 28, and three cheap runs beat one pass of Opus 5 or Grok on total coverage.Category: News
5日前

Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack
2
Aikido Security's Blog
A supply chain attack compromised popular Rust crates, arrayref, append-only-vec, and internment, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.Category: Vulnerabilities & Threats
6日前

AI pentesting evaluation checklist: What to look for in an AI pentesting vendor
Aikido Security's Blog
A checklist for scoring AI pentesting vendors on validation, code access, scope control, and reliability, plus the red flags that separate a real platform from a strong demo.Category: Aikido
7日前

Yet another RCE in Gogs, but it's fixed this time!
Aikido Security's Blog
CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.Category: Vulnerabilities & Threats
7日前

Top enterprise SCA tools in 2026
Aikido Security's Blog
Compare enterprise SCA tools for 2026: Aikido, Sonatype, Snyk, Endor Labs, Checkmarx, Black Duck, and Veracode on intelligence, remediation, and compliance.Category: DevSec Tools & Comparisons
12日前

Top enterprise DAST tools in 2026
Aikido Security's Blog
Compare the top enterprise DAST tools of 2026 on authenticated coverage, API discovery, exploit validation, governance, compliance, and AI pentestingCategory: DevSec Tools & Comparisons
12日前

Top unified security tools in 2026
Aikido Security's Blog
Compare the top unified security tools of 2026: Aikido, Cortex Cloud, Wiz, Checkmarx, Snyk, and Orca, across coverage, correlation, governance, and cost.Category: DevSec Tools & Comparisons
12日前

From Hugging Face to Fable: this summer shows AI control matters more than trust
Aikido Security's Blog
An autonomous AI breach at Hugging Face and Anthropic's Fable suspension show the same thing: trusting a vendor isn't the same as being in controlCategory: News
13日前

Finding vulnerabilities at every stage: what to run, and when
Aikido Security's Blog
SAST, Deep PR Review, Code Security Audit and AI Pentest each catch different vulnerabilities at different stages. Here's when to use each, and whyCategory: Product & Company Updates
14日前

What is AI harness engineering?
Aikido Security's Blog
Harness engineering is the code around an AI model that turns it into an agent. What a harness does, why it beats picking a model, and how to build one.Category: News
20日前

Who was behind the attack? Possibly nobody
Aikido Security's Blog
Three summer disclosures documented AI agents attacking real organizations with no human intent in the chain. Incident response has no box for this yet.Category: News
21日前

The Aikido Machine: on-prem AI pentesting that never leaves your network
Aikido Security's Blog
Continuous AI pentesting for teams that can't use the cloud. The Aikido Machine keeps models, code, and results entirely inside your network.Category: Product & Company Updates
21日前

Keyv and friends compromised in active Shai-Hulud supply chain attack
Aikido Security's Blog
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub accountCategory: Vulnerabilities & Threats
22日前

Top enterprise SAST tools 2026
Aikido Security's Blog
Comparing the best enterprise SAST tools on noise reduction, AI remediation, governance, compliance, and costCategory: DevSec Tools & Comparisons
1ヶ月前

Anthropic's Fever Dream: Claude's package that stole real keys
Aikido Security's Blog
Anthropic disclosed an agent that pushed real malware to PyPI. We think we found the package, and every mistake in it points back to the AI.Category: Vulnerabilities & Threats
1ヶ月前

Top Astra Security alternatives for automated pentesting in 2026
Aikido Security's Blog
Compare Astra Security alternatives for AI pentesting in 2026 on depth, white-box testing, compliance output, and platform breadthCategory: DevSec Tools & Comparisons
1ヶ月前

Four incident-response decisions from the Hugging Face breach
Aikido Security's Blog
Recon, stolen credentials, hidden C2, and rebuild-or-patch. Four Hugging Face breach decisions that show whether you can catch an attack in progress.Category: News
1ヶ月前

Top SAST tools 2026
Aikido Security's Blog
Compare the top SAST tools of 2026 across detection depth, noise, remediation, and enterprise fit Category: DevSec Tools & Comparisons
1ヶ月前

Top LLM security tools to protect AI applications
Aikido Security's Blog
Compare the top LLM security tools for AI applications, including Aikido, Snyk, Semgrep, Endor Labs, and Wiz, across code, supply chain, and runtime.Category: DevSec Tools & Comparisons
1ヶ月前

Top Acunetix alternatives for automated vulnerability scanning
Aikido Security's Blog
Exploring Acunetix alternatives? Its DAST covers rule-based checks but can't reason about business logic or produce audit-grade pentests. Five options that go further.Category: DevSec Tools & Comparisons
1ヶ月前

Better generic secrets detection starts with finding non-secrets
Aikido Security's Blog
Some API keys are meant to be public. Betterleaks now removes them from generic secret findings, dropping thousands of false positives per scan. Category: News
1ヶ月前

Finding eight high-severity vulnerabilities in NodeBB in six hours
Aikido Security's Blog
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.Category: Vulnerabilities & Threats
1ヶ月前

SQL injection isn't dead
Aikido Security's Blog
The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it.Category: News
1ヶ月前

The upgrade trap: when upgrading is the wrong answer to a CVE
Aikido Security's Blog
Upgrading to fix a CVE sounds straightforward. But the patched version often breaks your app, hasn't shipped yet, or doesn't exist. Here's why, and what actually works.Category: News
1ヶ月前

Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Aikido Security's Blog
Tyro CISO Arun Singh on developer trust as a finite resource, and what happens when supply chain attacks force teams to spend itCategory: Guides & Best Practices
1ヶ月前

What developers need to know about DSPM and data exposure in code
Aikido Security's Blog
Traditional DSPM finds where sensitive data lives. Code-based DSPM finds how it gets exposed, and points to the fix in your code. Category: Guides & Best Practices
1ヶ月前

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
Aikido Security's Blog
SleeperGem: two dormant RubyGems maintainer accounts were hijacked to inject malware into trusted gems, one with over 500,000 total downloadsCategory: Vulnerabilities & Threats
1ヶ月前

Unauthenticated RCE in WordPress core (wp2shell), via SQL injection
Aikido Security's Blog
WordPress core has an unauthenticated RCE (wp2shell), confirmed as SQL injection. Update to 7.0.2 or 6.9.5 now, with mitigations if you can't patch yet. Block the attack class at runtime with Aikido Zen.Category: Vulnerabilities & Threats
1ヶ月前

Top Pentera alternatives for automated penetration testing
Aikido Security's Blog
Compare the top Pentera alternatives for automated pentesting in 2026. See where Aikido Security, XBOW, Horizon3, Hadrian, RunSybil, Terra, and Astra fit best.Category: DevSec Tools & Comparisons
1ヶ月前

Benchmarking 13 AI models on rediscovering known CVEs
Aikido Security's Blog
We tested 13 AI models against 26 known CVEs to see which finds the most vulnerabilities — and whether the priciest model is worth the cost.Category: News
1ヶ月前

The practical checklist for defending against supply chain attacks
Aikido Security's Blog
Thirty prioritized defenses against the recent wave of software supply chain attacks. Graded critical, high, or medium. Category: Guides & Best Practices
1ヶ月前

AsyncAPI npm packages backdoored via GitHub Actions
Aikido Security's Blog
Five package versions, including specs at roughly 2 million weekly downloads, shipped an obfuscated dropper on 2026-07-14. Here is what we have confirmed so far.Category: Vulnerabilities & Threats
1ヶ月前

How Aikido Intel detects malware and vulnerabilities first
Aikido Security's Blog
Aikido Intel is a real-time feed that catches malware and undisclosed vulnerabilities across open-source ecosystems, often within 8 minutes of release.Category: Product & Company Updates
1ヶ月前

What is a dependency firewall?
Aikido Security's Blog
A dependency firewall blocks malicious open-source packages before they install. Learn how they work and how Aikido Safe Chain stops supply chain attacks. Category: Guides & Best Practices
1ヶ月前

How to maintain code quality standards with AI code and vibe coding
Aikido Security's Blog
Vibe coding ships features fast and leaves review debt behind. See how benchmarked, per-rule code quality checks give teams one consistent answer across PRs and repos.Category: News
1ヶ月前

Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry
Aikido Security's Blog
A malicious release of @injectivelabs/sdk-ts hid a wallet-key stealer inside code labeled as usage telemetry, then spread it across 17 more npm packages. Here's how it worked and how to check your projects.Category: Vulnerabilities & Threats
2ヶ月前

AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Aikido Security's Blog
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.Category: Guides & Best Practices
2ヶ月前

Top Burp Suite alternatives for web application security testing
Aikido Security's Blog
Compare the top Burp Suite alternatives for DAST and AI pentesting, including Aikido, Caido, ZAP, and Invicti.Category: DevSec Tools & Comparisons
2ヶ月前

Top Chainguard alternatives 2026
Aikido Security's Blog
Comparing the best Chainguard alternatives in 2026, from Aikido Security to Docker Hardened Images, Minimus, RapidFort, and Echo.Category: DevSec Tools & Comparisons
2ヶ月前

Predicting MongoDB ObjectId continuously in Rocket.Chat
Aikido Security's Blog
Aikido's AI pentester found this file-access flaw in Rocket.Chat. A closer look at MongoDB's ObjectId showed the weak randomness that makes it exploitable.Category: Vulnerabilities & Threats
2ヶ月前

Authentication Bypass in the default configuration phpBB
Aikido Security's Blog
Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix.Category: Vulnerabilities & Threats
2ヶ月前

And another one. GitHub ships break-glass credential revocation
Aikido Security's Blog
Break-glass credential revocation is live on GitHub Enterprise. The Trivy and Microsoft durabletask repeats show why fast, complete revocation was needed..Category: News
2ヶ月前

Aikido acquires Root to secure the supply chain
Aikido Security's Blog
Aikido has acquired Root to secure the software supply chain, fixing open source vulnerabilities in the version you already run, no upgrade required. Critical fixes go back to the community, free.Category: Product & Company Updates
2ヶ月前

npm now freezes high-impact accounts after risky account changes
Aikido Security's Blog
A look at npm's new 72-hour account freeze, what triggers it, what it blocks, and how it works alongside trusted and staged publishing. Category: News
2ヶ月前

Top Koi alternatives in 2026
Aikido Security's Blog
Looking for a Koi Security alternative after the Palo Alto acquisition? Compare competitors on device protection, platform breadth, and pricing.Category: DevSec Tools & Comparisons
2ヶ月前

Packagist is now protected by Aikido Intel and other updates to the PHP registry
Aikido Security's Blog
Aikido's malware feed now blocks bad package versions in Composer by default. A look at how Packagist is closing whole classes of supply chain attacks.Category: Product & Company Updates
2ヶ月前

Everybody's shipping code they can't read
Aikido Security's Blog
With AI, everyone's a developer now, and a lot of code gets shipped without a careful review from trained eyes. Category: News
2ヶ月前

Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
Aikido Security's Blog
codfish/semantic-release-action was compromised on June 24, 2026. Attackers repointed v2–v5 tags to a Miasma credential-stealing payload targeting CI/CD secrets. Here's what happened and how to check if you're affected.Category: Vulnerabilities & Threats
2ヶ月前

Aikido x Drydock | A way for maintainers to catch malware before it ships
Aikido Security's Blog
Aikido partners with Drydock to bring pre-publish package review to npm and PyPI. See exactly what's inside a release before it ships, malware caught before download number one.Category: Product & Company Updates
2ヶ月前

Aikido x OWASP: 200 free credits for individual members
Aikido Security's Blog
OWASP individual members get 200 free Aikido credits to run Code Audit. Here is who qualifies and how to claim yours in two steps.Category: Aikido
2ヶ月前

Over 140 popular Mastra npm Packages Hit by Supply Chain Attack
Aikido Security's Blog
141 Mastra npm packages were compromised in a supply chain attack that injected a malicious dependency to silently download and execute a payload at install time.Category: Vulnerabilities & Threats
2ヶ月前

Multiple JetBrains IDE plugins caught stealing AI keys
Aikido Security's Blog
A coordinated campaign of at least 15 JetBrains IDE plugins, published under seven vendor accounts, exfiltrates the AI provider API key you paste into their settings.Category: Vulnerabilities & Threats
2ヶ月前

Introducing AI Code Analysis: Find complex vulnerabilities hidden in your source code
Aikido Security's Blog
SAST catches patterns. AI Code Analysis reasons through your code like an attacker would, finding the logic flaws that only show up after you ship.Category: Product & Company Updates
2ヶ月前

Full Fathom Five: The context of Anthropic’s Mythos-class public release
Aikido Security's Blog
You never needed Mythos to find your IDORs and business logic flaws. A look at what Anthropic shipped with Fable 5, and why infosec stays a people problem at heart.Category: News
2ヶ月前

5 Socket security alternatives and why they are better
Aikido Security's Blog
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.Category: DevSec Tools & Comparisons
2ヶ月前

npm v12 delivers one of the biggest security improvements in years
Aikido Security's Blog
npm v12 makes install scripts opt-in by default, closing the install-time execution path behind a year of npm supply chain worms from Nx to Red Hat.Category: News
2ヶ月前

Aikido x Docker: less noise, more signal in your containers
Aikido Security's Blog
Aikido now supports Docker Hardened Images with built-in VEX integration, helping teams reduce CVE noise and focus on container vulnerabilities that actually need attention.Category: Product & Company Updates
2ヶ月前

Code is being written everywhere, and the device is the only constant
Aikido Security's Blog
Developers are coding everywhere. AI agents, Slack bots, and MCP servers have made the developer device the biggest security blindspot.Category: News
3ヶ月前

SBOMs in 2026: Everyone's generating them, no one's using them
Aikido Security's Blog
ENISA's 2026 SBOM adoption report covers 334 organizations and surfaces a consistent gap between generating SBOMs and actually using them. Here is what stood out.Category: News
3ヶ月前

Compromised Rust crate onering performs code exfiltration
Aikido Security's Blog
The compromised onering Rust crate v1.4.1 on crates.io shipped a malicious build.rs that exfiltrates the diff of your latest commit to a hosted Sentry endpoint every time you build.Category: Vulnerabilities & Threats
3ヶ月前

10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums
Aikido Security's Blog
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account — a vulnerability that's been sitting in the codebase since 2014.Category: Vulnerabilities & Threats
3ヶ月前

Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System
Aikido Security's Blog
Deep dive into binding.gyp, the often overlooked npm build file that can execute malicious code at install time through shell expansions, sandbox escapes, and compiler hijacking.Category: Vulnerabilities & Threats
3ヶ月前

What is AI SAST?
Aikido Security's Blog
AI SAST is emerging as a new SAST category, but the meaning is unclear. We clarify the difference between AI-native SAST and AI-assisted SAST, as well as how AI SAST sits in the stack between traditional SAST and AI pentesting.Category: DevSec Tools & Comparisons
3ヶ月前

Top 5 Tenable Nessus alternatives in 2026
Aikido Security's Blog
Tenable Nessus is a powerful scanner, but powerful tools that nobody uses don't make software more secure. Compare five alternatives built for how engineering teams actually work.Category: DevSec Tools & Comparisons
3ヶ月前

Why EDR and proxy won’t save you from supply chain malware
Aikido Security's Blog
EDR and proxies weren't built for supply chain malware. When malicious code arrives through npm install, it looks like normal behavior. Here's why that matters.Category: News
3ヶ月前

Move over, Mythos. Here comes... pretty much any other model with a good harness
Aikido Security's Blog
Mythos has real edges in exploit chain construction. But for most AppSec work, the harness around the model matters more than which model you pick.Category: News
3ヶ月前

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
Aikido Security's Blog
Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines.Category: Vulnerabilities & Threats
3ヶ月前

What MDM can't protect on developer machines (and what to do about it)
Aikido Security's Blog
MDM tools like Jamf and Kandji are essential but they don't see npm installs, IDE extensions, or AI coding tools. Here's what's actually unprotected on your developer machines and how to close the gap.Category: Guides & Best Practices
3ヶ月前

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
Aikido Security's Blog
A polished Codex remote UI, the npm package codexui-android, has active development and thousands of weekly users. It has been quietly exfiltrating OpenAI auth tokens for the past month.Category: Vulnerabilities & Threats
3ヶ月前

Top GitGuardian alternatives for secrets scanning in 2026
Aikido Security's Blog
Compare the Top GitGuardian Alternatives for secrets scanning in 2026. See where Aikido Security, GitHub Secret Protection, TruffleHog, Gitleaks, Semgrep, Snyk, Cycode, Checkmarx, and GitLab fit best.Category: DevSec Tools & Comparisons
3ヶ月前

Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark
Aikido Security's Blog
Aikido vs XBOW compared in an independent benchmark by Doyensec. Aikido found 58% more vulnerabilities at the same price. See setup time, false positive rates & full resultsCategory: News
3ヶ月前

Why developer machines are now the number one target for supply chain attacks
Aikido Security's Blog
Teams at Omnea, Cognism, Glasswall, Raisin and the UK public sector reveal why EDR and MDM miss what's really happening on developer machines.Category: News
3ヶ月前

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
Aikido Security's Blog
Attackers injected a credential stealer into 200+ versions of popular Laravel-Lang packages, delivering a credential stealer targeting cloud keys, SSH keys, browsers, crypto wallets and more.Category: Vulnerabilities & Threats
3ヶ月前

5 Gitleaks alternatives and why they are better
Aikido Security's Blog
Looking for a Gitleaks alternative? We compare Betterleaks, TruffleHog, Aikido, GitHub Advanced Security, and Spectral so you can find the best secrets scanner for your team.Category: DevSec Tools & Comparisons
3ヶ月前

Google API keys keep working after you delete them
Aikido Security's Blog
Deleting a Google API key doesn't revoke it immediately. Our testing found successful authentications up to 23 minutes after deletion, and Google has declined to fix it.Category: Vulnerabilities & Threats
3ヶ月前

The Wild West of VS Code extensions and how a poisoned extension breached GitHub
Aikido Security's Blog
A poisoned VS Code extension breached GitHub yesterday, one day after Nx Console (2.2M installs) was compromised for 18 minutes on the Visual Studio Marketplace and reached every user with auto-update on.Category: Vulnerabilities & Threats
3ヶ月前

GitHub breached via a malicious VS Code extension: why developer devices are the real target
Aikido Security's Blog
GitHub confirmed a poisoned VS Code extension compromised an employee device, exposing 3,800 internal repos. Why developer workstations are now the top supply chain target.Category: Vulnerabilities & Threats
3ヶ月前

Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
Aikido Security's Blog
Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systemsCategory: Vulnerabilities & Threats
3ヶ月前

Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages
Aikido Security's Blog
The Mini Shai-Hulud npm worm has hit Alibaba's @antv packages, echarts-for-react, and timeago.js. The payload steals CI/CD secrets, plants backdoors in VS Code and Claude Code, and spreads by republishing compromised packages. Here is what happened and how to protect your team.Category: Vulnerabilities & Threats
3ヶ月前

Penetration testing vs. red teaming: what’s the difference?
Aikido Security's Blog
Not sure whether you need a pentest or a red team engagement? This guide breaks down the key differences, when to use each, and how AI is changing both.Category: Guides & Best Practices
3ヶ月前

One year of Opengrep: What we built and what’s next
Aikido Security's Blog
A year after forking Semgrep, Opengrep is faster, supports deeper taint analysis, and produces consistent, reproducible results.Category: Product & Company Updates
3ヶ月前

Shadow AI is a fear response, and banning it makes it worse
Aikido Security's Blog
Employees aren't using unapproved AI tools to cause problems. They're scared of falling behind. Here's why banning shadow AI increases your security risk, and what to do instead.Category: News
3ヶ月前

Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack
Aikido Security's Blog
Mini Shai-Hulud is back, compromising 169 npm packages across TanStack, UiPath, Squawk, and more to steal developer and CI/CD secrets, then spread through trusted publishing workflows.Category: Vulnerabilities & Threats
3ヶ月前

The complete GitHub Actions security checklist
Aikido Security's Blog
GitHub Actions misconfigurations have been behind some of the biggest supply chain attacks of 2025 and 2026. Here's what went wrong and how to prevent them from happening to your org.Category: Guides & Best Practices
4ヶ月前

Top OWASP scanners in 2026 for web application security
Aikido Security's Blog
Most scanners don't cover the full OWASP Top 10. We break down the top OWASP scanners in 2026 so you can choose one that actually keeps you covered.Category: DevSec Tools & Comparisons
4ヶ月前

Rolling out developer security in a 5,000+ engineer organization
Aikido Security's Blog
Most developer security rollouts fail because they're designed like software deployments, not cultural changes. A practitioner's guide for enterprise CISOs.Category: Guides & Best Practices
4ヶ月前

Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks
Aikido Security's Blog
AppSec has flatlined under modern complexity. Project Glasswing and the Mythos era demand a security discipline that operates at the velocity of the threats it faces.Category: Guides & Best Practices
4ヶ月前

Why browser extensions are a major security risk and what you can do about it
Aikido Security's Blog
Browser extensions have lots of security risks, more than we care to admit. We discuss the full extent of the threat and what both individuals and organizations can do about it.Category: Guides & Best Practices
4ヶ月前

Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud
Aikido Security's Blog
Malware found in popular PyTorch Lightning version 2.6.2 and 2.6.3, stealing credentials, crypto wallets, and VPN configs as part of the Mini Shai-Hulud campaign.Category: Vulnerabilities & Threats
4ヶ月前

Aikido integrates with AWS Kiro: Catching in review doesn't scale anymore
Aikido Security's Blog
AI agents writing your code. Aikido integrates directly into AWS Kiro's agentic workflow to keep security in the loop, automatically, from the first line. Aikido is AWS's first global security partner for Kiro.Category: Product & Company Updates
4ヶ月前

Top CVE scanners in 2026 to identify known vulnerabilities
Aikido Security's Blog
We evaluated the top CVE scanners in 2026 on coverage breadth, intelligence sources, signal-to-noise ratio, and auto-fix capability. Here's how they compare and which is right for your stack.Category: DevSec Tools & Comparisons
4ヶ月前