Aikido Security's Blog
https://www.aikido.dev
Detect, pentest, and block security threats across your entire stack - from one unified platform.
フィード

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
Aikido Security's Blog
A polished Codex remote UI, the npm package codexui-android, has active development and thousands of weekly users. It has been quietly exfiltrating OpenAI auth tokens for the past month.Category: Vulnerabilities & Threats
4時間前

Top GitGuardian alternatives for secrets scanning in 2026
Aikido Security's Blog
Compare the Top GitGuardian Alternatives for secrets scanning in 2026. See where Aikido Security, GitHub Secret Protection, TruffleHog, Gitleaks, Semgrep, Snyk, Cycode, Checkmarx, and GitLab fit best.Category: DevSec Tools & Comparisons
8時間前

Why developer machines are now the number one target for supply chain attacks
Aikido Security's Blog
Teams at Omnea, Cognism, Glasswall, Raisin and the UK public sector reveal why EDR and MDM miss what's really happening on developer machines.Category: News
2日前

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
Aikido Security's Blog
Attackers injected a credential stealer into 200+ versions of popular Laravel-Lang packages, delivering a credential stealer targeting cloud keys, SSH keys, browsers, crypto wallets and more.Category: Vulnerabilities & Threats
5日前

5 Gitleaks alternatives and why they are better
Aikido Security's Blog
Looking for a Gitleaks alternative? We compare Betterleaks, TruffleHog, Aikido, GitHub Advanced Security, and Spectral so you can find the best secrets scanner for your team.Category: DevSec Tools & Comparisons
6日前

Google API keys keep working after you delete them
Aikido Security's Blog
Deleting a Google API key doesn't revoke it immediately. Our testing found successful authentications up to 23 minutes after deletion, and Google has declined to fix it.Category: Vulnerabilities & Threats
6日前

The Wild West of VS Code extensions and how a poisoned extension breached GitHub
Aikido Security's Blog
A poisoned VS Code extension breached GitHub yesterday, one day after Nx Console (2.2M installs) was compromised for 18 minutes on the Visual Studio Marketplace and reached every user with auto-update on.Category: Vulnerabilities & Threats
7日前

GitHub breached via a malicious VS Code extension: why developer devices are the real target
Aikido Security's Blog
GitHub confirmed a poisoned VS Code extension compromised an employee device, exposing 3,800 internal repos. Why developer workstations are now the top supply chain target.Category: Vulnerabilities & Threats
8日前

Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
Aikido Security's Blog
Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systemsCategory: Vulnerabilities & Threats
8日前

Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages
Aikido Security's Blog
The Mini Shai-Hulud npm worm has hit Alibaba's @antv packages, echarts-for-react, and timeago.js. The payload steals CI/CD secrets, plants backdoors in VS Code and Claude Code, and spreads by republishing compromised packages. Here is what happened and how to protect your team.Category: Vulnerabilities & Threats
9日前

Penetration testing vs. red teaming: what’s the difference?
Aikido Security's Blog
Not sure whether you need a pentest or a red team engagement? This guide breaks down the key differences, when to use each, and how AI is changing both.Category: Guides & Best Practices
13日前

One year of Opengrep: What we built and what’s next
Aikido Security's Blog
A year after forking Semgrep, Opengrep is faster, supports deeper taint analysis, and produces consistent, reproducible results.Category: Product & Company Updates
16日前

Shadow AI is a fear response, and banning it makes it worse
Aikido Security's Blog
Employees aren't using unapproved AI tools to cause problems. They're scared of falling behind. Here's why banning shadow AI increases your security risk, and what to do instead.Category: News
16日前

Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack
Aikido Security's Blog
Mini Shai-Hulud is back, compromising 169 npm packages across TanStack, UiPath, Squawk, and more to steal developer and CI/CD secrets, then spread through trusted publishing workflows.Category: Vulnerabilities & Threats
16日前

The complete GitHub Actions security checklist
Aikido Security's Blog
GitHub Actions misconfigurations have been behind some of the biggest supply chain attacks of 2025 and 2026. Here's what went wrong and how to prevent them from happening to your org.Category: Guides & Best Practices
17日前

Top OWASP scanners in 2026 for web application security
Aikido Security's Blog
Most scanners don't cover the full OWASP Top 10. We break down the top OWASP scanners in 2026 so you can choose one that actually keeps you covered.Category: DevSec Tools & Comparisons
21日前

Rolling out developer security in a 5,000+ engineer organization
Aikido Security's Blog
Most developer security rollouts fail because they're designed like software deployments, not cultural changes. A practitioner's guide for enterprise CISOs.Category: Guides & Best Practices
22日前

Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks
Aikido Security's Blog
AppSec has flatlined under modern complexity. Project Glasswing and the Mythos era demand a security discipline that operates at the velocity of the threats it faces.Category: Guides & Best Practices
22日前

Why browser extensions are a major security risk and what you can do about it
Aikido Security's Blog
Browser extensions have lots of security risks, more than we care to admit. We discuss the full extent of the threat and what both individuals and organizations can do about it.Category: Guides & Best Practices
1ヶ月前

Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud
Aikido Security's Blog
Malware found in popular PyTorch Lightning version 2.6.2 and 2.6.3, stealing credentials, crypto wallets, and VPN configs as part of the Mini Shai-Hulud campaign.Category: Vulnerabilities & Threats
1ヶ月前

Aikido integrates with AWS Kiro: Catching in review doesn't scale anymore
Aikido Security's Blog
AI agents writing your code. Aikido integrates directly into AWS Kiro's agentic workflow to keep security in the loop, automatically, from the first line. Aikido is AWS's first global security partner for Kiro.Category: Product & Company Updates
1ヶ月前

Top CVE scanners in 2026 to identify known vulnerabilities
Aikido Security's Blog
We evaluated the top CVE scanners in 2026 on coverage breadth, intelligence sources, signal-to-noise ratio, and auto-fix capability. Here's how they compare and which is right for your stack.Category: DevSec Tools & Comparisons
1ヶ月前

A practical CTO security checklist to be Mythos-ready
Aikido Security's Blog
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.Category: Guides & Best Practices
1ヶ月前

Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer
Aikido Security's Blog
Compromised SAP npm packages use a Bun-based preinstall payload to steal GitHub, npm, cloud, and CI secrets, then spread via GitHub using OhNoWhatsGoingOnWithGitHub.Category: Vulnerabilities & Threats
1ヶ月前

Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files
Aikido Security's Blog
A fake "tanstack" npm package published four malicious versions in 27 minutes today, exfiltrating .env files via a postinstall hook. Here's what happened, who was affected, and how to rotate your credentials.Category: Vulnerabilities & Threats
1ヶ月前

It's time to treat browser extensions like supply chain attack vectors
Aikido Security's Blog
The Vercel breach followed a pattern the security industry knows well, where third-party code is implicitly trusted, then compromised upstream. We have a framework for that. We just haven't applied it to browser extensions yet. (Spoiler: We do this for software dependencies)Category: Vulnerabilities & Threats
1ヶ月前

Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
Aikido Security's Blog
Malware found in @bitwarden/cli v2026.4.0 steals SSH keys, cloud secrets, and AI coding tool credentials, then spreads through victims' own npm packages. Inside: a worm calling itself "Shai-Hulud: The Third Coming."Category: Vulnerabilities & Threats
1ヶ月前

GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays
Aikido Security's Blog
A newly discovered npm and PyPI malware campaign installs hidden LLM proxies on compromised servers, turning them into relay nodes for LLM traffic.Category: Vulnerabilities & Threats
1ヶ月前

Introducing Device Protection: Security for Developer Devices
Aikido Security's Blog
Supply chain attacks target developer devices. Aikido Device Protection monitors every install across npm, PyPI, VS Code extensions, browser extensions, and AI tools.Category: Product & Company Updates
1ヶ月前

Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow
Aikido Security's Blog
Aikido's AI pentest agent found three XSS vulnerabilities in Mailcow, one of which let unauthenticated attackers take over administrator accounts. All issues have been patched as of version 2026-03b.Category: Vulnerabilities & Threats
1ヶ月前

Reliable CVE sources in the age of NIST NVD cutbacks
Aikido Security's Blog
NIST will no longer enrich most CVEs. Here's what changes, what breaks, and what comes next.Category: News
1ヶ月前

Axios CVE-2026-40175: a critical bug that’s… not exploitable
Aikido Security's Blog
Axios CVE-2026-40175 is rated critical, but in real Node.js environments it’s not practically exploitable. Here’s why.Category: Vulnerabilities & Threats
1ヶ月前

Bug bounty isn’t dead, but the old model is breaking
Aikido Security's Blog
Bug bounty is hitting a breaking point as AI overwhelms programs, pushing a shift toward more sustainable, quality-focused security models.Category: Technical
1ヶ月前

GlassWorm goes native: New Zig dropper infects every IDE on your machine
Aikido Security's Blog
GlassWorm deploys a Zig-based native dropper hidden within a fake extension, silently compromising VS Code, Cursor, VSCodium, and other IDEs.Category: Vulnerabilities & Threats
2ヶ月前

Aikido Attack finds multiple 0-days in Hoppscotch
Aikido Security's Blog
Aikido’s AI pentesting agents discovered multiple high-severity vulnerabilities in Hoppscotch, including account takeover, stored XSS, and access control flaws. All issues are now patched.Category: Vulnerabilities & Threats
2ヶ月前

The cybersecurity doomerism around Mythos doesn't match what we see on the ground
Aikido Security's Blog
Anthropic's leaked Mythos model has triggered panic about AI-powered cyberattacks. We ran 1,000 AI penetration tests. The results suggest the threat is more nuanced than the headlines claim.Category: News
2ヶ月前

axios compromised on npm: maintainer account hijacked, RAT deployed
Aikido Security's Blog
Malicious axios versions 1.14.1 and 0.30.4 were published via a hijacked maintainer account. A hidden dependency deploys a cross-platform RAT. Check if you are affected and remediate now.Category: Vulnerabilities & Threats
2ヶ月前

Popular telnyx package compromised on PyPI by TeamPCP
Aikido Security's Blog
The popular telnyx packageon PyPI, used by big AI companies, has been compromised by TeamPCPCategory: Vulnerabilities & Threats
2ヶ月前

Aikido × Lovable: Vibe, Fix, Ship
Aikido Security's Blog
Lovable and Aikido bring pentesting into the platform, allowing builders to simulate real-world attacks and fix issues before shipping.Category: Product & Company Updates
2ヶ月前

CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran
Aikido Security's Blog
CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets IranCategory: Vulnerabilities & Threats
2ヶ月前
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
Aikido Security's Blog
TeamPCP deploys CanisterWorm on NPM following Trivy compromiseCategory: Vulnerabilities & Threats
2ヶ月前

Security testing is validating software that no longer exists
Aikido Security's Blog
Modern teams ship faster than pentesting can keep up. Explore the growing speed gap in security testing—and why traditional approaches are falling behind.Category: Guides & Best Practices
2ヶ月前

Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM
Aikido Security's Blog
Frost & Sullivan recognized Aikido with the 2026 Customer Value Leadership Award in ASPM. We break down what the recognition criteria reveal about how the AppSec market is maturingCategory: News
2ヶ月前

GlassWorm Hides a RAT Inside a Malicious Chrome Extension
Aikido Security's Blog
GlassWorm deploys a multi-stage RAT that force-installs a malicious Chrome extension to log keystrokes, steal cookies, and exfiltrate data via Solana-based C2.Category: Vulnerabilities & Threats
2ヶ月前

fast-draft Open VSX Extension Compromised by BlokTrooper
Aikido Security's Blog
The fast-draft Open VSX extension was compromised to deploy a BlokTrooper RAT and infostealer via GitHub-hosted payloads. Multiple malicious versions identified.Category: Vulnerabilities & Threats
2ヶ月前

Glassworm Strikes Popular React Native Phone Number Packages
Aikido Security's Blog
Aikido Security researchers recovered and decrypted the full payload chain from two malicious React Native packages. Here's what the malware does and what to look for.Category: Vulnerabilities & Threats
2ヶ月前

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories
Aikido Security's Blog
The Glassworm supply chain attack is back. Researchers uncovered malware hidden in invisible Unicode characters across 150+ GitHub repositories, plus npm packages and VS Code extensions.Category: Vulnerabilities & Threats
3ヶ月前

How Security Teams Fight Back Against AI-Powered Hackers
Aikido Security's Blog
AI has lowered the bar for hackers dramatically. Here's what that means for defenders and how continuous AI pentesting changes the equation.Category: Vulnerabilities & Threats
3ヶ月前

Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks
Aikido Security's Blog
Betterleaks is a new open source secrets scanner from the creator of Gitleaks. A drop-in replacement with faster scans, token efficiency detection, configurable validation, and more.Category: Product & Company Updates
3ヶ月前

Trump’s 2026 cybersecurity strategy: From compliance to consequence
Aikido Security's Blog
The Trump administration’s 2026 cybersecurity strategy shifts the focus from compliance checklists to real consequences for cybercriminals. Here’s what CISOs need to know.Category: News
3ヶ月前

How does AI pentesting work with compliance?
Aikido Security's Blog
AI pentesting is being accepted for SOC 2, ISO 27001, and HIPAA (with more likely to come). Here's what auditors actually look for, and where the real limitations are.Category: Compliance
3ヶ月前

What continuous pentesting actually requires
Aikido Security's Blog
Continuous pentesting promises real-time security validation, but most implementations fall short. Here’s what continuous pentesting actually requires—from change-aware testing to exploit validation and remediation loops.Category: Guides & Best Practices
3ヶ月前

Rare Not Random: Using Token Efficiency for Secrets Scanning
Aikido Security's Blog
Entropy often struggles with generic secrets and short strings. We look at how token efficiency can better identify strings that don’t look like normal text.Category: Guides & Best Practices
3ヶ月前

Persistent XSS/RCE using WebSockets in Storybook’s dev server
Aikido Security's Blog
CVE-2026-27148 exposes a WebSocket hijacking flaw in Storybook that can escalate into supply chain compromise. Learn the attack path, impact, and how to remediate.Category: Vulnerabilities & Threats
3ヶ月前

Why Determinism Is Still a Necessity in Security
Aikido Security's Blog
AI scanning finds what rules miss. Deterministic scanning finds it every time. Here's why the best security pipelines don't choose between them.Category: Engineering
3ヶ月前

WAF vs. RASP vs. ADR
Aikido Security's Blog
WAF, RASP, and ADR protect your app in completely different ways. Here's what each layer actually does, where it falls short, and which ones you need.Category: Guides
3ヶ月前

Introducing Aikido Infinite: A new model of self-securing software
Aikido Security's Blog
Aikido Infinite runs AI penetration testing on every code change, validates exploitability, generates patches, and retests fixes before code hits production, making self-securing software a reality.Category: Product & Company Updates
3ヶ月前

How Aikido secures AI pentesting agents by design
Aikido Security's Blog
Learn how Aikido secures AI pentesting agents with architectural isolation, runtime scope enforcement, and network-level controls to prevent production drift and data leakage.Category: Product & Company Updates
3ヶ月前

Astro Full-Read SSRF via Host Header Injection
Aikido Security's Blog
Aikido Security's AI pentesting agent discovered a Server-Side Request Forgery vulnerability in Astro's SSR implementation. Learn how Host header injection in prerendered error pages allowed full internal network access.Category: Vulnerabilities & Threats
3ヶ月前

How to Get Your Board to Care About Security (Before a Breach Forces the Issue)
Aikido Security's Blog
Boards don’t fund security because it’s important. They fund defensible decisions. Here’s how to frame risk, reduce ambiguity, and win real support before a breach forces the issue.Category: Guides
3ヶ月前

What is Slopsquatting? The AI Package Hallucination Attack Already Happening
Aikido Security's Blog
AI models hallucinate npm package names. Attackers register them first. Here's what slopsquatting is, how it's spreading through agent skills, and how to protect yourself.Category: Guides & Best Practices
3ヶ月前

SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel
Aikido Security's Blog
SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnerable and how to mitigate risk.Category: Vulnerabilities & Threats
3ヶ月前

Top 6 Wiz Code Alternatives
Aikido Security's Blog
Looking for Wiz Code alternatives? Compare 6 tools across SAST, DAST, SCA, pricing, and developer experience to find the best AppSec platform for 2026.Category: Guides & Best Practices
3ヶ月前

Aikido recognized as Platform Leader in Latio Tech's 2026 Application Security Report
Aikido Security's Blog
Aikido Security recognized as Platform Leader, AI Pentesting Innovator, and Supply Chain Innovator in Latio Tech’s 2026 AppSec Report.Category: News
3ヶ月前

From detection to prevention: How Zen stops IDOR vulnerabilities at runtime
Aikido Security's Blog
IDOR vulnerabilities are one of the most common causes of cross-tenant data leaks in multi-tenant SaaS. Learn how Zen enforces tenant isolation at runtime by analyzing SQL queries and preventing unsafe access before it ships.Category: Product & Company Updates
3ヶ月前

npm backdoor lets hackers hijack gambling outcomes
Aikido Security's Blog
A targeted npm supply chain attack installs an Express backdoor, enables remote SQL/file access, and rewrites gambling balances while keeping logs consistent.Category: Vulnerabilities & Threats
3ヶ月前

Introducing Upgrade Impact Analysis: When breaking changes actually matter to your code
Aikido Security's Blog
Aikido automatically detects breaking changes in dependency upgrades and analyzes your codebase to show real impact, so teams can merge security fixes safely.Category: Product & Company Updates
3ヶ月前

Why Trying to Secure OpenClaw is Ridiculous
Aikido Security's Blog
OpenClaw's security issues explained: malware in ClawHub, exposed instances, and why hardening guides miss the point. Can you use the AI agent safely??Category: News
3ヶ月前

Claude Opus 4.6 found 500 vulnerabilities. What does this change for software security?
Aikido Security's Blog
Anthropic claims Claude Opus 4.6 uncovered 500+ high-severity vulnerabilities in open source. Here’s what that means for vulnerability discovery, exploitability validation, and production security workflows.Category: News
4ヶ月前

Introducing Aikido Expansion Packs: Safer defaults inside the IDE
Aikido Security's Blog
Aikido Expansion Packs add focused security controls directly inside your IDE. Enable secrets protection, supply chain malware checks, and AI-assisted code security without changing developer workflows.Category: Product & Company Updates
4ヶ月前

International AI Safety Report 2026: What It Means for Autonomous AI Systems
Aikido Security's Blog
Aikido Security's analysis of the International AI Safety Report 2026. We examine deployment-time controls, validation requirements, and practical safety baselines for autonomous AI systems.Category: News
4ヶ月前

Self-Securing Software: What It Is, Why It Matters, and How It Works
Aikido Security's Blog
Self-securing software is a security model where systems continuously validate and remediate real risk as they change. Learn why periodic testing no longer scales.Category: Product & Company Updates
4ヶ月前

What Is Continuous Pentesting?
Aikido Security's Blog
Continuous pentesting automatically tests real attack paths every time software changes, validating and fixing issues as part of the development lifecycle. Learn how it compares to AI and manual pentesting.Category: Guides & Best Practices
4ヶ月前

npx Confusion: Packages That Forgot to Claim Their Own Name
Aikido Security's Blog
We claimed 128 unclaimed npm package names that official docs told developers to npx. Seven months later: 121,000 downloads. All would have run arbitrary code.Category: Vulnerabilities & Threats
4ヶ月前

Introducing Aikido Package Health: a Better Way to Trust Your Dependencies
Aikido Security's Blog
See how stable and well-maintained an open source package really is. Aikido Package Health helps devs choose safer dependencies with confidence.Category: Product & Company Updates
4ヶ月前

AI Pentesting: Minimum Safety Requirements for Security Testing
Aikido Security's Blog
AI pentesting systems act autonomously against live environments. Learn when AI pentesting is safe to use, the minimum technical safeguards required, and how to evaluate AI security testing tools responsibly.Category: Guides & Best Practices
4ヶ月前

Secure SDLC for Engineering Teams (+ Checklist)
Aikido Security's Blog
Learn what a Secure SDLC is, why it matters, and the five pillars every team needs. Includes a practical Secure SDLC checklist for CTOs and engineering leaders.Category: Guides & Best Practices
4ヶ月前

Fake Clawdbot VS Code Extension Installs ScreenConnect RAT
Aikido Security's Blog
A malicious VS Code extension impersonating Clawdbot is installing ScreenConnect RAT on developer machines. Category: Vulnerabilities & Threats
4ヶ月前

G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets
Aikido Security's Blog
npm package ansi-universal-ui delivers GWagon infostealer targeting 100+ crypto wallets, browser credentials, and cloud keys. We analyzed all 10 versions as the attacker iterated in real-time.Category: Vulnerabilities & Threats
4ヶ月前

Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages
Aikido Security's Blog
A targeted spear-phishing campaign used npm packages and jsDelivr as free phishing infrastructure, serving custom credential harvesters per victimCategory: Vulnerabilities & Threats
4ヶ月前

Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT
Aikido Security's Blog
Attackers published fake spellchecker packages to PyPI with malware hidden in plain sight. We break down the attack and what developers need to watch for.Category: Vulnerabilities & Threats
4ヶ月前

Top 10 AI Security Tools For 2026
Aikido Security's Blog
Explore the top AI security tools for 2026. Compare platforms for AI code review, vulnerability detection, pentesting, and risk management to secure modern applications.Category: DevSec Tools & Comparisons
4ヶ月前

Agent Skills Are Spreading Hallucinated npx Commands
Aikido Security's Blog
AI agent skills are propagating hallucinated npx commands, creating real security and reliability risks for developers and supply chains.Category: Vulnerabilities & Threats
4ヶ月前

Understanding Open-Source License Risk in Modern Software
Aikido Security's Blog
Open-source license risk hides in dependencies and container images. Learn what it is, why it matters, and how to catch issues early.Category: Guides & Best Practices
4ヶ月前

The CISO Vibe Coding Checklist for Security
Aikido Security's Blog
A practical security checklist for CISOs managing AI and vibe-coded applications. Covers technical guardrails, AI controls, and organizational policies. Category: Guides & Best Practices
4ヶ月前

Top 6 Graphite alternatives for AI code review in 2026
Aikido Security's Blog
Compare the best Graphite alternatives for AI-driven code review. Check free options like Aikido Security and enterprise tools like SonarQube to improve code quality.Category: DevSec Tools & Comparisons
4ヶ月前

From “No Bullsh*t Security” to $1B: We Just Raised Our $60m Series B
Aikido Security's Blog
Aikido announces $60M Series B funding at a $1B valuation, accelerating its vision for self-securing software and continuous penetration testing.Category: Product & Company Updates
4ヶ月前

Critical n8n Vulnerability Allows Unauthenticated Remote Code Execution (CVE-2026-21858)
Aikido Security's Blog
A critical vulnerability in n8n (CVE-2026-21858) allows unauthenticated remote code execution on self-hosted instances. Learn who is affected and how to remediate.Category: Vulnerabilities & Threats
5ヶ月前

Top 14 VS Code Extensions for 2026
Aikido Security's Blog
A practical guide to the best VS Code extensions for 2026, covering productivity, testing, collaboration, and security tools that improve real-world developer workflows.Category: DevSec Tools & Comparisons
5ヶ月前

AI-Driven Pentesting of Coolify: Seven CVEs Identified
Aikido Security's Blog
AI-driven pentesting of Coolify identified seven CVEs, including privilege escalation and remote code execution vulnerabilities. Findings were responsibly disclosed and fixed.Category: Aikido
5ヶ月前

Top 6 Continuous Pentesting Tools in 2026
Aikido Security's Blog
Discover the leading continuous pentesting tools that provide real-time, AI-powered security testing for modern applications.Category: DevSec Tools & Comparisons
5ヶ月前

SAST vs SCA: Securing the Code You Write and the Code You Depend On
Aikido Security's Blog
earn how SAST and SCA differ, what risks each addresses, and why modern AppSec teams need both to secure code and dependencies.Category: Technical
5ヶ月前

JavaScript, MSBuild, and the Blockchain: Anatomy of the NeoShadow npm Supply-Chain Attack
Aikido Security's Blog
A deep technical analysis of the NeoShadow npm supply-chain attack, detailing how JavaScript, MSBuild, and blockchain techniques were combined to compromise developers.Category: Vulnerabilities & Threats
5ヶ月前

How Engineering and Security Teams Can Meet DORA’s Technical Requirements
Aikido Security's Blog
Understand DORA’s technical requirements for engineering and security teams, including resilience testing, risk management, and audit-ready evidence.Category: Compliance
5ヶ月前

IDOR Vulnerabilities Explained: Why They Persist in Modern Applications
Aikido Security's Blog
Learn what an IDOR vulnerability is, why insecure direct object references persist in modern APIs, and why traditional testing tools struggle to detect real authorization failures.Category: Vulnerabilities & Threats
5ヶ月前

Shai Hulud strikes again - The golden path
Aikido Security's Blog
A new strain of Shai Hulud has been observed in the wild. Category: Vulnerabilities & Threats
5ヶ月前

MongoBleed: MongoDB Zlib Vulnerability (CVE-2025-14847) and How to Fix It
Aikido Security's Blog
MongoBleed, tracked as CVE-2025-14847, allows unauthenticated memory disclosure in MongoDB via zlib compression. See impact and remediation.Category: Vulnerabilities & Threats
5ヶ月前

First Sophisticated Malware Discovered on Maven Central via Typosquatting Attack on Jackson
Aikido Security's Blog
We uncovered the first sophisticated malware campaign on Maven Central: a typosquatted Jackson package delivering multi-stage payloads and Cobalt Strike beacons via Spring Boot auto-execution.Category: Vulnerabilities & Threats
5ヶ月前

The Fork Awakens: Why GitHub’s Invisible Networks Break Package Security
Aikido Security's Blog
A deep dive into a GitHub security flaw where forked commits let attackers spoof dependencies. Understand the commit SHA issue and why package managers need API-level protection.Category: Vulnerabilities & Threats
5ヶ月前

Top 10 Cyber Security Tools For 2026
Aikido Security's Blog
A practical breakdown of the top 10 cybersecurity tools for 2026, covering endpoint, cloud, identity, vulnerability management, and XDR. Learn how to choose the right tool for your stack and risk profile.Category: DevSec Tools & Comparisons
5ヶ月前