
.avif)
Welcome to our blog.

We Got Lucky: The Supply Chain Disaster That Almost Happened
Eighteen widely used open source packages were compromised, downloaded billions of times and embedded across nearly every cloud environment. The community dodged a bullet. But this close call shows just how fragile our software supply chain really is.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Compliance
Stay ahead of audits with clear, dev-friendly guidance on SOC 2, ISO standards, GDPR, NIS, and more.
Guides & Best Practices
Actionable tips, security workflows, and how-to guides to help you ship safer code faster.
DevSec Tools & Comparisons
Deep dives and side-by-sides of the top tools in the AppSec and DevSecOps landscape.
Complying with the Cyber Resilience Act (CRA) using Aikido Security
Learn how to comply with the EU Cyber Resilience Act (CRA). Aikido Security helps developers and security teams meet CRA requirements with automated scanning, SBOM, and runtime protection
duckdb npm packages compromised
The popular package duckdb was compromised by same attackers that hit debug and chalk
AutoTriage Integration in IDE
Aikido's IDE plugin can detect vulnerable code, and AutoTriage can help you ro priotiize what to fix
Quantum Incident Response
Quantum computers will break today’s encryption. Learn why incident response won’t help and how quantum readiness can protect your data before it’s too late.
Aikido for Students and Educators
Aikido for Education offers students hands-on cybersecurity training with real-world security tools, free for all educators.
Free hands-on security labs for your students
Aikido for Education offers students hands-on cybersecurity training with real-world security tools, free for all educators.
Popular nx packages compromised on npm
The popular nx package on npm was compromised, and stolen data was published on GitHub publicly
WTF is Vibe Coding Security? Risks, Examples, and How to Stay Safe
Vibe coding is the new AI coding trend where anyone can spin up an app in hours. But from Replit’s database wipe to exposed tea apps, the risks are real. Learn what vibe coding security means, the difference from agentic coding, and how CISOs can keep the vibes without the vulnerabilities.
Why Securing Bazel Builds is So Hard (And How to Make It Easier)
Bazel builds are fast but notoriously hard to secure. Learn why traditional tools miss vulnerabilities - and how Aikido automates dependency scanning, CVE alerts, and secrets detection for Bazel projects without lockfiles or CI hacks.
Security-Conscious AI Software Development with Windsurf x Aikido
AI is accelerating software delivery, but are your security practices keeping up? Discover how to integrate AI agents like Windsurf and Devin with developer-first tools like Aikido to build secure, high-velocity applications. Learn how to embed security across your SDLC from prompt to production.
Reducing Cybersecurity Debt with AI Autotriage
We dive into how AI can assist us in a meaningful way to triage vulnerabilities and get rid of our security debt.
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
Top Container Scanning Tools in 2025
Discover the best Container Scanning tools in 2025. Compare features, pros, cons, and integrations to choose the right solution for your DevSecOps pipeline.
SAST vs DAST: What you need to know.
Get an overview of SAST vs DAST, what they are, how to use them together, and why they matter for your application security.
Get secure for free
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.
.avif)
