
.avif)
Welcome to our blog.
.png)
From Hugging Face to Fable: this summer shows AI control matters more than trust
One AI agent broke into Hugging Face on its own. One AI vendor's access vanished overnight. Here's what they have in common.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
A supply chain attack compromised two popular Rust crates, arrayref and append-only-vec, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.
What is AI harness engineering?
Harness engineering is the code around an AI model that turns it into an agent. What a harness does, why it beats picking a model, and how to build one.
Who was behind the attack? Possibly nobody
Three summer disclosures documented AI agents attacking real organizations with no human intent in the chain. Incident response has no box for this yet.
Four incident-response decisions from the Hugging Face breach
Recon, stolen credentials, hidden C2, and rebuild-or-patch. Four Hugging Face breach decisions that show whether you can catch an attack in progress.
Better generic secrets detection starts with finding non-secrets
Some API keys are meant to be public. Betterleaks now removes them from generic secret findings, dropping thousands of false positives per scan.
Finding eight high-severity vulnerabilities in NodeBB in six hours
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.
SQL injection isn't dead
The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it.
Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Tyro CISO Arun Singh on developer trust as a finite resource, and what happens when supply chain attacks force teams to spend it
Finding vulnerabilities at every stage: what to run, and when
SAST, Deep PR Review, AI Code Analysis, and AI Pentest each catch different vulnerabilities at different stages. Here's when to use each, and why.
Keyv and friends compromised in active Shai-Hulud supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



