
.avif)
Welcome to our blog.

Anthropic's Fever Dream: Claude's package that stole real keys
Anthropic disclosed that one of its own agents published live malware to PyPI and compromised a real third-party company in the process. I went looking, and I might have found the package it left behind.

The upgrade trap: when upgrading is the wrong answer to a CVE
"Upgrade to fix it" assumes that a fixed version exists, that it's shipped and that it won't break your app. Often none of these are true. This is the "upgrade trap," where both upgrading and not upgrading come with security risks and breaking prod. We look at what the way out looks like.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Authentication Bypass in the default configuration phpBB
Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix.
And another one. GitHub ships break-glass credential revocation
GitHub Enterprise can now revoke all of an account's credentials in one action. The Trivy attack and Microsoft's own durabletask compromise demonstrate why this was a long time coming.
npm now freezes high-impact accounts after risky account changes
A look at npm's new 72-hour account freeze, what triggers it, what it blocks, and how it works alongside trusted and staged publishing.
Everybody's shipping code they can't read
With AI, everyone's a developer now, and a lot of code gets shipped without a careful review from trained eyes.
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
codfish/semantic-release-action was compromised on June 24, 2026. Attackers repointed v2–v5 tags to a Miasma credential-stealing payload targeting CI/CD secrets. Here's what happened and how to check if you're affected.
Aikido x Drydock | A way for maintainers to catch malware before it ships
Aikido is partnering with Drydock so npm and PyPI maintainers can see exactly what's inside a release before it goes live. Catch malware before it ships, not after.
Aikido x OWASP: 200 free credits for individual members
OWASP individual members get 200 free Aikido credits to run Code Audit. Here is how to claim yours in two steps.
Over 140 popular Mastra npm Packages Hit by Supply Chain Attack
141 Mastra npm packages were compromised in a supply chain attack that injected a malicious dependency to silently download and execute a payload at install time.
Full Fathom Five: The context of Anthropic’s Mythos-class public release
You never needed Mythos to find your IDORs and business logic flaws. A look at what Anthropic shipped with Fable 5, and why infosec stays a people problem at heart.
npm v12 delivers one of the biggest security improvements in years
npm v12 makes install scripts opt-in by default, closing the install-time execution path behind a year of npm supply chain worms from Nx to Red Hat.
How Aikido Intel detects malware and vulnerabilities first
Aikido Intel is a real-time feed that catches malware and undisclosed vulnerabilities across open-source ecosystems, often within 8 minutes of release.
Anthropic's Fever Dream: Claude's package that stole real keys
Anthropic disclosed an agent that pushed real malware to PyPI. We think we found the package, and every mistake in it points back to the AI.
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.


