
.avif)
Welcome to our blog.

Move over, Mythos. Here comes... pretty much any other model with a good harness
Mythos has real edges in exploit chain construction. But for most AppSec work, the harness around the model matters more than which model you pick.

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines.
2026 State of AI in Security & Development
Our new report captures the voices of 450 security leaders (CISOs or equivalent), developers, and AppSec engineers across Europe and the US. Together, they reveal how AI-generated code is already breaking things, how tool sprawl is making security worse, and how developer experience is directly tied to incident rates. This is where speed and safety collide in 2025.

Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
ISO 27001 certification: 8 things we learned
We wished we'd known these tips before we started the ISO 27001:2022 compliance process. This is our advice to any SaaS company going for ISO 27001.
Cronos Group chooses Aikido Security to strengthen security posture for its companies and customers
The Cronos Group chooses Aikido Security to strengthen its security posture. Aikido's Partner Portal gives The Cronos Group a central overview of the companies in their group. Additionally, as a reseller, The Cronos Group will offer Aikido to its clients.
How Loctax uses Aikido Security to get rid of irrelevant security alerts & false positives
By embracing Aikido Security's solutions, Loctax optimized its security posture, including getting rid of false positives. This has saved precious time each month and achieved remarkable cost efficiencies.
How StoryChief’s CTO uses Aikido Security to sleep better at night
Losing sleep over startup security concerns? Discover how Aikido Security improved StoryChief's security posture, providing peace of mind and better sleep for the CTO.
What is a CVE?
CVEs are the security world's shared language for known vulnerabilities, but in 2026, the system is under serious strain. This guide covers how CVEs work, how they're scored with CVSS, and why the databases teams rely on are no longer complete. It also covers what to do about it, including how Aikido Intel surfaces vulnerabilities that never make it into any public database.
New Aikido Security Features: August 2023
In the last few weeks, we’ve released many new features and expanded support for different tool stacks. We’ve upgraded our reachability engine to fully support PNPM, expanded AWS rules, pointed Autofix toward Python, and increased support for containers registries.
Aikido’s 2025 SaaS CTO Security Checklist
SaaS companies have a huge target painted on their backs when it comes to security. Aikido's 2024 SaaS CTO Security Checklist gives you over 40 items to enhance security 💪 Download it now and make your company and code 10x more secure. #cybersecurity #SaaSCTO #securitychecklist
Aikido’s 2024 SaaS CTO Security Checklist
SaaS companies have a huge target painted on their backs when it comes to security. Aikido's 2024 SaaS CTO Security Checklist gives you over 40 items to enhance security 💪 Download it now and make your company and code 10x more secure. #cybersecurity #SaaSCTO #securitychecklist
15 Top Cloud and Code Security Challenges Revealed by CTOs
CTOs all face challenges in securing their product. We wanted to find the trends and discover the needs and concerns of SaaS CTOs. We consulted 15 CTOs from cloud-native software companies about their cloud and code security challenges. Priorities, blockers, flaws, desired outcomes!
One year of Opengrep: What we built and what’s next
A year after forking Semgrep, Opengrep is faster, supports deeper taint analysis, and produces consistent, reproducible results.
Google API keys keep working after you delete them
Deleting a Google API key doesn't revoke it immediately. Our testing found successful authentications up to 23 minutes after deletion, and Google has declined to fix it.
The Wild West of VS Code extensions and how a poisoned extension breached GitHub
A poisoned VS Code extension breached GitHub yesterday, one day after Nx Console (2.2M installs) was compromised for 18 minutes on the Visual Studio Marketplace and reached every user with auto-update on.
Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systems
Top 12 Dynamic Application Security Testing (DAST) Tools in 2026
Discover the 12 top best Dynamic Application Security Testing (DAST) tools in 2026. Compare features, pros, cons, and integrations to choose the right DAST solution for your DevSecOps pipeline.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.


