Welcome to our blog.

Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Altar is our first open-weight AI model, and the first step toward sovereign security intelligence. It runs entirely inside a customer's own infrastructure, powering Aikido Machine's autonomous pentesting without any code ever leaving the building.

Aikido achieves AWS Security Competency for Application Security
AWS checked our homework: we're officially an AWS Security Competency Partner for Application Security.

The CVE spike across major software companies is a remediation problem
A viral chart this month showed CVEs climbing sharply across 21 major software companies, and the industry split into two camps arguing about what it means. Both are missing the number that actually determines risk: how fast the vulnerabilities that matter get fixed.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

Aikido and Deel: set up once, secure every hire
Code, cloud, and devices, covered automatically once someone's hired through Deel.
Send GitLab an email, push to main
GitLab gives you a private email address to create issues. If leaked, anyone who has it can push code, execute CI/CD jobs, and bypass IP restrictions across all of your public and private projects.
Cyber Resilience Act is here! Myth busting and first impressions
The Cyber Resilience Act's first deadline just came up on September 11, 2026. What the new Single Reporting Platform looks like, and four common CRA myths debunked.
Graphalgo campaign spreads to Terraform providers and Go Modules
Graphalgo malware has now spread to Go, showing up in two Terraform providers and two Go modules.
Jason Haddix: Stop fearing AI pentesting
Jason Haddix on why manual pentesting can't keep up, what disappears first, and why human methodology is what makes AI pentesting work
Compromised Flutter package on pub.dev contains XCSSET malware
We detected XCSSET malware inside a compromised Flutter package on pub.dev. Here is a full breakdown of the infection chain, propagation modules, and stealer logic we found inside.
Stop breaking SLAs: how to patch vulnerabilities before the fix even ships
Learn how to meet security SLAs for dependency vulnerabilities with Aikido Libraries by using delivering secure, backported patches.
MECCHA CHAMELEON can't hide from the RCE
We found a second delayed RCE in MECCHA CHAMELEON: a malicious custom map could write files anywhere on your system and run code after a restart. Now patched in 4.0.0.
Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Aikido Altar is a compressed, open-weight AI model built for sovereign security intelligence, powering Aikido Machine's on-prem, air-gapped pentesting.
Novel supplychain.local Go worm appears
"supplychain.local": malicious code found in MemTensor's npm plugin (0.1.21, 0.1.23) and PyPI's MemoryOS (2.0.34).
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure today,
quickly and for free.
Secure your code, cloud, and runtime in one central system.
Connect a repo to discover what the reasoning agents find in your codebase.