Welcome to our blog.

Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Altar is our first open-weight AI model, and the first step toward sovereign security intelligence. It runs entirely inside a customer's own infrastructure, powering Aikido Machine's autonomous pentesting without any code ever leaving the building.

Aikido achieves AWS Security Competency for Application Security
AWS checked our homework: we're officially an AWS Security Competency Partner for Application Security.

The CVE spike across major software companies is a remediation problem
A viral chart this month showed CVEs climbing sharply across 21 major software companies, and the industry split into two camps arguing about what it means. Both are missing the number that actually determines risk: how fast the vulnerabilities that matter get fixed.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

The practical checklist for defending against supply chain attacks
Thirty prioritized defenses against the recent wave of software supply chain attacks. Graded critical, high, or medium.
How to maintain code quality standards with AI code and vibe coding
Vibe coding ships features fast and leaves review debt behind. See how benchmarked, per-rule code quality checks give teams one consistent answer across PRs and repos.
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry
A malicious release of @injectivelabs/sdk-ts hid a wallet-key stealer inside code labeled as usage telemetry, then spread it across 17 more npm packages. Here's how it worked and how to check your projects.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and an evaluation checklist.
Predicting MongoDB ObjectId continuously in Rocket.Chat
Aikido's AI pentester found this file-access flaw in Rocket.Chat. A closer look at MongoDB's ObjectId() showed the weak randomness that makes it exploitable.
Authentication Bypass in the default configuration phpBB
Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix.
And another one. GitHub ships break-glass credential revocation
GitHub Enterprise can now revoke all of an account's credentials in one action. The Trivy attack and Microsoft's own durabletask compromise demonstrate why this was a long time coming.
npm now freezes high-impact accounts after risky account changes
A look at npm's new 72-hour account freeze, what triggers it, what it blocks, and how it works alongside trusted and staged publishing.
Everybody's shipping code they can't read
With AI, everyone's a developer now, and a lot of code gets shipped without a careful review from trained eyes.
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
codfish/semantic-release-action was compromised on June 24, 2026. Attackers repointed v2–v5 tags to a Miasma credential-stealing payload targeting CI/CD secrets. Here's what happened and how to check if you're affected.
Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Aikido Altar is a compressed, open-weight AI model built for sovereign security intelligence, powering Aikido Machine's on-prem, air-gapped pentesting.
Novel supplychain.local Go worm appears
"supplychain.local": malicious code found in MemTensor's npm plugin (0.1.21, 0.1.23) and PyPI's MemoryOS (2.0.34).
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure today,
quickly and for free.
Secure your code, cloud, and runtime in one central system.
Connect a repo to discover what the reasoning agents find in your codebase.