Welcome to our blog.

Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Altar is our first open-weight AI model, and the first step toward sovereign security intelligence. It runs entirely inside a customer's own infrastructure, powering Aikido Machine's autonomous pentesting without any code ever leaving the building.

Aikido achieves AWS Security Competency for Application Security
AWS checked our homework: we're officially an AWS Security Competency Partner for Application Security.

The CVE spike across major software companies is a remediation problem
A viral chart this month showed CVEs climbing sharply across 21 major software companies, and the industry split into two camps arguing about what it means. Both are missing the number that actually determines risk: how fast the vulnerabilities that matter get fixed.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

How Security Teams Fight Back Against AI-Powered Hackers
A single hacker and a Claude subscription just took down nine Mexican government agencies. AI has handed attackers a serious power upgrade. Security teams need a new playbook.
How does AI pentesting work with compliance?
AI pentesting is being accepted for SOC 2, ISO 27001, HIPAA, and PCI DSS. Here's what auditors actually look for, and where the real limitations are.
Persistent XSS/RCE using WebSockets in Storybook’s dev server
Aikido Attack found a WebSocket hijacking vulnerability in Storybook's dev server that can lead to persistent XSS, remote code execution, and, in the worst case, supply chain compromise. We walk through how an attacker can exploit this without any user interaction at all, and a developer just has to visit the wrong website while to run into this attack.
Why Determinism Is Still a Necessity in Security
AI-powered security tools are getting better at finding vulnerabilities. But deterministic tools give you the consistency that pipelines, compliance, and audit trails depend on. We look at what deterministic scanning does well, where AI takes over, and how the two work together for effective security.
What is Slopsquatting? The AI Package Hallucination Attack Already Happening
AI models hallucinate package names — and attackers are registering them before anyone notices. Slopsquatting is the AI-era evolution of typosquatting, and unlike its predecessor, npm's existing protections don't work. We look at the real-world research showing it's already happening, from confirmed malicious packages still pulling hundreds of weekly downloads to a hallucinated package name that spread to 237 repositories through AI agent skill files.
International AI Safety Report 2026: What It Means for Autonomous AI Systems
Over 100 experts contributed to the International AI Safety Report 2026, documenting risks from autonomous AI systems and proposing defense-in-depth frameworks. As a team operating AI pentesting systems in production, we break down where the report gets it right and where it needs more technical specificity.
Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Aikido Altar is a compressed, open-weight AI model built for sovereign security intelligence, powering Aikido Machine's on-prem, air-gapped pentesting.
Novel supplychain.local Go worm appears
"supplychain.local": malicious code found in MemTensor's npm plugin (0.1.21, 0.1.23) and PyPI's MemoryOS (2.0.34).
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure today,
quickly and for free.
Secure your code, cloud, and runtime in one central system.
Connect a repo to discover what the reasoning agents find in your codebase.