
.avif)
Welcome to our blog.

The CVE spike across major software companies is a remediation problem
A viral chart this month showed CVEs climbing sharply across 21 major software companies, and the industry split into two camps arguing about what it means. Both are missing the number that actually determines risk: how fast the vulnerabilities that matter get fixed.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

SBOMs in 2026: Everyone's generating them, no one's using them
ENISA's 2026 SBOM adoption report covers 334 organizations and surfaces a consistent gap between generating SBOMs and actually using them. Here is what stood out.
Why EDR and proxy won’t save you from supply chain malware
EDR and proxies weren't built for supply chain malware. When malicious code arrives through npm install, it looks like normal behavior. Here's why that matters.
What MDM can't protect on developer machines (and what to do about it)
Most security teams have MDM deployed. The problem is that npm installs, VS Code extensions, and AI coding tools happen completely outside MDM's view. Here's what's actually unprotected and how to close the gap.
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
A polished Codex remote UI, the npm package codexui-android, has active development and thousands of weekly users. It has been quietly exfiltrating OpenAI auth tokens for the past month.
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
Attackers injected a credential stealer into 200+ versions of popular Laravel-Lang packages, delivering a credential stealer targeting cloud keys, SSH keys, browsers, crypto wallets and more.
Shadow AI is a fear response, and banning it makes it worse
Shadow AI is a fear response. Employees are hiding the tools they use because they're correctly reading a job market that demands AI skills. Here's why banning makes it worse, and what to do instead.
Rolling out developer security in a 5,000+ engineer organization
Most developer security rollouts fail because they're designed like software deployments, not cultural changes. Here's the phased model experienced CISOs converge on to fix that.
Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks
AppSec has flatlined under modern complexity. Project Glasswing and the Mythos era demand a security discipline that operates at the velocity of the threats it faces.
It's time to treat browser extensions like supply chain attack vectors
The Vercel breach followed a pattern the security industry knows well, where third-party code is implicitly trusted, then compromised upstream. We have a framework for that. We just haven't applied it to browser extensions yet. (Spoiler: We do this for software dependencies)
Finding vulnerabilities at every stage: what to run, and when
SAST, Deep PR Review, Code Security Audit and AI Pentest each catch different vulnerabilities at different stages. Here's when to use each, and why
Compromised Flutter package on pub.dev contains XCSSET malware
We detected XCSSET malware inside a compromised Flutter package on pub.dev. Here is a full breakdown of the infection chain, propagation modules, and stealer logic we found inside.
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



