
.avif)
Welcome to our blog.

Secure Code in Your IDE, Now Free.
Aikido’s IDE extensions are now free for VSCode, Cursor, and Windsurf — with real-time SAST and secrets scanning for JavaScript, TypeScript, and Python. Ship secure code without leaving your editor (or paying for it).

A deeper look into the threat actor behind the react-native-aria attack
We investigate the activity of the threat actor that compromised react-native-aria packages on npm, and how they are evolving their attacks.
.png)
Malicious crypto-theft package targets Web3 developers in North Korean operation
Aikido Security uncovers a North Korean-linked supply chain attack using the fake npm package web3-wrapper-ethers to steal private keys from Web3 developers. Linked to Void Dokkaebi, the threat actor mirrors past DPRK crypto theft operations. Learn how the attack worked and what to do if you're affected.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Compliance
Stay ahead of audits with clear, dev-friendly guidance on SOC 2, ISO standards, GDPR, NIS, and more.
Guides & Best Practices
Actionable tips, security workflows, and how-to guides to help you ship safer code faster.
DevSec Tools & Comparisons
Deep dives and side-by-sides of the top tools in the AppSec and DevSecOps landscape.
Launching Opengrep | Why we forked Semgrep
Meet Opengrep, the open source SAST engine – a fork of Semgrep. We initiated Opengrep to advance and commoditize SAST across the appsec industry.
Your Client Requires NIS2 Vulnerability Patching. Now What?
Discover vulnerability requirements for NIS2 vulnerability patching compliance. Learn about critical timelines, proper documentation, and strategies to streamline your processes. Ensure your business meets EU cybersecurity standards efficiently.
Top 10 AI-powered SAST tools in 2025
AI has changed how many of the leading SAST tools work. This list breaks down the leaders in SAST tooling and how they are impementing AI.
Snyk vs Aikido Security | G2 Reviews Snyk Alternative
Looking for a Snyk alternative? Compare Aikido vs Snyk with verified user reviews, directly from G2.
Top 10 Software Composition Analysis (SCA) tools in 2025
SCA tools are our best line of defense for open-source security, this article explores the top 10 open-source dependency scanners for 2025
The Startup's Open-Source Guide to Application Security
This comprehensive guide explores the some of the best open-source tools to build a security program for start-ups.
Launching Aikido for Cursor AI
Is Gen AI code secure? Integrate security directly into your AI Code editor with Aikido for Cursor AI. Devs can secure code as it's generated.
Meet Intel: Aikido’s Open Source threat feed powered by LLMs.
Aikido launches Intel, the AI-powered open-source security threat feed that identifies vulnerabilities in projects before disclosed
Aikido joins the AWS Partner Network
Aikido has joined the AWS Partner Network, offering industry-leading "time-to-security" for new AWS users. As a validated AWS partner, Aikido simplifies cloud security and compliance, enhancing visibility across services like EC2 and S3. Discover more on the AWS Marketplace.
Command injection in 2024 unpacked
Command injection continues to be a significant vulnerability in applications. This report reviews how many injection vulnerabilities are found in closed and open-source projects throughout 2024
Reducing Cybersecurity Debt with AI Autotriage
We dive into how AI can assist us in a meaningful way to triage vulnerabilities and get rid of our security debt.
XRP supply chain attack: Official NPM package infected with crypto stealing backdoor
The official XPRL (Ripple) NPM package was compromised by sophisticated attackers who put in a backdoor to steal cryptocurrency private keys and gain access to cryptocurrency wallets.
Top Container Scanning Tools in 2025
Discover the best Container Scanning tools in 2025. Compare features, pros, cons, and integrations to choose the right solution for your DevSecOps pipeline.
SAST vs DAST: What you need to know.
Get an overview of SAST vs DAST, what they are, how to use them together, and why they matter for your application security.
Get secure for free
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.
.avif)
