
.avif)
Welcome to our blog.

Compromised Rust crate onering performs code exfiltration
The compromised onering Rust crate v1.4.1 on crates.io shipped a malicious build.rs that exfiltrates the diff of your latest commit to a hosted Sentry endpoint every time you build.
2026 State of AI in Security & Development
Our new report captures the voices of 450 security leaders (CISOs or equivalent), developers, and AppSec engineers across Europe and the US. Together, they reveal how AI-generated code is already breaking things, how tool sprawl is making security worse, and how developer experience is directly tied to incident rates. This is where speed and safety collide in 2025.

Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
We just raised our $17 million Series A
We've raised $17M to bring “no BS” security to devs. We’re happy to welcome Henri Tilloy from Singular.vc on board, who is again joined by Notion Capital and Connect Ventures. This round comes just 6 months after we raised $5.3M in seed funding. That’s fast.
Webhook security checklist: How to build secure webhooks
Building webhooks in your SaaS? Use this webhook security checklist to make sure you're taking the necessary steps to protect your app and user data.
The Cure For Security Alert Fatigue Syndrome
Aikido aims to cure Security Alert Fatigue Syndrome by reducing noise and false positives that waste developers' time. Learn how Aikido intelligently ignores irrelevant security alerts for you, adapts severity scores. This helps Aikido users to easily prioritize fixes for genuine threats. This win-win approach improves developer productivity and resolves security issues faster.
NIS2: Who is affected?
Is your B2B company in scope of the NIS2 Directive? Find out if you need to comply with NIS2 based on industry and size criteria. What are essential and important sectors and company size thresholds? Aikido's app has a NIS2 report feature.
ISO 27001 certification: 8 things we learned
We wished we'd known these tips before we started the ISO 27001:2022 compliance process. This is our advice to any SaaS company going for ISO 27001.
Cronos Group chooses Aikido Security to strengthen security posture for its companies and customers
The Cronos Group chooses Aikido Security to strengthen its security posture. Aikido's Partner Portal gives The Cronos Group a central overview of the companies in their group. Additionally, as a reseller, The Cronos Group will offer Aikido to its clients.
How Loctax uses Aikido Security to get rid of irrelevant security alerts & false positives
By embracing Aikido Security's solutions, Loctax optimized its security posture, including getting rid of false positives. This has saved precious time each month and achieved remarkable cost efficiencies.
How StoryChief’s CTO uses Aikido Security to sleep better at night
Losing sleep over startup security concerns? Discover how Aikido Security improved StoryChief's security posture, providing peace of mind and better sleep for the CTO.
What is a CVE?
CVEs are the security world's shared language for known vulnerabilities, but in 2026, the system is under serious strain. This guide covers how CVEs work, how they're scored with CVSS, and why the databases teams rely on are no longer complete. It also covers what to do about it, including how Aikido Intel surfaces vulnerabilities that never make it into any public database.
One year of Opengrep: What we built and what’s next
A year after forking Semgrep, Opengrep is faster, supports deeper taint analysis, and produces consistent, reproducible results.
10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account — a vulnerability that's been sitting in the codebase since 2014.
Top 12 Dynamic Application Security Testing (DAST) Tools in 2026
Discover the 12 top best Dynamic Application Security Testing (DAST) tools in 2026. Compare features, pros, cons, and integrations to choose the right DAST solution for your DevSecOps pipeline.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.


.jpg)
