logo

Aikido Security's Blog

ID: 61c95bae-ad62-5694-99d1-ae7b12ee2a9a

STIX ID: identity--61c95bae-ad62-5694-99d1-ae7b12ee2a9a

Feed Type: rss

Earliest post: 2023-01-19

Latest post: 2026-08-06

Discover today's best security practices and the latest trends that your software company should be aware of. Stay ahead of the game and read Aikido's industry-leading blog today.

01/01/2020
08/11/2026
Title Date Published Describes IncidentAuthorVisible
Who was behind the attack? Possibly nobody2026-08-05TrueTrue
Keyv and friends compromised in active Shai-Hulud supply chain attack2026-08-04TrueTrue
Anthropic's Fever Dream: Claude's package that stole real keys2026-07-31TrueTrue
Four incident-response decisions from the Hugging Face breach2026-07-29TrueTrue
Top LLM security tools to protect AI applications2026-07-24TrueTrue
Finding eight high-severity vulnerabilities in NodeBB in six hours2026-07-22TrueTrue
SQL injection isn't dead2026-07-22TrueTrue
The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22TrueTrue
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts2026-07-19TrueTrue
Unauthenticated RCE in WordPress core (wp2shell), via SQL injection2026-07-17TrueTrue
Benchmarking 13 AI models on rediscovering known CVEs2026-07-16TrueTrue
The practical checklist for defending against supply chain attacks2026-07-14TrueTrue
AsyncAPI npm packages backdoored via GitHub Actions2026-07-14TrueTrue
How Aikido Intel detects malware and vulnerabilities first2026-07-13TrueTrue
What is a dependency firewall?2026-07-13TrueTrue
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry2026-07-09TrueTrue
Predicting MongoDB ObjectId continuously in Rocket.Chat2026-07-06TrueTrue
Authentication Bypass in the default configuration phpBB2026-07-03TrueTrue
And another one. GitHub ships break-glass credential revocation2026-07-01TrueTrue
npm now freezes high-impact accounts after risky account changes2026-06-26TrueTrue
Everybody's shipping code they can't read2026-06-25TrueTrue
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets2026-06-24TrueTrue
Over 140 popular Mastra npm Packages Hit by Supply Chain Attack2026-06-17TrueTrue
Multiple JetBrains IDE plugins caught stealing AI keys2026-06-16TrueTrue
npm v12 delivers one of the biggest security improvements in years2026-06-11TrueTrue
Code is being written everywhere, and the device is the only constant2026-06-10TrueTrue
Compromised Rust crate onering performs code exfiltration2026-06-10TrueTrue
10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums2026-06-10TrueTrue
Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System2026-06-09TrueTrue
Why EDR and proxy won’t save you from supply chain malware 2026-06-02TrueTrue
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm2026-06-01TrueTrue
What MDM can't protect on developer machines (and what to do about it)2026-05-28TrueTrue
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens2026-05-27TrueTrue
Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark2026-05-27TrueTrue
Why developer machines are now the number one target for supply chain attacks 2026-05-26TrueTrue
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer2026-05-23TrueTrue
Google API keys keep working after you delete them 2026-05-21TrueTrue
The Wild West of VS Code extensions and how a poisoned extension breached GitHub2026-05-20TrueTrue
GitHub breached via a malicious VS Code extension: why developer devices are the real target2026-05-20TrueTrue
Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!2026-05-19TrueTrue
Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages2026-05-19TrueTrue
Shadow AI is a fear response, and banning it makes it worse2026-05-12TrueTrue
Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack2026-05-11TrueTrue
The complete GitHub Actions security checklist 2026-05-11TrueTrue
Why browser extensions are a major security risk and what you can do about it2026-05-01TrueTrue
Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud2026-04-30TrueTrue
Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer2026-04-29TrueTrue
Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files2026-04-29TrueTrue
It's time to treat browser extensions like supply chain attack vectors2026-04-24TrueTrue
Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm2026-04-23TrueTrue

1–50 of 85