logo

Aikido Security's Blog

ID: 61c95bae-ad62-5694-99d1-ae7b12ee2a9a

STIX ID: identity--61c95bae-ad62-5694-99d1-ae7b12ee2a9a

Feed Type: rss

Earliest post: 2023-01-19

Latest post: 2026-07-23

Discover today's best security practices and the latest trends that your software company should be aware of. Stay ahead of the game and read Aikido's industry-leading blog today.

01/01/2020
07/24/2026
Title Date Published Describes IncidentAuthorVisible
Finding eight high-severity vulnerabilities in NodeBB in six hours2026-07-22TrueTrue
SQL injection isn't dead2026-07-22TrueTrue
The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22TrueTrue
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts2026-07-19TrueTrue
Unauthenticated RCE in WordPress core (wp2shell), via SQL injection2026-07-17TrueTrue
Benchmarking 13 AI models on rediscovering known CVEs2026-07-16TrueTrue
The practical checklist for defending against supply chain attacks2026-07-14TrueTrue
AsyncAPI npm packages backdoored via GitHub Actions2026-07-14TrueTrue
How Aikido Intel detects malware and vulnerabilities first2026-07-13TrueTrue
What is a dependency firewall?2026-07-13TrueTrue
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry2026-07-09TrueTrue
Predicting MongoDB ObjectId continuously in Rocket.Chat2026-07-06TrueTrue
Authentication Bypass in the default configuration phpBB2026-07-03TrueTrue
And another one. GitHub ships break-glass credential revocation2026-07-01TrueTrue
npm now freezes high-impact accounts after risky account changes2026-06-26TrueTrue
Everybody's shipping code they can't read2026-06-25TrueTrue
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets2026-06-24TrueTrue
Over 140 popular Mastra npm Packages Hit by Supply Chain Attack2026-06-17TrueTrue
Multiple JetBrains IDE plugins caught stealing AI keys2026-06-16TrueTrue
npm v12 delivers one of the biggest security improvements in years2026-06-11TrueTrue
Code is being written everywhere, and the device is the only constant2026-06-10TrueTrue
Compromised Rust crate onering performs code exfiltration2026-06-10TrueTrue
10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums2026-06-10TrueTrue
Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System2026-06-09TrueTrue
Why EDR and proxy won’t save you from supply chain malware 2026-06-02TrueTrue
Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark2026-05-27TrueTrue
Why developer machines are now the number one target for supply chain attacks 2026-05-26TrueTrue
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer2026-05-23TrueTrue
Google API keys keep working after you delete them 2026-05-21TrueTrue
The complete GitHub Actions security checklist 2026-05-11TrueTrue
Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer2026-04-29TrueTrue
GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays2026-04-22TrueTrue
Introducing Device Protection: Security for Developer Devices2026-04-20TrueTrue
Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow2026-04-17TrueTrue
Reliable CVE sources in the age of NIST NVD cutbacks2026-04-16TrueTrue
Axios CVE-2026-40175: a critical bug that’s… not exploitable2026-04-14TrueTrue
GlassWorm goes native: New Zig dropper infects every IDE on your machine2026-04-08TrueTrue
Aikido Attack finds multiple 0-days in Hoppscotch2026-04-08TrueTrue
axios compromised on npm: maintainer account hijacked, RAT deployed2026-03-30TrueTrue
CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran2026-03-22TrueTrue
TeamPCP deploys CanisterWorm on NPM following Trivy compromise2026-03-20TrueTrue
GlassWorm Hides a RAT Inside a Malicious Chrome Extension2026-03-18TrueTrue
fast-draft Open VSX Extension Compromised by BlokTrooper2026-03-18TrueTrue
Glassworm Strikes Popular React Native Phone Number Packages2026-03-16TrueTrue
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories2026-03-13TrueTrue
How Security Teams Fight Back Against AI-Powered Hackers2026-03-12TrueTrue
The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties2025-10-31TrueTrue
Bugs in Shai-Hulud: Debugging the Desert2025-09-18TrueTrue
We Got Lucky: The Supply Chain Disaster That Almost Happened2025-09-12TrueTrue
duckdb npm packages compromised2025-09-09TrueTrue

1–50 of 62