logo

Aikido Security's Blog

ID: 61c95bae-ad62-5694-99d1-ae7b12ee2a9a

STIX ID: identity--61c95bae-ad62-5694-99d1-ae7b12ee2a9a

Feed Type: rss

Earliest post: 2023-01-19

Latest post: 2026-09-04

Discover today's best security practices and the latest trends that your software company should be aware of. Stay ahead of the game and read Aikido's industry-leading blog today.

01/01/2020
09/08/2026
Title Date Published Describes IncidentAuthorVisible
Popular code generator for TanStack Query hit by supply chain worm2026-08-28TrueTrue
Good riddance, TeamPCP. Now for the hard part.2026-08-27TrueTrue
Software supply chain security requires decisions rather than defaults 2026-08-26TrueTrue
Could OpenClaw have actually hacked that Australian gym? We decided to test it.2026-08-25TrueTrue
How Aikido finds more vulnerabilities than Claude Security at half the cost2026-08-24TrueTrue
Shai-Hulud was the best thing to happen to supply chain security2026-08-24TrueTrue
What is CVE remediation in 2026?2026-08-21TrueTrue
We burned 11.7bn tokens to find the best cyber AI model2026-08-21TrueTrue
Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack2026-08-20TrueTrue
Top enterprise SCA tools in 20262026-08-14TrueTrue
From Hugging Face to Fable: this summer shows AI control matters more than trust2026-08-13TrueTrue
Who was behind the attack? Possibly nobody2026-08-05TrueTrue
Keyv and friends compromised in active Shai-Hulud supply chain attack2026-08-04TrueTrue
Anthropic's Fever Dream: Claude's package that stole real keys2026-07-31TrueTrue
Four incident-response decisions from the Hugging Face breach2026-07-29TrueTrue
Top LLM security tools to protect AI applications2026-07-24TrueTrue
Finding eight high-severity vulnerabilities in NodeBB in six hours2026-07-22TrueTrue
SQL injection isn't dead2026-07-22TrueTrue
The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22TrueTrue
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts2026-07-19TrueTrue
Unauthenticated RCE in WordPress core (wp2shell), via SQL injection2026-07-17TrueTrue
Benchmarking 13 AI models on rediscovering known CVEs2026-07-16TrueTrue
The practical checklist for defending against supply chain attacks2026-07-14TrueTrue
AsyncAPI npm packages backdoored via GitHub Actions2026-07-14TrueTrue
How Aikido Intel detects malware and vulnerabilities first2026-07-13TrueTrue
What is a dependency firewall?2026-07-13TrueTrue
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry2026-07-09TrueTrue
Predicting MongoDB ObjectId continuously in Rocket.Chat2026-07-06TrueTrue
Authentication Bypass in the default configuration phpBB2026-07-03TrueTrue
And another one. GitHub ships break-glass credential revocation2026-07-01TrueTrue
npm now freezes high-impact accounts after risky account changes2026-06-26TrueTrue
Everybody's shipping code they can't read2026-06-25TrueTrue
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets2026-06-24TrueTrue
Over 140 popular Mastra npm Packages Hit by Supply Chain Attack2026-06-17TrueTrue
Multiple JetBrains IDE plugins caught stealing AI keys2026-06-16TrueTrue
npm v12 delivers one of the biggest security improvements in years2026-06-11TrueTrue
Code is being written everywhere, and the device is the only constant2026-06-10TrueTrue
Compromised Rust crate onering performs code exfiltration2026-06-10TrueTrue
10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums2026-06-10TrueTrue
Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System2026-06-09TrueTrue
Why EDR and proxy won’t save you from supply chain malware 2026-06-02TrueTrue
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm2026-06-01TrueTrue
What MDM can't protect on developer machines (and what to do about it)2026-05-28TrueTrue
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens2026-05-27TrueTrue
Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark2026-05-27TrueTrue
Why developer machines are now the number one target for supply chain attacks 2026-05-26TrueTrue
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer2026-05-23TrueTrue
Google API keys keep working after you delete them 2026-05-21TrueTrue
The Wild West of VS Code extensions and how a poisoned extension breached GitHub2026-05-20TrueTrue
GitHub breached via a malicious VS Code extension: why developer devices are the real target2026-05-20TrueTrue

1–50 of 96