News

Aikido Security
aikido. dev > blog > supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer

1+ day, 19+ hour ago  (512+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats On May 22, 2026, we detected an active supply chain attack against Laravel-Lang. We filed a report with the maintainers immediately....

Symbols: setup.js
Aikido Security
aikido. dev > blog > google-api-keys-deletion

Google API keys keep working after you delete them long enough to be exploited

3+ day, 8+ hour ago  (1433+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats tl; dr When you delete a Google API key, it says it's immediately deleted. Our testing says ~23 minutes. During…...

Aikido Security
aikido. dev > blog > opengrep-sast-one-year

Opengrep SAST After One Year: Faster, Deterministic Static Analysis

1+ week, 5+ day ago  (752+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats It's been a year since a group of security vendors: Aikido Security, Arnica, Amplify, Endor Labs, Jit, Kodem, Legit,…...

Symbols: btc-usd,eth-usd
Aikido Security
aikido. dev > blog > shadow-ai-is-a-fear-response-and-banning-it-makes-it-worse

Why shadow AI risks start with fear (and banning makes them worse)

1+ week, 5+ day ago  (418+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats This post is based on Mackenzie's conversation with Noora Ahmed-Moshe on The Secure Disclosure podcast. Listen to the full…...

Symbols: saaq.pvt,btc-usd,anth.pvt
Google News
aikido. dev > blog > checklist-github-actions

Security Checklist for Git Hub Actions

1+ week, 6+ day ago  (1695+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Git Hub Actions has been exploited a lot in a lot of supply chain attacks lately, and workflow misconfigurations…...

Symbols: btc-usd,eth-usd,cwe-77
Aikido Security
aikido. dev > blog > coinbase-vibe-coding-mess

Coinbase's layoffs signal a dangerous move into a vibe-coding security mess

2+ week, 3+ day ago  (833+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Among the laundry list of problems with the tweet (including the tweet being written by AI itself), one of…...

Symbols: nasdaq:coin,btc-usd
Aikido Security
aikido. dev > blog > rolling-out-developer-security-in-a-5-000-engineer-organization

Developer Security at Scale: A CISO's Rollout Guide

2+ week, 4+ day ago  (1074+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Large engineering organizations like to believe their biggest problems are technical. If only someone would approve the budget for…...

Symbols: btc-usd
Aikido Security
aikido. dev > blog > mythos-ready-checklist

Mythos-Ready Checklist

3+ week, 3+ day ago  (557+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats For the teams that want to prepare for Mythos, this is for you. In this new Mythos-Ready checklist, each…...

Symbols: btc-usd
Aikido Security
aikido. dev > blog > mini-shai-hulud-has-appeared

Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer

3+ week, 4+ day ago  (872+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats A new npm supply-chain compromise is targeting the SAP developer ecosystem. The affected packages we are tracking so far…...

Symbols: index.js
Aikido Security
aikido. dev > blog > shai-hulud-npm-bitwarden-cli-compromise

Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm

1+ mon, 1+ day ago  (484+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats @bitwarden/cli@2026. 4. 0 introduced a malicious preinstall hook pointing to a new file bw_setup. js. This fires automatically on npm install…...

Symbols: index.js