News

Aikido Security
aikido. dev > blog > opengrep-sast-one-year

Opengrep SAST After One Year: Faster, Deterministic Static Analysis

5+ day, 21+ hour ago  (752+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats It's been a year since a group of security vendors: Aikido Security, Arnica, Amplify, Endor Labs, Jit, Kodem, Legit,…...

Symbols: btc-usd,eth-usd
Aikido Security
aikido. dev > blog > shadow-ai-is-a-fear-response-and-banning-it-makes-it-worse

Why shadow AI risks start with fear (and banning makes them worse)

5+ day, 20+ hour ago  (418+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats This post is based on Mackenzie's conversation with Noora Ahmed-Moshe on The Secure Disclosure podcast. Listen to the full…...

Symbols: saaq.pvt,btc-usd,anth.pvt
Google News
aikido. dev > blog > checklist-github-actions

Security Checklist for Git Hub Actions

6+ day, 22+ hour ago  (1695+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Git Hub Actions has been exploited a lot in a lot of supply chain attacks lately, and workflow misconfigurations…...

Symbols: btc-usd,eth-usd,cwe-77
Aikido Security
aikido. dev > blog > coinbase-vibe-coding-mess

Coinbase's layoffs signal a dangerous move into a vibe-coding security mess

1+ week, 3+ day ago  (833+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Among the laundry list of problems with the tweet (including the tweet being written by AI itself), one of…...

Symbols: nasdaq:coin,btc-usd
Aikido Security
aikido. dev > blog > rolling-out-developer-security-in-a-5-000-engineer-organization

Developer Security at Scale: A CISO's Rollout Guide

1+ week, 5+ day ago  (1074+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Large engineering organizations like to believe their biggest problems are technical. If only someone would approve the budget for…...

Symbols: btc-usd
Aikido Security
aikido. dev > blog > mythos-ready-checklist

Mythos-Ready Checklist

2+ week, 4+ day ago  (557+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats For the teams that want to prepare for Mythos, this is for you. In this new Mythos-Ready checklist, each…...

Symbols: btc-usd
Aikido Security
aikido. dev > blog > mini-shai-hulud-has-appeared

Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer

2+ week, 5+ day ago  (872+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats A new npm supply-chain compromise is targeting the SAP developer ecosystem. The affected packages we are tracking so far…...

Symbols: index.js
Aikido Security
aikido. dev > blog > shai-hulud-npm-bitwarden-cli-compromise

Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm

3+ week, 3+ day ago  (484+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats @bitwarden/cli@2026. 4. 0 introduced a malicious preinstall hook pointing to a new file bw_setup. js. This fires automatically on npm install…...

Symbols: index.js
Aikido Security
aikido. dev > blog > gpt-proxy-backdoor-npm-pypi-chinese-llm-relay

GPT-Proxy Backdoor in npm and Py PI turns Servers into Chinese LLM Relays

3+ week, 4+ day ago  (819+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Both packages ship a compiled native binary as their payload carrier. The two stage 1 files are: The npm dropper…...

Symbols: index.js
Aikido Security
aikido. dev > blog > glassworm-zig-dropper-infects-every-ide-on-your-machine

Glass Worm goes native: New Zig dropper infects every IDE on your machine

1+ mon, 1+ week ago  (313+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Once loaded, the binary's first job is to find every IDE installed on the machine that supports the VS…...

Symbols: ide