Blog

Learn about software supply chain security and Endor Labs

AI-Generated Malware Risk: A Practical Guide for Developers

AI-Generated Malware Risk: A Practical Guide for Developers

Understand ai-generated malware risk and learn how developers can detect malicious packages, stop supply chain attacks, and harden workflows

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform Engineering

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform Engineering

Endor Labs named a Representative Vendor for Software Supply Chain Security.

Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware

Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware

Malicious PyPI package durabletask 1.4.1-1.4.3 steals AWS, Azure, and GCP credentials on import. 417k monthly downloads affected.

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security

Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack

Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack

Mini Shai-Hulud Returns: 42 Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack

Designing Agent Governance: A New Surface for AI Risk

Designing Agent Governance: A New Surface for AI Risk

Designing Agent Governance: A New Surface for AI Risk

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms

From Code to Cloud: Endor Labs Joins the Wiz Integration Network

From Code to Cloud: Endor Labs Joins the Wiz Integration Network

Endor Labs joins the Wiz Integration Network (WIN), bringing reachability-backed SCA and AI SAST to Wiz for unified code-to-cloud risk context.

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

A technical explainer of the attack chain behind the May 11, 2026 TanStack compromise

Introducing Agent Governance: Using Hooks to Bring Visibility to AI Coding Agents

Introducing Agent Governance: Using Hooks to Bring Visibility to AI Coding Agents

Learn how hooks turn AI coding agents like Claude Code and Cursor into governed systems with deterministic policy, centralized audit, and defense in depth.

Introducing Package Firewall

Introducing Package Firewall

Introducing Package Firewall

Introducing Security for AI Coding Agents and Workstations

Introducing Security for AI Coding Agents and Workstations

AURI secures the code AI agents write. Now, in collaboration with Cursor and Google, it secures the agents themselves.

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Shai-Hulud compromises the @tanstack ecosystem: 80+ packages compromised

What Is Mythos and Why It Matters for Software Security

What Is Mythos and Why It Matters for Software Security

Learn what Mythos is, how it found zero-day bugs, and why Mythos could reshape software security and vulnerability prioritization

Secure AI Workflows: From Development to Deployment

Secure AI Workflows: From Development to Deployment

Learn how secure AI workflows protect code, dependencies, and deployments with inline controls, policy enforcement, and reachability

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

Learn how to reduce ai risks with practical mitigation strategies for AI code, prompt injection, compliance, and scalable governance

How to Secure AI Models in Production Environments

How to Secure AI Models in Production Environments

Learn how to secure ai models in production with controls for prompt injection, model theft, malicious files, and inference attacks

AI Model Security Strategies for CISOs and Security Leaders

AI Model Security Strategies for CISOs and Security Leaders

Learn ai model security best practices for CISOs, from threat models and frameworks to governance and monitoring that reduce AI risk

AI Model Risk Assessment: Framework and Best Practices

AI Model Risk Assessment: Framework and Best Practices

Learn ai model risk assessment with a practical framework, key risk categories, and best practices for compliance and security

Vulnerability Blast Radius: How to Measure and Reduce Impact

Vulnerability Blast Radius: How to Measure and Reduce Impact

Learn how to assess vulnerability blast radius, understand BlastRADIUS, and reduce risk with reachability, segmentation, and fixes

Understanding Software Distribution Security: Key Concepts Explained

Understanding Software Distribution Security: Key Concepts Explained

Learn software distribution security basics, risks, and best practices to secure dependencies, containers, pipelines, and deployments

What Is Package Integrity? Definition and Best Practices

What Is Package Integrity? Definition and Best Practices

Learn what package integrity means in software, the top supply chain threats, and best practices to verify dependencies in CI/CD

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

OpenAI's newest model now holds the top security score on the Agent Security League through Cursor as the agent harness. Through Codex, it ties for third on security but trails on functional correctness.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.