Blog

Learn about software supply chain security and Endor Labs

The Bitwarden CLI Supply Chain Attack: What Happened and What to Do

The Bitwarden CLI Supply Chain Attack: What Happened and What to Do

How attackers compromised Bitwarden's CLI and enlisted the help of AI coding agents to spread a worm and harvest developer secrets.

The agent control plane needs a security layer

The agent control plane needs a security layer

Security has to be embedded across the agent harness, orchestrator, and control plane if your organization wants to run software agents at scale.

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

C++ security vulnerabilities like buffer overflows, use-after-free, and integer overflow cause 70% of critical exploits. Learn how to detect and prevent them.

Developer Security Tools Compared: A Practical Guide for 2026

Developer Security Tools Compared: A Practical Guide for 2026

Developer security tools compared by reachability analysis, false positive rates, and workflow fit. This guide covers how 7 leading platforms perform in 2026.

Best SCA Solutions for 2026: Reachability-Driven Analysis

Best SCA Solutions for 2026: Reachability-Driven Analysis

SCA tools with reachability analysis cut false positives by up to 95%. Compare 7 platforms tested for dependency coverage, noise reduction, and remediation.

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

SCA security tools identify open source vulnerabilities in your codebase. Compare 8 top platforms ranked by signal-to-noise, reachability, and fix quality.

6 Best DAST Tools for DevSecOps Teams in 2026

6 Best DAST Tools for DevSecOps Teams in 2026

Best DAST tools for DevSecOps in 2026, with 6 top scanners compared on API coverage, false positive reduction, CI/CD integration, and remediation guidance.

Malicious Package Detection: Beyond CVEs and Scanners

Malicious Package Detection: Beyond CVEs and Scanners

Malicious package detection requires more than CVE scanning. Learn behavioral analysis and practical strategies to catch supply chain threats scanners miss.

Dependency Management Tools Every Engineering Team Needs

Dependency Management Tools Every Engineering Team Needs

Dependency management tools automate tracking, securing, and updating third-party packages. Learn what your engineering team needs from scanners to lock files.

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application security testing is the practice of finding and fixing software vulnerabilities before production. Learn about SAST, DAST, IAST, SCA, and RASP.

Organizational Behavior Predicts OSS Malware Program Success

Organizational Behavior Predicts OSS Malware Program Success

Your org structure and dependency hygiene predict malware outcomes more than your tooling does. Here's what the data shows.

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Anthropic's newest model reaches the highest functional and security scores we've ever measured. But roughly four out of five solutions still ship with vulnerabilities.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

Is AI Coding Safe? Introducing the Agent Security League

Is AI Coding Safe? Introducing the Agent Security League

AI coding agents can write working code, but mostly not secure code. Explore benchmark results showing over 80% of AI-generated code contains vulnerabilities.

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain

Blockchain-based C2 lets attackers run malware infrastructure that can’t be taken down. Learn how it works, why it’s spreading, and what defenders can still do.

Top 10 SAST Tools in 2026: Accuracy, Speed, and Noise

Top 10 SAST Tools in 2026: Accuracy, Speed, and Noise

SAST tools scan source code for security vulnerabilities without running the application. Compare the top 10 tools by accuracy, speed, and noise reduction.

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)

WebSocket pre-auth RCE, confirmed exploited in the wild within 10 hours of disclosure. Tens to hundreds of instances may remain exposed. Upgrade to 0.23.0.

What Security and Engineering Teams Fear Most About Malware

What Security and Engineering Teams Fear Most About Malware

What do security practitioners and software engineers actually fear about open source malware? We asked 605 professionals. Here is what 141 of them said, in their own words.

Top Gen AI AppSec Tools in 2026: A Practitioner's Guide

Top Gen AI AppSec Tools in 2026: A Practitioner's Guide

Gen AI AppSec tools compared for 2026. Seven platforms evaluated on noise reduction, reachability analysis, AI-specific threat detection, and developer fit.

Best DevSecOps Tools for AppSec Teams in 2026

Best DevSecOps Tools for AppSec Teams in 2026

Best DevSecOps tools for 2026: seven platforms compared on false positive rates, reachability analysis, and actionable remediation guidance for AppSec teams.

Best Application Security Testing (AST) Tools Compared

Best Application Security Testing (AST) Tools Compared

Best AST tools compared on false positive rates, reachability depth, and workflow integration. See how 7 platforms reduce real security risk for dev teams.

10 Best DevSecOps Platforms for AppSec Teams in 2026

10 Best DevSecOps Platforms for AppSec Teams in 2026

DevSecOps platforms compared: 10 tools tested with real codebases for alert noise reduction, reachability analysis, and CI/CD integration for AppSec teams.

Best Application Security Tools for DevSecOps in 2026

Best Application Security Tools for DevSecOps in 2026

AppSec tools for 2026 ranked by noise reduction, false positive rates, and workflow integration. 10 platforms compared across SAST, SCA, DAST, and ASPM.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.