Blog

Learn about software supply chain security and Endor Labs

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

Beyond MCP: The New Security Playbook for Coding Agents

Beyond MCP: The New Security Playbook for Coding Agents

Beyond MCP: The New Security Playbook for Coding Agents

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

Everyone Wins Their Own Benchmark

Everyone Wins Their Own Benchmark

Everyone Wins Their Own Benchmark

Securing Open Source Dependencies: A Developer's Guide

Securing Open Source Dependencies: A Developer's Guide

Securing Open Source Dependencies: A Developer's Guide

Dependency Confusion: How Attackers Poison Your Build

Dependency Confusion: How Attackers Poison Your Build

Dependency Confusion: How Attackers Poison Your Build

AI-Generated Malware and the Software Supply Chain

AI-Generated Malware and the Software Supply Chain

AI-Generated Malware and the Software Supply Chain

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Veiled in Trust: Software Supply Chain Attacks Explained

Veiled in Trust: Software Supply Chain Attacks Explained

Veiled in Trust: Software Supply Chain Attacks Explained

What Is Malicious Code? Types, Examples & How to Protect Yourself

What Is Malicious Code? Types, Examples & How to Protect Yourself

What Is Malicious Code? Types, Examples & How to Protect Yourself

Best SBOM Tools in 2026, Compared

Best SBOM Tools in 2026, Compared

Best SBOM Tools in 2026, Compared

What Is a Software Bill of Materials? A Practical Guide

What Is a Software Bill of Materials? A Practical Guide

What Is a Software Bill of Materials? A Practical Guide

What Is Software Supply Chain Security? The Complete Guide

What Is Software Supply Chain Security? The Complete Guide

What Is Software Supply Chain Security? The Complete Guide

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Cyber insurers are pricing based on patching speed

Cyber insurers are pricing based on patching speed

Cyber insurers are pricing based on patching speed

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest

Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library

Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library

Endor Labs’ AI SAST Finds CVE-2026-55407: Memory-Amplification DoS in buffa

Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier models

Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier models

AI SAST found 192 real vulnerabilities, 2.6x more than Claude Code

Shai-Hulud Strikes Leo Platform npm

Shai-Hulud Strikes Leo Platform npm

Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.

Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.