Blog

Learn about software supply chain security and Endor Labs

Software Supply Chain Security: Why SCA Alone Falls Short

Software Supply Chain Security: Why SCA Alone Falls Short

Software supply chain security protects your entire development lifecycle against compromises in third-party libraries, build tools, and CI/CD pipelines.

CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm

CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm

Best Checkmarx Alternatives & Competitors in 2026

Best Checkmarx Alternatives & Competitors in 2026

Checkmarx alternatives compared by false positive reduction, developer experience, and pricing. See how Endor Labs, Snyk, Veracode, and 4 more rank.

Top 8 Snyk Alternatives for Security & Engineering Teams

Top 8 Snyk Alternatives for Security & Engineering Teams

Alternatives to Snyk compared for 2026. See how Endor Labs, Checkmarx, Veracode, and others reduce false positives and fit complex engineering workflows.

Endor Labs vs Snyk: SCA, SAST, and Containers Compared

Endor Labs vs Snyk: SCA, SAST, and Containers Compared

Endor Labs vs Snyk: Endor Labs cuts alert noise by up to 95% with reachability analysis across 40+ languages. Snyk offers broader coverage and a free tier.

Best DevSecOps Platform Tools for AppSec Teams in 2026

Best DevSecOps Platform Tools for AppSec Teams in 2026

DevSecOps platform comparison: 7 tools rated on reachability analysis, full-stack scanning coverage, and evidence-based remediation for AppSec teams in 2026.

10 Best Application Security Tools for 2026

10 Best Application Security Tools for 2026

Best appsec tools for 2026 ranked by scan accuracy, false positive rates, and developer experience. 10 platforms compared across SAST, SCA, DAST, and more.

Top 10 Veracode Alternatives for AppSec Teams in 2026

Top 10 Veracode Alternatives for AppSec Teams in 2026

Veracode alternatives compared: 10 AppSec tools ranked by scan speed, accuracy, and pricing. See how Endor Labs, Snyk, Checkmarx, and Semgrep stack up.

Top 10 Semgrep Alternatives for AppSec Teams in 2026

Top 10 Semgrep Alternatives for AppSec Teams in 2026

Semgrep alternatives for AppSec teams compared: Endor Labs, SonarQube, Snyk, Checkmarx, and 6 more tools ranked by accuracy, coverage, and noise reduction.

Best Black Duck Alternatives for SCA With Less Noise

Best Black Duck Alternatives for SCA With Less Noise

Black Duck alternatives for SCA with less noise. Compare Endor Labs, Snyk, Checkmarx, Veracode, Mend, Semgrep, and FOSSA on reachability and scan speed.

7 Best Application Security Tools for the AI Era (2026)

7 Best Application Security Tools for the AI Era (2026)

Application security tools compared for 2026. Eight platforms evaluated on reachability analysis, false positive rates, AI-code scanning, and pricing.

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution

The malicious Python package pyronut copies the entire project description and code of the popular pyrogram Telegram framework to pass itself off as the real thing, while silently installing a runtime backdoor that grants the attacker arbitrary Python and shell command execution on every victim's machine.

npm is serving malware to 134,000 developers, and the maintainer can’t stop it

npm is serving malware to 134,000 developers, and the maintainer can’t stop it

The Glassworm threat attacker took over the npm account of a maintainer

Endor Labs + Zscaler: Zero Trust Application Security for the AI Era

Endor Labs + Zscaler: Zero Trust Application Security for the AI Era

Endor Labs has partnered with Zscaler to bring Zero Trust to the AI-native software supply chain

How the EU Cyber Resilience Act (CRA) rewrites the rules of software liability

How the EU Cyber Resilience Act (CRA) rewrites the rules of software liability

The EU Cyber Resilience Act shifts software liability to vendors, requiring continuous vulnerability management and security updates across the product lifecycle.

The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks

The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks

We detected 88 malicious open source packages on npm

Intelligence and governance in the software supply chain with Endor Labs and Cloudsmith

Intelligence and governance in the software supply chain with Endor Labs and Cloudsmith

Endor Labs and Cloudsmith combine deep vulnerability intelligence with artifact governance to secure the modern software and AI supply chain.

Introducing AURI: Security Intelligence for AI Coding Agents and Developers

Introducing AURI: Security Intelligence for AI Coding Agents and Developers

AURI shifts security into the architecture of agentic coding with free tools for developers and agents to detect vulnerabilities, block malware, and fix security bugs.

Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks Havoc

Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks Havoc

We discovered a serious RCE in Ghost CMS

CVE-2026-27959: Userinfo Host Header Injection in Koa

CVE-2026-27959: Userinfo Host Header Injection in Koa

Endor Labs researcher found CVE-2026-27959 in Koa

Anthropic just validated that AppSec is the biggest opportunity in cybersecurity

Anthropic just validated that AppSec is the biggest opportunity in cybersecurity

Anthropic’s announcement of Claude Code Security validates that application security is the critical frontier in agentic software development and cybersecurity.

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser

CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser

Critical vulnerability in fast-xml-parser allows injection attacks

AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass

AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass

How Endor Labs' AI SAST engine identified a path traversal vulnerability in OpenClaw's apply_patch tool tracked as (GHSA-r5fq-947m-xm57)

Supply Chain Attack targeting Cline installs OpenClaw

Supply Chain Attack targeting Cline installs OpenClaw

A compromised release of the popular Cline CLI npm package silently installs OpenClaw globally on any machine.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.