Blog

Learn about software supply chain security and Endor Labs

Top 10 Semgrep Alternatives for AppSec Teams in 2026

Top 10 Semgrep Alternatives for AppSec Teams in 2026

Semgrep alternatives for AppSec teams compared: Endor Labs, SonarQube, Snyk, Checkmarx, and 6 more tools ranked by accuracy, coverage, and noise reduction.

Best Black Duck Alternatives for SCA With Less Noise

Best Black Duck Alternatives for SCA With Less Noise

Black Duck alternatives for SCA with less noise. Compare Endor Labs, Snyk, Checkmarx, Veracode, Mend, Semgrep, and FOSSA on reachability and scan speed.

7 Best Application Security Tools for the AI Era (2026)

7 Best Application Security Tools for the AI Era (2026)

Application security tools compared for 2026. Eight platforms evaluated on reachability analysis, false positive rates, AI-code scanning, and pricing.

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution

The malicious Python package pyronut copies the entire project description and code of the popular pyrogram Telegram framework to pass itself off as the real thing, while silently installing a runtime backdoor that grants the attacker arbitrary Python and shell command execution on every victim's machine.

npm is serving malware to 134,000 developers, and the maintainer can’t stop it

npm is serving malware to 134,000 developers, and the maintainer can’t stop it

The Glassworm threat attacker took over the npm account of a maintainer

Endor Labs + Zscaler: Zero Trust Application Security for the AI Era

Endor Labs + Zscaler: Zero Trust Application Security for the AI Era

Endor Labs has partnered with Zscaler to bring Zero Trust to the AI-native software supply chain

How the EU Cyber Resilience Act (CRA) rewrites the rules of software liability

How the EU Cyber Resilience Act (CRA) rewrites the rules of software liability

The EU Cyber Resilience Act shifts software liability to vendors, requiring continuous vulnerability management and security updates across the product lifecycle.

The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks

The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks

We detected 88 malicious open source packages on npm

Intelligence and governance in the software supply chain with Endor Labs and Cloudsmith

Intelligence and governance in the software supply chain with Endor Labs and Cloudsmith

Endor Labs and Cloudsmith combine deep vulnerability intelligence with artifact governance to secure the modern software and AI supply chain.

Introducing AURI: Security Intelligence for AI Coding Agents and Developers

Introducing AURI: Security Intelligence for AI Coding Agents and Developers

AURI shifts security into the architecture of agentic coding with free tools for developers and agents to detect vulnerabilities, block malware, and fix security bugs.

Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks Havoc

Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks Havoc

We discovered a serious RCE in Ghost CMS

CVE-2026-27959: Userinfo Host Header Injection in Koa

CVE-2026-27959: Userinfo Host Header Injection in Koa

Endor Labs researcher found CVE-2026-27959 in Koa

Anthropic just validated that AppSec is the biggest opportunity in cybersecurity

Anthropic just validated that AppSec is the biggest opportunity in cybersecurity

Anthropic’s announcement of Claude Code Security validates that application security is the critical frontier in agentic software development and cybersecurity.

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack

CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser

CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser

Critical vulnerability in fast-xml-parser allows injection attacks

AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass

AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass

How Endor Labs' AI SAST engine identified a path traversal vulnerability in OpenClaw's apply_patch tool tracked as (GHSA-r5fq-947m-xm57)

Supply Chain Attack targeting Cline installs OpenClaw

Supply Chain Attack targeting Cline installs OpenClaw

A compromised release of the popular Cline CLI npm package silently installs OpenClaw globally on any machine.

How AI SAST Traced Data Flows to Uncover Six OpenClaw Vulnerabilities

How AI SAST Traced Data Flows to Uncover Six OpenClaw Vulnerabilities

We discovered six vulnerabilities in OpenClaw using Endor Labs’ AI SAST data flow analysis and validated working exploits.

The Missing Layer: Why Container OS Libraries Need Reachability Analysis

The Missing Layer: Why Container OS Libraries Need Reachability Analysis

As CVEs surge and AI speeds delivery, container OS reachability is key to reducing noise and real AppSec risk.

Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise

Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise

Cut container vulnerability noise by up to 90% with full-stack reachability analysis spanning application and container image OS layers.

AI SAST in Action: Finding Real Vulnerabilities in OpenClaw

AI SAST in Action: Finding Real Vulnerabilities in OpenClaw

How Endor Labs AI SAST identified 7 exploitable vulnerabilities in OpenClaw through accurate data flow analysis and systematic exploit validation.

Design Flaws in AI Generated Code

Design Flaws in AI Generated Code

AI coding assistants are introducing systemic architectural weaknesses that have major consequences for application security.

The Architectural Shift Behind the AI SDLC

The Architectural Shift Behind the AI SDLC

AI is reshaping software development. Learn how security can become invisible guardrails inside the AI SDLC, so teams move faster without compromising safety.

Test-First Prompting: Using TDD for Secure AI-Generated Code

Test-First Prompting: Using TDD for Secure AI-Generated Code

Use a “test-first” prompting pattern to improve AI-generated code security through test-driven development (TDD).

CVE-2026-25049 Expression Escape Vulnerability Leading to RCE in n8n

CVE-2026-25049 Expression Escape Vulnerability Leading to RCE in n8n

CVE in n8n allows unauthenticated users to achieve remote code execution (RCE) via sandbox escape.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.