Blog

Learn about software supply chain security and Endor Labs

What Is Mythos and Why It Matters for Software Security

What Is Mythos and Why It Matters for Software Security

Learn what Mythos is, how it found zero-day bugs, and why Mythos could reshape software security and vulnerability prioritization

Secure AI Workflows: From Development to Deployment

Secure AI Workflows: From Development to Deployment

Learn how secure AI workflows protect code, dependencies, and deployments with inline controls, policy enforcement, and reachability

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

Learn how to reduce ai risks with practical mitigation strategies for AI code, prompt injection, compliance, and scalable governance

How to Secure AI Models in Production Environments

How to Secure AI Models in Production Environments

Learn how to secure ai models in production with controls for prompt injection, model theft, malicious files, and inference attacks

AI Model Security Strategies for CISOs and Security Leaders

AI Model Security Strategies for CISOs and Security Leaders

Learn ai model security best practices for CISOs, from threat models and frameworks to governance and monitoring that reduce AI risk

AI Model Risk Assessment: Framework and Best Practices

AI Model Risk Assessment: Framework and Best Practices

Learn ai model risk assessment with a practical framework, key risk categories, and best practices for compliance and security

Vulnerability Blast Radius: How to Measure and Reduce Impact

Vulnerability Blast Radius: How to Measure and Reduce Impact

Learn how to assess vulnerability blast radius, understand BlastRADIUS, and reduce risk with reachability, segmentation, and fixes

Understanding Software Distribution Security: Key Concepts Explained

Understanding Software Distribution Security: Key Concepts Explained

Learn software distribution security basics, risks, and best practices to secure dependencies, containers, pipelines, and deployments

What Is Package Integrity? Definition and Best Practices

What Is Package Integrity? Definition and Best Practices

Learn what package integrity means in software, the top supply chain threats, and best practices to verify dependencies in CI/CD

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

OpenAI's newest model now holds the top security score on the Agent Security League through Cursor as the agent harness. Through Codex, it ties for third on security but trails on functional correctness.

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

How attackers compromised Bitwarden's CLI and enlisted the help of AI coding agents to spread a worm and harvest developer secrets.

The agent control plane needs a security layer

The agent control plane needs a security layer

Security has to be embedded across the agent harness, orchestrator, and control plane if your organization wants to run software agents at scale.

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

C++ security vulnerabilities like buffer overflows, use-after-free, and integer overflow cause 70% of critical exploits. Learn how to detect and prevent them.

Developer Security Tools Compared: A Practical Guide for 2026

Developer Security Tools Compared: A Practical Guide for 2026

Developer security tools compared by reachability analysis, false positive rates, and workflow fit. This guide covers how 7 leading platforms perform in 2026.

Best SCA Solutions for 2026: Reachability-Driven Analysis

Best SCA Solutions for 2026: Reachability-Driven Analysis

SCA tools with reachability analysis cut false positives by up to 95%. Compare 7 platforms tested for dependency coverage, noise reduction, and remediation.

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

SCA security tools identify open source vulnerabilities in your codebase. Compare 8 top platforms ranked by signal-to-noise, reachability, and fix quality.

6 Best DAST Tools for DevSecOps Teams in 2026

6 Best DAST Tools for DevSecOps Teams in 2026

Best DAST tools for DevSecOps in 2026, with 6 top scanners compared on API coverage, false positive reduction, CI/CD integration, and remediation guidance.

Malicious Package Detection: Beyond CVEs and Scanners

Malicious Package Detection: Beyond CVEs and Scanners

Malicious package detection requires more than CVE scanning. Learn behavioral analysis and practical strategies to catch supply chain threats scanners miss.

Dependency Management Tools Every Engineering Team Needs

Dependency Management Tools Every Engineering Team Needs

Dependency management tools automate tracking, securing, and updating third-party packages. Learn what your engineering team needs from scanners to lock files.

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application security testing is the practice of finding and fixing software vulnerabilities before production. Learn about SAST, DAST, IAST, SCA, and RASP.

Organizational Behavior Predicts OSS Malware Program Success

Organizational Behavior Predicts OSS Malware Program Success

Your org structure and dependency hygiene predict malware outcomes more than your tooling does. Here's what the data shows.

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Anthropic's newest model reaches the highest functional and security scores we've ever measured. But roughly four out of five solutions still ship with vulnerabilities.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.