Blog

Learn about software supply chain security and Endor Labs

From Code to Cloud: Endor Labs Joins the Wiz Integration Network

From Code to Cloud: Endor Labs Joins the Wiz Integration Network

Endor Labs joins the Wiz Integration Network (WIN), bringing reachability-backed SCA and AI SAST to Wiz for unified code-to-cloud risk context.

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

A technical explainer of the attack chain behind the May 11, 2026 TanStack compromise

Introducing AI Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC

Introducing AI Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC

Learn how hooks turn AI coding agents like Claude Code and Cursor into governed systems with deterministic policy, centralized audit, and defense in depth.

Introducing Package Firewall

Introducing Package Firewall

Introducing Package Firewall

Introducing Security for AI Coding Agents and Workstations

Introducing Security for AI Coding Agents and Workstations

AURI secures the code AI agents write. Now, in collaboration with Cursor and Google, it secures the agents themselves.

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Shai-Hulud compromises the @tanstack ecosystem: 80+ packages compromised

What Is Mythos and Why It Matters for Software Security

What Is Mythos and Why It Matters for Software Security

Learn what Mythos is, how it found zero-day bugs, and why Mythos could reshape software security and vulnerability prioritization

Secure AI Workflows: From Development to Deployment

Secure AI Workflows: From Development to Deployment

Learn how secure AI workflows protect code, dependencies, and deployments with inline controls, policy enforcement, and reachability

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026

Learn how to reduce ai risks with practical mitigation strategies for AI code, prompt injection, compliance, and scalable governance

How to Secure AI Models in Production Environments

How to Secure AI Models in Production Environments

Learn how to secure ai models in production with controls for prompt injection, model theft, malicious files, and inference attacks

AI Model Security Strategies for CISOs and Security Leaders

AI Model Security Strategies for CISOs and Security Leaders

Learn ai model security best practices for CISOs, from threat models and frameworks to governance and monitoring that reduce AI risk

AI Model Risk Assessment: Framework and Best Practices

AI Model Risk Assessment: Framework and Best Practices

Learn ai model risk assessment with a practical framework, key risk categories, and best practices for compliance and security

Vulnerability Blast Radius: How to Measure and Reduce Impact

Vulnerability Blast Radius: How to Measure and Reduce Impact

Learn how to assess vulnerability blast radius, understand BlastRADIUS, and reduce risk with reachability, segmentation, and fixes

Understanding Software Distribution Security: Key Concepts Explained

Understanding Software Distribution Security: Key Concepts Explained

Learn software distribution security basics, risks, and best practices to secure dependencies, containers, pipelines, and deployments

What Is Package Integrity? Definition and Best Practices

What Is Package Integrity? Definition and Best Practices

Learn what package integrity means in software, the top supply chain threats, and best practices to verify dependencies in CI/CD

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

LLM Development Risks: Security Threats and Mitigation Strategies

LLM Development Risks: Security Threats and Mitigation Strategies

Learn the top llm development risks, from prompt injection to data leakage, plus practical mitigation strategies for secure AI apps

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

OpenAI's newest model now holds the top security score on the Agent Security League through Cursor as the agent harness. Through Codex, it ties for third on security but trails on functional correctness.

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

How attackers compromised Bitwarden's CLI and enlisted the help of AI coding agents to spread a worm and harvest developer secrets.

The agent control plane needs a security layer

The agent control plane needs a security layer

Security has to be embedded across the agent harness, orchestrator, and control plane if your organization wants to run software agents at scale.

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

Common C/C++ Vulnerabilities: A Practical Guide to Prevention

C++ security vulnerabilities like buffer overflows, use-after-free, and integer overflow cause 70% of critical exploits. Learn how to detect and prevent them.

Developer Security Tools Compared: A Practical Guide for 2026

Developer Security Tools Compared: A Practical Guide for 2026

Developer security tools compared by reachability analysis, false positive rates, and workflow fit. This guide covers how 7 leading platforms perform in 2026.

Best SCA Solutions for 2026: Reachability-Driven Analysis

Best SCA Solutions for 2026: Reachability-Driven Analysis

SCA tools with reachability analysis cut false positives by up to 95%. Compare 7 platforms tested for dependency coverage, noise reduction, and remediation.

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise

SCA security tools identify open source vulnerabilities in your codebase. Compare 8 top platforms ranked by signal-to-noise, reachability, and fix quality.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.