Blog

Learn about software supply chain security and Endor Labs

Static Analysis in the Age of AI, Part I: AI Coding Assistants

Static Analysis in the Age of AI, Part I: AI Coding Assistants

AI coding assistants are reducing simple security flaws, but SAST tools need better context and agent integration to catch what remains.

7 Snyk Alternatives for Engineering Teams in 2026

7 Snyk Alternatives for Engineering Teams in 2026

Evaluate Snyk alternatives that solve alert fatigue and false positives while driving remediation. Compare developer-friendly AppSec platforms, open source tools, and runtime solutions.

npm Account Takeovers are a Growing Malware Trend

npm Account Takeovers are a Growing Malware Trend

Learn why this malware attack vector is a big risk for open source software consumers.

CVE-2026-22709: Critical Sandbox Escape in vm2 Enables Arbitrary Code Execution

CVE-2026-22709: Critical Sandbox Escape in vm2 Enables Arbitrary Code Execution

Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec

Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec

MCP servers inherit classical vulnerabilities like command injection, path traversal, and SSRF. Here's why LLMs and MCP deserve the same security practices as traditional applications.

How Fake Font Packages Abused npm as a CDN

How Fake Font Packages Abused npm as a CDN

101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.

Your Next Breach Won’t Be a CVE: Connecting Real Incidents to AI-Aware Code Review

Your Next Breach Won’t Be a CVE: Connecting Real Incidents to AI-Aware Code Review

Most breaches aren’t CVEs. Learn how subtle code and config changes caused real incidents, and why AI-aware code review is now critical.

Eight for One: Multiple Vulnerabilities Fixed in the Node.js Runtime

Eight for One: Multiple Vulnerabilities Fixed in the Node.js Runtime

Multiple Vulnerabilities Fixed in the Node.js Runtime

n8mare on auth street: supply chain attack targets n8n ecosystem

n8mare on auth street: supply chain attack targets n8n ecosystem

Attackers weaponized n8n's community nodes to steal credentials

CVE-2025-12543: Host Header Validation Bypass in Undertow

CVE-2025-12543: Host Header Validation Bypass in Undertow

Critical Host Header Validation Bypass in the Undertow

CVE-2025-68428: Critical Path Traversal in jsPDF

CVE-2025-68428: Critical Path Traversal in jsPDF

Critical vulnerability requires upgrade to jsPDF 4.0.0

Bringing Malware Detection Into AI Coding Workflows with Cursor Hooks

Bringing Malware Detection Into AI Coding Workflows with Cursor Hooks

Endor Labs integrates with Cursor hooks to detect malicious packages before AI agents install dependencies, preventing supply chain attacks at the moment of risk.

When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin

When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin

CVE-2025-13780 is a critical vulnerability in pgAdmin 4 where whitespace characters bypass regex filters, a common failure mode in input validation.

When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo

When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo

Treating a security patch as a signal, not a conclusion, led us to discover how arbitrary file writes became remote code execution in Argo Workflows.

From Vision to Reality: How Endor Labs Delivers Developer-First Security

From Vision to Reality: How Endor Labs Delivers Developer-First Security

See how Endor Labs brings developer-friendly security to life with real demo clips. Watch how vulnerabilities are prevented, prioritized, and fixed—right inside IDEs, PRs, pipelines, and Jira.

Developer Experience: The Key to Successful Security

Developer Experience: The Key to Successful Security

AI coding tools promise speed, but hidden security burdens drain developer productivity. Learn how context-aware AppSec cuts noise, boosts velocity, and improves DX.

Critical Remote Code Execution (RCE) Vulnerabilities in React and Next.js

Critical Remote Code Execution (RCE) Vulnerabilities in React and Next.js

React and Next.js contain a critical RCE vulnerability

Understanding NPM Worms and the Shai-Hulud Attack

Understanding NPM Worms and the Shai-Hulud Attack

A breakdown of npm worms, how Shai-Hulud spread across the ecosystem, and the key security practices every team needs to prevent large-scale compromise.

Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime

Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime

Analysis of Shai-Hulud 2, a new npm supply chain attack

The OWASP Top 10 Gets Modernized

The OWASP Top 10 Gets Modernized

A look at the 2025 update to the OWASP Top 10, the most significant update since 2021

How Endor Labs Is Supporting Bryce, a Next-Gen AppSec Builder

How Endor Labs Is Supporting Bryce, a Next-Gen AppSec Builder

Endor Labs celebrates emerging AppSec talent at OWASP Global AppSec, highlighting Bryce’s Space Badge and investing in his future with a $5,000 scholarship.

StackHawk + Endor Labs: Correlating SAST and DAST Alerts

StackHawk + Endor Labs: Correlating SAST and DAST Alerts

Cut through duplicate alerts by mapping findings from static and dynamic analysis, so teams can focus on remediating the vulnerabilities that matter.

Introducing AI SAST That Thinks Like a Security Engineer

Introducing AI SAST That Thinks Like a Security Engineer

Endor Labs AI SAST detects business logic flaws and reduces false positives by up to 95% by orchestrating multiple AI agents to review code.

Code-to-Cloud Application Risk Management with Upwind and Endor Labs

Code-to-Cloud Application Risk Management with Upwind and Endor Labs

Together Endor Labs and Upwind deliver complete visibility across code and cloud for strong security posture management across the SLDC.

The Great Indonesian TEA Theft: Analyzing a NPM Spam Campaign

The Great Indonesian TEA Theft: Analyzing a NPM Spam Campaign

How a sophisticated spam campaign hijacked popular NPM packages with Indonesian food names as part of a global software supply chain attack.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.