Blog

Learn about software supply chain security and Endor Labs

6 Best DAST Tools for DevSecOps Teams in 2026

6 Best DAST Tools for DevSecOps Teams in 2026

Best DAST tools for DevSecOps in 2026, with 6 top scanners compared on API coverage, false positive reduction, CI/CD integration, and remediation guidance.

Malicious Package Detection: Beyond CVEs and Scanners

Malicious Package Detection: Beyond CVEs and Scanners

Malicious package detection requires more than CVE scanning. Learn behavioral analysis and practical strategies to catch supply chain threats scanners miss.

Dependency Management Tools Every Engineering Team Needs

Dependency Management Tools Every Engineering Team Needs

Dependency management tools automate tracking, securing, and updating third-party packages. Learn what your engineering team needs from scanners to lock files.

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application Security Testing: A 2026 Guide to Types, Tools, and Methods

Application security testing is the practice of finding and fixing software vulnerabilities before production. Learn about SAST, DAST, IAST, SCA, and RASP.

Organizational Behavior Predicts OSS Malware Program Success

Organizational Behavior Predicts OSS Malware Program Success

Your org structure and dependency hygiene predict malware outcomes more than your tooling does. Here's what the data shows.

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Anthropic's newest model reaches the highest functional and security scores we've ever measured. But roughly four out of five solutions still ship with vulnerabilities.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

Is AI Coding Safe? Introducing the Agent Security League

Is AI Coding Safe? Introducing the Agent Security League

AI coding agents can write working code, but mostly not secure code. Explore benchmark results showing over 80% of AI-generated code contains vulnerabilities.

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain

Blockchain-based C2 lets attackers run malware infrastructure that can’t be taken down. Learn how it works, why it’s spreading, and what defenders can still do.

Top 10 SAST Tools in 2026: Accuracy, Speed, and Noise

Top 10 SAST Tools in 2026: Accuracy, Speed, and Noise

SAST tools scan source code for security vulnerabilities without running the application. Compare the top 10 tools by accuracy, speed, and noise reduction.

Fable 5.1 takes the top spot — faster than Opus 5, cheaper, and cleaner

Fable 5.1 takes the top spot — faster than Opus 5, cheaper, and cleaner

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)

WebSocket pre-auth RCE, confirmed exploited in the wild within 10 hours of disclosure. Tens to hundreds of instances may remain exposed. Upgrade to 0.23.0.

What Security and Engineering Teams Fear Most About Malware

What Security and Engineering Teams Fear Most About Malware

What do security practitioners and software engineers actually fear about open source malware? We asked 605 professionals. Here is what 141 of them said, in their own words.

Top Gen AI AppSec Tools in 2026: A Practitioner's Guide

Top Gen AI AppSec Tools in 2026: A Practitioner's Guide

Gen AI AppSec tools compared for 2026. Seven platforms evaluated on noise reduction, reachability analysis, AI-specific threat detection, and developer fit.

Best DevSecOps Tools for AppSec Teams in 2026

Best DevSecOps Tools for AppSec Teams in 2026

Best DevSecOps tools for 2026: seven platforms compared on false positive rates, reachability analysis, and actionable remediation guidance for AppSec teams.

Best Application Security Testing (AST) Tools Compared

Best Application Security Testing (AST) Tools Compared

Best AST tools compared on false positive rates, reachability depth, and workflow integration. See how 7 platforms reduce real security risk for dev teams.

10 Best DevSecOps Platforms for AppSec Teams in 2026

10 Best DevSecOps Platforms for AppSec Teams in 2026

DevSecOps platforms compared: 10 tools tested with real codebases for alert noise reduction, reachability analysis, and CI/CD integration for AppSec teams.

Best Application Security Tools for DevSecOps in 2026

Best Application Security Tools for DevSecOps in 2026

AppSec tools for 2026 ranked by noise reduction, false positive rates, and workflow integration. 10 platforms compared across SAST, SCA, DAST, and ASPM.

Best Code Security Platforms in 2026: Compared for CVE Volume and Mythos Readiness

Best Code Security Platforms in 2026: Compared for CVE Volume and Mythos Readiness

Compare eight code security platforms on SCA depth, reachability, and remediation. See which tools hold up as AI-scale discovery drives CVE volume.

🐱 The Inevitable Feline Takeover: A Serious Analysis

🐱 The Inevitable Feline Takeover: A Serious Analysis

New research: malware in open source ecosystems surges 14x as attackers hijack trusted packages

New research: malware in open source ecosystems surges 14x as attackers hijack trusted packages

New Endor Labs research reveals 92% of npm account takeovers occurred in 2025, targeting packages with millions of downloads

Axios compromised: hijacked maintainer account pushes malicious npm versions

Axios compromised: hijacked maintainer account pushes malicious npm versions

TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM

TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM

TeamPCP Strikes Again: Telnyx Compromised

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.