Blog

Learn about software supply chain security and Endor Labs

Happier DOMs: The perils of running untrusted JavaScript code outside of a web browser

Happier DOMs: The perils of running untrusted JavaScript code outside of a web browser

Endor Labs reveals critical RCE flaws in Happy DOM, showing how weak JavaScript sandboxes enable prototype pollution and unsafe code execution in Node.js.

Announcing Native Support for OWASP Secure Pipeline Verification Standard

Announcing Native Support for OWASP Secure Pipeline Verification Standard

Endor Labs now offers native support for OWASP SPVS, helping teams secure every stage of the software delivery pipeline from Plan to Operate.

OWASP Top 10 Adds A03:2025: Software Supply Chain Failures

OWASP Top 10 Adds A03:2025: Software Supply Chain Failures

The 2025 update to the OWASP Top 10 for Web Applications elevated software supply chain failures to the third leading risk.

Critical SQL Injection Vulnerability in Django (CVE-2025-64459)

Critical SQL Injection Vulnerability in Django (CVE-2025-64459)

Critical SQL Injection Vulnerability in Django (CVE-2025-64459). Learn what happened, root cause, impact, and how to mitigate.

False Negatives in SAST: Hidden Risks Behind the Noise

False Negatives in SAST: Hidden Risks Behind the Noise

Traditional SAST tools miss vulnerabilities while overwhelming teams with false positives. Here's why the silent failures are more dangerous than the noise.

Why AI Code Gets Less Secure With Every Prompt

Why AI Code Gets Less Secure With Every Prompt

New research shows that AI-generated code becomes less secure with each iteration—highlighting why developers need guardrails and structured approaches.

From Shift Left to Shift Down: Making SAST Work for Developers

From Shift Left to Shift Down: Making SAST Work for Developers

Shift-left security programs are failing and SAST is partly to blame. Shifting security down, not left, is how we make it work for developers.

Why SAST Failed (And What’s Next)

Why SAST Failed (And What’s Next)

Static analysis promised scalable secure coding. Instead, it delivered false positives and fatigue. Here’s why—and what the next era of analysis must do differently.

CVE-2025-53967 Remote Code Execution in Framelink Figma MCP Server

CVE-2025-53967 Remote Code Execution in Framelink Figma MCP Server

Learn about CVE-2025-53967, a high-severity RCE vulnerability in Framelink Figma MCP, including mitigation and vetting recommendations.

Rethinking the Interface: How Agentic UX is Shaping the Future of Endor Labs

Rethinking the Interface: How Agentic UX is Shaping the Future of Endor Labs

Discover how agentic UX streamlines application security workflows with proactive automation, faster decisions, and a more intuitive experience.

Why Cooldown Windows Belong in Every npm Security Strategy

Why Cooldown Windows Belong in Every npm Security Strategy

Block risky npm releases before they spread. Endor Labs’ new cooldown policy enforces wait times to stop malware attacks.

Zero Trust for Open Source: Why Enterprises Need a New AppSec Playbook

Zero Trust for Open Source: Why Enterprises Need a New AppSec Playbook

Enterprises must extend Zero Trust security principles to open source: assume nothing is safe, verify every dependency, and enforce guardrails across the software supply chain.

It’s Time to Take Malware Seriously (Attackers Do)

It’s Time to Take Malware Seriously (Attackers Do)

Too often, malware isn’t a priority until there’s a high-profile attack. But with the recent escalation of attacks, it’s time to make malware a first-party citizen in application security programs.

How to Defend Against NPM Software Supply Chain Attacks

How to Defend Against NPM Software Supply Chain Attacks

Practical steps security teams and developers can take to reduce risks from software supply chain attacks targeting the npm registry.

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

A virus-like npm malware attack has spread to 180+ packages so far, including CrowdStrike and Tinycolor.

Endor Labs Drives 225% Revenue Growth, Pioneers the Future of Secure SDLC

Endor Labs Drives 225% Revenue Growth, Pioneers the Future of Secure SDLC

AppSec company’s rapid growth reflects rising demand for security built for the speed and scale of engineering teams shaping the future of software with AI

Major Supply Chain Attack Compromises Popular npm Packages Including chalk and debug

Major Supply Chain Attack Compromises Popular npm Packages Including chalk and debug

Popular npm packages including chalk and debug were compromised in a major supply chain attack. Learn what happened, root cause, impact, and how to mitigate.

Nx build platform compromised by supply chain attack – How attackers collude with AI code assistants

Nx build platform compromised by supply chain attack – How attackers collude with AI code assistants

Nx supply chain attack: malicious npm versions of Nx exfiltrated SSH keys and tokens to GitHub—abusing AI code assistants. Learn how to detect and fix.

How We Cracked SCA for C/C++ Codebases

How We Cracked SCA for C/C++ Codebases

Endor Labs improves C/C++ SCA by combining cryptographic hashing, code embeddings, and a curated index for accurate dependency and vulnerability detection.

When CodeRabbit became PwnedRabbit: A cautionary tale for every GitHub App vendor (and their customers)

When CodeRabbit became PwnedRabbit: A cautionary tale for every GitHub App vendor (and their customers)

Kudelski Security uncovered an RCE flaw in CodeRabbit exposing 1M+ repos. Here’s what happened, how it was fixed, and key lessons for secure AI apps.

Shadow AI in Your Codebase: A Hidden Supply Chain Risk

Shadow AI in Your Codebase: A Hidden Supply Chain Risk

Unvetted AI models and services are entering your codebase. Do you have a plan to find and govern them?

Under the Hood: How I Vet Early-Stage Startups for Critical Security Programs

Under the Hood: How I Vet Early-Stage Startups for Critical Security Programs

Greg Pettengill, a Principal Product Security Engineer at Five9, is an early adopter of startup technology. In this article he shares his methodology for picking vendors that can deliver on promises.

Detect End-of-Life (EOL) Software in Containers with Endor Labs

Detect End-of-Life (EOL) Software in Containers with Endor Labs

Endor Labs now detects end-of-life (EOL) software in containers, helping AppSec teams eliminate risk early.

The Most Common Security Vulnerabilities in AI-Generated Code

The Most Common Security Vulnerabilities in AI-Generated Code

Learn about the most common and emerging security risks of AI-generated code, from injection flaws to hallucinated dependencies.

The Last Mile of AI Productivity Is Code Review

The Last Mile of AI Productivity Is Code Review

Developers are generating more code with AI coding assistants, but release velocity isn’t increasing. Here’s how to fix it.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.