Learn
Learn about agentic coding security and Endor Labs

Blog
The first part of the EU Cyber Resiliency Act comes into effect on September 11th. Are you Ready?
September 10, 2026
News
Compliance & SBOM
First Party Code
Open Source

Blog
Better models are making agent patch review more expensive, not less
September 8, 2026
AI/ML
Developer Productivity
DevSecOps Tools

Blog
GPT-6 Astra on Codex - the Biggest Codex Leap to Date
September 8, 2026
AI/ML
First Party Code
Security & Compliance
News
.png)
Blog
How Endor Labs AI SAST Learns What Matters to Your Organization
September 7, 2026
First Party Code

Blog
From SDLC to ADLC: why application security needs coding agent governance
September 3, 2026
AI/ML
Opinion

Blog
The real test of AI-native code analysis: is your security debt shrinking?
August 31, 2026
AI/ML
First Party Code

Blog
Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI
August 28, 2026
Malware
Open Source
Security

Blog
FedRAMP 2026 vulnerability rules make reachability a requirement
August 26, 2026
Open Source
Security & Compliance

Blog
Heaps of Built-in's: How JavaScript Sandboxes work
August 20, 2026
DevSecOps Tools
Open Source
Security

Blog
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
August 20, 2026
Open Source
Security
News

Blog
Why C Has Always Broken Static Analysis
August 19, 2026
Opinion
First Party Code

Blog
Why Endor Labs AI SAST for C finds what other tools miss
August 19, 2026
First Party Code
News

Blog
Hacking your life with AI can get you hacked
August 18, 2026
Open Source
Security

Ebook/Report
How AI orchestration platforms ship RCE by design
August 18, 2026
Open Source
Security

Blog
The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.
August 7, 2026
Open Source
Malware

Solution Brief
Endor Labs for Connected Products
July 27, 2026
No items found.

Solution Brief
Endor Labs for Software & Tech
July 27, 2026
No items found.

Solution Brief
Endor Labs for Financial Services
July 27, 2026
No items found.

Solution Brief
SBOM Hub & VEX
July 27, 2026
No items found.

Solution Brief
Endor Patches
July 27, 2026
No items found.

Solution Brief
Artifact Signing
July 27, 2026
No items found.

Solution Brief
AI Model Governance
July 27, 2026
No items found.

Solution Brief
AI Code Review
July 27, 2026
No items found.

Solution Brief
Container Security & Reachability
July 27, 2026
No items found.

Solution Brief
Coding Agent Governance
July 27, 2026
No items found.

Solution Brief
Package Firewall
July 27, 2026
No items found.

Solution Brief
Secrets Detection
July 27, 2026
No items found.

Solution Brief
Software Supply Chain Security
July 27, 2026
No items found.

Solution Brief
AI Code Governance: Secure AI-Generated Code and Govern the Agents That Write It
July 27, 2026
No items found.

Solution Brief
Agentic Remediation: Remediation at Machine Speed, Grounded in Security Context
July 27, 2026
No items found.

Blog
Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security
July 23, 2026
News

Blog
The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
July 22, 2026
AI/ML
Opinion

Blog
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
July 17, 2026
AI/ML
Customer Story
Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs
July 8, 2026
Customer Stories
SCA
Developer Productivity
Compliance & SBOM

Blog
Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering
July 2, 2026
News

Blog
Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library
June 30, 2026
Open Source
Security

Blog
Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier models
June 30, 2026
News
First Party Code

Blog
Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.
June 25, 2026
News
Open Source

Blog
AppSec was built to find problems. The Mythos era demands you fix them, fast.
June 17, 2026
AI/ML
Developer Productivity
Open Source

Blog
Build vs. Buy Code Security: Same Model, Same Tasks, 12x the Token Bill
June 11, 2026
AI/ML
Opinion

Blog
Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
June 10, 2026
AI/ML
Security

Blog
Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens
June 8, 2026
Malware
Security

Blog
Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp
June 3, 2026
Security
Malware

Blog
Endor Labs Recognized in the Forrester Agentic Development Security Tools Landscape
June 1, 2026
News

Blog
Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform Engineering
May 21, 2026
News
Open Source

Blog
Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware
May 19, 2026
Malware
News
Security
Open Source

Blog
Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security
May 19, 2026
Partner blogs

Blog
Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack
May 19, 2026
Malware
News
Open Source
Security

Blog
When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms
May 18, 2026
AI/ML

Blog
How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise
May 14, 2026
Malware
Security

Blog
Introducing AI Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC
May 12, 2026
AI/ML
Open Source
Security

Blog
Introducing Package Firewall
May 12, 2026
Open Source
News

Blog
Introducing Security for AI Coding Agents and Workstations
May 12, 2026
AI/ML
News
Open Source

Blog
Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised
May 11, 2026
Malware
Open Source
Security

Blog
Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave
April 30, 2026
Malware
Security

Blog
Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.
April 17, 2026
Open Source
Security
Blog
The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)
April 17, 2026
Security
Open Source
Blog
It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)
April 16, 2026
Security
Open Source

Blog
The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain
April 13, 2026
Malware
Open Source
Security

Blog
Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)
April 9, 2026
Security
News
Open Source
Want to stay in the loop?
Sign up for our newsletter.






.png)


























