Learn

Learn about software supply chain security and Endor Labs.

Featured resources

Introducing security for AI coding agents and workstations
Blog

Introducing Security for AI Coding Agents and Workstations

May 12, 2026
Beyond Mythos: A CISO's Guide to Building an Effective Software Security Program for the AI Era
Ebook/Report

Beyond Mythos: A CISO's Guide to Building an Effective Software Security Program for the AI Era

Apr 29, 2026
Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League
Blog

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Apr 17, 2026
Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.
Blog

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Apr 17, 2026
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Open Source
Security
Decorative icon
Blog

Eight for One: Multiple Vulnerabilities Fixed in the Node.js Runtime

Jan 13, 2026
Security
Malware
Open Source
Blog

n8mare on auth street: supply chain attack targets n8n ecosystem

Jan 9, 2026
Open Source
Security
CVE-2025-12543: Host Header Validation Bypass in Undertow
Blog

CVE-2025-12543: Host Header Validation Bypass in Undertow

Jan 9, 2026
Security
Open Source
CVE-2025-68428
Blog

CVE-2025-68428: Critical Path Traversal in jsPDF

Jan 6, 2026
AI/ML
Malware
Open Source
Security
Endor Labs integrates with Cursor hooks to detect malicious packages before AI agents install dependencies, preventing supply chain attacks at the moment of risk.
Blog

Bringing Malware Detection Into AI Coding Workflows with Cursor Hooks

Dec 17, 2025
Open Source
Security
When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin
Blog

When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin

Dec 12, 2025
Security
Open Source
When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo
Blog

When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo

Dec 12, 2025
Developer Productivity
From Vision to Reality: How Endor Labs Delivers Developer-First Security
Blog

From Vision to Reality: How Endor Labs Delivers Developer-First Security

Dec 9, 2025
Developer Productivity
Developer Experience: The Key to Successful Security
Blog

Developer Experience: The Key to Successful Security

Dec 9, 2025
Security
Open Source
CVE-2025-55182
Blog

Critical Remote Code Execution (RCE) Vulnerabilities in React and Next.js

Dec 3, 2025
No items found.
Ebook/Report

The New era of Code-to-Cloud Security

Dec 2, 2025
Customer Stories
SCA
Tech
Compliance & SBOM
Malware
Rubrik Hits Aggressive SLAs via Endor Labs
Customer Story

Rubrik Hits Aggressive SLAs via Endor Labs

Dec 2, 2025
Malware
Understanding NPM Worms and the Shai-Hulud Attack
Blog

Understanding NPM Worms and the Shai-Hulud Attack

Nov 25, 2025
Security
News
Malware
Blog

Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime

Nov 24, 2025
Open Source
News
The OWASP Top 10 Gets Modernized
Blog

The OWASP Top 10 Gets Modernized

Nov 21, 2025
News
How Endor Labs Is Supporting Bryce, a Next-Gen AppSec Builder
Blog

How Endor Labs Is Supporting Bryce, a Next-Gen AppSec Builder

Nov 21, 2025
News
StackHawk + Endor Labs: Correlating SAST and DAST Alerts
Blog

StackHawk + Endor Labs: Correlating SAST and DAST Alerts

Nov 20, 2025
Security
Developer Productivity
AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security
Ebook/Report

AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security

Nov 19, 2025
First Party Code
News
Introducing AI SAST That Thinks Like a Security Engineer
Blog

Introducing AI SAST That Thinks Like a Security Engineer

Nov 19, 2025
Malware
Security
Invisible Threats and the Blind Spots of Security
Ebook/Report

Invisible Threats and the Blind Spots of Security 


Nov 13, 2025
News
Blog

Code-to-Cloud Application Risk Management with Upwind and Endor Labs

Nov 12, 2025

Want to stay in the loop?

Sign up for our newsletter.