Search Results

Learn about software supply chain security and Endor Labs

Search all our {count} unique resources
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Loading the Results...
Customer Zero: Implementing Package Firewall at Endor Labs
chrome_reader_mode
Blog

Customer Zero: Implementing Package Firewall at Endor Labs

Customer Zero: Implementing Package Firewall at Endor Labs

Heaps of Built-in's: How JavaScript Sandboxes work
chrome_reader_mode
Blog

Heaps of Built-in's: How JavaScript Sandboxes work

How JavaScript Sandboxes Work

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
chrome_reader_mode
Blog

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

Why C Has Always Broken Static Analysis
chrome_reader_mode
Blog

Why C Has Always Broken Static Analysis

Why C Has Always Broken Static Analysis

Why Endor Labs AI SAST for C finds what other tools miss
chrome_reader_mode
Blog

Why Endor Labs AI SAST for C finds what other tools miss

Why Endor Labs AI SAST for C finds what other tools miss

Hacking your life with AI can get you hacked
chrome_reader_mode
Blog

Hacking your life with AI can get you hacked

Hacking your life with AI can get you hacked

How AI orchestration platforms ship RCE by design
chrome_reader_mode
Ebook/Report

How AI orchestration platforms ship RCE by design

How AI orchestration platforms ship RCE by design

When you can't upgrade: open source examples of Endor Patches
chrome_reader_mode
Blog

When you can't upgrade: open source examples of Endor Patches

When you can't upgrade: open source examples of Endor Patches

AI SAST: Code Security for the Agentic SDLC
chrome_reader_mode
Ebook/Report

AI SAST: Code Security for the Agentic SDLC

How Endor Labs AI SAST combines program analysis, agentic reasoning, and deterministic engineering to find and fix the flaws that matter in AI-written code.

CISO's Guide: Build vs Buy AI Code Security
chrome_reader_mode
Ebook/Report

CISO's Guide: Build vs Buy AI Code Security

CISO's Guide: Build vs Buy AI Code Security

Why NPM Malware Keeps Reaching for Bun
chrome_reader_mode
Blog

Why NPM Malware Keeps Reaching for Bun

Why NPM Malware Keeps Reaching for Bun | Supply Chain Security

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern
chrome_reader_mode
Blog

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.
chrome_reader_mode
Blog

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
chrome_reader_mode
Blog

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

Critical Security Controls for Governing AI Coding Agents
chrome_reader_mode
Blog

Critical Security Controls for Governing AI Coding Agents

Endor Labs for Connected Products
chrome_reader_mode
Solution Brief

Endor Labs for Connected Products

Endor Labs for Connected Products

Endor Labs for Software & Tech
chrome_reader_mode
Solution Brief

Endor Labs for Software & Tech

Endor Labs for Software & Tech

Endor Labs for Financial Services
chrome_reader_mode
Solution Brief

Endor Labs for Financial Services

Endor Labs for Financial Services

SBOM Hub & VEX
chrome_reader_mode
Solution Brief

SBOM Hub & VEX

SBOM Hub & VEX

Endor Patches
chrome_reader_mode
Solution Brief

Endor Patches

Endor Patches

Artifact Signing
chrome_reader_mode
Solution Brief

Artifact Signing

Artifact Signing

AI Model Governance
chrome_reader_mode
Solution Brief

AI Model Governance

AI Model Governance

AI Code Review
chrome_reader_mode
Solution Brief

AI Code Review

AI Code Review

Container Security & Reachability
chrome_reader_mode
Solution Brief

Container Security & Reachability

Container Security & Reachability

AI Coding Agent Governance
chrome_reader_mode
Solution Brief

AI Coding Agent Governance

AI Coding Agent Governance: The Security Layer for the Agentic SDLC

Package Firewall
chrome_reader_mode
Solution Brief

Package Firewall

Package Firewall

Secrets Detection
chrome_reader_mode
Solution Brief

Secrets Detection

Secrets Detection: Find the Secrets That Are Actually Live

Software Supply Chain Security
chrome_reader_mode
Solution Brief

Software Supply Chain Security

Software Supply Chain Security

AI Code Governance: Secure AI-Generated Code and Govern the Agents That Write It
chrome_reader_mode
Solution Brief

AI Code Governance: Secure AI-Generated Code and Govern the Agents That Write It

AI Code Governance: Secure AI-Generated Code and Govern the Agents That Write It

Agentic Remediation: Remediation at Machine Speed, Grounded in Security Context
chrome_reader_mode
Solution Brief

Agentic Remediation: Remediation at Machine Speed, Grounded in Security Context

Agentic Remediation: Remediation at Machine Speed, Grounded in Security Context

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security
chrome_reader_mode
Blog

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
chrome_reader_mode
Blog

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

Beyond MCP: The New Security Playbook for Coding Agents
chrome_reader_mode
Blog

Beyond MCP: The New Security Playbook for Coding Agents

Beyond MCP: The New Security Playbook for Coding Agents

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
chrome_reader_mode
Blog

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

How Unprotected Release Branches Let Attackers Compromise AsyncAPI
chrome_reader_mode
Blog

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

Everyone Wins Their Own Benchmark
chrome_reader_mode
Blog

Everyone Wins Their Own Benchmark

Everyone Wins Their Own Benchmark

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse
chrome_reader_mode
Blog

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness
chrome_reader_mode
Blog

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs
chrome_reader_mode
Customer Story

Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs

Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs

Cyber insurers are pricing based on patching speed
chrome_reader_mode
Blog

Cyber insurers are pricing based on patching speed

Cyber insurers are pricing based on patching speed

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering
chrome_reader_mode
Blog

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering

Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest
chrome_reader_mode
Blog

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest

Claude Sonnet 5 with Claude Code: strong on function, average on security, and unusually honest

Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library
chrome_reader_mode
Blog

Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library

Endor Labs’ AI SAST Finds CVE-2026-55407: Memory-Amplification DoS in buffa

Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier models
chrome_reader_mode
Blog

Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier models

AI SAST found 192 real vulnerabilities, 2.6x more than Claude Code

Shai-Hulud Strikes Leo Platform npm
chrome_reader_mode
Blog

Shai-Hulud Strikes Leo Platform npm

Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.
chrome_reader_mode
Blog

Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.

Endor Labs is a Visionary in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security
chrome_reader_mode
Blog

Endor Labs is a Visionary in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

Endor Labs is a Visionary in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

Claude Fable 5, take two: same model, different harness, and a very different result
chrome_reader_mode
Blog

Claude Fable 5, take two: same model, different harness, and a very different result

Claude Fable 5, take two: same model, different harness, and a very different result

AppSec was built to find problems. The Mythos era demands you fix them, fast.
chrome_reader_mode
Blog

AppSec was built to find problems. The Mythos era demands you fix them, fast.

AppSec was built to find problems. The Mythos era demands you fix them, fast.

Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js
chrome_reader_mode
Blog

Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js

A single hijacked maintainer account pushed multiple trojanized packages across the entire @mastra scope in 27 minutes, each carrying a typosquat dependency that runs a remote payload on install. Combined reach is over 28 million downloads a month.

The Token Economics of AI AppSec Agents
chrome_reader_mode
Ebook/Report

The Token Economics of AI AppSec Agents

A controlled benchmark of AI agents with and without access to deterministic tools for performing common security tasks

Build vs. Buy Code Security: Same Model, Same Tasks, 12x the Token Bill
chrome_reader_mode
Blog

Build vs. Buy Code Security: Same Model, Same Tasks, 12x the Token Bill

The token economics of using AI coding agents for security tasks

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
chrome_reader_mode
Blog

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries

Average results with 59.8% on functional solves and just 19.0% on security solves

Recall, not reasoning: how AI coding agents cheat security benchmarks
chrome_reader_mode
Blog

Recall, not reasoning: how AI coding agents cheat security benchmarks

Recall, not reasoning: how AI coding agents cheat security benchmarks

Endor Labs Named a Representative Vendor in the 2026 Gartner® Innovation Insight for Agentic Application Security Testing
chrome_reader_mode
Blog

Endor Labs Named a Representative Vendor in the 2026 Gartner® Innovation Insight for Agentic Application Security Testing

Endor Labs Named a Representative Vendor in the 2026 Gartner® Innovation Insight for Agentic Application Security Testing

Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens
chrome_reader_mode
Blog

Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens

Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages

Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp
chrome_reader_mode
Blog

Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp

Malicious Payload in ai-sdk-ollama npm Package

Endor Labs Recognized in the Forrester Agentic Development Security Tools Landscape
chrome_reader_mode
Blog

Endor Labs Recognized in the Forrester Agentic Development Security Tools Landscape

Endor Labs Recognized in the Forrester Agentic Development Security Tools Landscape

Endor Labs + Cursor: Building the security foundation for agentic coding
chrome_reader_mode
Blog

Endor Labs + Cursor: Building the security foundation for agentic coding

Endor Labs + Cursor: Building the security foundation for agentic coding

Designing Reports for Three Different Workflows
chrome_reader_mode
Blog

Designing Reports for Three Different Workflows

Designing Reports for Three Different Workflows

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform Engineering
chrome_reader_mode
Blog

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform Engineering

Endor Labs named a Representative Vendor for Software Supply Chain Security.

Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware
chrome_reader_mode
Blog

Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware

Malicious PyPI package durabletask 1.4.1-1.4.3 steals AWS, Azure, and GCP credentials on import. 417k monthly downloads affected.

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security
chrome_reader_mode
Blog

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security

Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security

Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack
chrome_reader_mode
Blog

Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack

Mini Shai-Hulud Returns: 42 Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack

Designing AI Coding Agent Governance: A New Surface for AI Risk
chrome_reader_mode
Blog

Designing AI Coding Agent Governance: A New Surface for AI Risk

Designing AI Coding Agent Governance: A New Surface for AI Risk

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms
chrome_reader_mode
Blog

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms

When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms

From Code to Cloud: Endor Labs Joins the Wiz Integration Network
chrome_reader_mode
Blog

From Code to Cloud: Endor Labs Joins the Wiz Integration Network

Endor Labs joins the Wiz Integration Network (WIN), bringing reachability-backed SCA and AI SAST to Wiz for unified code-to-cloud risk context.

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise
chrome_reader_mode
Blog

How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise

A technical explainer of the attack chain behind the May 11, 2026 TanStack compromise

Introducing AI Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC
chrome_reader_mode
Blog

Introducing AI Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC

Learn how hooks turn AI coding agents like Claude Code and Cursor into governed systems with deterministic policy, centralized audit, and defense in depth.

Introducing Package Firewall
chrome_reader_mode
Blog

Introducing Package Firewall

Introducing Package Firewall

Malware Defense: A Multi-Agent Detection Engine and Package Firewall
chrome_reader_mode
Ebook/Report

Malware Defense: A Multi-Agent Detection Engine and Package Firewall

Introducing Security for AI Coding Agents and Workstations
chrome_reader_mode
Blog

Introducing Security for AI Coding Agents and Workstations

AURI secures the code AI agents write. Now, in collaboration with Cursor and Google, it secures the agents themselves.

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised
chrome_reader_mode
Blog

Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Shai-Hulud compromises the @tanstack ecosystem: 80+ packages compromised

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave
chrome_reader_mode
Blog

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Beyond Mythos: A CISO's Guide to Building an Effective Software Security Program for the AI Era
chrome_reader_mode
Ebook/Report

Beyond Mythos: A CISO's Guide to Building an Effective Software Security Program for the AI Era

Anthropic's Claude Mythos disclosure has every security leader asking the same question: what now?

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages
chrome_reader_mode
Blog

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League
chrome_reader_mode
Blog

GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League

OpenAI's newest model now holds the top security score on the Agent Security League through Cursor as the agent harness. Through Codex, it ties for third on security but trails on functional correctness.

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)
chrome_reader_mode
Blog

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

How attackers compromised Bitwarden's CLI and enlisted the help of AI coding agents to spread a worm and harvest developer secrets.

The agent control plane needs a security layer
chrome_reader_mode
Blog

The agent control plane needs a security layer

Security has to be embedded across the agent harness, orchestrator, and control plane if your organization wants to run software agents at scale.

Organizational Behavior Predicts OSS Malware Program Success
chrome_reader_mode
Blog

Organizational Behavior Predicts OSS Malware Program Success

Your org structure and dependency hygiene predict malware outcomes more than your tooling does. Here's what the data shows.

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League
chrome_reader_mode
Blog

Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security League

Anthropic's newest model reaches the highest functional and security scores we've ever measured. But roughly four out of five solutions still ship with vulnerabilities.

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.
chrome_reader_mode
Blog

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)
chrome_reader_mode
Blog

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)
chrome_reader_mode
Blog

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)

Agent Security League: Evaluating the Security of AI-Coded Software
chrome_reader_mode
Ebook/Report

Agent Security League: Evaluating the Security of AI-Coded Software

AI-generated code passes tests but fails security. This report benchmarks agents, exposing a persistent gap between functional correctness and secure outcomes.

Is AI Coding Safe? Introducing the Agent Security League
chrome_reader_mode
Blog

Is AI Coding Safe? Introducing the Agent Security League

AI coding agents can write working code, but mostly not secure code. Explore benchmark results showing over 80% of AI-generated code contains vulnerabilities.

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain
chrome_reader_mode
Blog

The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain

Blockchain-based C2 lets attackers run malware infrastructure that can’t be taken down. Learn how it works, why it’s spreading, and what defenders can still do.

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)
chrome_reader_mode
Blog

Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)

WebSocket pre-auth RCE, confirmed exploited in the wild within 10 hours of disclosure. Tens to hundreds of instances may remain exposed. Upgrade to 0.23.0.

What Security and Engineering Teams Fear Most About Malware
chrome_reader_mode
Blog

What Security and Engineering Teams Fear Most About Malware

What do security practitioners and software engineers actually fear about open source malware? We asked 605 professionals. Here is what 141 of them said, in their own words.

Malware in Open Source Ecosystems
chrome_reader_mode
Ebook/Report

Malware in Open Source Ecosystems

New research: malware in open source ecosystems surges 14x as attackers hijack trusted packages
chrome_reader_mode
Blog

New research: malware in open source ecosystems surges 14x as attackers hijack trusted packages

New Endor Labs research reveals 92% of npm account takeovers occurred in 2025, targeting packages with millions of downloads

Axios compromised: hijacked maintainer account pushes malicious npm versions
chrome_reader_mode
Blog

Axios compromised: hijacked maintainer account pushes malicious npm versions

A Practitioner’s Guide to Responding to the TeamPCP Supply Chain Attacks
chrome_reader_mode
Ebook/Report

A Practitioner’s Guide to Responding to the TeamPCP Supply Chain Attacks

Investigating, remediating, and hardening your environment in the wake of the TeamPCP campaign — from an organization that went through the process itself.

TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM
chrome_reader_mode
Blog

TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM

TeamPCP Strikes Again: Telnyx Compromised

What We Can Learn About GitHub Actions Security from the Trivy Breach
chrome_reader_mode
Blog

What We Can Learn About GitHub Actions Security from the Trivy Breach

Lessons in Hardening GitHub Actions

SolarWinds took a nation-state. The next attack just needs an LLM and $5.
chrome_reader_mode
Blog

SolarWinds took a nation-state. The next attack just needs an LLM and $5.

AI has collapsed the cost of offense to pocket change.

TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million Monthly Downloads on PyPI
chrome_reader_mode
Blog

TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million Monthly Downloads on PyPI

Supply Chain Attack on popular PyPI library LiteLLM

CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm
chrome_reader_mode
Blog

CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm

AURI: Security Intelligence for Agentic Software Development
chrome_reader_mode
Solution Brief

AURI: Security Intelligence for Agentic Software Development

AI agents have transformed how software gets built, but they’re introducing risk at a scale humans can’t review. This solution brief shows how AURI by Endor Labs embeds security directly into developer workflows, combining agentic reasoning with deterministic program analysis to enable teams to code without compromise.

no-results
Sorry, no results matching your search.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.