|
AI Coding Agent Security Benchmark
|
-- |
2026-04-16 |
400 |
--
|
|
Endor Labs Threat Research
|
-- |
2026-05-07 |
1,060 |
--
|
|
The OpenAI and Hugging Face security incident: why AI agents need deterministic …
|
Andrew Stiefel |
2026-07-22 |
995 |
--
|
|
Endor Labs is a Visionary in the 2026 Gartner® Magic Quadrant™ for …
|
Andrew Stiefel |
2026-06-18 |
987 |
--
|
|
Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
|
Luca Compagna |
2026-06-10 |
1,593 |
--
|
|
Software Supply Chain Security: How to Manage Risk at Scale
|
Sarah Hartland |
2026-03-24 |
2,192 |
--
|
|
Structuring Prompts for Secure Code Generation
|
Andrew Stiefel |
2025-07-16 |
685 |
--
|
|
Top 8 Application Security Platforms: Ranked for 2026
|
Sarah Hartland |
2026-03-23 |
2,565 |
--
|
|
AI Code Review
|
AI/ML |
2026-07-27 |
244 |
--
|
|
Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application …
|
Andrew Stiefel |
2026-07-23 |
998 |
--
|
|
Surge in submissions forces NIST to change how it handles CVEs. Here's …
|
Henrik Plate |
2026-04-17 |
782 |
--
|
|
Endor Patches
|
AI/ML |
2026-07-27 |
230 |
--
|
|
Design Flaws in AI Generated Code
|
Andrew Stiefel |
2026-02-09 |
1,094 |
--
|
|
Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload …
|
Peyton Kennedy |
2026-06-16 |
2,107 |
--
|
|
Endor Outpost: Deploy Endor Labs Behind Your Firewall
|
Ron Harnik |
2025-07-16 |
699 |
--
|
|
AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass
|
Peyton Kennedy |
2026-02-19 |
2,041 |
--
|
|
Code-to-Cloud Application Risk Management with Upwind and Endor Labs
|
Eli Scherr |
2025-11-12 |
498 |
--
|
|
Package Firewall
|
Security & Compliance |
2026-07-27 |
166 |
--
|
|
How We Cracked SCA for C/C++ Codebases
|
Georgios Gousios |
2025-08-21 |
846 |
--
|
|
Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens
|
Kiran Raj |
2026-06-08 |
2,666 |
--
|
|
DeepSeek R1: What Security Teams Need to Know
|
George Apostolopoulos |
2025-01-29 |
2,382 |
--
|
|
Everything You Need To Know About The FedRAMP RFC-0012
|
Chris Hughes |
2025-07-18 |
1,474 |
--
|
|
Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Platform …
|
Andrew Stiefel |
2026-05-21 |
916 |
--
|
|
The Last Mile of AI Productivity Is Code Review
|
Varun Badhwar |
2025-08-11 |
910 |
--
|
|
Best DevSecOps Platform Tools for AppSec Teams in 2026
|
Sarah Hartland |
2026-03-18 |
2,824 |
--
|
|
Endor Labs Recognized in the Forrester Agentic Development Security Tools Landscape
|
Andrew Stiefel |
2026-06-01 |
812 |
--
|
|
Slopsquatting: When AI Agents Hallucinate Malicious Packages
|
Andrew Stiefel |
2026-07-13 |
1,189 |
--
|
|
Why Your AI Code Assistant Might Be Shipping CVEs
|
Andrew Stiefel |
2025-08-05 |
1,013 |
--
|
|
Mastering Security Automation: Exception and Remediation Policies
|
Matt Brown |
2025-05-15 |
630 |
--
|
|
The Token Economics of AI AppSec Agents
|
Matt Brown |
2026-06-11 |
233 |
--
|
|
Zero Trust for Open Source: Why Enterprises Need a New AppSec Playbook
|
Varun Badhwar |
2025-09-22 |
1,437 |
--
|
|
The OWASP Top 10 Gets Modernized
|
Chris Hughes |
2025-11-21 |
1,426 |
--
|
|
Endor Labs & Oligo: Closing the Loop Between Secure Code and Secure …
|
Tom Gleason |
2025-07-10 |
569 |
--
|
|
How a Misconfigured CI Workflow Became an npm Supply-Chain Compromise
|
Robert Haynes |
2026-05-14 |
2,512 |
--
|
|
From Shift Left to Shift Down: Making SAST Work for Developers
|
Andrew Stiefel |
2025-10-27 |
1,407 |
--
|
|
🐱 The Inevitable Feline Takeover: A Serious Analysis
|
Sarah Hartland |
2026-04-02 |
395 |
--
|
|
Top 10 Veracode Alternatives for AppSec Teams in 2026
|
Sarah Hartland |
2026-03-18 |
3,212 |
--
|
|
Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem …
|
Peyton Kennedy |
2026-05-19 |
2,493 |
--
|
|
Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse
|
Luca Compagna |
2026-07-09 |
1,392 |
--
|
|
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
|
Luca Compagna |
2026-07-17 |
2,296 |
--
|
|
Secure AI Workflows: From Development to Deployment
|
-- |
2026-05-06 |
2,236 |
--
|
|
What Is Mythos and Why It Matters for Software Security
|
-- |
2026-05-07 |
1,818 |
--
|
|
The UK Software Security Code of Practice through a Software Supply Chain …
|
Rob Osborn |
2025-05-22 |
531 |
--
|
|
False Negatives in SAST: Hidden Risks Behind the Noise
|
Andrew Stiefel |
2025-11-06 |
951 |
--
|
|
The Great Indonesian TEA Theft: Analyzing a NPM Spam Campaign
|
Cris Staicu |
2025-11-11 |
1,909 |
--
|
|
The AppSec Maturity Staircase: Climbing Faster, Not Harder with Endor Labs
|
Jamie Scott |
2025-02-11 |
1,883 |
--
|
|
Malicious Package Detection: Beyond CVEs and Scanners
|
Sarah Hartland |
2026-04-22 |
3,045 |
--
|
|
Best Application Security Tools for DevSecOps in 2026
|
Sarah Hartland |
2026-04-02 |
3,595 |
--
|
|
How to Get Developers to Accept Security PRs Faster
|
Andrew Stiefel |
2025-02-04 |
949 |
--
|
|
Endor Labs Policies: Developer-Friendly Security Automation
|
Security |
2025-05-19 |
206 |
--
|
|
Endor Labs Named in the 2026 Gartner® Hype Cycle™ for Secure Software …
|
Andrew Stiefel |
2026-07-02 |
887 |
--
|
|
Astronomer Modernizes AppSec with Endor Labs
|
Jenn Gile |
2026-01-20 |
1,100 |
--
|
|
CVE-2025-53967 Remote Code Execution in Framelink Figma MCP Server
|
Jenn Gile |
2025-10-10 |
1,162 |
--
|
|
How to Detect LLM Prompt Injection Risks
|
Andrew Stiefel |
2025-08-06 |
598 |
--
|
|
The Most Common Security Vulnerabilities in AI-Generated Code
|
Andrew Stiefel |
2025-08-12 |
411 |
--
|
|
Blast Radius of the tj-actions/changed-files Supply Chain Attack
|
Henrik Plate |
2025-03-19 |
1,128 |
--
|
|
The Unkillable C2: How Attackers Are Moving Command and Control to the …
|
Robert Haynes |
2026-04-13 |
2,808 |
--
|
|
Why AI Code Gets Less Secure With Every Prompt
|
Chris Hughes |
2025-10-28 |
1,054 |
--
|
|
Software Supply Chain Security: Why SCA Alone Falls Short
|
Sarah Hartland |
2026-03-23 |
2,672 |
--
|
|
Benchmarking Opengrep Performance Improvements
|
Julien Sobrier |
2025-05-29 |
1,117 |
--
|
|
Secrets Detection
|
Security |
2026-07-27 |
252 |
--
|
|
Axios compromised: hijacked maintainer account pushes malicious npm versions
|
Meenakshi S L |
2026-03-30 |
3,837 |
--
|
|
AI Risk Reduction: Complete Guide to Mitigation Strategies for 2026
|
-- |
2026-05-06 |
2,058 |
--
|
|
A Practitioner’s Guide to Responding to the TeamPCP Supply Chain Attacks
|
Malware |
2026-03-27 |
157 |
--
|
|
Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs
|
Andrew Stiefel |
2026-07-08 |
1,791 |
--
|
|
Best DevSecOps Tools for AppSec Teams in 2026
|
Sarah Hartland |
2026-04-02 |
2,639 |
--
|
|
Best Software Supply Chain Security Tools for AppSec Teams
|
Sarah Hartland |
2026-03-24 |
2,985 |
--
|
|
The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain …
|
Rachana Misal |
2026-03-10 |
1,074 |
--
|
|
Under the Hood: People.ai's Proactive Approach to AI Security
|
Aman Sirohi |
2025-07-01 |
1,224 |
--
|
|
Shai-Hulud Strikes Leo Platform npm
|
Kiran Raj |
2026-06-25 |
3,728 |
--
|
|
What Is Malicious Code? Types, Examples & How to Protect Yourself
|
Andrew Stiefel |
2026-07-13 |
1,142 |
--
|
|
Secure AI-Generated Code at the Source
|
AI/ML |
2025-04-23 |
577 |
--
|
|
How to Defend Against NPM Software Supply Chain Attacks
|
Jamie Scott |
2025-09-16 |
1,496 |
--
|
|
What We Can Learn About GitHub Actions Security from the Trivy Breach
|
Robert Haynes |
2026-03-26 |
1,888 |
--
|
|
TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits …
|
Kiran Raj |
2026-03-24 |
683 |
--
|
|
Critical RCE Vulnerability in Apache Parquet (CVE-2025-30065) – Advisory and Analysis
|
Tom Gleason |
2025-04-02 |
738 |
--
|
|
SolarWinds took a nation-state. The next attack just needs an LLM and …
|
Varun Badhwar |
2026-03-26 |
1,311 |
--
|
|
Claude Opus 4.7 Sets New Records in the Endor Labs Agent Security …
|
Robert Haynes |
2026-04-17 |
1,061 |
--
|
|
Top 10 Software Composition Analysis (SCA) Tools in 2026
|
Sarah Hartland |
2026-03-26 |
3,235 |
--
|
|
Supply Chain Attack targeting Cline installs OpenClaw
|
Henrik Plate |
2026-02-18 |
453 |
--
|
|
7 Best Application Security Tools for the AI Era (2026)
|
Sarah Hartland |
2026-03-18 |
4,449 |
--
|
|
Endor Labs for Connected Products
|
Security |
2026-07-27 |
225 |
--
|
|
The Missing Layer: Why Container OS Libraries Need Reachability Analysis
|
Chris Hughes |
2026-02-13 |
1,739 |
--
|
|
Endor Labs Drives 225% Revenue Growth, Pioneers the Future of Secure SDLC
|
AI/ML |
2025-09-16 |
864 |
--
|
|
Endor Labs vs Snyk: SCA, SAST, and Containers Compared
|
Sarah Hartland |
2026-03-19 |
2,107 |
--
|
|
Endor Labs + Zscaler: Zero Trust Application Security for the AI Era
|
Eli Scherr |
2026-03-17 |
1,151 |
--
|
|
Beyond MCP: The New Security Playbook for Coding Agents
|
George Apostolopoulos |
2026-07-21 |
3,063 |
--
|
|
Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security
|
Eli Scherr |
2026-05-19 |
757 |
--
|
|
The agent control plane needs a security layer
|
Andrew Stiefel |
2026-04-23 |
1,260 |
--
|
|
Why Security Policies Frustrate Developers (and How We Can Fix Them)
|
Matt Brown |
2025-05-06 |
701 |
--
|
|
Malware Defense: A multi-agent detection engine and package firewall
|
Robert Haynes |
2026-05-12 |
201 |
--
|
|
9 Best SAST Tools in 2026: Top SAST Solutions Compared
|
Sarah Hartland |
2026-03-24 |
3,030 |
--
|
|
When CodeRabbit became PwnedRabbit: A cautionary tale for every GitHub App vendor …
|
Varun Badhwar |
2025-08-20 |
1,410 |
--
|
|
Announcing Native Support for OWASP Secure Pipeline Verification Standard
|
Amod Gupta |
2025-11-10 |
1,154 |
--
|
|
Anthropic just validated that AppSec is the biggest opportunity in cybersecurity
|
Varun Badhwar |
2026-02-24 |
1,721 |
--
|
|
Static Analysis in the Age of AI, Part I: AI Coding Assistants
|
Robert Haynes |
2026-02-03 |
1,012 |
--
|
|
Eight for One: Multiple Vulnerabilities Fixed in the Node.js Runtime
|
Peyton Kennedy |
2026-01-13 |
1,311 |
--
|
|
Software Supply Chain Security
|
Security |
2026-07-27 |
240 |
--
|
|
How AI SAST Traced Data Flows to Uncover Six OpenClaw Vulnerabilities
|
Peyton Kennedy |
2026-02-18 |
2,918 |
--
|
|
Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware
|
Peyton Kennedy |
2026-05-19 |
1,932 |
--
|
|
AppSec’s Exploitation Era: What Verizon, Mandiant, and Datadog Are Telling Us
|
Chris Hughes |
2025-06-04 |
1,514 |
--
|
|
Securing Open Source Dependencies: A Developer's Guide
|
Andrew Stiefel |
2026-07-13 |
906 |
--
|
|
Uncover Trends and Show AppSec Value with the Endor Labs Dashboard
|
Ron Harnik |
2025-01-21 |
900 |
--
|
|
Top 8 Aikido Alternatives for Developer Security in 2026
|
Sarah Hartland |
2026-03-23 |
2,568 |
--
|
|
Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime
|
Henrik Plate |
2025-11-24 |
2,479 |
--
|
|
6 Best DAST Tools for DevSecOps Teams in 2026
|
Sarah Hartland |
2026-04-22 |
2,599 |
--
|
|
It’s Time to Take Malware Seriously (Attackers Do)
|
Jenn Gile |
2025-09-19 |
1,704 |
--
|
|
AI Model Risk Assessment: Framework and Best Practices
|
-- |
2026-05-06 |
2,197 |
--
|
|
Claude Sonnet 5 with Claude Code: strong on function, average on security, …
|
Luca Compagna |
2026-07-02 |
622 |
--
|
|
Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)
|
Kiran Raj |
2026-04-23 |
3,621 |
--
|
|
Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised
|
Peyton Kennedy |
2026-05-11 |
2,916 |
--
|
|
Fireside Chat: Building a High-Trust Product Security Program at Zebra
|
Jasyn Voshell |
2025-08-06 |
6,255 |
--
|
|
Your Next Breach Won’t Be a CVE: Connecting Real Incidents to AI-Aware …
|
Matt Brown |
2026-01-21 |
1,684 |
--
|
|
When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in …
|
Meenakshi S L |
2025-12-12 |
1,136 |
--
|
|
Artifact Signing
|
Security |
2026-07-27 |
212 |
--
|
|
Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa …
|
Peyton Kennedy |
2026-06-30 |
2,671 |
--
|
|
Under the Hood: Mysten Labs’ Strategies for Building the Most Secure Blockchain
|
Paul Padilla |
2025-06-17 |
1,379 |
--
|
|
CVE-2025-54313: eslint-config-prettier Compromise — High Severity but Windows-Only
|
Security |
2025-07-19 |
711 |
--
|
|
Organizational Behavior Predicts OSS Malware Program Success
|
Andrew Stiefel |
2026-04-22 |
1,041 |
--
|
|
CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser
|
Peyton Kennedy |
2026-02-21 |
851 |
--
|
|
Understanding Software Distribution Security: Key Concepts Explained
|
-- |
2026-05-06 |
1,930 |
--
|
|
Why SAST Failed (And What’s Next)
|
Dimitri Stiliadis |
2025-10-16 |
1,040 |
--
|
|
New research: malware in open source ecosystems surges 14x as attackers hijack …
|
Andrew Stiefel |
2026-04-01 |
708 |
--
|
|
AI Model Security Strategies for CISOs and Security Leaders
|
-- |
2026-05-06 |
2,222 |
--
|
|
Under the Hood: How I Vet Early-Stage Startups for Critical Security Programs
|
Greg Pettengill |
2025-08-20 |
835 |
--
|
|
Best SBOM Tools in 2026, Compared
|
Andrew Stiefel |
2026-07-13 |
1,372 |
--
|
|
npm is serving malware to 134,000 developers, and the maintainer can’t stop …
|
Kiran Raj |
2026-03-18 |
2,277 |
--
|
|
Top 8 Snyk Alternatives for Security & Engineering Teams
|
Sarah Hartland |
2026-03-19 |
2,384 |
--
|
|
Top Gen AI AppSec Tools in 2026: A Practitioner's Guide
|
Sarah Hartland |
2026-04-02 |
2,460 |
--
|
|
Bringing Malware Detection Into AI Coding Workflows with Cursor Hooks
|
George Apostolopoulos |
2025-12-17 |
1,058 |
--
|
|
Application Security Testing: A 2026 Guide to Types, Tools, and Methods
|
Sarah Hartland |
2026-04-22 |
4,017 |
--
|
|
Vulnerability Blast Radius: How to Measure and Reduce Impact
|
-- |
2026-05-06 |
1,926 |
--
|
|
CVE-2025-12543: Host Header Validation Bypass in Undertow
|
Meenakshi S L |
2026-01-09 |
812 |
--
|
|
Why We Raised a $93M Series B (In This Market)
|
Varun Badhwar |
2025-04-23 |
690 |
--
|
|
Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp
|
Danny Kim |
2026-06-03 |
3,534 |
--
|
|
Identifying and Tracking FedRAMP False Positives
|
Jenn Gile |
2025-01-14 |
1,288 |
--
|
|
AI-Generated Malware and the Software Supply Chain
|
Andrew Stiefel |
2026-07-13 |
1,026 |
--
|
|
What is AppSec? A 2025 Guide for Security Practitioners
|
Sarah Hartland |
2025-06-19 |
2,676 |
--
|
|
How to Evaluate Endor Labs SCA for C/C++ Projects
|
Robert Haynes |
2025-07-22 |
1,233 |
--
|
|
CVE-2026-27959: Userinfo Host Header Injection in Koa
|
Peyton Kennedy |
2026-02-25 |
1,951 |
--
|
|
CVE-2025-68428: Critical Path Traversal in jsPDF
|
Peyton Kennedy |
2026-01-06 |
1,078 |
--
|
|
Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise
|
Kyle Quest |
2026-02-11 |
1,781 |
--
|
|
AI Model Governance
|
AI/ML |
2026-07-27 |
216 |
--
|
|
Fireside Chat: CISOs on AI, Shift Left, and Building Trust at People.ai …
|
Aman Sirohi |
2025-08-07 |
2,754 |
--
|
|
Mysten Labs Improves DevEx with Endor Labs
|
Jenn Gile |
2025-06-17 |
1,073 |
--
|
|
Introducing Coding Agent Governance: Using Hooks to Bring Visibility to the ADLC
|
Robert Haynes |
2026-05-12 |
1,607 |
--
|
|
Is AI Coding Safe? Introducing the Agent Security League
|
Luca Compagna |
2026-04-15 |
2,089 |
--
|
|
Major Supply Chain Attack Compromises Popular npm Packages Including chalk and debug
|
Andrew Stiefel |
2025-09-08 |
560 |
--
|
|
Endor Labs Now Available on Google Cloud Marketplace
|
Eli Scherr |
2025-07-29 |
583 |
--
|
|
Agent Governance
|
AI/ML |
2026-07-27 |
207 |
--
|
|
What Security and Engineering Teams Fear Most About Malware
|
Andrew Stiefel |
2026-04-08 |
1,943 |
--
|
|
Rubrik Hits Aggressive SLAs via Endor Labs
|
Jenn Gile |
2025-12-02 |
1,415 |
--
|
|
Best Checkmarx Alternatives & Competitors in 2026
|
Sarah Hartland |
2026-03-20 |
2,374 |
--
|
|
Securing AI Coding Assistants: A Total Cost Analysis
|
Varun Badhwar |
2025-07-30 |
1,052 |
--
|
|
CVE-2025-47949 Reveals Flaw in samlify That Opens Door to SAML Single Sign-On …
|
Meenakshi S L |
2025-05-20 |
861 |
--
|
|
Developer Experience: The Key to Successful Security
|
Robert Haynes |
2025-12-09 |
2,293 |
--
|
|
Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
|
Peyton Kennedy |
2026-01-23 |
1,469 |
--
|
|
Five9 Transforms Software Supply Chain Security with Endor Labs
|
Jenn Gile |
2025-08-20 |
1,280 |
--
|
|
Everyone Wins Their Own Benchmark
|
Sarah Johnson |
2026-07-14 |
1,204 |
--
|
|
How Endor Patches Are Built and Tested
|
Henrik Plate |
2025-02-18 |
1,514 |
--
|
|
Zebra Technologies Cuts SCA Noise by 97% with Endor Labs
|
Jenn Gile |
2025-06-11 |
797 |
--
|
|
Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave
|
Henrik Plate |
2026-04-30 |
2,618 |
--
|
|
7 Snyk Alternatives for Engineering Teams in 2026
|
Developer Productivity |
2026-02-02 |
3,716 |
--
|
|
Intelligence and governance in the software supply chain with Endor Labs and …
|
Eli Scherr |
2026-03-10 |
752 |
--
|
|
Introducing Security for AI Coding Agents and Workstations
|
Amod Gupta |
2026-05-12 |
991 |
--
|
|
Streamline Investigation with Enriched Vulnerability Search
|
Pawan Shankar |
2025-06-25 |
450 |
--
|
|
CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm
|
Henrik Plate |
2026-03-21 |
1,497 |
--
|
|
5 Tips for Managing Bazel Dependencies (Without Losing Friends)
|
Alexandre Wilhelm |
2025-05-12 |
1,740 |
--
|
|
OWASP Top 10 Adds A03:2025: Software Supply Chain Failures
|
Jenn Gile |
2025-11-06 |
838 |
--
|
|
Build vs. Buy Code Security: Same Model, Same Tasks, 12x the Token …
|
Varun Badhwar |
2026-06-11 |
1,401 |
--
|
|
SANDWORM_MODE: Dissecting a Multi-Stage npm Supply Chain Attack
|
Kiran Raj |
2026-02-23 |
3,861 |
--
|
|
AppSec was built to find problems. The Mythos era demands you fix …
|
Robert Haynes |
2026-06-17 |
1,871 |
--
|
|
SBOM Hub & VEX
|
Security |
2026-07-27 |
230 |
--
|
|
Cyber insurers are pricing based on patching speed
|
Andrew Stiefel |
2026-07-07 |
975 |
--
|
|
How Fake Font Packages Abused npm as a CDN
|
Henrik Plate |
2026-01-23 |
1,244 |
--
|
|
Nx build platform compromised by supply chain attack – How attackers collude …
|
Henrik Plate |
2025-08-27 |
1,256 |
--
|
|
Designing Reports for Three Different Workflows
|
Karen Ng |
2026-05-27 |
1,288 |
--
|
|
Remote Code Execution Vulnerabilities in Apache Struts
|
Jenn Gile |
2025-01-24 |
1,206 |
--
|
|
Introducing AI Security Code Review
|
Julien Sobrier |
2025-04-23 |
1,416 |
--
|
|
Designing Coding Agent Governance: A New Surface for AI Risk
|
Karen Ng |
2026-05-18 |
1,609 |
--
|
|
Introducing Package Firewall
|
Amod Gupta |
2026-05-12 |
705 |
--
|
|
AI Code Governance: Secure AI-Generated Code and Govern the Agents That Write …
|
AI/ML |
2026-07-27 |
234 |
--
|
|
Critical Remote Code Execution (RCE) Vulnerabilities in React and Next.js
|
Henrik Plate |
2025-12-03 |
1,037 |
--
|
|
How to Detect Infrastructure as Code (IaC) Misconfigurations with AI Security Code …
|
Pawan Shankar |
2025-07-28 |
385 |
--
|
|
Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution
|
Henrik Plate |
2026-03-18 |
2,086 |
--
|
|
Anti-Pattern Avoidance: A Simple Prompt Pattern for Safer AI-Generated Code
|
Andrew Stiefel |
2025-08-05 |
297 |
--
|
|
Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)
|
Kiran Raj |
2026-04-09 |
1,923 |
--
|
|
Cursor Develops a Secure Product with Endor Labs
|
Jenn Gile |
2025-08-20 |
973 |
--
|
|
How Unprotected Release Branches Let Attackers Compromise AsyncAPI
|
Kiran Raj |
2026-07-14 |
3,694 |
--
|
|
Best Software Composition Analysis (SCA) Tools for 2026
|
Sarah Hartland |
2026-03-23 |
2,675 |
--
|
|
What Is Software Supply Chain Security? The Complete Guide
|
Andrew Stiefel |
2026-07-13 |
2,207 |
--
|
|
Developer Security Tools Compared: A Practical Guide for 2026
|
Sarah Hartland |
2026-04-22 |
2,671 |
--
|
|
Secure-Insecure Diff: A Smarter Way to Prompt for Safer Code
|
Andrew Stiefel |
2025-07-22 |
614 |
--
|
|
AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws …
|
AI/ML |
2025-04-23 |
207 |
--
|
|
What You Need to Know About UK Cyber Essentials Certification
|
Rob Osborn |
2025-03-18 |
1,535 |
--
|
|
Rethinking the Interface: How Agentic UX is Shaping the Future of Endor …
|
Karen Ng |
2025-10-02 |
814 |
--
|
|
Cracking the Code: Solving the Challenges of C/C++ Software Composition Analysis
|
Andrew Stiefel |
2025-06-18 |
199 |
--
|
|
Endor Labs Named a Representative Vendor in the 2026 Gartner® Innovation Insight …
|
Andrew Stiefel |
2026-06-08 |
1,275 |
--
|
|
Everything You Need to Know About Opengrep
|
Varun Badhwar |
2025-01-23 |
678 |
--
|
|
CVE-2026-22709: Critical Sandbox Escape in vm2 Enables Arbitrary Code Execution
|
Peyton Kennedy |
2026-01-27 |
1,712 |
--
|
|
Recall, not reasoning: how AI coding agents cheat security benchmarks
|
Luca Compagna |
2026-06-10 |
1,896 |
--
|
|
From Vision to Reality: How Endor Labs Delivers Developer-First Security
|
Robert Haynes |
2025-12-09 |
1,189 |
--
|
|
Best SCA Solutions for 2026: Reachability-Driven Analysis
|
Sarah Hartland |
2026-04-22 |
2,642 |
--
|
|
Critical SQL Injection Vulnerability in Django (CVE-2025-64459)
|
Meenakshi S L |
2025-11-06 |
885 |
--
|
|
From Code to Cloud: Endor Labs Joins the Wiz Integration Network
|
News |
2026-05-15 |
402 |
--
|
|
Shadow AI in Your Codebase: A Hidden Supply Chain Risk
|
Julien Sobrier |
2025-08-20 |
845 |
--
|
|
Application Security Posture Management (ASPM) Explained
|
Andrew Stiefel |
2025-03-11 |
2,193 |
--
|
|
Endor Labs now integrates with GitHub Copilot in VS Code
|
Jamie Scott |
2025-07-31 |
506 |
--
|
|
CVE-2026-25049 Expression Escape Vulnerability Leading to RCE in n8n
|
Cris Staicu |
2026-02-04 |
1,645 |
--
|
|
Dependency Confusion: How Attackers Poison Your Build
|
Andrew Stiefel |
2026-07-13 |
1,306 |
--
|
|
The Architectural Shift Behind the AI SDLC
|
Aditya Patil |
2026-02-06 |
774 |
--
|
|
Container Security & Reachability
|
Security |
2026-07-27 |
228 |
--
|
|
Critical SQL Injection Vulnerability in LlamaIndex (CVE-2025-1793) – Advisory and Analysis
|
Meenakshi S L |
2025-06-09 |
843 |
--
|
|
AI SAST in Action: Finding Real Vulnerabilities in OpenClaw
|
Peyton Kennedy |
2026-02-10 |
696 |
--
|
|
GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in …
|
Henrik Plate |
2026-04-27 |
1,016 |
--
|
|
Open Source Gets Political: What The easyjson Debate Misses (and what to …
|
Ron Harnik |
2025-05-05 |
831 |
--
|
|
OWASP OSS Risk 2: Compromise of Legitimate Package
|
Camilla Odlund |
2025-03-25 |
2,519 |
--
|
|
What Is a Software Bill of Materials? A Practical Guide
|
Andrew Stiefel |
2026-07-13 |
2,359 |
--
|
|
Dependency Management Tools Every Engineering Team Needs
|
Sarah Hartland |
2026-04-22 |
3,970 |
--
|
|
Common C/C++ Vulnerabilities: A Practical Guide to Prevention
|
Sarah Hartland |
2026-04-22 |
2,140 |
--
|
|
10 Best DevSecOps Platforms for AppSec Teams in 2026
|
Sarah Hartland |
2026-04-02 |
3,061 |
--
|
|
Reducing Noise and Fixing What Matters
|
Andrew Stiefel |
2025-04-02 |
103 |
--
|
|
TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM
|
Kiran Raj |
2026-03-27 |
2,323 |
--
|
|
Best Code Security Platforms in 2026, Compared
|
Sarah Hartland |
2026-04-02 |
2,457 |
--
|
|
How Endor Labs Prioritizes Open Source Security Patches
|
Andrew Stiefel |
2025-01-07 |
870 |
--
|
|
It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478)
|
Cris Staicu |
2026-04-16 |
2,473 |
--
|
|
When the Guardrails Slip: The Case for Hook-Based Governance Across Agent Platforms
|
George Apostolopoulos |
2026-05-18 |
1,811 |
--
|
|
Cursor Security: How to Secure AI-Generated Code in 2026
|
Sarah Hartland |
2026-03-23 |
2,192 |
--
|
|
CVE-2025-4641 is Critical, But Likely Unreachable
|
Ron Harnik |
2025-05-16 |
596 |
--
|
|
Next-Gen SCA for C/C++: Closing the Detection Gap
|
Julien Sobrier |
2025-06-11 |
855 |
--
|
|
Struggling to Patch Spring-Web? Try This Instead
|
Somak Dutta |
2025-07-09 |
1,538 |
--
|
|
Endor Labs for Financial Services
|
-- |
2026-07-27 |
145 |
--
|
|
Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness
|
Luca Compagna |
2026-07-09 |
1,608 |
--
|
|
Malware Package Firewall: Block Threats Before They Hit Your Code
|
Sarah Hartland |
2026-03-24 |
2,610 |
--
|
|
npm Account Takeovers are a Growing Malware Trend
|
Jenn Gile |
2026-01-29 |
2,311 |
--
|
|
When AI Imports Vulnerable Dependencies: Securing AI-Generated Code
|
Andrew Stiefel |
2026-07-13 |
1,082 |
--
|
|
AURI: Security Intelligence for Agentic Software Development
|
AI/ML |
2026-03-19 |
247 |
--
|
|
Top 10 SAST Tools in 2026: Accuracy, Speed, and Noise
|
Sarah Hartland |
2026-04-09 |
3,452 |
--
|
|
Best Black Duck Alternatives for SCA With Less Noise
|
Sarah Hartland |
2026-03-18 |
2,329 |
--
|
|
10 Best Application Security Tools for 2026
|
Sarah Hartland |
2026-03-18 |
2,878 |
--
|
|
Benchmarking Endor Labs AI SAST: 2.6x more real vulnerabilities found than frontier …
|
Sarah Johnson |
2026-06-30 |
1,733 |
--
|
|
Veiled in Trust: Software Supply Chain Attacks Explained
|
Andrew Stiefel |
2026-07-13 |
1,007 |
--
|
|
Fireside Chat: Building an AppSec Program for Cursor
|
Jenn Gile |
2025-09-19 |
7,125 |
--
|
|
Why Cooldown Windows Belong in Every npm Security Strategy
|
Camilla Odlund |
2025-09-22 |
888 |
--
|
|
Open source carries the world. Patching it at Mythos-scale can't fall to …
|
Varun Badhwar |
2026-06-25 |
1,449 |
--
|
|
AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security
|
Security |
2025-11-19 |
210 |
--
|
|
Mini Shai-Hulud: npm Worm Hits SAP Developer Packages
|
Kiran Raj |
2026-04-29 |
2,926 |
--
|
|
Introducing the Endor Labs MCP Server: fix-first security for the vibe coding …
|
Dimitri Stiliadis |
2025-04-23 |
564 |
--
|
|
Introducing AURI: Security Intelligence for AI Coding Agents and Developers
|
Amod Gupta |
2026-03-03 |
1,234 |
--
|
|
When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin
|
Meenakshi S L |
2025-12-12 |
1,258 |
--
|
|
Introducing AI SAST That Thinks Like a Security Engineer
|
Amod Gupta |
2025-11-19 |
1,444 |
--
|
|
Beyond Mythos: A CISO's Guide to Building an Effective Software Security Program …
|
Varun Badhwar |
2026-04-29 |
187 |
--
|
|
Detect End-of-Life (EOL) Software in Containers with Endor Labs
|
Pawan Shankar |
2025-08-13 |
402 |
--
|
|
Best Application Security Testing (AST) Tools Compared
|
Sarah Hartland |
2026-04-02 |
2,818 |
--
|
|
Endor Labs now integrates with Cursor AI Code Editor
|
Jamie Scott |
2025-07-24 |
472 |
--
|
|
n8mare on auth street: supply chain attack targets n8n ecosystem
|
Kiran Raj |
2026-01-09 |
1,708 |
--
|
|
8 Best SCA Security Tools for 2026, Ranked by Signal-to-Noise
|
Sarah Hartland |
2026-04-22 |
2,710 |
--
|
|
Test-First Prompting: Using TDD for Secure AI-Generated Code
|
Jenn Gile |
2026-02-04 |
855 |
--
|
|
Proactive Protection from Malware Attacks
|
Malware |
2025-09-23 |
438 |
--
|
|
Meet the application security platform built for the AI era
|
Amod Gupta |
2025-04-23 |
1,432 |
--
|
|
Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks …
|
Cris Staicu |
2026-03-02 |
1,743 |
--
|
|
What Is Package Integrity? Definition and Best Practices
|
-- |
2026-05-06 |
2,071 |
--
|
|
Agent Security League: Evaluating the Security of AI-Coded Software
|
Luca Compagna |
2026-04-15 |
173 |
--
|
|
The Dangers of Reusing Protobuf Definitions: Critical Code Execution in protobuf.js (GHSA-xq3m-2v4x-88gg)
|
Cris Staicu |
2026-04-17 |
3,141 |
--
|
|
How to Discover Open Source AI Models in Your Code
|
Rachel Lim |
2025-01-28 |
1,456 |
--
|
|
How to Secure AI Models in Production Environments
|
-- |
2026-05-06 |
2,461 |
--
|
|
Understanding NPM Worms and the Shai-Hulud Attack
|
Robert Haynes |
2025-11-25 |
1,563 |
--
|
|
How Endor Labs Is Supporting Bryce, a Next-Gen AppSec Builder
|
Aya Estrin |
2025-11-21 |
1,157 |
--
|
|
Happier DOMs: The perils of running untrusted JavaScript code outside of a …
|
Cris Staicu |
2025-11-11 |
1,911 |
--
|
|
Endor Labs for Software & Tech
|
Security |
2026-07-27 |
228 |
--
|
|
People.ai Transforms Security and Compliance with Endor Labs
|
Jenn Gile |
2025-07-01 |
1,354 |
--
|
|
Top 10 Semgrep Alternatives for AppSec Teams in 2026
|
Sarah Hartland |
2026-03-18 |
3,217 |
--
|
|
Endor Labs + Cursor: Building the security foundation for agentic coding
|
Andrew Davidson |
2026-05-28 |
996 |
--
|
|
Claude Fable 5, take two: same model, different harness, and a very …
|
Luca Compagna |
2026-06-17 |
2,306 |
--
|
|
npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised
|
Henrik Plate |
2025-09-16 |
972 |
--
|
|
StackHawk + Endor Labs: Correlating SAST and DAST Alerts
|
Eli Scherr |
2025-11-20 |
488 |
--
|
|
How the EU Cyber Resilience Act (CRA) rewrites the rules of software …
|
Andrew Stiefel |
2026-03-13 |
1,550 |
--
|
|
GitHub Action tj-actions/changed-files supply chain attack: what you need to know
|
Dimitri Stiliadis |
2025-03-15 |
840 |
--
|
|
Agentic Remediation: Remediation at Machine Speed, Grounded in Security Context
|
AI/ML |
2026-07-27 |
221 |
--
|
|
AI-Generated Malware Risk: A Practical Guide for Developers
|
Endor Labs |
2026-04-09 |
1,740 |
--
|
|
Critical Security Controls for Governing AI Coding Agents
|
Robert Haynes |
2026-07-29 |
1,732 |
--
|
|
SCA Remediation: A Complete Guide for AppSec Teams
|
Open Source |
2026-07-31 |
1,380 |
--
|
|
How to Automate Vulnerability Remediation in 2026
|
Open Source |
2026-07-31 |
1,928 |
--
|
|
Mean Time to Remediate (MTTR): How to Measure It and Cut It
|
-- |
2026-08-01 |
1,098 |
--
|
|
What Is Reachability Analysis and Why Does It Matter?
|
Open Source |
2026-07-31 |
1,681 |
--
|
|
Upgrade Impact Analysis: Patch Without Breaking Your Build
|
Open Source |
2026-07-31 |
1,398 |
--
|
|
Automated Dependency Updates Done Right: A Security-First Guide
|
Open Source |
2026-07-31 |
1,603 |
--
|
|
What Is Agentic Remediation? The Complete Guide
|
-- |
2026-07-31 |
1,628 |
--
|
|
How AI Vulnerability Remediation Actually Works in 2026
|
AI/ML |
2026-07-31 |
1,747 |
--
|
|
Top Vulnerability Remediation Tools for AppSec Teams in 2026
|
DevSecOps Tools |
2026-07-31 |
2,540 |
--
|
|
Agentic Remediation vs. Manual Patching: What Changes When AI Fixes Vulnerabilities
|
Open Source |
2026-07-31 |
1,047 |
--
|