May 2026 Summaries
25 posts from Endor Labs
Filter
Month:
Year:
Post Summaries
Back to Blog
Cursor and Endor Labs are collaborating to enhance the security and productivity of engineering teams using agentic coding tools. As the use of AI-driven coding agents increases, so does the need for robust security measures, especially in regulated industries like finance and healthcare. This partnership aims to provide seamless integration of security features without hindering the speed of development. Cursor, known for prioritizing enterprise security, has integrated Endor Labs' AURI to offer visibility into agent activities and enforce policy compliance across workstations. The collaboration includes features such as monitoring, deterministic policy enforcement, and a package firewall to block malicious dependencies. By ensuring that AI-generated code is governable, traceable, and defensible, the partnership allows companies to adopt agentic coding at scale. The initiative underscores the importance of balancing coding velocity with security, with a focus on maintaining audit-ready processes that are defensible before corporate executives and boards.
May 28, 2026
996 words in the original blog post.
Endor Labs has developed a sophisticated reporting system that caters to the diverse workflows of developers, compliance leads, and AppSec engineers, addressing the unique needs of each group. Initially, reports were simple CSV exports for quick checks, but as the platform integrated deeper into security programs, the reports evolved to accommodate complex tasks like audit artifacts, quarterly trend reports, and automation pipelines. By understanding the distinct rhythms of each user type—developers needing seamless flow, compliance leads requiring durable and shareable audit documents, and AppSec engineers integrating data into broader pipelines—the system is designed to be versatile yet unified. Reports run as background jobs, allowing users to trigger them and continue their work without interruption. The platform's new Reports page centralizes access, ensuring consistency and adaptability across different use cases, all while maintaining a single reporting system that supports both UI and API access, thus empowering teams to operate independently and efficiently.
May 27, 2026
1,288 words in the original blog post.
Endor Labs has been recognized as a Representative Vendor in the Gartner® Hype Cycle™ for Platform Engineering, 2026, within the Software Supply Chain Security category, underscoring the importance of embedding security within the software development lifecycle (SDLC) rather than treating it as an add-on tool. The company addresses the challenge of managing exponentially increasing vulnerabilities in third-party code by utilizing AI coding assistants and internal developer platforms (IDPs) to integrate security seamlessly into platform architecture. Endor Labs' approach involves a graph-based model that provides engineering and security teams with detailed context, allowing them to manage vulnerabilities more effectively through function-level reachability and upgrade impact analysis. This strategy is particularly critical given the rise of AI, which accelerates the time-to-exploit window and shifts traditional security paradigms. The company's roadmap focuses on enhancing platform engineering capabilities, securing semi-autonomous cloud agent pipelines, and expanding security tools for AI agents, ensuring engineering teams can govern their environments with precision and minimal disruption.
May 21, 2026
916 words in the original blog post.
Endor Labs discovered a significant malware campaign affecting the npm ecosystem on May 19, 2026, identifying 42 initial malicious packages, which later expanded to 633, including many dormant and widely-used packages like jest-canvas-mock and size-sensor. The campaign, propagating swiftly across the AntV ecosystem, utilized a novel method of Sigstore provenance forgery, making malicious packages appear legitimate by embedding a payload that generates valid Sigstore attestations. Attackers targeted dormant accounts, exploiting their inactivity to compromise them with minimal detection risk, and used two types of delivery mechanisms: phantom commit droppers and embedded payloads. The attack also involved credential harvesting and persistence mechanisms, with a primary exfiltration channel disguised as legitimate traffic. The breadth of the compromise suggests the use of a single stolen npm token for the AntV organization, while the worm's ability to produce valid provenance without authorization highlights a need for defensive strategies that do not rely solely on provenance verification.
May 19, 2026
2,493 words in the original blog post.
Endor Labs has partnered with Chainguard to enhance software supply chain security by integrating their solutions to tackle vulnerability debt and risk verification at a granular level. This collaboration addresses the growing threat of supply chain attacks by combining Chainguard's zero-CVE container images and libraries with Endor Labs' precise risk verification capabilities, offering a unified and authoritative view of container vulnerability data. The integration provides security teams with a verified chain of trust and operational efficiency by reducing false alerts and focusing remediation efforts on genuinely reachable vulnerabilities. This partnership benefits different teams, from security and AppSec to DevOps and AI development, by embedding security measures in the development pipeline, thus reducing the need for extensive patching while meeting regulatory requirements. The partnership aims to provide a robust defense-in-depth posture that enhances security without disrupting existing workflows, and the integration will soon be available, initially focusing on Chainguard container images.
May 19, 2026
757 words in the original blog post.
Endor Labs identified a significant security breach involving three compromised versions of the durabletask package, a Python SDK for Microsoft's Azure Durable Functions, which were discovered on May 19, 2026. These versions, numbered 1.4.1, 1.4.2, and 1.4.3, contained malicious code that executed upon import, posing a severe threat as it targeted various cloud service credentials including AWS, Azure, and GCP, among others. Notably, the malware was designed to operate quietly, without generating errors or visible signs, making detection challenging. It was specifically configured to affect Linux systems and included a payload capable of wiping filesystems and facilitating lateral movement to AWS ECS and Kubernetes pods. The attackers employed sophisticated exfiltration methods, using credentials to interact with GitHub's API for data transfer, and the malware's execution path was meticulously crafted to appear as routine network activity. The incident underscores the importance of vigilant monitoring, restricting CI/CD permissions, and employing hash pinning in software development practices to mitigate such threats.
May 19, 2026
1,932 words in the original blog post.
Endor Labs has developed AI Coding Agent Governance to address the evolving risks in developer environments by integrating AI coding agents that operate beyond the codebase, affecting workstations with access to critical resources. The platform is designed for three key user groups: engineering and security leaders, security teams, and agent developers, each with specific roles in managing AI risks. To accommodate these diverse needs, the platform integrates seamlessly into existing workflows, offering a unified user experience while maintaining distinct risk assessment criteria for different technologies like MCP servers and open-source packages. The governance system is structured to ensure that policies are actionable, with a Policy Violations page that provides a detailed, consistent framework for security teams to review and respond to incidents effectively. By enabling a cohesive risk management approach, the platform aids in tracking and controlling AI-related activities across organizations, while remaining adaptable to future security challenges.
May 18, 2026
1,609 words in the original blog post.
Recent disclosures have highlighted vulnerabilities in widely used coding agents, specifically Claude Code, Gemini CLI, and GitHub Copilot, with three distinct attacks emphasizing the failures of platform guardrails and the need for a universal governance layer. These attacks include a chain of command-injection CVEs in Claude Code, a cross-vendor prompt-injection attack exploiting GitHub comments, and a deny-rule bypass in Claude Code due to subcommand limits. The common issue across these platforms is the breakdown of internal security measures, suggesting that a platform-agnostic governance layer using hooks can effectively mitigate such threats. Hooks, which intercept tool calls, file reads, and more, provide a centralized policy management solution that transcends individual agent platforms, making them an appealing choice for enterprises operating multiple coding agents. While not a replacement for comprehensive sandboxing, hooks offer a critical first layer of defense that can adapt across different vendor environments, addressing vulnerabilities in the middle stages of attack chains and highlighting the importance of cross-platform security strategies.
May 18, 2026
1,811 words in the original blog post.
Endor Labs has joined the Wiz Integration Network (WIN) to enhance its partnership with Wiz, a leader in cloud security, aiming to help mutual customers reduce cloud risks and prioritize application vulnerabilities. The collaboration integrates Endor Labs' reachability-enriched Software Composition Analysis (SCA) and AI-powered Static Application Security Testing (SAST) with Wiz's security framework, providing users with a unified, actionable view of risk from code to cloud. By combining noise-free vulnerability prioritization and code-to-cloud attack path visibility, the partnership allows security teams to focus on the most impactful vulnerabilities, trace vulnerabilities across environments, and achieve faster remediation of critical threats. This integration aims to streamline cloud security by offering a comprehensive view of application risk correlated with cloud exposure, enhancing collaboration between security and engineering teams, and strengthening the WIN ecosystem for cloud security operations.
May 15, 2026
402 words in the original blog post.
In May 2026, a sophisticated supply-chain attack was executed on the npm registry, targeting 42 @tanstack/* packages through 84 malicious versions, despite the presence of rigorous security measures such as two-factor authentication and OIDC trusted publishing. The attack exploited overlooked vulnerabilities in GitHub Actions, specifically using the "Pwn Request" pattern to run fork-controlled code in a trusted context, cache poisoning across trust boundaries, and extracting OIDC tokens from runner memory. This allowed the attacker to publish malicious packages without stealing credentials or bypassing established security controls. The attack chain involved PR-time cache poisoning, erasing evidence, leveraging legitimate pushes to main, and stealing tokens for unauthorized publishing, all while maintaining the appearance of legitimate operations. The incident highlights the challenges of defending against attacks that exploit legitimate workflow behaviors and emphasizes the need for stronger isolation boundaries and more granular trust models in CI/CD systems to prevent similar compromises in the future.
May 14, 2026
2,512 words in the original blog post.
In September 2025, the Shai-Hulud worm rapidly propagated through npm by compromising maintainer credentials to publish altered versions of legitimate packages, affecting hundreds of packages within hours. This incident illustrates a growing trend where attackers bypass traditional vulnerabilities by directly distributing malicious code, signed by trusted maintainers, to developers. The document discusses the limitations of traditional Software Composition Analysis (SCA) in detecting open-source malware and introduces Endor Labs' advanced detection engine, which uses a combination of code analysis, metadata, maintainer behavior, and install-time analysis, enhanced by LLM-based reasoning, to deliver precise verdicts. Additionally, it highlights the Package Firewall's role in translating these verdicts into immediate enforcement during installations, using YAML policy, version range matching, and minimum-age controls to prevent malware from reaching developer environments. The paper also identifies four primary malware delivery methods and explains how the Firewall intercepts each before they can compromise a developer's system.
May 12, 2026
201 words in the original blog post.
AI coding harnesses such as Claude Code and Cursor are increasingly used by software development teams for tasks ranging from writing code to executing shell commands, but their capabilities also present security risks if not properly managed. To address these concerns, a security layer known as "hooks" is utilized, which provides a deterministic and auditable means to oversee the actions of AI agents. Hooks work by intercepting lifecycle events within the coding harness, allowing scripts to determine whether specific actions should be allowed, denied, or modified, thereby offering an additional layer of security beyond the AI model itself. This system is supported by platforms like Endor Labs, which centralize policy enforcement and audit trails, ensuring consistent application of security measures across all developers' environments. Hooks, while simple in concept, are crucial for enabling enterprise security teams to adopt AI coding agents with confidence, enabling auditability, policy enforcement, and protection against unauthorized actions.
May 12, 2026
1,607 words in the original blog post.
AI coding agents have transitioned from simple assistants to complex systems capable of writing code, managing dependencies, and engaging with external services, but this evolution has expanded the digital attack surface, challenging traditional security measures. In response to this, Endor Labs has introduced Coding Agent Governance and Package Firewall, integrated with the AURI platform, to address the rising threat of software supply chain attacks that target these agentic environments. These new capabilities provide a security layer across various AI coding agents, offering visibility and control over systems generating code, including monitoring agent usage, model interactions, and potential compliance gaps. With the ability to enforce policies and detect high-risk patterns, these tools aim to safeguard enterprises by preventing unauthorized actions and blocking malicious packages before they reach development environments. Through collaborations with companies like Cursor and Google Cloud, Endor Labs enhances security intelligence, ensuring that businesses can scale AI-native workflows securely while maintaining the necessary oversight and governance.
May 12, 2026
991 words in the original blog post.
Endor Labs has introduced Package Firewall, a new feature on the AURI platform designed to block malicious, vulnerable, and non-compliant open-source packages before they are accessed by AI coding agents. Positioned between developer machines, private package registries, CI pipelines, and public registries, the firewall filters every install request, ensuring that known malicious packages are blocked and clean ones proceed normally. Integrated with Endor Labs' policy engine, it allows for the enforcement of security policies and license compliance, facilitating the blocking of packages with known vulnerabilities or those that do not match specified license policies. The firewall can be deployed through integration with private package registries or via endpoint mode, making it adaptable to various development environments. The need for such a tool is underscored by a significant increase in open-source software supply chain attacks, with the firewall's real-time malware detection capabilities offering rapid response times. Endor Labs' system employs AI-enhanced analysis to identify malicious packages across major open-source ecosystems quickly, reporting them to registries like npm and PyPI for swift removal.
May 12, 2026
705 words in the original blog post.
In May 2026, attackers compromised over 160 package versions in the npm ecosystem, embedding credential-stealing malware within popular libraries, particularly targeting GitHub Actions secrets and other sensitive credentials. The attack, part of the Shai-Hulud malware family, marked its fifth occurrence within eight months and the second in two weeks. It exploited a novel technique involving an orphaned commit pushed to a fork of the TanStack repository, enabling the attacker to acquire a legitimate short-lived npm publish token despite TanStack's adherence to security measures like 2FA and OIDC trusted publishing. The campaign's payload, obscured by sophisticated obfuscation techniques, allowed for widespread deployment and replication, leveraging GitHub's shared object storage and bypassing branch protection rules. This attack is a significant escalation in the technical sophistication of the Shai-Hulud campaigns, highlighting vulnerabilities in dependency management and the importance of narrowing OIDC trust scopes to prevent unauthorized workflows.
May 11, 2026
2,916 words in the original blog post.
The text provides an overview of various security vulnerabilities and risks identified in different software and systems, ranging from low to high risk levels. It includes specific details about vulnerabilities such as remote code execution, command injection, and cryptographic weaknesses affecting platforms like Linux, IBM Db2, and Spring Boot, among others. The text also highlights the availability of reports and guides related to building effective software security programs, evaluating AI-coded software security, and responding to supply chain attacks. Additionally, it mentions the role of Endor Labs in providing patches that offer maintainer-approved fixes compatible with older software versions, allowing for security enhancements without immediate full upgrades.
May 07, 2026
1,060 words in the original blog post.
Claude Mythos, Anthropic's generative AI model, is tailored for extended autonomous reasoning and has demonstrated notable capabilities in cybersecurity by identifying zero-day vulnerabilities in open source code that had previously eluded human detection. Unlike previous AI models that assisted with code reviews, Mythos operates more like an independent researcher, conducting sustained, goal-directed work without continuous human guidance. It was developed through Anthropic's Project Glasswing, which focused on creating AI systems capable of maintaining context and pursuing multi-step goals autonomously. During testing, Mythos discovered long-standing vulnerabilities, such as a 27-year-old TCP flaw in OpenBSD and a 16-year-old issue in FFmpeg, while also generating working exploits and reverse-engineering binaries. Despite its advancements, Mythos accelerates rather than revolutionizes existing vulnerability discovery processes, and it functions most effectively in controlled environments with well-defined objectives. Its emergence signals an era where software security teams must adapt to faster and more frequent vulnerability findings, emphasizing the need for reachability analysis to prioritize actual risks amidst an increased volume of potential issues.
May 07, 2026
1,818 words in the original blog post.
Secure AI workflows are necessary to address the unique security challenges introduced by AI coding assistants, which generate code faster than traditional security tools can keep pace with. These workflows integrate security controls directly into the code generation process, providing real-time guidance rather than acting as barriers, and encompass a range of elements from AI coding assistants and dependencies to container security and policy enforcement. Traditional security measures, designed for slower, human-paced development, struggle to manage the rapid output and novel vulnerabilities associated with AI-generated code, such as logic flaws, vulnerable dependencies, and exposed secrets. Inline security measures, including real-time vulnerability scanning and context-aware credential validation, help mitigate these risks by providing immediate feedback to developers. Additionally, policies as code and reachability analysis ensure consistent security enforcement across different AI tools and development environments, reducing false positives and enabling streamlined compliance with regulatory frameworks such as FedRAMP and the EU Cyber Resilience Act. Security tools that effectively integrate with AI coding assistants and continuous integration/continuous deployment (CI/CD) pipelines allow for immediate remediation and maintain development velocity without compromising security.
May 06, 2026
2,236 words in the original blog post.
AI systems present unique security challenges that extend beyond the capabilities of traditional security tools due to factors such as model behavior unpredictability, training data vulnerabilities, and prompt injection attacks, as well as the rapid generation of potentially vulnerable code by AI coding assistants like Cursor, Claude Code, and Copilot. While frameworks like the NIST AI Risk Management Framework (RMF) and the EU AI Act provide structural guidance, organizations often struggle with implementation. The risks associated with AI include supply chain attacks, adversarial inputs, model theft, data leakage, prompt injection, and algorithmic bias. Effective AI risk mitigation involves continuous risk assessment, policy enforcement, and secure development practices integrated into the software development lifecycle. The EU AI Act mandates risk-based requirements for AI systems, enforceable from August 2026, while the NIST AI RMF offers voluntary guidelines. AI risk management differs from traditional software security by requiring strategies that account for AI's distinct vulnerabilities and the speed at which AI-generated code can enter production.
May 06, 2026
2,058 words in the original blog post.
AI model risk assessment is a critical process that involves identifying, evaluating, and mitigating the risks associated with AI systems, including biases, security vulnerabilities, and unpredictable outputs. Given that AI models are comparable to software dependencies, they face similar supply chain risks, such as unknown provenance and hidden vulnerabilities, in addition to unique challenges like model drift and data bias. The assessment process typically includes inventorying models, assessing their impact, and applying frameworks like the NIST AI RMF and ISO/IEC standards to manage risks effectively throughout their lifecycle. Organizations prioritize AI risk assessment to avoid operational friction, meet regulatory compliance requirements, and protect business and reputational interests. Key risk categories include data risks, model risks, operational risks, and ethical/legal risks, each requiring specific mitigation strategies. Effective AI risk management also involves continuous monitoring and adopting best practices such as automating model discovery, integrating risk assessment into development pipelines, and establishing clear ownership of risk decisions. Various tools, including those from Endor Labs, aid in automating aspects of risk assessment while ensuring comprehensive governance and policy enforcement for AI models within organizations.
May 06, 2026
2,197 words in the original blog post.
Software distribution security, also known as software supply chain security, is crucial for protecting software from tampering, unauthorized access, and malicious code insertion throughout its lifecycle—from development to deployment. Modern software applications often comprise numerous components, including first-party code, third-party dependencies, container images, and build pipelines, each posing potential security risks. Key risks include compromised dependencies, malicious packages, vulnerable container images, exposed secrets, and unverified build pipelines. High-profile attacks, such as those on SolarWinds and Log4j, underscore the importance of securing the entire software supply chain. Distinct from traditional application security, which focuses on first-party code vulnerabilities, software distribution security encompasses the entire supply chain, using tools like Software Bill of Materials (SBOM), dependency analysis, and container scanning to mitigate risks. Best practices involve generating and monitoring SBOMs, analyzing dependencies, prioritizing vulnerabilities by reachability, and enforcing security policies as code. The approach requires continuous monitoring and automation to address challenges such as alert fatigue, dependency upgrade complexity, and scaling security with development velocity.
May 06, 2026
1,930 words in the original blog post.
AI model security is an emerging discipline focused on safeguarding machine learning systems from attacks that exploit their probabilistic nature, such as poisoned training data, adversarial inputs, and model extraction, which traditional application security tools often fail to address. As AI adoption grows, with models sourced from third-party APIs, open-source repositories, and AI coding assistants, the attack surface has expanded, prompting the need for robust AI security programs. This practice involves protecting key assets like training data, model weights, and inference endpoints while addressing business risks, regulatory pressures, and the diverse AI attack vectors that current security frameworks and standards, such as NIST AI RMF and OWASP ML Security Top 10, aim to manage. Implementing AI model security requires organizations to establish AI asset inventories, integrate security into development workflows, deploy continuous monitoring, and develop incident response capabilities tailored to AI threats. This also includes securing third-party AI models, managing AI-generated code risks, and fostering collaboration between security, data science, and engineering teams to ensure comprehensive governance and policy enforcement.
May 06, 2026
2,222 words in the original blog post.
In cybersecurity, the term "blast radius" refers to the extent of impact a vulnerability can have across systems, data, and users if exploited, similar to the fallout from a physical explosion. This concept has garnered attention due to the disclosure of BlastRADIUS (CVE-2024-3596), a critical vulnerability in the RADIUS authentication protocol that allows attackers to forge access responses without user credentials, affecting various systems using RADIUS over UDP. Mitigating this vulnerability involves enabling the Message-Authenticator attribute, updating RADIUS components, and segmenting network traffic. Beyond specific vulnerabilities, measuring blast radius involves evaluating the reachability of vulnerable code paths and dependencies, with tools providing full-stack analysis to differentiate between theoretically present and actually exploitable vulnerabilities. Reducing blast radius can be achieved through prioritizing reachable vulnerabilities, applying patches without major upgrades, segmenting networks, removing unused dependencies, and enforcing least privilege. Effective communication of blast radius to stakeholders involves translating technical details into potential business impacts and visualizing dependency paths, with tools like AURI from Endor Labs offering comprehensive visibility across application stacks.
May 06, 2026
1,926 words in the original blog post.
Package integrity in software development ensures that a software package from registries like npm, PyPI, or Maven is authentic, unmodified, and exactly as its maintainers intended to publish, safeguarding against tampering during distribution. Unlike physical packaging integrity in industries like pharmaceuticals, which focuses on preventing contamination with seal testing, software package integrity utilizes cryptographic methods such as checksums, signatures, and provenance attestations. The importance of package integrity is highlighted by the risk of compromised packages propagating through software supply chains, leading to unauthorized code execution, credential theft, and build pipeline compromises. Common threats include malicious package injection, dependency confusion, typosquatting, compromised maintainer accounts, and build system tampering. To combat these, methods like cryptographic signature verification, checksum validation, provenance attestation, behavioral analysis, and Software Bills of Materials (SBOM) integrity validation are employed. Tools and practices in CI/CD pipelines facilitate pre-commit verification, build-time integrity checks, and continuous monitoring to ensure ongoing security, with full-stack reachability analysis helping prioritize real risks over false alarms.
May 06, 2026
2,071 words in the original blog post.
AI models in production environments face a unique set of threats that are not addressed by traditional application security tools, necessitating specialized controls throughout their lifecycle. These threats include model extraction, adversarial inputs, prompt injection, data poisoning, and risks associated with insecure model formats. The probabilistic nature of AI systems creates a different attack surface compared to deterministic traditional applications, requiring protection of model artifacts, training data, and inference endpoints. To mitigate these risks, techniques such as cryptographic signing, encryption, and secure registries are used to safeguard model artifacts, while hardening deployment infrastructure and implementing secrets management protect inference environments. Additionally, securing the AI model supply chain involves vetting third-party models, dependency scanning, and generating a Software Bill of Materials (SBOM) for compliance. Runtime protections like input validation, rate limiting, and output monitoring help defend models during inference, while layered defenses are necessary to counter prompt injection attacks. AI model governance incorporates role-based access, policy enforcement, and compliance with emerging regulations, allowing for scalable security without hindering engineering productivity. As AI systems evolve, continuous monitoring and incident response tailored to AI are critical to maintain security and address any emerging vulnerabilities.
May 06, 2026
2,461 words in the original blog post.