
.avif)
News

Move over, Mythos. Here comes... pretty much any other model with a good harness
Mythos has real edges in exploit chain construction. But for most AppSec work, the harness around the model matters more than which model you pick.
Full Fathom Five: The context of Anthropic’s Mythos-class public release
You never needed Mythos to find your IDORs and business logic flaws. A look at what Anthropic shipped with Fable 5, and why infosec stays a people problem at heart.
npm v12 delivers one of the biggest security improvements in years
npm v12 makes install scripts opt-in by default, closing the install-time execution path behind a year of npm supply chain worms from Nx to Red Hat.
Code is being written everywhere, and the device is the only constant
Developers are coding everywhere. AI agents, Slack bots, and MCP servers have made the developer device the biggest security blindspot.
SBOMs in 2026: Everyone's generating them, no one's using them
ENISA's 2026 SBOM adoption report covers 334 organizations and surfaces a consistent gap between generating SBOMs and actually using them. Here is what stood out.
Why EDR and proxy won’t save you from supply chain malware
EDR and proxies weren't built for supply chain malware. When malicious code arrives through npm install, it looks like normal behavior. Here's why that matters.
Move over, Mythos. Here comes... pretty much any other model with a good harness
Mythos has real edges in exploit chain construction. But for most AppSec work, the harness around the model matters more than which model you pick.
Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark
Aikido vs XBOW compared in an independent benchmark by Doyensec. Aikido found 58% more vulnerabilities at the same price. See setup time, false positive rates & full results
Why developer machines are now the number one target for supply chain attacks
Teams at Omnea, Cognism, Glasswall, Raisin and the UK public sector reveal why EDR and MDM miss what's really happening on developer machines.
Shadow AI is a fear response, and banning it makes it worse
Employees aren't using unapproved AI tools to cause problems. They're scared of falling behind. Here's why banning shadow AI increases your security risk, and what to do instead.
Reliable CVE sources in the age of NIST NVD cutbacks
NIST will no longer enrich most CVEs. Here's what changes, what breaks, and what comes next.
Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



