
.avif)
Welcome to our blog.

The upgrade trap: when upgrading is the wrong answer to a CVE
"Upgrade to fix it" assumes that a fixed version exists, that it's shipped and that it won't break your app. Often none of these are true. This is the "upgrade trap," where both upgrading and not upgrading come with security risks and breaking prod. We look at what the way out looks like.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

Vulnerabilities & Threats
Cut through the noise with real-world CVE breakdowns, malware analysis, exploits, and emerging risks.
Customer Stories
See how teams like yours are using Aikido to simplify security and ship with confidence.
Better generic secrets detection starts with finding non-secrets
Some API keys are meant to be public. Betterleaks now removes them from generic secret findings, dropping thousands of false positives per scan.
Finding eight high-severity vulnerabilities in NodeBB in six hours
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.
SQL injection isn't dead
The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it.
Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Tyro CISO Arun Singh on developer trust as a finite resource, and what happens when supply chain attacks force teams to spend it
Benchmarking 13 AI models on rediscovering known CVEs
We tested 13 AI models on finding 26 known CVEs. GPT-5.6 found the most, but the priciest model wasn't the best use of budget.
The practical checklist for defending against supply chain attacks
Thirty prioritized defenses against the recent wave of software supply chain attacks. Graded critical, high, or medium.
How to maintain code quality standards with AI code and vibe coding
Vibe coding ships features fast and leaves review debt behind. See how benchmarked, per-rule code quality checks give teams one consistent answer across PRs and repos.
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry
A malicious release of @injectivelabs/sdk-ts hid a wallet-key stealer inside code labeled as usage telemetry, then spread it across 17 more npm packages. Here's how it worked and how to check your projects.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and an evaluation checklist.
How Aikido Intel detects malware and vulnerabilities first
Aikido Intel is a real-time feed that catches malware and undisclosed vulnerabilities across open-source ecosystems, often within 8 minutes of release.
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
SleeperGem: two dormant RubyGems maintainer accounts were hijacked to inject malware into trusted gems, one with over 500,000 total downloads
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



