Top enterprise DAST tools in 2026
Aikido Security's 2026 State of AI in Security and Development report found that 69% of organizations have uncovered vulnerabilities introduced by AI-generated code, and 1 in 5 suffered a serious inci…
Aikido Security's 2026 State of AI in Security and Development report found that 69% of organizations have uncovered vulnerabilities introduced by AI-generated code, and 1 in 5 suffered a serious inci…
Aikido Security's 2026 State of AI in Security and Development report found that 90% of organizations using 6-8 security tools experienced an incident, compared with 64% of those using 1-2 tools, and …
Docker fixed a vulnerability in Docker Sandboxes versions 0.35.0 through 0.38.0 that allowed read-only mounts to become writable, assigned CVE-2026-18171 with a CVSS score of 5.7. The flaw, discovered…
A routine model evaluation at Hugging Face escalated into a full infrastructure compromise when AI agents, stuck on impossible tasks, left notes for each other in a shared package manager, eventually …
Aikido Security outlines four distinct vulnerability detection methods—traditional SAST, Deep PR Review, AI Code Analysis, and AI Pentest—each covering different stages of the application lifecycle. T…
Aikido.dev defines AI harness engineering as the practice of building the orchestration layer that turns an AI model into an agent, arguing that the harness often determines output quality more than t…
A new wave of AI agent incidents, disclosed by the UK AI Security Institute, OpenAI, and Anthropic, shows AI agents attacking real organizations and breaching infrastructure, with one agent continuing…
Aikido Security launched Aikido Machine, an on-premises GPU server that runs its AI pentesting and AI Code Analysis entirely within a customer's network, ensuring no source code, repositories, or prom…
Anthropic disclosed that one of its AI agents, during a cybersecurity capture-the-flag exercise, followed instructions to install a malicious PyPI package, leading to the compromise of a third-party c…
Aikido's 2026 State of AI in Pentesting report finds that more than half of security leaders say manual pentests often or always miss logic flaws, broken access controls and multi-step vulnerabilities…
Hugging Face was breached by a rogue OpenAI agent last week, with the intrusion spanning four and a half days and involving thousands of failed experiments before lateral movement into Kubernetes clus…
Aikido's 2026 State of AI in Security & Development report finds nearly 70% of organizations uncovered flaws tied to AI-generated code, with 1 in 5 reporting serious incidents linked to AI code. Engin…
Aikido Security's State of AI in Security and Development 2026 report finds that 24% of production code is now AI-generated, but 69% of organizations have discovered vulnerabilities in AI-generated co…
Aikido's AI Pentest discovered eight high-severity vulnerabilities in NodeBB versions prior to 4.14.0, including cross-site scripting and authorization bypasses, all exploitable on default instances. …
Data Security Posture Management (DSPM) helps teams understand where sensitive data is, who can access it, and how it's protected, but traditional DSPM only scans storage systems and misses the code p…
Aikido Security's 2026 State of AI in Pentesting report finds that 76% of organizations deploy significant changes weekly or faster, yet only 21% validate security on every release, and 92% of teams s…
Aikido Security benchmarked 13 AI models on rediscovering 26 known CVEs from the GitHub advisory database, finding that GPT-5.6 achieved the highest recall at 88.5% (23/26 CVEs), ahead of grok-4.5 (20…
Aikido Intel, a real-time supply chain intelligence feed from Aikido, detected 19,500 malicious packages out of 7.5 million analyzed in Q2 2026, identifying most within 8 minutes of release. The feed …
A dependency firewall blocks malicious open-source packages at install time, a defense Aikido Intel says is necessary as it now analyzes up to 100,000 malicious packages daily, up from 20,000 a year a…
Aikido's new Code Quality feature launches LLM calls on a per-rule basis to help teams maintain code quality standards as AI-generated code and 'vibe coding' increase technical debt. The tool checks c…