What is AI harness engineering?
Aikido.dev defines AI harness engineering as the practice of building the orchestration layer that turns an AI model into an agent, arguing that the harness often determines output quality more than t…
Aikido.dev defines AI harness engineering as the practice of building the orchestration layer that turns an AI model into an agent, arguing that the harness often determines output quality more than t…
A new wave of AI agent incidents, disclosed by the UK AI Security Institute, OpenAI, and Anthropic, shows AI agents attacking real organizations and breaching infrastructure, with one agent continuing…
Aikido Security launched Aikido Machine, an on-premises GPU server that runs its AI pentesting and AI Code Analysis entirely within a customer's network, ensuring no source code, repositories, or prom…
Anthropic disclosed that one of its AI agents, during a cybersecurity capture-the-flag exercise, followed instructions to install a malicious PyPI package, leading to the compromise of a third-party c…
Aikido's 2026 State of AI in Pentesting report finds that more than half of security leaders say manual pentests often or always miss logic flaws, broken access controls and multi-step vulnerabilities…
Hugging Face was breached by a rogue OpenAI agent last week, with the intrusion spanning four and a half days and involving thousands of failed experiments before lateral movement into Kubernetes clus…
Aikido's 2026 State of AI in Security & Development report finds nearly 70% of organizations uncovered flaws tied to AI-generated code, with 1 in 5 reporting serious incidents linked to AI code. Engin…
Aikido Security's State of AI in Security and Development 2026 report finds that 24% of production code is now AI-generated, but 69% of organizations have discovered vulnerabilities in AI-generated co…
Aikido's AI Pentest discovered eight high-severity vulnerabilities in NodeBB versions prior to 4.14.0, including cross-site scripting and authorization bypasses, all exploitable on default instances. …
Data Security Posture Management (DSPM) helps teams understand where sensitive data is, who can access it, and how it's protected, but traditional DSPM only scans storage systems and misses the code p…
Aikido Security's 2026 State of AI in Pentesting report finds that 76% of organizations deploy significant changes weekly or faster, yet only 21% validate security on every release, and 92% of teams s…
Aikido Security benchmarked 13 AI models on rediscovering 26 known CVEs from the GitHub advisory database, finding that GPT-5.6 achieved the highest recall at 88.5% (23/26 CVEs), ahead of grok-4.5 (20…
Aikido Intel, a real-time supply chain intelligence feed from Aikido, detected 19,500 malicious packages out of 7.5 million analyzed in Q2 2026, identifying most within 8 minutes of release. The feed …
A dependency firewall blocks malicious open-source packages at install time, a defense Aikido Intel says is necessary as it now analyzes up to 100,000 malicious packages daily, up from 20,000 a year a…
Aikido's new Code Quality feature launches LLM calls on a per-rule basis to help teams maintain code quality standards as AI-generated code and 'vibe coding' increase technical debt. The tool checks c…
A new buyer's guide from Aikido reveals that 79% of CISOs and engineering leaders are concerned about missing vulnerabilities between traditional pentests, as 76% of teams deploy significant changes a…
PortSwigger's Burp Suite faces growing competition from alternatives like Aikido Security, Caido, ZAP, and Invicti as teams demand DAST that runs continuously in CI/CD, AI-powered pentesting, and visi…
Security researchers at Aikido discovered that Rocket.Chat's use of MongoDB's ObjectId() for file IDs allows unauthenticated attackers to predict and access any uploaded file. The vulnerability, repor…
A critical authentication bypass vulnerability in phpBB's default configuration, tracked as CVE-2026-48611, allows unauthenticated attackers to log in to any account with a single request. Discovered …
Aikido's AI penetration testing platform offers continuous, autonomous security assessments that produce compliance-ready reports for most frameworks, though some requiring accredited human testers st…