Aikido acquires Root to secure the supply chain
Aikido acquires Root to secure the software supply chain by using AI-generated patches for open-source vulnerabilities. Root's agent-native system produces hundreds of verified CVE patches daily witho…
Aikido acquires Root to secure the software supply chain by using AI-generated patches for open-source vulnerabilities. Root's agent-native system produces hundreds of verified CVE patches daily witho…
Palo Alto Networks completed its acquisition of Koi in April 2026 for an estimated $400 million, folding the startup's supply chain security technology into Cortex XDR and Prisma AIRS. Teams evaluatin…
A supply-chain attack on the @mastra AI-agent ecosystem saw an attacker republish 141 packages with a malicious dependency that targeted crypto wallets. The incident highlights how AI coding tools lik…
A coordinated malware campaign on the JetBrains Marketplace has compromised at least 15 IDE plugins, installed nearly 70,000 times, that steal AI provider API keys entered by users. The plugins, posin…
A supply chain attack compromised over 140 npm packages in the @mastra scope, including @mastra/core with 918K weekly downloads, by injecting a malicious dependency that executes a postinstall script …
Aikido launched Code Audit, a tool that uses agentic AI to find multi-step, logic-based vulnerabilities in source code, filling the gap between SAST and pentesting. The release follows Anthropic's wit…
Anthropic released Claude Fable 5, a public version of its Mythos Preview model, routing cybersecurity prompts to a less capable Opus 4.8 model for safety. The release follows Mythos Preview's debut a…
PostHog co-founder James Hawkins warns that the fragmentation of coding interfaces—from Slack bots to AI agents and MCP servers—is expanding the attack surface on developer devices faster than securit…
Aikido's AI pentesting tool discovered a critical authentication bypass vulnerability in phpBB, affecting tens of millions of users across thousands of forums. The flaw, present in versions up to 3.3.…
A new variant of the Miasma worm has been discovered exploiting npm's binding.gyp build file to execute malicious code during package installation, bypassing traditional package.json script audits. Th…
AI SAST is a new category of static application security testing where an AI reasons about code to find vulnerabilities like IDORs and business logic flaws that traditional rules-based SAST misses. It…
Mythos, despite being a top AI model, is not significantly ahead of competitors like GPT-5.5, and its hype is disproportionate to its actual improvement. The harness used to deploy AI models matters m…
A malicious npm package named 'codexui-android' posing as a legitimate remote web UI for OpenAI Codex has been stealing authentication tokens from developers for the past month. The package, which ach…
Independent security consultancy Doyensec found that Aikido's AI pentesting tool discovered 49 verified vulnerabilities versus XBOW's 31 in a head-to-head benchmark on two real applications, a 58% inc…
Developer workstations have become the primary target for software supply chain attacks, with attackers exploiting unmonitored endpoints to steal credentials and install malicious packages. Security t…