Mend.io Application Security

TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog cover TEAM PCP attack V2

TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer

Check and fix your install for the new LiteLLM PyPI compromise.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog cover CanisterWorm

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

Deep dive into the self-spreading CanisterWorm.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Mend Partnership Expansion 1000x650

Mend.io Expands Its Global Infrastructure with a Dedicated Cloud Region in India

Local cloud infrastructure in India for data residency requirements.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Claude code security

Why Claude Code Security Is a Big Moment for Application Security

Discover why enterprise scale requires more than just AI code review - it requires governance.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Cover Open Source Security with AI

You can’t rely on open source for security — not even when AI is involved

Learn how to manage OSS risk and build remediation that actually lands.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog BlackDuck SAST

Understanding Black Duck SAST: Pros/Cons and Technical Architecture

A detailed review of Black Duck SAST plus a Mend SAST alternative.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog BlackDuck SCA

Black Duck SCA: Pros/Cons, Architecture, and Quick Tutorial

A detailed review of Black Duck SCA plus a Mend SCA alternative.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Veracode SAST

Understanding Veracode SAST: Pros/Cons, Architecture, and Pricing

A detailed review of Veracode SAST plus a Mend SAST alternative.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Veracode SCA

Veracode SCA Solution Overview: Features, Limitations, and Tutorial

A detailed review of Veracode SCA plus a Mend SCA alternative.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Announcement post Azi Cohen

Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth

An update on Mend.io's leadership as we enter the next phase of growth.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - ServiceNow Blog Featured image

Why AppSec and Network Risk Management Must Be Unified in the Modern Enterprise

See how Mend.io’s ServiceNow integration unifies application, network, and operational risk.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - blog post npm fake font packages

NPM User Flooding Registry with Fake Font Packages

Analysis of an npm account flooding the registry with malformed font packages.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog critical CVE 2025 55182

From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications

Discover a critical security flaw that enables remote code execution in React Server Components.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Mend Wiz integration graphic

Mend.io + Wiz: A New Code-to-Cloud Integration for Accurate, Context-Driven Risk Prioritization

See how Mend.io and Wiz deliver true code-to-cloud visibility.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog cover Top 7 AST providers post 1

Best Application Security Testing Providers: Top 7 in 2025

Discover how AST providers help teams find and fix vulnerabilities.

Read More
TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer - Blog Zero day Shai hulud V2

Shai-Hulud: The Second Coming

See how the latest Shai-Hulud attack works.

Read More

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.