Mend.io Blog

Poisoned axios: npm account takeover, 50 million downloads, and a rat that vanishes after install

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

LATEST
Learn more

Filter & Search

Understanding black duck sast: pros/cons and technical architecture - blog blackduck sast

Understanding Black Duck SAST: Pros/Cons and Technical Architecture

A detailed review of Black Duck SAST plus a Mend SAST alternative.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog cover ai security maturity checklist

Introducing Mend.io’s AI Security Maturity Survey + Compliance Checklist available today

A new tool to help security teams quantify AI risk and prepare for 2026 regulations.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog best software composition analysis enterprise

Best Software Composition Analysis for Enterprise: Top 8 in 2026

Explore this guide to the best software composition analysis tools for large teams.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - llm red teaming blog image

LLM Red Teaming: Threats, Testing Process & Best Practices

A practical guide to LLM red teaming.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog blackduck sca

Black Duck SCA: Pros/Cons, Architecture, and Quick Tutorial

A detailed review of Black Duck SCA plus a Mend SCA alternative.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - automated red teaming

Automated Red Teaming: Capabilities, Pros/Cons, and Latest Trends

Learn how automated red teaming simulates cyberattacks at scale.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog veracode sast

Understanding Veracode SAST: Pros/Cons, Architecture, and Pricing

A detailed review of Veracode SAST plus a Mend SAST alternative.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog veracode sca

Veracode SCA Solution Overview: Features, Limitations, and Tutorial

A detailed review of Veracode SCA plus a Mend SCA alternative.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - announcement post azi cohen

Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth

An update on Mend.io's leadership as we enter the next phase of growth.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - servicenow blog featured image

Why AppSec and Network Risk Management Must Be Unified in the Modern Enterprise

See how Mend.io’s ServiceNow integration unifies application, network, and operational risk.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog post npm fake font packages

NPM User Flooding Registry with Fake Font Packages

Analysis of an npm account flooding the registry with malformed font packages.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog mcp security

MCP Security: 10 Key Elements to Secure and Critical Best Practices

Learn what MCP security is, key risks like prompt injection, and best practices.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog critical cve 2025 55182

From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications

Discover a critical security flaw that enables remote code execution in React Server Components.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - mend wiz integration graphic

Mend.io + Wiz: A New Code-to-Cloud Integration for Accurate, Context-Driven Risk Prioritization

See how Mend.io and Wiz deliver true code-to-cloud visibility.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog cover top 7 ast providers post 1

Best Application Security Testing Providers: Top 7 in 2025

Discover how AST providers help teams find and fix vulnerabilities.

Read More Read More
Understanding black duck sast: pros/cons and technical architecture - blog zero day shai hulud v2

Shai-Hulud: The Second Coming

See how the latest Shai-Hulud attack works.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.