Filter & Search

The butlerian jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP’s latest supply chain attack.

Read More Read More
Blog cover team pcp part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More Read More
Blog zero day visibility 1000x650

From Panic to Playbook: Modernizing Zero‑Day Response in AppSec

Learn how AppSec teams build a repeatable zero-day response workflow.

Read More Read More
Sast all about static application security testing post

What Is SAST – Static Application Security Testing

Learn about Static Application Security Testing (SAST).

Read More Read More
Blog image red teaming companies

Best AI Red Teaming Tools: Top 7 Platforms and Services in 2026

The top 7 AI red teaming services and platforms in 2026, compared.

Read More Read More
Blog image sca tools 1

Best Software Composition Analysis (SCA) Tools: Top Solutions in 2026

Learn what SCA tools do and how they help secure your open source dependencies.

Read More Read More
Blog project glasswing 1000x650

Anthropic’s Project Glasswing: How Claude Mythos is Changing the Rules for AppSec

See what AI-powered offense means for your AppSec & AI Security program.

Read More Read More
Docker hardened images integration

Container Security Without Context Is Just More Noise

Smarter container security with Docker Hardened Images.

Read More Read More
Blog ai application security 1000x650

AI Application Security: 6 Focus Areas and Critical Best Practices

Learn how AI application security differs from traditional AppSec.

Read More Read More
Blog cover poisoned axios

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

See how the attack works, what to look for, and how to remediate.

Read More Read More
Blog cover team pcp part 3

Famous Telnyx Pypi Package compromised by TeamPCP

See how the attack works, what to look for, and how to remediate.

Read More Read More
Blog graphic 58 generative ai statistics

62 Generative AI Statistics to Know in 2026

Explore 62 key generative AI statistics for 2026.

Read More Read More
Blog cover team pcp attack v2

TeamPCP Supply Chain Attack Part 2: LiteLLM PyPI Credential Stealer

Check and fix your install for the new LiteLLM PyPI compromise.

Read More Read More
Blog cover canisterworm

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

Deep dive into the self-spreading CanisterWorm.

Read More Read More
Cursor incident

Moonshot AI governance breakdown: Lessons from the Cursor/Kimi K2.5 incident

Cursor’s Composer 2 identified as Moonshot’s Kimi K2.5 exposing an AI governance gap.

Read More Read More
Blog mend partnership expansion 1000x650

Mend.io Expands Its Global Infrastructure with a Dedicated Cloud Region in India

Local cloud infrastructure in India for data residency requirements.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.