Guides
Protect AI models, data, and systems
Test for behavioral risks in conversational AI
Mitigating risks and future trends
AppSec types, tools, and best practices
Automating dependency updates
Manage open source code
Keep source code safe
Improve transparency, security, and compliance
Pre-production scanning and runtime protection
Secure containerized applications
AI Risk Management: Process, Frameworks, and 5 Mitigation Methods
Learn how to identify, assess, and mitigate AI risks.
Why Claude Code Security Is a Big Moment for Application Security
Discover why enterprise scale requires more than just AI code review - it requires governance.
Securing the New Control Plane: Introducing Static Scanning for AI Agent Configurations
Announcing the launch of AI Agent Configuration Scanning.
You can’t rely on open source for security — not even when AI is involved
Learn how to manage OSS risk and build remediation that actually lands.
Understanding Black Duck SAST: Pros/Cons and Technical Architecture
A detailed review of Black Duck SAST plus a Mend SAST alternative.
Introducing Mend.io’s AI Security Maturity Survey + Compliance Checklist available today
A new tool to help security teams quantify AI risk and prepare for 2026 regulations.
LLM Red Teaming: Threats, Testing Process & Best Practices
A practical guide to LLM red teaming.
Black Duck SCA: Pros/Cons, Architecture, and Quick Tutorial
A detailed review of Black Duck SCA plus a Mend SCA alternative.
Automated Red Teaming: Capabilities, Pros/Cons, and Latest Trends
Learn how automated red teaming simulates cyberattacks at scale.
Understanding Veracode SAST: Pros/Cons, Architecture, and Pricing
A detailed review of Veracode SAST plus a Mend SAST alternative.
Veracode SCA Solution Overview: Features, Limitations, and Tutorial
A detailed review of Veracode SCA plus a Mend SCA alternative.
Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth
An update on Mend.io's leadership as we enter the next phase of growth.
Why AppSec and Network Risk Management Must Be Unified in the Modern Enterprise
See how Mend.io’s ServiceNow integration unifies application, network, and operational risk.
NPM User Flooding Registry with Fake Font Packages
Analysis of an npm account flooding the registry with malformed font packages.
MCP Security: 10 Key Elements to Secure and Critical Best Practices
Learn what MCP security is, key risks like prompt injection, and best practices.
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications
Discover a critical security flaw that enables remote code execution in React Server Components.
Never miss a post. Opt-out at any time.
You’re all set to receive our latest posts.
Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.