Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

That's a wrap: Mend.io at Black Hat USA 2026

Another Black Hat USA is in the books, and what a week it was. From a main stage keynote at the AI Summit to candid podcast conversations, a video interview with Cyber Defense Magazine, and a booth game that just wouldn’t quit, Mend.io showed up in Las Vegas ready to talk about the question every security leader is wrestling with right now: as AI reshapes both the software we ship and the systems we have to defend, who do we trust to verify that it’s safe?

Patch faster isn't the answer. Patch smarter is.

The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours.

Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

On August 4, 2026, a malicious version of keyv was published to npm as keyv@6.0.0, one of a number of npm packages affected across the Keyv and Cacheable ecosystem. The release follows the Mini Shai-Hulud pattern: a trojanized version of a heavily depended-on package, with an install-time hook that reaches cloud and CI credentials. It leaves the compiled library untouched and instead adds a preinstall hook and two files.

Move faster than AI-driven risk: Inside Mend.io's latest AI application security update

AI didn’t just change how fast you ship. It changed what your AI application security program has to protect. Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded.

199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran

Mend.io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend.io reported the full batch to RubyGems for takedown. Every gem was pulled within hours. Mend.io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works.

Best 6 AI security posture management platforms (AI-SPM) in 2026

AI Security Posture Management (AI-SPM) platforms are specialized tools that discover, monitor, and secure AI models, pipelines, and data, mitigating risks like data leakage and model poisoning. They offer continuous visibility, manage misconfigurations, and enforce security policies across cloud services like Azure OpenAI and Bedrock.

Independence is the moat

Why the independent layer keeps winning as the models get better, not despite them. This series has been building to one question, and it is the objection every honest reader has been holding since the first piece. If the frontier models keep getting better this fast, why does an independent security layer keep winning? Why not wait for the model that writes safe code and verifies its own work?

Dependency management tools: Key features and 6 tools to know in 2026

Dependency management tools are software solutions designed to automate and streamline the process of handling external libraries, modules, or packages that a project relies on. These tools help developers specify, install, update, and track dependencies, ensuring that all required components are present and compatible.

The ECB just gave banks four months to fix AI vulnerability gaps. Most of the work starts in the software supply chain.

On July 7, 2026, the European Central Bank sent a letter to the CEO of every bank it directly supervises with an unambiguous instruction: build a formal action plan against AI-enabled cyberattacks, and submit it to your supervisory team by October 31.