Ghent, Belgium
2022
  |  By Mario Popescu
TL;DR: Aikido now pentests Android apps. The same agents that test your web apps and APIs can now work through your APK, log into the app, and reason through it, alongside the backend it talks to, in a single assessment. Findings come back with reproduction steps and are ready for an AutoFix, the same as any other Aikido pentest. Aikido has been running autonomous pentests against web apps and APIs since November 2025.
  |  By Dylen Vandewalle
Aikido Security has achieved ISO 42001:2023 certification, the international standard for AI management systems, a step few security vendors have taken so far. The certification confirms that Aikido runs a structured, continuously improving governance system for managing the risks introduced by its AI-enabled features, across our entire platform.
  |  By Debarshi
Claude Mythos is arguably the strongest cybersecurity model that Anthropic has built. But we know that model capability is only part of what determines how well an AI vulnerability product performs. To test that, we put Anthropic’s Claude Security, which runs on Mythos, and Aikido Code Security Audit head-to-head on the exact same target to see which harness can deliver the best coverage and at what cost. Code Security Audit is part of Aikido’s AI Code Analysis suite.
  |  By Charlie Eriksen
npm launched Package Provenance in late 2022. For two years, adoption averaged 20-50 packages per week. Followed by Trusted Publishing in 2024. Blog posts were written. CISA advisories were issued. The line barely moved. Eventually Trusted Publishing with OIDC was made Generally Available in July 2025 Then Shai-Hulud hit. Weekly adoption jumped to 430 packages. In 18 months, cumulative adoption grew 3.4x.
  |  By Ilyas Makari
On August 20, we detected two popular Rust crates from the same maintainer, append-only-vec (4M downloads) and arrayref (244M downloads), were compromised. The attacker added a malicious dependency on a package called proc-macro1, which downloads a remote payload during the build and executes it on the developer's machine.
  |  By Jorian Woltjer
Gogs is an open-source Git hosting platform like GitHub or GitLab. The application allows users to manage their own repositories and organizations. Under the hood, it relies heavily on the git CLI.
  |  By Dania Durnas
Harness engineering is the practice of building the layer, including code, that turns an AI model from a text generator into an agent that can take actions. In short, an AI agent is a model plus a harness. The model decides what to do next, and the harness makes it happen, connecting the model to tools, context, external systems, and validation. In a lot of practical work, and especially in security work, the harness decides the quality of the output more than the choice of model does.
  |  By Charlie Eriksen
The fever dream continues, and I'm not even in Vegas for Hacker Summer Camp. Last week I wrote about Anthropic disclosing that one of their models published live malware to PyPI while believing it was inside a simulation. I was running a fever when I read the report. The metaphor was too good: a model that couldn't tell simulation from reality, covered by a writer who wasn't sure which way was up. I thought that was a one-week story. Very naive of me to have so much faith, I know.
  |  By Mike Wilkes
Hugging Face was breached by a rogue OpenAI agent last week, and the intrusion continues to deliver insights and understanding. The Hugging Face team published a detailed timeline along with a 17,600-event trace streaming replay visualizing what happened, and it’s marvelously and intoxicatingly detailed. I recommend you read it if you have the time.
  |  By Zach Rice
This article was co-written by Zach Rice and Joe Leon, both at Aikido Security. tl;dr Some credentials are meant to be public, but secret scanners still flag them as generic secrets. We wrote suppression rules for the most common ones and reduced false positives by ~2%. These rules now ship by default in Betterleaks. Secrets scanners are built on regular expressions. Each pattern targets a specific credential type, like an AWS secret access key, a GitHub PAT, or a Stripe token.

Aikido Security is an automated application security platform designed specifically for software engineering teams.

We secure your entire stack - code, open-source dependencies, infrastructure, and more and integrate into your existing workflows to provide visibility and control across your entire application infrastructure.

Our goal is to simplify security for developers through features like auto-triage of vulnerabilities, tied to whether the vulnerable code is actually used. This cuts through the noise, enabling engineering teams to focus on what matters most. Trusted by leading technology companies and validated by security experts, Aikido is the easiest way to implement application security monitoring and achieve compliance with regulations like ISO & SOC2.

We focus on the developer experience, allowing engineering teams to fix critical problems without security getting in the way of building.

The only platform that satisfies all code & cloud security needs for scaling dev teams.