惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
博客园 - 司徒正美
美团技术团队
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Troy Hunt's Blog
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
Cisco Talos Blog
Cisco Talos Blog
T
Tor Project blog
B
Blog
NISL@THU
NISL@THU
月光博客
月光博客
博客园 - 【当耐特】
AWS News Blog
AWS News Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
腾讯CDC
L
Lohrmann on Cybersecurity
The Cloudflare Blog
L
LINUX DO - 最新话题
S
Security @ Cisco Blogs
S
Secure Thoughts
Spread Privacy
Spread Privacy
有赞技术团队
有赞技术团队
The Last Watchdog
The Last Watchdog
Project Zero
Project Zero
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Vercel News
Vercel News
H
Hacker News: Front Page
S
SegmentFault 最新的问题
Schneier on Security
Schneier on Security
aimingoo的专栏
aimingoo的专栏
P
Privacy & Cybersecurity Law Blog
博客园 - 三生石上(FineUI控件)
Forbes - Security
Forbes - Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
T
Tailwind CSS Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
G
GRAHAM CLULEY
W
WeLiveSecurity
小众软件
小众软件
Recorded Future
Recorded Future
Cyberwarzone
Cyberwarzone
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

Aikido Security's Blog

Axios CVE-2026-40175: a critical bug that’s… not exploitable GlassWorm goes native: New Zig dropper infects every IDE on your machine Aikido Attack finds multiple 0-days in Hoppscotch The cybersecurity doomerism around Mythos doesn't match what we see on the ground axios compromised on npm: maintainer account hijacked, RAT deployed Popular telnyx package compromised on PyPI by TeamPCP Aikido × Lovable: Vibe, Fix, Ship CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran TeamPCP deploys CanisterWorm on NPM following Trivy compromise Security testing is validating software that no longer exists Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM GlassWorm Hides a RAT Inside a Malicious Chrome Extension fast-draft Open VSX Extension Compromised by BlokTrooper Glassworm Strikes Popular React Native Phone Number Packages Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories How Security Teams Fight Back Against AI-Powered Hackers Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks Trump’s 2026 cybersecurity strategy: From compliance to consequence How does AI pentesting work with compliance? What continuous pentesting actually requires Rare Not Random: Using Token Efficiency for Secrets Scanning Persistent XSS/RCE using WebSockets in Storybook’s dev server Why Determinism Is Still a Necessity in Security WAF vs. RASP vs. ADR How Aikido secures AI pentesting agents by design Astro Full-Read SSRF via Host Header Injection How to Get Your Board to Care About Security (Before a Breach Forces the Issue) What is Slopsquatting? The AI Package Hallucination Attack Already Happening SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Top 6 Wiz Code Alternatives Aikido recognized as Platform Leader in Latio Tech's 2026 Application Security Report From detection to prevention: How Zen stops IDOR vulnerabilities at runtime npm backdoor lets hackers hijack gambling outcomes Introducing Upgrade Impact Analysis: When breaking changes actually matter to your code Why Trying to Secure OpenClaw is Ridiculous Claude Opus 4.6 found 500 vulnerabilities. What does this change for software security? Introducing Aikido Expansion Packs: Safer defaults inside the IDE International AI Safety Report 2026: What It Means for Autonomous AI Systems Self-Securing Software: What It Is, Why It Matters, and How It Works npx Confusion: Packages That Forgot to Claim Their Own Name What Is Continuous Pentesting? Introducing Aikido Package Health: a Better Way to Trust Your Dependencies AI Pentesting: Minimum Safety Requirements for Security Testing Secure SDLC for Engineering Teams (+ Checklist) Fake Clawdbot VS Code Extension Installs ScreenConnect RAT G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT Top 10 AI Security Tools For 2026 Agent Skills Are Spreading Hallucinated npx Commands Understanding Open-Source License Risk in Modern Software The CISO Vibe Coding Checklist for Security Top 6 Graphite alternatives for AI code review in 2026 From “No Bullsh*t Security” to $1B: We Just Raised Our $60m Series B Critical n8n Vulnerability Allows Unauthenticated Remote Code Execution (CVE-2026-21858) Top 14 VS Code Extensions for 2026 AI-Driven Pentesting of Coolify: Seven CVEs Identified Top Continuous Pentesting Tools in 2026 SAST vs SCA: Securing the Code You Write and the Code You Depend On JavaScript, MSBuild, and the Blockchain: Anatomy of the NeoShadow npm Supply-Chain Attack How Engineering and Security Teams Can Meet DORA’s Technical Requirements IDOR Vulnerabilities Explained: Why They Persist in Modern Applications Shai Hulud strikes again - The golden path MongoBleed: MongoDB Zlib Vulnerability (CVE-2025-14847) and How to Fix It First Sophisticated Malware Discovered on Maven Central via Typosquatting Attack on Jackson The Fork Awakens: Why GitHub’s Invisible Networks Break Package Security Top 10 Cyber Security Tools For 2026 SAST in the IDE is now free: Moving SAST to where development actually happens AI Pentesting in Action: A TL;DV Recap of Our Live Demo The Top 7 Threat Intelligence Tools in 2026 React & Next.js DoS Vulnerability (CVE-2025-55184): What You Need to Fix After React2Shell OWASP Top 10 for Agentic Applications (2026): What Developers and Security Teams Need to Know DAST vs Pentesting v AI Pentesting: Why DAST Cannot Replace Modern Pentesting PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents Top 7 Cloud Security Vulnerabilities Critical React & Next.js RCE Vulnerability (CVE-2025-55182): What You Need to Fix Now How to Comply With the UK Cybersecurity & Resilience Bill: A Practical Guide for Modern Engineering Teams Shai Hulud 2.0: What the Unknown Wonderer Tells Us About the Attackers’ Endgame SCA Everywhere: Scan and Fix Open-Source Dependencies in Your IDE Safe Chain now enforces a minimum package age before install Shai Hulud Attacks Persist Through GitHub Actions Vulnerabilities Shai Hulud Launches Second Supply-Chain Attack: Zapier, ENS, AsyncAPI, PostHog, Postman Compromised CORS Security: Beyond Basic Configuration Revolut Selects Aikido Security to Power Developer-First Software Security The Future of Pentesting Is Autonomous How Aikido and Deloitte are bringing developer-first security to enterprise Secrets Detection: A Practical Guide to Finding and Preventing Leaked Credentials Invisible Unicode Malware Strikes OpenVSX, Again AI as a Power Tool: How Windsurf and Devin Are Changing Secure Coding Building Fast, Staying Secure: Supabase’s Approach to Secure-by-Default Development OWASP Top 10 2025: Official List, Changes, and What Developers Need to Know Top 10 JavaScript Security Vulnerabilities in Modern Web Apps The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties Top 7 Black Duck Alternatives in 2026 What Is IaC Security Scanning? Terraform, Kubernetes & Cloud Misconfigurations Explained AutoTriage and the Swiss Cheese Model of Security Noise Reduction Top Software Supply Chain Security Vulnerabilities Explained The Top 7 Kubernetes Security Tools Top 10 Web Application Security Vulnerabilities Every Team Should Know What Is CSPM (and CNAPP)? Cloud Security Posture Management Explained
Introducing Aikido Infinite: A new model of self-securing software
Madeline Lawrence · 2026-02-26 · via Aikido Security's Blog

You already know this problem, because you live it.

If you're a growing company, you pentest once a year… maybe twice if compliance demands it. You schedule the engagement, freeze changes, wait weeks, get a PDF. By the time the report lands, your application has already changed.

If you're a larger organization with an in-house security team, the picture is different but the constraint is the same. Your team is testing. They're good at it. But they're making hard choices every day about what to cover and what to skip, because they can't review every change across every area at the depth it deserves. They're triaging not just findings, but what to even look at.

On both sides, testing never keeps pace with shipping. Today, that changes.

The gap that widens with every deploy

Picture your commit history over the past year. Now picture your pentests, whether that's two external engagements or your in-house team's continuous effort.

(yes, this is our CEO's actual github contributions)

Your engineering org might push thousands of lines a day. Your security team, no matter how skilled or well-resourced, can manually review a fraction of that at pentest depth.

Every change that didn't get tested is a version of your application that was never fully validated. If a vulnerability was introduced between tests, it sits in production until the next time someone reviews that path. The attack surface grows with every deploy. Security capacity doesn't scale with it.

This is a structural problem. You can't fix it with faster scans, better alerts, or more headcount. We need to change the model. Of 400 security and engineering leaders we surveyed, 76% deploy significant production changes every week or faster. Only 21% validate security on every release. And 85% said their security findings are already outdated by the time the analysis arrives.

That gap between ship and secure isn't theoretical. It's the window attackers walk through. And they're getting faster: this week, researchers revealed that a single hacker used Claude to breach multiple Mexican government agencies, exfiltrating 150GB of taxpayer and voter records. One person, one AI tool, thousands of automated commands. Attackers have superpower toys now. It's time defenders had theirs.

Last month, when we announced our Series B, we made a promise: the next chapter of Aikido would be about self-securing software. Software that protects itself as it's built and released. Today, we're delivering on that promise.

What it is

Aikido Infinite is continuous autonomous penetration testing with built-in remediation. Every time your application changes, autonomous agents pentest the deployment, validate what's actually exploitable, generate patches, and retest the fixes, all before code hits production: Pentest every release. Patch automatically.

No, it’s not DAST with LLM lipstick

For years, DAST was the closest thing the industry had to continuous security testing, and nobody ever said "this DAST is great" (sorry not sorry). The depth isn’t there. The signal-to-noise ratio isn’t there. The fix isn’t there. Infinite works differently: autonomous offensive agents that reason about application behavior, chain multi-step attack paths, leverage extensive tool suite, and validate exploitability through real exploitation. In one case, the agents discovered signature forgery was possible in a document signing application: Discovered changes in authentication -> Logged in as member -> Escalated privileges -> Confirmed broken authorization. This isn't your grandfathers 'dynamic scanning.'

How it works

When new code lands, Aikido Infinite analyzes the diff and identifies changes that impact your attack surface. Updated a README and button color? Skipped. Changed auth logic or API endpoints? Agents scope the impact and launch.

1. Discover: Infinite ingests context from Aikido's code-to-runtime platform (source code, application architecture, API specs, cloud config) and maps the full attack surface, including undocumented endpoints, hidden logic paths, and architectural anomalies too time-consuming for manual review. The agents reason about your system as a whole, understanding how components interact and where assumptions break down.

2. Exploit every path that changed: This is where Infinite diverges from scanner checks, which looks at components in isolation, one repo, one file, one theoretical risk at a time. In reality, security breaks at the seams. A single line change can affect every protected route in your application. Two changes that are individually safe can be dangerous in combination: a new API field here, a relaxed permission check there, and suddenly there's a cross-tenant data leak that neither change would have introduced alone.

These are the kinds of issues that pentesting exists to find, because they only surface in the real, running configuration where components interact as a whole. The problem has always been that testing every combination at that depth is hard and expensive. Infinite makes it the default. Specialized agents pursue every viable attack route across the affected surface: injection flaws, broken access control, auth weaknesses, SSRF, business logic errors, cross-tenant data exposure, all using real attack paths rather than fixed payloads. When an agent finds something, that intelligence feeds back into the loop, uncovering chained risks. Agents work in parallel across all security-relevant features simultaneously.

3. Validate: Every finding is confirmed through direct exploitation against the live target. Issues that can't be reproduced don't make it into the results.

4. AutoFix and retest: AutoFix generates a merge-ready PR with the specific code-level fix, targeted to your actual implementation. Developers review, merge, and agents automatically retest to confirm the fix holds. Within hours, a vulnerability goes from discovered to resolved to verified.

Because Infinite lives inside the Aikido platform, it has context that standalone pentesting tools simply don't. That infrastructure-to-code context is what makes the discovery deeper, the fixes more precise, and continuous testing actually viable.

What used to take weeks or quarters now happens in hours. The agents do the gruntwork. Your team reviews, merges, and moves on.

Release → Pentest diff→ Patch → Retest → Push to prod.

Proven on real-world code

These agents are already finding complex vulnerabilities in widely-used applications and frameworks, issues that had gone undetected even with years of community review and expert scrutiny.

In Coolify, our agents identified seven CVEs including privilege escalation and full host compromise via RCE as root, across 52,000+ exposed instances. In Astro, they found CVE-2026-25545, an SSRF in the Node.js adapter exposing internal network resources. In SvelteKit on Vercel, they traced SvelteSpill, a cache deception flaw across 150,000 lines of code affecting every default deployment. Vercel deployed a platform-wide fix after disclosure.

In a head-to-head comparison on a document signing application, the agents discovered a critical workflow integrity flaw that allowed e-signatures to be forged, along with 12 XSS instances. The manual pentesters, a senior team over two weeks, found one XSS and one SSRF. Seven of their nine findings were hardening checks, they missed the signature forgery entirely. (Full whitepaper here).

In all cases, these are deep, multi-step issues in mature codebases. The experts who missed them aren’t junior. They are senior professionals working under the same constraints every security team faces: limited hours, competing priorities, high pressure, and more code to review than any team can get through at depth.

For AI, that constraint disappears. Giving agents access to source code is instant, and they scale with the richness of the context they ingest. More code, more architecture context, better results, not higher cost. The expert testers focused on compliance and configuration because that's where their time went. The agents went deeper because they could.

Even the largest companies don't have enough experts to exhaustively test every code change pushed to their applications. Now, we can empower every team with access to deep analysis, always on, for every change. Think of it as a team of elite hackers 100% dedicated to your application, on-call around the clock.

What Infinite means for your teams

Attackers have superpower toys. This gives defenders theirs.

For security professionals: Infinite multiplies your team's testing capability. Agents handle the exhaustive validation across every release, expanding coverage automatically so your experts can focus on the crown jewels and judgement calls. Breadth, speed, deep testing on every diff that would otherwise consume the team's bandwidth, or just not get done. Security professionals get more capacity for creativity, business context, and the hardest problems. Infinite allows security teams to shift from resource-constrained "check critical" mode to "check everything” by default.

For developers: Your team is shipping 10x more code than a year ago. Infinite means you can be confident in the diff. No more security tickets showing up mid-cycle with unclear reproduction steps. Infinite finds issues, generates fixs, and opens the PR. You review it, merge it, and get back to building.

What's next?

Infinite is our flagship product and the realisation of a vision we've been building toward: self-securing software. ✨

Today, Infinite closes the loop between shipping and securing. Every run enriches Aikido's security knowledge base of your application with real findings, validated attack paths, and confirmed fixes. Where that knowledge base goes next, how it feeds back into the way code gets written (or generated) in the first place, well, you can probably imagine why we chose the name Infinite. As James Berthoty, founder of Latio Tech, alludes:

In a crowded market, Aikido Infinite is a genuinely unique approach to securing AI generated code, utilizing continuous AI pentesting to make every test better than the last, and code generation more secure by default.

Next time you hear from me, it will be with a cliché but well-designed "security through the software lifecycle as an infinity sign" graphic. We have a lot more to build. And we'll keep pushing until security works at the speed software demands, and developers deserve.

Want to try out Infinite today? You can start for free, book a demo, or enter the infinite next month at RSA in San Francisco.

xo Madeline, Aikido

And yes, the launch video is a parody of the Matrix: