Log inSign up
Aikido Security
2,129 posts
Image
user avatar
Aikido Security
@AikidoSecurity
Secure everything devs build, ship & run. 🌐 aikido.dev ⭐️ github.com/AikidoSec Get developers back to building.
San Francisco, CA
aikido.dev
Joined September 2022
1,171
Following
11.8K
Followers
  • Pinned
    user avatar
    Aikido Security
    @AikidoSecurity
    May 14
    Aikido Intel is your earliest warning for supply chain threats. Our engine detects malware and vulnerabilities in open-source ecosystems within minutes. Built by our team of security researchers & AI engineers. Bookmark it: intel.aikido.dev
    Image
    63K
  • user avatar
    Aikido Security
    @AikidoSecurity
    14h
    ⚡️ Betterleaks v1.6.0 is here. Faster startup, lower cold-scan overhead, smaller runtime. - CEL replaced with Expr for filtering and validation. Existing CEL-shaped configs remain supported, but new configs should use Expr syntax. - Much faster cold starts by lazily
    Image
    896
    user avatar
    Aikido Security
    @AikidoSecurity
    14h
    Image
    Release v1.6.0 · betterleaks/betterleaks
    From github.com
    356
  • user avatar
    Aikido Security
    @AikidoSecurity
    15h
    npm now freezes high-impact accounts for 72 hours after sensitive actions like an email swap or 2FA recovery code use. It's a direct response to the axios and Mastra attacks. Changing the account email is how attackers cut off the real owner's recovery path. Now npm catches it.
    Image
    1.1K
    user avatar
    Aikido Security
    @AikidoSecurity
    15h
    Image
    npm now freezes high-impact accounts after risky account changes
    From aikido.dev
    248
  • user avatar
    Aikido Security
    @AikidoSecurity
    17h
    Ramen Club is coming to @BlackHatEvents soon 🍜👀
    Image
    00:00
    596
  • Aikido Security reposted
    user avatar
    Charles Maddock
    Strawberry
    @charles_maddock
    Jun 27
    New LLM benchmark just dropped
    Image
    655K
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 26
    ❗Miasma hit the @ImmobiliareLabs Backstage LDAP auth and GitLab backend plugins today via GitHub Actions. Auth plugins are a big target for a credential-stealing worm. The affected packages appear to include: - immobiliarelabs/backstage-plugin-ldap-auth-backend -
    1.1K
  • Aikido Security reposted
    user avatar
    Charlie Eriksen
    Aikido Security
    @CharlieEriksen
    Jun 26
    We just observed a surge in exfil repos occurring alongside several packages within the scope of @ImmobiliareLabs being compromised with a wormy boy. Stay vigilant out there in the heat!
    3.8K
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 26
    Article cover image
    Article
    June 2026 Newsletter: Fable's visit, npm improvements, and malware in the JetBrains Marketplace
    Hello friends, Second edition of our newsletter (first one on X), and we first need to address the AI-lephant in the room. Anthropic dropped Fable a couple weeks ago, and just like that, it was gone....
    1.9K
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 26
    Aikido now blocks malware in Composer by default, part of how Packagist is fixing PHP supply chain security one step at a time. On Composer 2.10+, any install, update, or require command will automatically skip package versions Aikido has flagged as malicious.
    Image
    1.3K
    user avatar
    Aikido Security
    @AikidoSecurity
    Jun 26
    Image
    Packagist is now protected by Aikido Intel and other updates to the PHP registry
    From aikido.dev
    354
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 25
    GitHub shipped actions/checkout v7, which now blocks pwn request patterns by default in pull_request_target workflows. Many recent supply chain attacks, like the S1ngularity and Shai-Hulud campaigns, exploited pwn requests. While you can still override the default, it's
    Image
    2.7K
    user avatar
    Aikido Security
    @AikidoSecurity
    Jun 25
    Image
    Security Checklist for GitHub Actions
    From aikido.dev
    352
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 24
    🔥 JUST DROPPED: State of AI in Pentesting 2026 Software is shipping faster than testing can keep up. We surveyed 400 CISOs, CTOs, and senior engineering leaders across Europe and the US to understand how AI is changing security testing. Key findings: • 76% deploy significant
    Image
    00:00
    2.6K
    user avatar
    Aikido Security
    @AikidoSecurity
    Jun 24
    Get the full report:
    Image
    State of AI in Pentesting 2026 | Aikido
    From aikido.dev
    367
  • Aikido Security reposted
    user avatar
    Docker
    @Docker
    Jun 24
    The expo floor closes. Time for the AI conversations you won't find on stage. If you're at AI Engineer World's Fair, join Docker, @Tailscale, @AikidoSecurity, @inngest, and @rootlyhq for drinks, darts, and good company. 📍 Golden Eye Social, SF 🕕 July 1, 6PM Register →
    Image
    6.2K
  • user avatar
    Aikido Security
    @AikidoSecurity
    Jun 23
    npm recently added staged publishing, but maintainers still can't see what's inside the package they're approving. We're partnering with Drydock.org so maintainers see exactly what's inside a package before approving it. Catch it before it ships, not after.
    Image
    2.2K
    user avatar
    Aikido Security
    @AikidoSecurity
    Jun 23
    More here:
    Image
    Aikido Partners with Drydock to Bring Pre-Publish Malware Review to npm and PyPI
    From aikido.dev
    306

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up