aikido | no bullsh*t security for devs's Avatar

aikido | no bullsh*t security for devs

@aikidosecurity.bsky.social

No bullsh*t security for devs. Secure code, cloud, and runtime in one central system. fix issues automatically. Get back to building. ๐Ÿ”— aikido.dev

477 Followers  |  273 Following  |  93 Posts  |  Joined: 18.11.2024  |  2.1248

Latest posts by aikidosecurity.bsky.social on Bluesky

Post image

Honored for protecting 2 billion requests per month. Because apparently, thatโ€™s plaque-worthy.

30.10.2025 12:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
State of AI in Security & Development 2026: CISOs & Devs Respond to AI Risks 450 CISOs and developers reveal how AI is reshaping security and software development, and how teams are responding to new risks and real breaches.

Key findings:
โ€ข 1 in 5 have faced a serious breach linked to AI code
โ€ข 96% believe AI will one day write secure code
โ€ข 65% say false positives are driving risky behavior

Read the full report -> www.aikido.dev/state-of-ai-...

22.10.2025 13:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

โšก๏ธJUST DROPPED: The State of AI in Security & Development
We asked 450 CISOs, AppSec engineers and developers across Europe and the US how AI is changing the way we build and secure software.

22.10.2025 13:01 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Aikido Attack | Autonomous AI Pentests Audit-ready pentests without the wait. Full report in days, instant retests, low cost, and continuous validation powered by AI agents.

Weโ€™re entering a new chapter in pentesting and weโ€™re excited to have the teams from Allseek and Haicker with us on this journey.

Get early access โ†’ www.aikido.dev/attack/aipen...

24.09.2025 08:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

Breaking: Allseek and Haicker are joining Aikido

Together weโ€™re launching Aikido Attack, autonomous pentests that think like hackers and run in hours, not weeks.

Weโ€™re entering a new chapter in pentesting and weโ€™re excited to have the teams from Allseek and Haicker with us on this journey.

24.09.2025 08:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Did you catch the premiere? โ†’ aikido.dev/meetjarno

22.09.2025 14:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Here are a few places where Jarno does interviews, the rest are better left offline. But you can always meet him and ask -> aikido.dev/meetjarno

19.09.2025 10:04 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

How did we scale from 30 to 140 team members in a year? Simple.
Always be recruiting.

Have you met Jarno? โ†’ aikido.dev/meetjarno

18.09.2025 15:50 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

#1 Product of the Day, #3 Developer Tool of the Week.

Crushed it.

18.09.2025 08:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿฟ

17.09.2025 15:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Secure everything you build, host, and run. Aikido now launching at #1 on Product Hunt ๐Ÿ”ฅ

Please upvote here โ†’ www.producthunt.com/products/aik...

11.09.2025 13:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

tHe biGGesT sUpplY cHaiN atTAck iN hISTory!!!!!11

safe chain stars went brrr
Free to use. Open source.

11.09.2025 11:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
a phishing message tied to the newly registered phishing domain npmjs[.]help, which is a tld away from NPM's real login page, npmjs.com.

npm <support@npmjs.help> 08:47 (55 minutes ago)
to marsup ยฅ Inbox ยฉ ยฎ O <& Reply Actionsv

Hi, marsup!

As part of our ongoing commitment to account security, we are requesting that all

users update their Two-Factor Authentication (2FA) credentials. Our records indicate

that it has been over 12 months since your last 2FA update.

To maintain the security and integrity of your account, we kindly ask that you

complete this update at your earliest convenience. Please note that accounts with

outdated 2FA credentials will be temporarily locked starting September 10, 2025, to

prevent unauthorized access.

Update 2FA Now

1f you have any questions or require assistance, our support team is available to help. You may

contact us through this link.

Preferences - Terms - Privacy - Sign in to npm

a phishing message tied to the newly registered phishing domain npmjs[.]help, which is a tld away from NPM's real login page, npmjs.com. npm <support@npmjs.help> 08:47 (55 minutes ago) to marsup ยฅ Inbox ยฉ ยฎ O <& Reply Actionsv Hi, marsup! As part of our ongoing commitment to account security, we are requesting that all users update their Two-Factor Authentication (2FA) credentials. Our records indicate that it has been over 12 months since your last 2FA update. To maintain the security and integrity of your account, we kindly ask that you complete this update at your earliest convenience. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access. Update 2FA Now 1f you have any questions or require assistance, our support team is available to help. You may contact us through this link. Preferences - Terms - Privacy - Sign in to npm

New, from me:

At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved in maintaining the projects was phished. The [โ€ฆ]

[Original post on infosec.exchange]

08.09.2025 23:01 โ€” ๐Ÿ‘ 27    ๐Ÿ” 49    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 0
Preview
duckdb npm packages compromised The popular package duckdb was compromised by same attackers that hit debug and chalk

it appears the same attackers also compromised the JavaScript package duckdb (~350k downloads a week):

https://www.aikido.dev/blog/duckdb-npm-packages-compromised

09.09.2025 16:15 โ€” ๐Ÿ‘ 6    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Le maintainer: โ€œIโ€™ve been pwned. Sorry everyone, very embarrassing.โ€

Brian Krebs covered the npm supply chain compromise, featuring insights from our own @charlieeriksen.bsky.social, who broke the news.

Full article โ†’ krebsonsecurity.com/2025/09/18-p...

09.09.2025 14:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

MAINTAINER UPDATE: The maintainer of debug & chalk has taken down the packages and locked down his account; some packages remain affected.

The phishing email used to target debug/chalk was 'support [at] npmjs [dot] help'

08.09.2025 15:56 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Update! The goal of the attacker is crypto.

08.09.2025 15:51 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

with a combined 2 billion weekly downloads, this is one of the largest supply chain attacks in npm history

08.09.2025 15:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ€ข supports-color (287.1m downloads per week)
โ€ข strip-ansi (261.17m downloads per week)
โ€ข chalk (299.99m downloads per week)
โ€ข debug (357.6m downloads per week)
โ€ข ansi-styles (371.41m downloads per week)

08.09.2025 15:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

โ€ข error-ex (47.17m downloads per week)
โ€ข color-name (191.71m downloads per week)
โ€ข is-arrayish (73.8m downloads per week)
โ€ข slice-ansi (59.8m downloads per week)
โ€ข color-convert (193.5m downloads per week)
โ€ข wrap-ansi (197.99m downloads per week)
โ€ข ansi-regex (243.64m downloads per week)

08.09.2025 15:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

โ€ข backslash (0.26m downloads per week)
โ€ข chalk-template (3.9m downloads per week)
โ€ข supports-hyperlinks (19.2m downloads per week)
โ€ข has-ansi (12.1m downloads per week)
โ€ข simple-swizzle (26.26m downloads per week)
โ€ข color-string (27.48m downloads per week)

08.09.2025 15:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

UPDATE: A massive supply-chain compromise has affected packages with over 2 billion weekly downloads owned by the popular maintainer qix

These include:
โ€ข ansi-regex (243.64m downloads per week)
โ€ข supports-color (287.1m downloads per week)
โ€ข strip-ansi (261.17m downloads per week)

08.09.2025 15:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐ŸšจURGENT: A series of popular packages maintained by qix have just been compromised.

Compromised packages include:
โ€ข has-ansi - 12 million weekly downloads - V6.0.1
โ€ข supports-hyperlinks - 19m weekly downloads - v4.1.1
โ€ข chalk-template - 3.9m weekly downlaods - V1.1.1

08.09.2025 15:45 โ€” ๐Ÿ‘ 5    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
The Future of Code Reviews in the AI Era โ€“ Cyber & Sake Podcast Clip with Khachatur Virabyan
YouTube video by The Secure Disclosure | Cyber, Sake, More. The Future of Code Reviews in the AI Era โ€“ Cyber & Sake Podcast Clip with Khachatur Virabyan

Trag is now part of Aikido. We sat down with Trag co-founder to talk AI, code quality, and what the future looks like. And yesโ€ฆ there was sake involved.

Full episode โ†’ www.youtube.com/watch?v=zUxe...

05.09.2025 12:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

In Khachaturโ€™s words: โ€œWe didnโ€™t make cars smaller so they could squeeze between trees, we built roads so we could drive them everywhere. AI code generation is the car. Together, weโ€™re building the road.โ€

05.09.2025 12:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Happening this Thursday โค๏ธโ€๐Ÿ”ฅ
Weโ€™re back with the next edition of ~all vibes /no vulns.

Hosted by our own Mackenzie Jackson, with special guests Igor A. (CISO @ Lovable) and Bil Harmer (CISO @ Supabase).

Together weโ€™ll build, hack, and secure an app in real time.

Join us โ†’ luma.com/lovablexaiki...

02.09.2025 07:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

The wait is over. Aikido Code Quality is live.

Our favorite part? Roast mode. ๐Ÿฅต
Activate at your own risk โ†’ aikido.dev/quality

28.08.2025 13:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Popular nx packages compromised on npm The popular nx package on npm was compromised, and stolen data was published on GitHub publicly

A clean version has since been published 21.4.1

โ€ข Check if you use this project npm ls nx
โ€ข Uninstall any malicious versions npm uninstall nx && npm install nx@latest
โ€ข Clear cache; rotate creds and tokens.

Full advisory - www.aikido.dev/blog/popular...

27.08.2025 10:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿšจ ALERT: The NPM package NX has been compromised (4.6m weekly downloads) - malicious versions (v20.9โ€“20.12 & 21.5โ€“21.8) were published on Aug 26 2025.

The compromised packages have a postinstall script that scans for credentials and post them to the users GitHub account.

27.08.2025 10:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Happening TOMORROW.
Willem Delbare (CEO & Co-founder, Aikido) and Khachatur V. (CEO & Co-founder, Trag) go live to talk about the future of code review.

Quality code is secure code. Letโ€™s talk about it โ†’ lu.ma/aikidoxtrag

27.08.2025 08:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@aikidosecurity is following 20 prominent accounts