Endor Labs's Avatar

Endor Labs

@endorlabs

At Endor Labs, we've created the first open source dependency lifecycle management platform to help OSS consumers select, secure and maintain dependencies effectively.

17
Followers
1
Following
24
Posts
20.11.2024
Joined
Posts Following

Latest posts by Endor Labs @endorlabs

Post image

AURI by Endor Labs is built for the AI-SDLC where agents write, review, and ship code.

Learn more:
www.endorlabs.com/learn/introducing-auri-security-intelligence-for-ai-coding-agents-and-developers

04.03.2026 07:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser | Blog | Endor Labs CVE-2026-25896 allows XSS and injection attacks by shadowing XML built-in entities in fast-xml-parser via regex wildcard in entity name

A critical entity encoding bypass affects fast-xml-parser (40M+ weekly npm downloads).

www.endorlabs.com/learn/cve-20...

21.02.2026 17:54 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Today we're announcing Container Reachability, delivering full-stack reachability across application and base layers.

www.endorlabs.com/learn/introducing-full-stack-reachability-container-scanning-that-actually-reduces-noise

#ContainerSecurity #DevSecOps #FedRAMP

11.02.2026 19:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

AI is great at copying homework, including the mistakes.

A 2025 study found:
❌ 15/20 AI snippets had design flaws
❌ 6/20 were invisible to security tools

AI follows patterns, not logic, effectively amplifying your code's existing flaws.

Read the full research:
www.endorlabs.com/learn/design...

10.02.2026 18:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Rubrik used Endor Labs to confirm they weren’t affected by a major npm attack in ~30 minutes.

29.01.2026 15:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How Fake Font Packages Abused npm as a CDN | Blog | Endor Labs 101 packages disguised as font files distributed 34 TiB of data via npm's infrastructureβ€”with a total of 4.3 PiB transferred via downloads.

101 fake font packages.
4.3 petabytes transferred.
Zero malware.

This wasn’t a supply-chain attack. npm was quietly used as a CDN at massive scale.

Henrik Plate explains how it happened and why abuse, not just malware, is becoming a serious OSS sustainability risk.
endorlabs.com/learn/how-fa...

23.01.2026 18:13 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - endorlabs/gemini-extension: Secure copilot for coding assistants Secure copilot for coding assistants. Contribute to endorlabs/gemini-extension development by creating an account on GitHub.

Gemini CLI @endorlabs.bsky.social Extension
github.com/endorlabs/ge...

23.12.2025 18:50 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin | Blog | Endor Labs CVE-2025-13780 is a critical vulnerability in pgAdmin 4 where whitespace characters bypass regex filters, a common failure mode in input validation.

We discovered a critical pgAdmin vulnerability (CVE-2025-13780): whitespace bypassed a regex meant to block dangerous psql meta-commands.
A great example of why regex is fragile for input validation.

Deep dive:
www.endorlabs.com/learn/when-r...

15.12.2025 17:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo | Blog | Endor Labs Treating a security patch as a signal, not a conclusion, led us to discover how arbitrary file writes became remote code execution in Argo Workflows.

A patch in Argo Workflows was supposed to fix a ZipSlip issue… but it didn’t.
Our research uncovered CVE-2025-66626 β€” a validation bug that let malicious tarballs escape the working directory and reach RCE.

Full write-up:
www.endorlabs.com/learn/when-a...

15.12.2025 17:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Shai Hulud’s latest wave shows cross-ecosystem spread: an infected posthog-node package was rebundled as a Java archive and pushed to Maven Central via mvnpm.

Version 4.18.1 is removed, and other rebundles appear clean.
Key point: malware is now moving between ecosystems automatically.

26.11.2025 16:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Shai-Hulud shows how fast npm worms can move through packages, CI workflows, and maintainer accounts. Shared code speeds development, and expands the impact of compromised creds.

Full breakdown from Robert Haynes:
www.endorlabs.com/learn/unders...

#ShaiHulud #Malware

25.11.2025 22:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime | Blog | Endor Labs Analysis of Shai-Hulud 2, a new npm supply chain attack using Bun for execution, credential theft, and CI/CD propagation, with mitigation guidance.

A new Shai-Hulud variant just escalated from stealing credentials to attempting to wipe the entire home directory when exfiltration fails.

If you use npm: audit your packages, remove bad versions, rotate tokens, and inspect every workflow.
www.endorlabs.com/learn/shai-h...

#ShaiHulud #malware

24.11.2025 18:05 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

Wednesday was a double dose of baseball! ⚾

From Braves vs. White Sox in Atlanta to Cubs vs. Brewers in Chicago, we had a great time enjoying the games with our partners at @endorlabs.bsky.social

A big thank you to everyone who joined us!

#AppSec #DevOps

21.08.2025 20:51 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

The @endorlabs.bsky.social + @stackhawk.bsky.social
integration connects SAST + DAST for one correlated finding.

Less noise. Real context. Faster fixes.

πŸ”— www.stackhawk.com/blog/endor-l...

20.11.2025 21:06 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Endor Labs’ 2025 State of Dependency Management report is live!
-49% of dependencies imported by AI agents had known vulns.
-34% didn’t exist at all.
-Only 1 in 5 was safe.
www.endorlabs.com/lp/state-of-...

#MCP #AIAgents #DMR2025

04.11.2025 14:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised | Blog | Endor Labs A virus-like npm malware attack has spread to 180+ packages so far, including CrowdStrike and Tinycolor

πŸ”” Update on the ongoing "Shai-Hulud" malware campaign

The Endor Labs security research team has identified more than 550+ packages and versions affected by the ongoing "Shai-Hulud" software supply chain attack targeting the npm registry.
www.endorlabs.com/learn/npm-ma...

18.09.2025 17:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

AI is changing how software gets built. Today, we’re changing how it gets secured with the expansion of our application security platform and a $93M Series B to accelerate what we’re building.

More here: bit.ly/42DqUmB

#AppSec #SeriesB #EndorLabs #DevSecOps #Cybersecurity

23.04.2025 16:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Developers are moving faster than ever with tools like GitHub Copilot.

The result?
62% of AI-generated code has flaws
Nearly 30% contains known security weaknesses

Next week, we’re announcing a new way for AppSec teams to understand what’s changing and why it matters.

#AppSec #AI #LLM #DevSecOps

17.04.2025 19:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
OWASP OSS Risk 2: Compromise of Legitimate Package | Blog | Endor Labs OWASP OSS Risk 2: Explore the compromise of legitimate open-source packages, with an in-depth case study of the tj-actions/changed-files GitHub Action supply chain attack.

OWASP OSS Risk 2: Explore the compromise of legitimate open-source packages, with an in-depth case study of the tj-actions/changed-files GitHub Action supply chain attack.

www.endorlabs.com/learn/owasp-...

#OSSRisk #OWASPOSSRisk #tjactions

08.04.2025 15:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub Action tj-actions/changed-files supply chain attack: what you need to know | Blog | Endor Labs GitHub Action tj-actions/changed-files was compromised, exposing CI/CD secrets. Learn how this attack impacts repositories and what steps to take now.

Attackers compromised tj-actions/changed-files, used by 23,000+ repos, injecting malicious code to steal CI/CD secrets.

What you need to know and how to mitigate:
www.endorlabs.com/learn/github...

16.03.2025 00:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Less than 9.5% of vulnerabilities are actually exploitable, but FedRAMP ConMon requires fixing everything.

With Endor Labs, you can:
- Prove false positives to your 3PAO
- Correlate SCA & container scans
- Patch vulnerabilities 6.2x faster with Endor Patches

www.endorlabs.com/landing-page...

15.03.2025 00:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

The latest CISO guide from The Hacker News makes it clear - EU AI Act, ISO 42001, and NIST AI RMF all require it.

But inventory is just the start. You also need to enforce AI policies. Endor Labs can help you there.

About CLEAR framework:
thehackernews.com/2025/02/how-...

#AI #AppSec #DevSecOps

18.02.2025 18:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Endor Labs ❀️ GitHub

Context switching is a productivity killer. Developers live on GitHub, so #AppSec should too.

With Endor Labs Reachability-based SCA now integrated into GHAS, teams can get best-in-class application security, all in one place.
github.blog/security/fro...

10.02.2025 19:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

DeepSeek R1 is the latest open source AI model to generate a lot of buzz. Developers are trying it out, and AppSec teams may be wondering about risks.

Endor Labs can give AppSec teams data and tools to make and enforce decisions about acceptable AI risk from DeepSeek R1.

#DeepSeek #AIModels #SCA

29.01.2025 16:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

On Dec 13, Semgrep's license changes limited access to key security tools and community rules. Enter Opengrep: a fully open source, drop-in replacement backed by 10+ security companies.

Key benefits: no paywalls, community rules accessible, foundation governance, and easy migration!

23.01.2025 19:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Curious to knowβ€”how often do AppSec and CloudSec work together? Share your thoughts in the comments!

a) Often, we're the same team!
b) Sometimes, depending on work
c) Lol, who?

26.11.2024 16:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Big news! πŸŽ‰ Microsoft has natively integrated our advanced SCA within Defender for Cloud. Our integration is in Public Preview and available to try now!
www.endorlabs.com/learn/micros...

20.11.2024 18:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0