Read More: www.aikido.dev/blog/introdu...
Software can now secure itself.
β www.aikido.dev/attack/infin...
Self-securing software is coming to RSAC. Yes, it's Matrix themed.
This is NOT a Super Bowl ad
From βno bullsh*t securityβ to $1 billion valuation in three years.
Announcing $60M Series B at $1B led by Tom Stafford at DST Global.
Whatβs next? Self-securing software.
Stay tuned.
feeling β¨ seasonal β¨
meet Jarno -> www.aikido.dev/meetjarno
Turn alert overload into instant clarity. Security Zen awaits.
Full research on "PromptPwnd" here: www.aikido.dev/blog/promptp...
2) Or use aikido, which automatically identifies unsafe AI prompt flows in our free tier: app.aikido.dev
How to check if you are affected:
1) Scan your GitHub Action files using Opengrep (we provides rules: github.com/AikidoSec/op...
Recommendations:
β’ Remove or restrict privileged tools available to AI agents
β’ Never send untrusted PR/issue content directly into AI prompts
β’ Treat AI-generated output as untrusted code
β’ Limit the blast radius of GitHub tokens (IP-restricted tokens recommended)
If you use AI agents in GitHub Actions/GitLab CI/CD check your pipelines
immediately.
What we found:
β’ Confirmed exposure in 5 F500 companies
β’ Googleβs Gemini CLI repository was also impacted (fixed)
β’ Vulnerability pattern is already present in real-world workflows
β’ Likely affects many more orgs using AI agents in CI/CD
Attackers can submit crafted issues/PRs that trick the AI into executing privileged GitHub CLI commands β leaking secrets or modifying CI/CD workflows.
We uncovered a systemic weakness in how AI agents like
GeminiApp, Claudeai code, OpenAI codex, and @github.com AI inference are integrated into GitHub Actions and @gitlab.com CI/CD
π¨We just hacked Googleβs Gemini CLI, and multiple undisclosed Fortune 500 companies, through prompt injections in GitHub Actions.
What does pentesting look like in the next era of development? Meet Aikido Attack.
-> www.aikido.dev/attack/aipen...
Aikido Original now streaming in SF
Weβve been waiting to share this. Aikido SF is now open for business. π€
Our middle-out expansion is real.
Honored for protecting 2 billion requests per month. Because apparently, thatβs plaque-worthy.
Key findings:
β’ 1 in 5 have faced a serious breach linked to AI code
β’ 96% believe AI will one day write secure code
β’ 65% say false positives are driving risky behavior
Read the full report -> www.aikido.dev/state-of-ai-...
β‘οΈJUST DROPPED: The State of AI in Security & Development
We asked 450 CISOs, AppSec engineers and developers across Europe and the US how AI is changing the way we build and secure software.
Weβre entering a new chapter in pentesting and weβre excited to have the teams from Allseek and Haicker with us on this journey.
Get early access β www.aikido.dev/attack/aipen...
Breaking: Allseek and Haicker are joining Aikido
Together weβre launching Aikido Attack, autonomous pentests that think like hackers and run in hours, not weeks.
Weβre entering a new chapter in pentesting and weβre excited to have the teams from Allseek and Haicker with us on this journey.
Did you catch the premiere? β aikido.dev/meetjarno
Here are a few places where Jarno does interviews, the rest are better left offline. But you can always meet him and ask -> aikido.dev/meetjarno
How did we scale from 30 to 140 team members in a year? Simple.
Always be recruiting.
Have you met Jarno? β aikido.dev/meetjarno
#1 Product of the Day, #3 Developer Tool of the Week.
Crushed it.
πΏ