Founder & CEO of Endor Labs. Formerly founded RedLock / Prisma Cloud (acq PANW) and CipherCloud (acq Lookout). Angel investor and board member in startups.
We are investigating a potential supply chain incident in the #mastra ecosystem. It appears that a malicious actor compromised the org and added a malicious typosquat package as a dependency throughout numerous additional packages. Detailed analysis will follow.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
GPT-5.5 just set a new security record on our Agent Security League, through Cursor.
Through Codex? Ties for third, and trails by ~26 points on functional correctness.
Same model, same week, two harnesses, two very different results: https://t.co/boGRSmQC8L
#claude Opus 4.7 reaches the highest functional and security scores we've ever measured. But roughly four out of five solutions still ship with vulnerabilities. 87% Functionally Correct and 20% Secure code.
https://t.co/lNcQCQRFGy
@martin_casado AI generates large amounts of insecure code, and a human SWE keeps having to correct it? There goes your productivity 🥲secure prompts don’t help materially. This paper is worth a read https://t.co/XSa9holGjK
@IceSolst Asking developers to pin all their dependencies would be a good start! Secondly, malware is usually found by researchers at @EndorLabs, @AikidoSecurity, @SocketSecurity, reported to npm and removed within hours 90 percent of the time. So slow your horses with upgrades just a bit
Don't let FOMO take the wheel! Escape the RSA frenzy with us with engaging discussions, plenty of laughs, and a well-deserved break. 🔥 This isn't just downtime; it's a chance to recharge! ⚡️ @GitHubSecurity#RSA 💌 RSVP now! [https://t.co/NpSn1Q9WF1
@lightspeedvp@EndorLabs@varun__badhwar .@varun__badhwar and team are not only addressing a massive, unmet need in the application security world, but are laying the foundation for a long and enduring company in a fast-growing market.
Thanks @github for featuring @theopenssf Scorecard project on ReadME blog-"In Scorecard we trust" by @snaveen(Endor) & Brian Russell(GOSST)."If you’re looking to start improving your software supply chain security, adopting Scorecard is a great first step" https://t.co/pYbXo66kGX
80-90% of code in modern systems is borrowed.
Amongst the growing dependency graph, how do you know the projects are secure? Or whether the projects your dependencies depend on are secure?
@varun__badhwar of @EndorLabs joins me to discuss this problem:
https://t.co/toJh6NDWaG
A few days ago we ran a poll asking how much time it takes a developer to investigate an OSS vulnerability.
24% reported it takes less than 2 hours - these were mostly security
55% reported it takes more than a day - these mostly devs
How would you explain the difference?