Cycode Complete ASPM
  • Products
    Back
    Products
    Cycode
    The Agentic Development
    Security Platform

    Cycode AI

    Maestro

    ADLC Security
    Secure & govern agentic development

    ADLC Security

    AI Visibility

    AI Governance

    AI Guardrails

    AI-BOM

    Change Impact Analysis

    AI Code Risk
    Deterministic scanning + AI reasoning

    AI Risk Detection

    SAST & AI SAST

    SCA

    Secrets Detection

    Container Security

    IaC Security

    Supply Chain Risk
    Modern software supply chain security

    Secrets & NHIs Detection

    CI/CD Security

    Code Leakage

    CI/CD Runtime

    SBOM & AI-BOM

    SSDF Security

    Risk Posture
    Risk context & CISO visibility

    Risk Intelligence

    Inventory

    Connectors (100+)

    Custom Dashboards

    Reporting & Analytics

    Compliance

  • Cycode AI
    Back
    Cycode AI
    AI Platform
    The AI brain of the control plane

    Cycode AI Overview

    Maestro AI

    Context Intelligence Graph

    AI Teammates

    Secure Your AI
    Govern the AI layer in your ADLC

    AI Visibility

    AI Governance

    AI Guardrails

    AI Risk Detection

    ADLC Security

    AI Does the Security
    Agentic security engineering at scale

    Cycode MCP Server

    AI Exploitability Agent

    AI Fix & Remediation Agent

    Change Impact Analysis Agent

    Graph Agent

    AI Resources
    Explore AI security best practices

    AI ROI Calculator

    Webinar: AI Orchestration

    IDC: AI Driven AppSec

    Secure AI Software Factory

    State of Product Security 2026

  • Resources
    Back
    Resources

    Product Security All-StarsNEW

    Meet the top leaders of 2026 who are shaping the industry through Product Security

    Blog15 NEW this month

    Learn & stay up to date on the latest in Agentic Development Security

    Solution Briefs, Whitepapers
    & Analyst Research

    Downloadable product overviews, expert guides, and in-depth reports

    State of Product SecurityNEW

    3rd annual research report on challenges & strategies for AI in 2026

    Application Security Accelerated

    Video series covering everything you need to know in AppSec

    Got Context?NEW

    See how the Context Intelligence Graph helps you win the race.

    AI ROI CalculatorNEW

    Calculate your organization potential savings

    ASPM University

    Ultimate educational destination for ASPM, curated learning hub with videos, articles & guides from top experts

    Cygives

    Community hub for free & open developer security tools
    Your Complete Mythos Toolkit
    Your Complete Mythos ToolkitResources, guides, and checklists to help you build your readiness plan before the public CVE window opens.Explore the Mythos Guide
  • Customers
  • Company
    Back
    Company

    About Us

    Who are we and what we stand for

    Partners

    The Collaboration Partner program empowers organizations to secure the software the world depends on

    Press & Media

    Hear what the world says about us in the news

    Events

    One stop shop for all Cycode’s events

    Careers

    Learn about career opportunities at Cycode

    Contact Us

    Write us and we promise to get back to you
    Agentic Development Security Summit 2026
    Agentic Development Security Summit 2026Hear from the biggest industry leaders on how they're gaining full visibility and control over the Agentic Development Security Life Cycle (ADLC)Register Now
  • US EU
US EU
See Cycode in Action

Schedule a 45-minute live product demo with expert Q&A

gartner
By submitting this form I agree to be contacted by Cycode via phone or email, all in accordance with Cycode's Privacy Policy.
Skip to content

Free Trial

Application Security

Cycode Discovers a Supply Chain Vulnerability in Bazel

August 11, 2025February 1, 2024 by Elad Pticha

The Cycode Research Team discovered a software supply chain vulnerability in one of Google’s open source flagship products, Bazel.
We found that a GitHub Actions workflow could have been injected by a malicious code due to a command injection vulnerability in one of Bazel’s dependent Actions.

Categories BLOG Tags Application Security, Research, Software Supply Chain Security

CI/CD Pipeline Security: Best Practices Beyond Build and Deploy

August 31, 2025January 26, 2024 by Julie Peterson
CICD pipeline infinity symbol

Given the demand for rapid innovation and the adoption of agile methodologies, Continuous Integration/Continuous Deployment…

Categories BLOG Tags Application Security, Software Supply Chain Security

Software Supply Chain Security Deconstructed

February 18, 2024January 4, 2024 by Julie Peterson

In the last several years, software supply chain security has become a critical focus for organizations worldwide…

Categories BLOG Tags Application Security, Application Security Posture Management, ASPM, Code Tampering, Software Supply Chain Security, SWSC

Connecting the Dots: NIST SSDF, Self-Attestation, and a Complete ASPM Platform

August 11, 2025December 20, 2023 by Ronen Slavin
Connecting the dots of NIST SSDF

In today’s hyper-connected world, secure software development is no longer an option, it’s a necessity. Yet achieving true security demands more than just guidelines and good intentions.

Categories BLOG Tags Application Security, Application Security Posture Management, Compliance & Frameworks, NIST SSDF

Three Lessons from the Ledger Connect Kit Supply Chain Attack

March 31, 2026December 18, 2023 by Alex Ilgayev
Ledger Connect Kit security breach

On December 14, 2023, the crypto community held its breath as news of a critical compromise involving the Ledger Connect Kit, a vital software component connecting hardware wallets to dApps, hit the industry.

Categories BLOG Tags Application Security, Application Security Posture Management, Code Tampering, Hardening SDLC, SCA, Software Supply Chain Security

Mastering Software Development Lifecycle Security: Best Practices

April 23, 2026December 12, 2023 by Julie Peterson

In the ever-evolving landscape of software development, it’s become absolutely paramount to ensure robust security measures throughout the Software Development Lifecycle (SDLC)…

Categories BLOG Tags Application Security, Application Security Posture Management, ASPM, Code Leakage, Code Tampering, Compliance & Frameworks, NIST SSDF, SLSA, Software Supply Chain Security

Introducing the State of ASPM 2024 Report

April 29, 2025December 6, 2023 by Julie Peterson

Cycode is excited to announce the release of our State of ASPM 2024 report, the first ever report to analyze the state of application security and Application Security Posture Management (ASPM)…

Categories BLOG Tags Application Security, Application Security Posture Management, ASPM, Software Supply Chain Security

Application Security Posture Management (ASPM) and Healthcare

August 11, 2025December 1, 2023 by Julie Peterson
A package of tablets / pills

Like many other industries, Healthcare has undergone significant digital transformation over the past decade. From the passage of the Health Information Technology…

Categories BLOG Tags Application Security, Application Security Posture Management, ASPM, Controlled Shift Left, Healthcare

Always Thankful for Our Customers

April 29, 2025November 21, 2023 by Julie Peterson
Leave falling around the Cycode logo

Thanksgiving is the perfect time of year to reflect on all the things we are truly grateful for. Here at Cycode, we try to practice gratitude every day. As we reflect what we are most thankful for, our customers are always at the top of our list…

Categories BLOG Tags Application Security, Application Security Posture Management, AppSec, ASPM, SAST, SCA, Secrets

ASPM vs. CSPM: Understanding the Key Differences

August 31, 2025November 16, 2023 by Julie Peterson
Illustration of two parallel highways converging

Organizations are looking for effective ways to protect both their applications and cloud-based assets…

Categories BLOG Tags Application Security, Application Security Posture Management, ASPM, CSPM
Older posts
Newer posts
← Previous Page1 Page2 Page3 Page4 Next →

RELATED CONTENT

  • Cycode Named as a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security
  • From Backlog to Burned Down: Managing Risk with Remediation Campaigns
  • GitHub Actions Supply Chain Attacks: How They Work and How to Stop Them
  • OWASP MCP Top 10: A Guide to Securing Model Context Protocol in 2026
  • Cycode Joins Anthropic’s Cyber Verification Program

Recent Comments

    Start Securing the 10x Developer Today
    Discover the power of Cycode for your team.

    Get a Demo
    • Platform
      • SAST – Static Application Security Testing
      • Next-Gen SCA – Software Composition Analysis
      • Secrets Scanning
      • ASPM – Application Security Posture Management
      • Source Code Leakage Detection
      • Source Control & CI/CD Security
      • Infrastructure as Code (IaC) Security
      • Container Security Scanning
      • Cycode AI – Achieve the Impossible
      • ASPM Marketplace – Connectors & Integrations
      • Application Security Testing (AST)
      • ConnectorX – Ingest & understand your security posture
      • Application Security Platform for the AI Era
      • Code Scanning Software
      • Cimon – Build Hardening and Artifact Integrity
    • Resource center
      • ASPM Book
      • State of ASPM 2025
      • Blog
      • AppSec Accelerated
      • Solution Briefs
      • Analyst Research
      • AppSec Best Practices
      • Cygives
      • ASPM – Guide
      • ASPM University
      • Integrations
    • COMPANY
      • About Us
      • Customers
      • Partners
      • Press & Media
      • Security & Trust
      • Events
      • CareersHIRING
      • Contact Us
      • Pricing
    • COMPARE
      • Veracode
      • Snyk
      • GitHub Advanced Security
      • Checkmarx
    • legal
      • Terms Of Use
      • Privacy Policy
      • Cookie Policy
      • Status Page
      • Sitemap

    ® 2026. Cycode Ltd. All Rights Reserved.

    Hey AI, learn about us

    • social_icon
    • social_icon
    • social_icon
    • social_icon
    • social_icon
    © 2026 Cycode • Built with GeneratePress