Cycode Complete ASPM
  • Products
    Back
    Products
    Cycode
    The Agentic Development
    Security Platform

    Cycode AI

    Maestro

    ADLC Security
    Secure & govern agentic development

    AI Visibility

    AI Governance

    AI Guardrails

    AI-BOM

    Change Impact Analysis

    AI Code Risk
    Deterministic scanning + AI reasoning

    AI Risk Detection

    SAST & AI SAST

    SCA

    Secrets Detection

    Container Security

    IaC Security

    Supply Chain Risk
    Modern software supply chain security

    Secrets & NHIs Detection

    CI/CD Security

    Code Leakage

    CI/CD Runtime

    SBOM & AI-BOM

    SSDF Security

    Risk Posture
    Risk context & CISO visibility

    Risk Intelligence

    Inventory

    Connectors (100+)

    Custom Dashboards

    Reporting & Analytics

    Compliance

  • Cycode AI
    Back
    Cycode AI
    AI Platform
    The AI brain of the control plane

    Cycode AI Overview

    Maestro AI

    Context Intelligence Graph

    AI Teammates

    Secure Your AI
    Govern the AI layer in your ADLC

    AI Visibility

    AI Governance

    AI Guardrails

    AI Risk Detection

    ADLC Security

    AI Does the Security
    Agentic security engineering at scale

    Cycode MCP Server

    AI Exploitability Agent

    AI Fix & Remediation Agent

    Change Impact Analysis Agent

    Graph Agent

    AI Resources
    Explore AI security best practices

    AI ROI Calculator

    Webinar: AI Orchestration

    IDC: AI Driven AppSec

    Secure AI Software Factory

    State of Product Security 2026

  • Resources
    Back
    Resources

    Product Security All-Stars

    Meet the top leaders of 2025 who are shaping the industry through Product Security

    Blog

    Learn & stay up to date on developments in ASPM

    Solution Briefs, Whitepapers
    & Analyst Research

    Downloadable product overviews, expert guides, and in-depth reports

    State of Product SecurityNEW

    3rd annual research report on challenges & strategies for AI in 2026

    Application Security Accelerated

    Video series covering everything you need to know in AppSec

    Got Context?NEW

    See how the Context Intelligence Graph helps you win the race.

    AI ROI CalculatorNEW

    Calculate your organization potential savings

    ASPM University

    Ultimate educational destination for ASPM, curated learning hub with videos, articles & guides from top experts

    Cygives

    Community hub for free & open developer security tools
    State of Product Security for the AI Era
    State of Product Security for the AI EraAI changed how software is created. How should you change how it's secured? Explore insights from the 2026 State of Product Security in the AI Era.Read Now
  • Customers
  • Company
    Back
    Company

    About Us

    Who are we and what we stand for

    Partners

    The Collaboration Partner program empowers organizations to secure the software the world depends on

    Press & Media

    Hear what the world says about us in the news

    Events

    One stop shop for all Cycode’s events

    Careers

    Learn about career opportunities at Cycode

    Contact Us

    Write us and we promise to get back to you
     2026 Product Security Summit
    2026 Product Security SummitAccess the on-demand sessions and learn how to gain full visibility and control over AI-driven risks, and how to strategically use AI to 10x the efficiency of your security teamWatch Now
  • Login
Login
See Cycode in Action

Schedule a 30-minute live product demo with expert Q&A

gartner
By submitting this form I agree to be contacted by Cycode via phone or email, all in accordance with Cycode's Privacy Policy.
Skip to content

Free Trial

Software Supply Chain Security

ESLint: Compromising the Build using Supply Chain Attack

August 10, 2025February 18, 2021 by Amnon Even-Zohar
Cover Image

A supply-chain attack is an indirect attack which targets the tools, automatic software updates or supply chain in general, in order to introduce malicious code or dependencies into existing software, without the developers being aware.

Categories BLOG Tags Code Tampering, Hardcoded Secrets, Least Privilege Enforcement, Software Supply Chain Security Leave a comment

A Unique Supply Chain Attack: The 2020 Sawfish

April 3, 2024January 31, 2021 by Amnon Even-Zohar
Cover Image

For attackers targeting technology businesses, the goal is often stealing intellectual property and other data, which can either be sold for profit…

Categories BLOG Tags Code Leakage, Code Tampering, Hardcoded Secrets, IaC Security, Least Privilege Enforcement, Software Supply Chain Security Leave a comment

Beyond SolarWinds: The “Octopus Scanner” Supply Chain Attack

June 20, 2024January 12, 2021 by Amnon Even-Zohar
Cover Image

The SolarWinds exploit and subsequent breaches unfolding appears to be an incredibly sophisticated supply chain attack. Not only was SolarWinds…

Categories BLOG Tags Software Supply Chain Security Leave a comment

Why Microsoft’s Latest SolarWinds Admission Can’t Be Ignored

August 12, 2025January 4, 2021 by Andrew Fife
Cover Image

Last week, on New Year’s Eve, Microsoft announced that the SolarWinds attackers had been deeper in their environment than previously believed and had viewed Microsoft’s source code.

Categories BLOG Tags Software Supply Chain Security Leave a comment

Six AppSec Learnings from SolarWinds

December 1, 2025December 15, 2020 by Ronen Slavin
Cover Image

The SolarWinds incident is a rapidly evolving situation as more and more organizations realize they’ve been breached. We don’t know exactly…

Categories BLOG Tags Code Tampering, Software Supply Chain Security

OWASP SAMM Framework: What You Need to Know

December 18, 2025September 9, 2020 by Ronen Slavin
Cover Image

We here at Cycode passionately advocate for protecting your source code and the secrets within it throughout its lifecycle and along all…

Categories BLOG Tags Software Supply Chain Security Leave a comment

Security Best Practices for Azure DevOps

March 30, 2026September 1, 2020 by Ronen Slavin
Cover Image

Microsoft Azure has been a popular platform for various kinds of cloud computing for years and, more specifically, Azure DevOps Services…

Categories BLOG Tags Code Tampering, Hardening SDLC, Software Supply Chain Security Leave a comment

How to Setup Branch Protection Rules

June 19, 2025August 5, 2020 by Tomer Almog
Cover Image

Branching is the cornerstone of cooperative work using Git. Developers utilize branches to work on the same source code repository in parallel…

Categories Uncategorized Tags Code Tampering, Hardening SDLC, Software Supply Chain Security Leave a comment

GitHub Permissions for Maximum Security

June 20, 2024July 23, 2020 by Ilia Shkolyar
Cover Image

Role-based access control (RBAC) is an approach to restricting system access to authorized users. GitHub enforces RBAC via “Access Permissions”…

Categories BLOG Tags Code Tampering, Hardening SDLC, Software Supply Chain Security Leave a comment

Keeping Your Secrets Safe

January 1, 2026July 14, 2020 by Maor Davidzon
Cover Image

Once upon a time, environments were segregated so compromising one developer’s machine would not impact the entire build or production…

Categories BLOG Tags Hardcoded Secrets, Software Supply Chain Security Leave a comment
Older posts
Newer posts
← Previous Page1 … Page6 Page7 Page8 Page9 Next →

RELATED CONTENT

  • Introducing Cycode Maestro: The Security Conductor of Your Agentic SDLC
  • Top AI Security Vulnerabilities to Watch out for in 2026
  • Shedding The Lite: Unfolding The Dramatic Turn of Events with the LiteLLM Compromise
  • Deterministic vs. Non-Deterministic vs. Probabilistic AI in AppSec: Why the Distinction Is Now a Security Control
  • The Rise of Agent Infrastructure as Code: Why Securing AI Agents Starts in the Repository

Recent Comments

    Start Securing the 10x Developer Today
    Discover the power of Cycode for your team.

    Get a Demo
    • Platform
      • SAST – Static Application Security Testing
      • Next-Gen SCA – Software Composition Analysis
      • Secrets Scanning
      • ASPM – Application Security Posture Management
      • Source Code Leakage Detection
      • Source Control & CI/CD Security
      • Infrastructure as Code (IaC) Security
      • Container Security Scanning
      • Cycode AI – Achieve the Impossible
      • ASPM Marketplace – Connectors & Integrations
      • Application Security Testing (AST)
      • ConnectorX – Ingest & understand your security posture
      • Application Security Platform for the AI Era
      • Code Scanning Software
      • Cimon – Build Hardening and Artifact Integrity
    • Resource center
      • ASPM Book
      • State of ASPM 2025
      • Blog
      • AppSec Accelerated
      • Solution Briefs
      • Analyst Research
      • AppSec Best Practices
      • Cygives
      • ASPM – Guide
      • ASPM University
      • Integrations
    • COMPANY
      • About Us
      • Customers
      • Partners
      • Press & Media
      • Security & Trust
      • Events
      • CareersHIRING
      • Contact Us
    • COMPARE
      • Veracode
      • Snyk
      • GitHub Advanced Security
      • Checkmarx
    • legal
      • Terms Of Use
      • Privacy Policy
      • Cookie Policy
      • Status Page
      • Sitemap

    ® 2026. Cycode Ltd. All Rights Reserved.

    Hey AI, learn about us

    • social_icon
    • social_icon
    • social_icon
    • social_icon
    • social_icon
    © 2026 Cycode • Built with GeneratePress