Concerned about recent npm, Shai-Hulud and TeamPCP?
Learn More
Kodem

Documents & Videos

Documents

Kodem Cyber & Beats (UK) Webinar

Kodem Cyber & Beats (UK) Webinar

AI coding agents are pushing production code faster than static analyzers can keep up. This session explores how combining code analysis, runtime intelligence, and active threat protection into a single AI-driven approach moves AppSec beyond SCA and SAST.

Watch Now
Watch Now
Kodem Overview

Kodem Overview

Learn how the application’s journey from code to runtime influences behaviors, components, interactions, and risks in a 2-page overview. Kodem's unified platform offers a comprehensive view powered by deep application context, which is crucial for both security and engineering.

Download
Download
White Paper: Prepare for the next Software Supply Chain Attack

White Paper: Prepare for the next Software Supply Chain Attack

Software supply chain attacks are no longer hypothetical. The SolarWinds breach demonstrated how trusted updates can be weaponized; the Log4j crisis exposed the systemic risks of ubiquitous dependencies; and in just the past year, the Shai Hulud worm in npm, the Qix malware package, and the Salesloft GitHub compromise showed how attackers continue to innovate.

Read Whitepaper
Read Whitepaper
Unlocking Growth Opportunities in Modern Application Security | Growth Webinar Highlights

Unlocking Growth Opportunities in Modern Application Security | Growth Webinar Highlights

From runtime visibility and real-time threat detection to overcoming the limitations of traditional AppSec tools, this session highlights how ADR is transforming security operations in cloud-native environments.

Watch Now
Watch Now
The Definitive Playbook to Secure Vibe Coding

The Definitive Playbook to Secure Vibe Coding

The Definitive Playbook to Secure Vibe Coding

AI-assisted coding is here to stay, supercharging productivity in cloud-native teams. But with great power comes real security risk. This playbook gives security and engineering leaders a clear, actionable roadmap for safely integrating AI development tools—from pair-programming assistants to citizen developers—into their software lifecycle.

Download Playbook
Download Playbook
White Paper

White Paper

ISO 42001 and Its Implications on Application Security in AI Systems

This white paper explores how ISO 42001 influences application security, including adversarial threat mitigation, AI supply chain security, and model robustness. It also introduces a comprehensive audit test plan, equipping security teams with a structured approach to evaluating AI governance and security controls.

Download Whitepaper
Download Whitepaper
Platform Overview Video

Platform Overview Video

Watch our short platform overview video to see how Kodem discovers real security risks in your code at runtime. Kodem's runtime-powered application security platform eliminates unnecessary noise, providing a fast, best-in-class accuracy set of findings.

Register
Register
The State of Application Security Workflow

The State of Application Security Workflow

This report aims to equip readers with actionable insights that can help future-proof their security programs.

Kodem, the publisher of this report, purpose built a platform that bridges these gaps by unifying shift-left strategies with runtime monitoring and protection.

Based on qualitative and quantitative responses of industry security leaders, practitioners, developers and DevOps professional

Download Report
Download Report
Executive Brief

Executive Brief

Learn about Runtime Intelligence and our eBPF sensor technolog.

Uncover the dynamic features of the Kodem' sensor technology, powered by our proprietary Runtime Intelligence. See how Kodem provides security analysis across the entire application stack with the innovative use of eBPF.

Register
Register
The State of Application Security Workflows

The State of Application Security Workflows

Our new report provides an in-depth analysis of how organizations manage risks within increasingly complex software environments. Drawing from recent survey data, the report examines workflows for discovering, triaging, remediating, and governing vulnerabilities across modern infrastructures.

Watch Now
Watch Now
Executive Brief

Executive Brief

Dynamic SBOMs for Agile
and AI Applications

This brief explores the technical specifications, regulatory implications, and strategic applications of these vital tools. Learn why dynamic SBOMs are essential components of a proactive cybersecurity strategy.

Register
Register
Google Cloud Partner

Google Cloud Partner

See How Kodem Secures Your Google Cloud Workloads

Through its integration with Google Cloud, Kodem enables proactive detection, allowing real-time scanning, analysis, and response to threats across your development lifecycle.

Register
Register

Interviews & Podcasts

When Agents Execute: RCE Paths in LLM-Powered Coding Tools

When Agents Execute: RCE Paths in LLM-Powered Coding Tools

This talk is a follow-on to our September 2025 research on denial-of-service and permission escape in Claude Code. We now examine how LLM-powered coding agents can be weaponized end-to-end, including paths to remote code execution. Using Claude Code as a primary case study, and extending to VS Code extension exploits and recent Cursor incidents, we show how agent autonomy, extension APIs, and execution boundaries collapse into a practical RCE surface.

Interview

Interview

Hear a lively discussion with de-FUD podcast hosts @Nancy Wang, Venture Partner, Felicis, and @Ashish Popli, RiskEyeQue as they chat with Aviv Mussinger about cloud security, the right way to shift left... and cake 😀

Direct Link to Watch
Interview

Interview

Hear the CEO of Kodem Security discuss the Kodem platform and our innovative approach to application security. Learn about Kodem's mission, vision and impact on the industry.

Watch Now
Podcast

Podcast

In this episode of "30 Minutes on: Vulnerability Management," host James Berthoty interviews Aviv Mussinger, CEO and Co-Founder of Kodem. Aviv shares his journey, highlighting how his deep-rooted interest in technology led to a career in application security that revolutionized the field.

Listen Now

AIrwaves Podcasts

Episode 1

Episode 1

AI in Security Workflows

James Berthoty and Surag Patel, CEO of Pixee, discuss the role of AI in application security and the challenges of integrating AI into security solutions. Both emphasize the importance of understanding the problem before deciding to use AI and highlight the need for AI to be additive and specific in its application. The conversation also delves into the use of AI in baselining and the considerations for using AI in security workflows.

Watch Now
Episode 2

Episode 2

The Path to MLBOM

James Berthoty interviews Jacob Barkay, a product security architect at Edwards Life Sciences. They discuss the impact of large language models (LLMs) on product security, especially in regulated industries like healthcare. Jacob emphasizes the importance of ensuring the security of LLMs, transparency, and rigorous checks. He highlights the evolving nature of AI security standards and the need for data scientists to understand these risks.

Watch Now
Episode 3

Episode 3

Prompt Injections and Beyond

In this conversation, James Berthoty talks with Elad Shulman, CEO and co-founder of Lasso Security. Elad emphasizes the importance of understanding and mitigating risks associated with GenAI, such as data leaks, manipulation of models, prompt injections and unknown threats. They also touch on how different teams within organizations approach AI security and the evolving use cases for AI in enterprises.

Watch Now
Episode 4

Episode 4

Hacking with AI

Joseph Thacker, Principal AI Engineer at AppOmni, discusses how AI and LLMs can boost creativity in tasks like testing and bug bounties by offering a variety of solutions. To maximize AI's effectiveness, Joseph emphasizes the importance of providing it with extensive context, ensuring the AI tool has a clear understanding of what’s being evaluated. When applying AI to active web applications, he highlights the need for a decision-making core that can effectively process key elements such as the host, path, and other contextual information. This deeper understanding enables AI to make more accurate and informed assessments, enhancing its overall performance in cybersecurity tasks.

Watch Now