2026 Mid-Year Update: On Pace for Our Biggest Year Yet

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

StepSecurity reports strong H1 2026 growth, closing roughly 7x more new customers than H1 2025, following 5x ARR growth in both 2024 and 2025. The company attributes acceleration to AI expanding both software output and attacker capabilities, making CI/CD and developer machine security more urgent. In H1, StepSecurity discovered or first reported several major supply chain attacks including the Axios npm compromise, the Shai-Hulud TanStack attack, the Nx Console VS Code extension breach affecting ~3,800 GitHub repositories, Microsoft's durabletask PyPI compromise, and Red Hat npm compromises. The platform now covers runtime security across all operating systems, package download protection, and fleet-wide threat intelligence. The post ends with a product demo CTA and open job listings.

6m read timeFrom stepsecurity.io
Post cover image
Table of contents
A Step Change in GrowthThe Customers Have ChangedWhy Now: AI Changed Both Sides of the EquationProtecting the Entire Pipeline, and Proving You Are Not ImpactedOn the Front Lines, First, AgainProduct Velocity: A Small but Mighty TeamWhat's Next
194 Impressions