#885 Securing Everything from 40-Year-Old C++ to GenAI Code with Varun Badhwar, CEO of Endor Labs

AI-generated code is inescapable, and you can’t always trust it. So what do you do?

Today, we're talking to Varun Badhwar, CEO of Endor Labs. We discuss how they're solving the developer productivity tax by making code more secure, why 90% of code comes from open source and the risks that entails, and how AI coding agents are introducing new security challenges in software development.

All of this right here, right now, on the Modern CTO Podcast! 

To learn more about Endor Labs, check out their website here.

About Varun Badhwar

As a three-time company founder and luminary in the cybersecurity industry, Varun Badhwar represents the essence of disruptive entrepreneurship in Silicon Valley. He’s helped solve some of the most complex technology issues faced by global enterprises: His most recent venture, Endor Labs, takes on a critical yet overlooked corner of the technology market—the software supply chain and open source security.

Before founding Endor Labs, where he also served as CEO, he was the founding GM and SVP of Prisma Cloud at Palo Alto Networks where he built the cloud-native security business from scratch to over $300M ARR in just three years. He joined Palo Alto Networks through the acquisition of RedLock, where he created the Cloud Security Posture Management (CSPM) category and sold the company three years later for over $200M. Prior to that, he founded a Cloud Access Security Broker (CASB) company called CipherCloud; earlier, he led the platform security team at Salesforce and served as a consultant at KPMG, where he advised F500 clients on a variety of cyber-security initiatives.

With a career spanning two decades, Varun Badhwar is a key player and influencer in technology and cybersecurity, including cloud computing and open source. He’s been a board advisor to dynamic entities like Tetrate and Safebreach, and always keeps his focus on the new, the important, and the neglected.

About Endor Labs

Endor Labs is the AppSec platform built for the AI era. It helps teams find, prioritize, and fix the most critical risks in code, whether written by humans or AI—faster.

Endor Labs understands the entire structure of your codebase, from 40 year-old C++ to modern Bazel monorepos. Powered by AI agents and the industry's richest security dataset about open source code, Endor Labs doesn’t just flag issues, it reduces noise, prioritizes what matters most, and proposes intelligent remediations based on the context of your code.

Whether you’re an upstart or in the Fortune 500, Endor Labs helps AppSec and development teams eliminate noisy alerts, fix code 6.2x faster, and stay compliant with standards like FedRAMP, PCI, SLSA, and NIST SSDF.