RL Blog
cube labelled ml-bom

Secure Your AI Supply Chain with the ML-BOM

The ML-BOM capability in RL's Spectra Assure SAFE Report provides immediate visibility into every ML model in your environment.

Read More about Secure Your AI Supply Chain with the ML-BOM
Secure Your AI Supply Chain with the ML-BOM
xBOM in block text

What is the xBOM?

Understand the difference between the SBOM and xBOM — and how it impacts software supply chain security.

Read More about What is the xBOM?
What is the xBOM?
microphone in front of blue curtain

Verizon 2025 DBIR: Third-party software risk takes the spotlight

The latest Data Breach Investigations Report puts the focus squarely on third-party risk. Here’s what you need to know.

Read More about Verizon 2025 DBIR: Third-party software risk takes the spotlight
Verizon 2025 DBIR: Third-party software risk takes the spotlight
cute hamster

Changes to CVE program are a call to action on your AppSec strategy

The CVE's challenges mean it's time to get off the vulnerability hamster wheel and modernize your risk program.

Read More about Changes to CVE program are a call to action on your AppSec strategy
Changes to CVE program are a call to action on your AppSec strategy
decapitated robot toy

NIST's adversarial ML guidance: 6 action items for your security team

ML attacks are evolving, putting mitigation a step behind. Here’s what to focus on — and why traditional AppSec tooling is not up to the job.

Read More about NIST's adversarial ML guidance: 6 action items for your security team
NIST's adversarial ML guidance: 6 action items for your security team
mug with text that says we're hiring

The cybersecurity job market is complicated: 3 key insights

While the state of cybersecurity careers is confusing, key trends are driving companies to think big-picture — and outside of traditional roles.

Read More about The cybersecurity job market is complicated: 3 key insights
The cybersecurity job market is complicated: 3 key insights
red road sign that says breakthrough

Quantum delivers really random numbers: How that boosts AppSec

Quantum random number generators can make software — including software development secrets — more secure. Here's how it works.

Read More about Quantum delivers really random numbers: How that boosts AppSec
Quantum delivers really random numbers: How that boosts AppSec
red microchip with bitcoin logo

Atomic and Exodus crypto wallets targeted in malicious npm campaign

RL researchers have identified yet another npm package that uses malicious patching of local software to hijack cryptocurrency transfers.

Read More about Atomic and Exodus crypto wallets targeted in malicious npm campaign
Atomic and Exodus crypto wallets targeted in malicious npm campaign
retro toy robot

Vibe coding: What automating development means for AppSec

Vibe coding — AI coding using prompt engineering — is making application security more challenging. Here's what you need to know.

Read More about Vibe coding: What automating development means for AppSec
Vibe coding: What automating development means for AppSec
six men in singlets running race on track

The race to secure the AI/ML supply chain is on — get out front

Software supply chain risks from artificial intelligence and machine learning are getting real. Here are key insights from RL’s new report.

Read More about The race to secure the AI/ML supply chain is on — get out front
The race to secure the AI/ML supply chain is on — get out front
gold coin with bitcoin symbol in front of paper money rolls

Malicious Python packages target popular Bitcoin library

RL researchers detected two Python libraries that are designed to steal sensitive data while posing as fixes for a popular cryptocurrency library.

Read More about Malicious Python packages target popular Bitcoin library
Malicious Python packages target popular Bitcoin library
man in glasses lenses reflecting computer data

CVEs lose relevance: Get proactive — and think beyond vulnerabilities

More cracks in the NVD emerge, making the CVE system less useful. Shift your approach to keep up with software risk.

Read More about CVEs lose relevance: Get proactive — and think beyond vulnerabilities
CVEs lose relevance: Get proactive — and think beyond vulnerabilities
neon open sign

OpenSSF guidelines encourage OSS developers to build securely

The Open Source Secure Baseline provides a framework for securing OSS development — but it could breed complacency.

Read More about OpenSSF guidelines encourage OSS developers to build securely
OpenSSF guidelines encourage OSS developers to build securely
line of soldiers in uniform from the knees down

AI coding tools weaponized: What your AppSec team needs to know

The Rules File Backdoor attack method is pernicious — and one that can be easily exploited with the rise of 'vibe coding' and agentic AI.

Read More about AI coding tools weaponized: What your AppSec team needs to know
AI coding tools weaponized: What your AppSec team needs to know
three men sitting in front of monitors

Malware found on npm infecting local package with reverse shell

For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.

Read More about Malware found on npm infecting local package with reverse shell
Malware found on npm infecting local package with reverse shell
Previous1...141516...59Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top