RL Blog
solid black cube versus black cube with red specks

How RL Spectra Assure Analyzes Reproducible Builds to Find Compromises

Early detection of software build environment tampering is key. Here's how RL's software supply chain security platform delivers this critical pre-release check.

Read More about How RL Spectra Assure Analyzes Reproducible Builds to Find Compromises
How RL Spectra Assure Analyzes Reproducible Builds to Find Compromises
distressed tired man at computer

AppSec alert fatigue: 4 ways to reduce burnout — and boost security

Tool sprawl is making alert fatigue a major problem for teams responsible for application security. Here are four ways to combat it in your organization.

Read More about AppSec alert fatigue: 4 ways to reduce burnout — and boost security
AppSec alert fatigue: 4 ways to reduce burnout — and boost security
computer insides melting like lava

Malicious NuGet campaign uses homoglyphs and IL weaving to fool devs

Malware authors upped their game, using homoglyphs to impersonate a protected NuGet prefix and IL weaving to inject malicious code, RL researchers found.

Read More about Malicious NuGet campaign uses homoglyphs and IL weaving to fool devs
Malicious NuGet campaign uses homoglyphs and IL weaving to fool devs
upgrade word in dictionary

The state of DevSecOps: Why upgrading your AppSec tooling is essential

Here's what's holding DevSecOps back — and why modernizing your application security tooling is critical in the software supply chain security era.

Read More about The state of DevSecOps: Why upgrading your AppSec tooling is essential
The state of DevSecOps: Why upgrading your AppSec tooling is essential
deep dive the new gartner report

Three Pillars to Strengthen Software Supply Chain Security

In a new report, Gartner® is redefining software supply chain security and calling on enterprises to make some big changes.

Read More about Three Pillars to Strengthen Software Supply Chain Security
Three Pillars to Strengthen Software Supply Chain Security
polyfill supply chain attack

The Polyfill.io vulnerability: Software supply chain attack lessons

The compromise of the widely used Polyfill.io CDN contains important lessons for organizations on trust.

Read More about The Polyfill.io vulnerability: Software supply chain attack lessons
The Polyfill.io vulnerability: Software supply chain attack lessons
team stacking their hands

OASIS Open's push for a software supply chain standard: All together now?

The aim is to build a unifying framework incorporating existing SBOM data models, including CSAF, CycloneDX, OpenVEX, and SPDX. Experts weigh in with key insights.

Read More about OASIS Open's push for a software supply chain standard: All together now?
OASIS Open's push for a software supply chain standard: All together now?
spectra assure community landing page

New Portal Helps Devs Spot Malicious Open Source Packages

RL's Spectra Assure Community offers free comprehensive risk assessment of more than 5 million npm, PyPi, and RubyGems packages.

Read More about New Portal Helps Devs Spot Malicious Open Source Packages
New Portal Helps Devs Spot Malicious Open Source Packages
npm cube ai

Malicious npm package targets AWS users

The history of the package is a lesson in why tracking open source threats is such a challenge — and highlights the value of RL's new Spectra Assure Community.

Read More about Malicious npm package targets AWS users
Malicious npm package targets AWS users
closing the software supply chain security gap booklet

The Power of Complex Binary Analysis

RL Spectra Assure’s AI-driven complex binary analysis delivers critical visibility into software binaries to flag malware and advanced software threats, closing the software supply chain security gap.

Read More about The Power of Complex Binary Analysis
The Power of Complex Binary Analysis
sprinters in a race

How platform engineering helps you get a good start on Secure by Design

Self-service portals for developers can help organizations overcome challenges to getting up and running with CISA's software security initiative.

Read More about How platform engineering helps you get a good start on Secure by Design
How platform engineering helps you get a good start on Secure by Design
third party software derisking mergers and acquisitions

How to secure mergers & acquisitions from software supply chain attacks

When engaging in M&A, acquiring firms often inherit a software stack that presents security concerns. Here’s how you can effectively manage these risks.

Read More about How to secure mergers & acquisitions from software supply chain attacks
How to secure mergers & acquisitions from software supply chain attacks
shield hologram coming out of tablet

Top cybersecurity Substacks to follow

Get up to speed on the state of security operations and related cybersecurity practices by subscribing to these 10 expert-curated Substacks.

Read More about Top cybersecurity Substacks to follow
Top cybersecurity Substacks to follow
car gear shift with ominous skull in wood grain

Why malware matters most: 6 ways to foil software threats faster

Making malware enemy No. 1 should be a top priority for AppSec teams. Here's why you need to shift your team's focus from vulnerabilities.

Read More about Why malware matters most: 6 ways to foil software threats faster
Why malware matters most: 6 ways to foil software threats faster
reversinglabs webinar title card for 2024 verizon DBIR

Verizon DBIR 2024: The rise in software supply chain attacks explained

Verizon's Data Breach Investigations Report marked a dramatic shift in threats. Learn about it from Verizon — and how to get ahead of risk — in this Webinar.

Read More about Verizon DBIR 2024: The rise in software supply chain attacks explained
Verizon DBIR 2024: The rise in software supply chain attacks explained
Previous1...222324...59Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top