RL Blog
booklet with cover title assess and manage commercial software risk

How to assess and manage commercial software risk

Major attacks show that commercial software is the principal attack surface. Here’s why – and how your team can mitigate its risks.

Read More about How to assess and manage commercial software risk
How to assess and manage commercial software risk
podcast microphone setup

Listen up: 10 cybersecurity podcasts you can learn from

Get up to speed on all things cybersecurity by subscribing to these knowledge-dropping podcasts. You're welcome.

Read More about Listen up: 10 cybersecurity podcasts you can learn from
Listen up: 10 cybersecurity podcasts you can learn from
monitor with world map with download icons scattered around the continents

Python downloader highlights noise problem in open source threat detection

RL discovered what appeared to be a malicious downloader on PyPI. It turned out to be red teaming — but highlights a growing problem for threat detection.

Read More about Python downloader highlights noise problem in open source threat detection
Python downloader highlights noise problem in open source threat detection
number nine floating above wooden blocks

9 best practices for leveraging threat intelligence in your security operations

Cyberthreat intelligence can bolster your SecOps with actionable info — if you choose wisely. Here's how to get started with CTI and what you need to know.

Read More about 9 best practices for leveraging threat intelligence in your security operations
9 best practices for leveraging threat intelligence in your security operations
yellow brick building with national security agency emblem projected

NSA's zero-trust maturity for AppSec: What you need to know

The new initiative aims to help teams secure application access — and ensure continuous visibility of the workload. Experts weigh in with key insights.

Read More about NSA's zero-trust maturity for AppSec: What you need to know
NSA's zero-trust maturity for AppSec: What you need to know
speed limit sign in spanish

Security operations by the numbers: 30 cybersecurity stats that matter

Get up to speed on the state of SecOps with key takeaways from recent research and surveys of cybersecurity practitioners and leaders.

Read More about Security operations by the numbers: 30 cybersecurity stats that matter
Security operations by the numbers: 30 cybersecurity stats that matter
glass of water on table

The state of AppSec: Are we getting ahead of attackers — or falling behind?

Is application security keeping up with modern supply chain attacks? One SME urges "glass half full"-optimism. The reality: AppSec tooling needs an upgrade.

Read More about The state of AppSec: Are we getting ahead of attackers — or falling behind?
The state of AppSec: Are we getting ahead of attackers — or falling behind?
the word share with arrows coming out of it drawn by marker

Making SBOMs actionable: Why sharing is essential

Factors are converging to make sharing of software bills of materials a reality. Here are key concerns — and why data sharing is essential to their effectiveness.

Read More about Making SBOMs actionable: Why sharing is essential
Making SBOMs actionable: Why sharing is essential
man with hand on chest pledging

Will CISA's Secure by Design pledge be a catalyst for better software security?

CISA has support from more than 60 companies, and it hopes more will follow. Here's what's in the pledge — and what experts say about its chances of success.

Read More about Will CISA's Secure by Design pledge be a catalyst for better software security?
Will CISA's Secure by Design pledge be a catalyst for better software security?
scrabble tiles spelling out threats

When it comes to threat modeling, not all threats are created equal

With inherent threats, which are core to the system being modeled, protective measures cannot be perfect or complete. Here's how to best manage that.

Read More about When it comes to threat modeling, not all threats are created equal
When it comes to threat modeling, not all threats are created equal
enrich highlighted in dictionary

CISA's 'vulnrichment' aims to fix the NVD

The new program, which follows NIST's slowdown on the National Vulnerability Database, will enrich CVEs with contextual data for better vulnerability management.

Read More about CISA's 'vulnrichment' aims to fix the NVD
CISA's 'vulnrichment' aims to fix the NVD
RSA 2024 conference mural

What you missed at RSA Conference 2024: Key trends and takeaways

Here are the highlights that practitioners and leaders should know if they skipped last week's RSAC, the mother of all cybersecurity shows.

Read More about What you missed at RSA Conference 2024: Key trends and takeaways
What you missed at RSA Conference 2024: Key trends and takeaways
two men in chairs at rsa conference

NSA: Nation state actors aren't after your data — they want your OT

In his “State of the Hack” session at RSA Conference, NSA’s David Luber said attackers are thinking beyond data theft and targeting operational technology. That's why your team needs to look deeper and longer for signs of compromise.

Read More about NSA: Nation state actors aren't after your data — they want your OT
NSA: Nation state actors aren't after your data — they want your OT
wrench tightening sink bend

CI/CD pipelines and the cloud: Are your development secrets at risk?

Combined with cloud service providers' CLIs, continuous delivery/continuous integration can pose a threat. Here's why — and how to keep a lid on your secrets.

Read More about CI/CD pipelines and the cloud: Are your development secrets at risk?
CI/CD pipelines and the cloud: Are your development secrets at risk?
touch screen AI and lock icons

Why GenAI fails at full SOC automation

In a new research note, Forrester analysts explain how the current limitations of AI-enabled SecOps tools keep autonomous security decision making out of reach.

Read More about Why GenAI fails at full SOC automation
Why GenAI fails at full SOC automation
Previous1...232425...59Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top