RL Blog
galaxy planet atom nucleus abstract
October 31, 2023

IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations

ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

Read More about IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
How mature is your open-source risk management? S2C2F helps map dependencies
October 26, 2023

How mature is your open-source risk management? S2C2F helps map dependencies

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Read More about How mature is your open-source risk management? S2C2F helps map dependencies
How mature is your open-source risk management? S2C2F helps map dependencies
App sec prioritization is priority No. 1 for CISOs
October 25, 2023

App sec prioritization is priority No. 1 for CISOs

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Read More about App sec prioritization is priority No. 1 for CISOs
App sec prioritization is priority No. 1 for CISOs
file folders labeled restricted, secret, confidential
October 24, 2023

GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Read More about GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk
GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk
rusty cog gear
October 19, 2023

Rust on Android goes bare metal: 3 key security benefits

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

Read More about Rust on Android goes bare metal: 3 key security benefits
Rust on Android goes bare metal: 3 key security benefits
rusty chain links near open body of water
October 10, 2023

Are APIs the weak link in your supply chain security?

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

Read More about Are APIs the weak link in your supply chain security?
Are APIs the weak link in your supply chain security?
The state of OSS security: Changes in attack methods, policy
October 5, 2023

The state of OSS security: Changes in attack methods, policy

What’s to come for the security of open source software? ConversingLabs caught up with Mikaël Barbero of the Eclipse Foundation to answer that question. Watch (or listen) and learn.

Read More about The state of OSS security: Changes in attack methods, policy
The state of OSS security: Changes in attack methods, policy
red cubes with letter s on them amid block cubes
October 4, 2023

Typosquatting campaign delivers r77 rootkit via npm

ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

Read More about Typosquatting campaign delivers r77 rootkit via npm
Typosquatting campaign delivers r77 rootkit via npm
new features for reversinglabs a1000 version 8.3
October 3, 2023

ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward

Version 8.3 of RL's A1000 Malware Analysis Platform delivers better visuals, search, and an improved cloud sandbox. Here are all of the updates.

Read More about ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward
ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward
pipeline
October 2, 2023

NIST supply chain security guidance for CI/CD environments: What you need to know

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Read More about NIST supply chain security guidance for CI/CD environments: What you need to know
NIST supply chain security guidance for CI/CD environments: What you need to know
pipeline with red shutoff wheel valve
October 2, 2023

NIST supply chain security guidance for CI/CD environments: What you need to know

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Read More about NIST supply chain security guidance for CI/CD environments: What you need to know
NIST supply chain security guidance for CI/CD environments: What you need to know
BlackCat (ALPHV): What we know about the MGM hack
September 28, 2023

BlackCat (ALPHV): What we know about the MGM hack

Ransomware-as-a-service gang ALPHV (a.k.a. BlackCat) carried out a sophisticated attack on the hotel and casino company MGM. Here’s what the ReversingLabs threat team understands.

Read More about BlackCat (ALPHV): What we know about the MGM hack
BlackCat (ALPHV): What we know about the MGM hack
conversinglabs podcast title card apple devices as a growing attack vector
September 27, 2023

With growing threats to Apple devices, Kandji ramps up

Kandji Director of Threat Intelligence Devin Byrd talks about the growing enterprise threats to macOS and iOS endpoints.

Read More about With growing threats to Apple devices, Kandji ramps up
With growing threats to Apple devices, Kandji ramps up
pressure gauge needle movement increasing
September 26, 2023

EPSS vs. CVSS: Exploit prediction could move the needle on software risk

Will the Exploit Prediction Scoring System improve application security now — and software supply chain security in the future? Here's what you need to know.

Read More about EPSS vs. CVSS: Exploit prediction could move the needle on software risk
EPSS vs. CVSS: Exploit prediction could move the needle on software risk
podcast title card the art of security chaos engineering with kelly shortride
September 20, 2023

The art of security chaos engineering

What if dev and app sec teams showed the same ingenuity, nimbleness and ruthless efficiency as cybercriminals? Fastly's Kelly Shortridge explains why that's essential to resilience.

Read More about The art of security chaos engineering
The art of security chaos engineering
Previous1...262728...55Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top