
IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

What’s to come for the security of open source software? ConversingLabs caught up with Mikaël Barbero of the Eclipse Foundation to answer that question. Watch (or listen) and learn.

ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

Version 8.3 of RL's A1000 Malware Analysis Platform delivers better visuals, search, and an improved cloud sandbox. Here are all of the updates.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Ransomware-as-a-service gang ALPHV (a.k.a. BlackCat) carried out a sophisticated attack on the hotel and casino company MGM. Here’s what the ReversingLabs threat team understands.

Kandji Director of Threat Intelligence Devin Byrd talks about the growing enterprise threats to macOS and iOS endpoints.

Will the Exploit Prediction Scoring System improve application security now — and software supply chain security in the future? Here's what you need to know.

What if dev and app sec teams showed the same ingenuity, nimbleness and ruthless efficiency as cybercriminals? Fastly's Kelly Shortridge explains why that's essential to resilience.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial