
DevOps teams: BGP security is BAD. But you can fix it
The security of the Border Gateway Protocol (BGP) is laughable. But we all rely on it every day. For everything.

The security of the Border Gateway Protocol (BGP) is laughable. But we all rely on it every day. For everything.

Discrepancies in reports to the national vulnerability databases (NVD) show the U.S. lags behind China, exposing U.S. firms to cyber attacks.

ReversingLabs’ YARA detection rule for Nokoyawa can help you find this ransomware in your environment.

The shift to remote work punched holes in government networks. But it also fostered a transformation in public-private cooperation, one NSA official noted at LABScon.

ReversingLabs has discovered a malicious npm package disguised as the software tool Material Tailwind. Here's an in-depth look at our discovery — and threat analysis.

t’s confirmed: The Linux kernel will have Rust support soon.

The famous hacking group Lapsus$ appears to be back in action. Also: Russian cyber spies are targeting Ukraine by posing as internet providers.

Selling software to the government? You must now attest to conformity with NIST standards. And SBOMs, while not required, are preferred.


A new U.S. federal government memo mandates the federal use of secure third-party software products and services. Also, Twitter whistleblower Mudge Zatko reveals new details of the company’s security practices (or lack thereof) with Congress.

Peiter “Mudge” Zatko (pictured) was grilled by U.S. senators this week. Twitter’s former head of security has some damning things to say about the service’s DevOps security — or lack of it.

Here's what you need to know about the new OpenSSF npm security best practices.

ReversingLabs’ YARA detection rule for GoodWill can help you find this ransomware in your environment.

In our latest episode of the ConversingLabs podcast, host Paul Roberts interviews ReversingLabs researcher Joseph Edwards about his analysis of Follina, a newly discovered exploit with a pretty name, but nasty intentions.

Vice Society ransomware group targets America’s education sector, the U.S. government’s new position on software supply chain security, and more.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial