RL Blog
text iconburst in middle of circle of flames

Update: IconBurst npm software supply chain attack grabs data from apps and websites

ReversingLabs researchers have uncovered a widespread campaign to install malicious npm modules that are harvesting sensitive data from forms embedded in mobile apps and websites.

Read More about Update: IconBurst npm software supply chain attack grabs data from apps and websites
Update: IconBurst npm software supply chain attack grabs data from apps and websites
The Week in Cybersecurity: NATO creates cyber rapid response

The Week in Cybersecurity: NATO creates cyber rapid response

International relations intersects with cybersecurity, learn how to leverage YARA rules, plus new developments on AstraLocker 2.0.

Read More about The Week in Cybersecurity: NATO creates cyber rapid response
The Week in Cybersecurity: NATO creates cyber rapid response
SBOM Facts: Know what's in your software to fend off supply chain attacks

SBOM Facts: Know what's in your software to fend off supply chain attacks

SBOM Facts: Know what's in your software to fend off supply chain attacks

Read More about SBOM Facts: Know what's in your software to fend off supply chain attacks
SBOM Facts: Know what's in your software to fend off supply chain attacks
Smash-and-grab: AstraLocker 2.0 pushes ransomware direct from Office docs

Smash-and-grab: AstraLocker 2.0 pushes ransomware direct from Office docs

ReversingLabs recently discovered instances of the AstraLocker 2.0 malware distributed directly from Microsoft Word files used in phishing attacks.

Read More about Smash-and-grab: AstraLocker 2.0 pushes ransomware direct from Office docs
Smash-and-grab: AstraLocker 2.0 pushes ransomware direct from Office docs
The Week in Cybersecurity: Austrian hackers-for-hire KNOTWEED serve up Subzero malware

The Week in Cybersecurity: Austrian hackers-for-hire KNOTWEED serve up Subzero malware

Austrian group KNOTWEED spreads malware via Microsoft products, new malware-infested apps pop up in the Google Play store, and mo

Read More about The Week in Cybersecurity: Austrian hackers-for-hire KNOTWEED serve up Subzero malware
The Week in Cybersecurity: Austrian hackers-for-hire KNOTWEED serve up Subzero malware
Paul Robers for Conversing Labs podcast

ConversingLabs highlights: RSA Conference spotlights software supply chain, critical infrastructure risk

The RSA Conference brings some of the brightest minds in information security together in one place.

Read More about ConversingLabs highlights: RSA Conference spotlights software supply chain, critical infrastructure risk
ConversingLabs highlights: RSA Conference spotlights software supply chain, critical infrastructure risk
RSA conference zero trust roundtable event

How to build trust in a zero-trust environment: Security leaders share insights

Read More about How to build trust in a zero-trust environment: Security leaders share insights
How to build trust in a zero-trust environment: Security leaders share insights
Omer Gil and Daniel Krivelevich outlined the top CI/CD security risks at RSA Conference 2022.

5 CI/CD breaches analyzed: Why you need to update your software security

Omer Gil and Daniel Krivelevich outlined the top CI/CD security risks at RSA Conference 2022. Here's what your software security team needs to know.

Read More about 5 CI/CD breaches analyzed: Why you need to update your software security
5 CI/CD breaches analyzed: Why you need to update your software security
Survey finds software supply chain security top of mind for dev teams — but tampering detection lags

Survey finds software supply chain security top of mind for dev teams — but tampering detection lags

A survey of more than 300 technology professionals found widespread concern about supply chain attacks, but only sporadic efforts to detect such attacks.

Read More about Survey finds software supply chain security top of mind for dev teams — but tampering detection lags
Survey finds software supply chain security top of mind for dev teams — but tampering detection lags
Taking the quiz: Are you up to speed on supply chain risk?

Taking the quiz: Are you up to speed on supply chain risk?

ReversingLabs delivered a game-show style review of its survey on software supply chain security at RSA Conference. Here are the questions and answers.

Read More about Taking the quiz: Are you up to speed on supply chain risk?
Taking the quiz: Are you up to speed on supply chain risk?
MITRE’s System of Trust: A standard for software supply chain security

MITRE’s System of Trust: A standard for software supply chain security

MITRE’s System of Trust framework is aiming to standardize how software supply chain security is assessed. MITRE's Robert Martin explains.

Read More about MITRE’s System of Trust: A standard for software supply chain security
MITRE’s System of Trust: A standard for software supply chain security
What’s hot at #RSAC? Our picks for the big security show

What’s hot at #RSAC? Our picks for the big security show

It's two years in, and COVID is still threatening to steal RSA Conference's mojo. But for those willing to brave Moscone in San Francisco (and those attending virtually), you won’t be disappointed. Here are our picks for must-see talks.

Read More about What’s hot at #RSAC? Our picks for the big security show
What’s hot at #RSAC? Our picks for the big security show
Go below the surface on tampering: The trouble with software integrity validation

Go below the surface on tampering: The trouble with software integrity validation

The growing number of software supply chain attacks is putting pressure on validation of software integrity and authenticity.

Read More about Go below the surface on tampering: The trouble with software integrity validation
Go below the surface on tampering: The trouble with software integrity validation
confused armadillo looking at pypi logo

It’s not a secret if you publish it on PyPI

Python packages can contain sensitive information. Here's how software development teams can keep secrets secret

Read More about It’s not a secret if you publish it on PyPI
It’s not a secret if you publish it on PyPI
Coinminer and npm: What you see is not always what you get

Coinminer and npm: What you see is not always what you get

Package repository content can be different from source code repository content. Here's what your software team needs to know.

Read More about Coinminer and npm: What you see is not always what you get
Coinminer and npm: What you see is not always what you get
Previous1...484950...57Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outWe're A Visionary
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top