RL Blog
OpenClaw agentic AI risk

OpenClaw and AI risk: 3 AppSec lessons

The OpenClaw saga is a case study on the threat from agentic AI, showing how it increases software risk.

Read More about OpenClaw and AI risk: 3 AppSec lessons
OpenClaw and AI risk: 3 AppSec lessons
Trip Hazard

Claude Code Security: The pros and cons

The new tool is a step forward on AI coding risk — but it trips on modern threats because it looks only at source code.

Read More about Claude Code Security: The pros and cons
Claude Code Security: The pros and cons
Fight fire with fire

AI-native AppSec: What it is — and why it matters

AI coding is a game-changer — and requires AI-powered application security to fight fire with fire.

Read More about AI-native AppSec: What it is — and why it matters
AI-native AppSec: What it is — and why it matters
AI coding and AppSec

BSIMM16 confirms: AI redefines AppSec

AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.

Read More about BSIMM16 confirms: AI redefines AppSec
BSIMM16 confirms: AI redefines AppSec
Inside the NuGet hack toolset

Inside the NuGet hackers' toolset

RL discovered two packages containing scripts that complete a typosquatting toolchain. Here's how it worked.

Read More about Inside the NuGet hackers' toolset
Inside the NuGet hackers' toolset
Malicious NuGet package targets Stripe

Malicious NuGet package targets Stripe

Threat actors targeted developers with a bogus package — a shift away from the recent crypto development hack focus.

Read More about Malicious NuGet package targets Stripe
Malicious NuGet package targets Stripe
AI upends SSCS

How AI agents upend supply chain security

Here’s what you need to know about their impact on software security — and what you can do to fight back. 

Read More about How AI agents upend supply chain security
How AI agents upend supply chain security
Cybercrime-as-a-service

Cybercrime-as-a-service forces a security rethink

With AI-powered tools readily available, sophisticated attacks no longer require sophisticated attackers.

Read More about Cybercrime-as-a-service forces a security rethink
Cybercrime-as-a-service forces a security rethink
Spectra Analyze: YARA Retrohunting

How to Use YARA Retrohunting for Defense

Learn how to use RL’s analysis of "pkr_mtsi" to advance your detection engineering in Spectra Analyze.

Read More about How to Use YARA Retrohunting for Defense
How to Use YARA Retrohunting for Defense
Commercial software risk

Commercial software risk: New controls required

Legacy strategies and tooling can’t manage today’s software threats. Here’s why binary analysis is necessary.

Read More about Commercial software risk: New controls required
Commercial software risk: New controls required
Inside the ‘graphalgo’ fake crypto developer recruitment campaign

Inside the fake crypto developer recruitment hack

Here’s a more-in-depth technical analysis of the packages involved in the "graphalgo" campaign.

Read More about Inside the fake crypto developer recruitment hack
Inside the fake crypto developer recruitment hack
Fake recruiter campaign targets crypto developers with RAT

Fake recruiter campaign targets crypto devs

A new branch of a fake job recruitment campaign, dubbed "graphalgo," is targeting developers with a RAT.

Read More about Fake recruiter campaign targets crypto devs
Fake recruiter campaign targets crypto devs
CISO Playbook Insights

Gartner® CISO Playbook for Commercial SSCS: 3 key insights

Here are the takeaways CISOs and other security leaders should consider for their TPCRM strategies.

Read More about Gartner® CISO Playbook for Commercial SSCS: 3 key insights
Gartner® CISO Playbook for Commercial SSCS: 3 key insights
AppSec and trust

Notepad++ hack: Supply chain threats evolve

A compromise of the source code editor underscores attack method diversification. It's time to go beyond trust.

Read More about Notepad++ hack: Supply chain threats evolve
Notepad++ hack: Supply chain threats evolve
MCP security robot

Lab offers 9 ways to improve MCP security

The Vulnerable MCP Servers Lab delivers integration training, demos, and instruction on attack methods.

Read More about Lab offers 9 ways to improve MCP security
Lab offers 9 ways to improve MCP security
Previous1...567...59Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top