RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Products & TechnologyJune 14, 2018

A Risk Not Worth Taking

Company’s are putting their data at risk by using VirusTotal, even when safer, superior options exist

FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us

Over the last few months, almost all global companies have been focused on implementing changes across their IT systems and websites to meet GDPR compliance. But how many have considered how their existing security practices are affected by this new privacy law?

Recently at the FS-ISAC event in Boca Raton, Florida the topic of GDPR and security practices was discussed and interestingly one area of great risk was how companies utilize the VirusTotal open source malware database and the privacy concerns its use creates.

One threat intelligence researcher from a large retail bank commenting, “When I do a YARA query in VirusTotal with keywords like company name/username/ password/ etc., I am shocked at the sensitive and classified documents that appear.”

It was clear that many security teams do not understand the risk of VirusTotal’s open source structure. It was also clear that many researchers use VirusTotal “on the side” even though its use may not be approved by their company.

Another large global financial company researcher said his team monitors VirusTotal because, “You can actually catch the bad guys testing their latest malware against the AV scanners and that is a great source of early intelligence for the team.”

The discussion ended with GDPR compliance and what would happen if someone accidentally loaded a file into VirusTotal that is suspected of infection but also contained a list of EU client PII data. There were many comments that once a file is loaded, it is very difficult to get it out. One SOC director saying, “It is too late, you are done.”

So why do companies take the risk of using VirusTotal at all?

Mostly because they are unaware there are better alternatives. ReversingLabs, for example, offers the largest, most up-to-date and complete file intelligence service on the market. You can read all about our service and how it compares to VirusTotal here.

1) Over 40 billion samples of malware and goodware, with millions of samples added daily.

2) Trusted intelligence not dependent on crowdsourcing – get the highest fidelity intelligence from curated, continuous file harvesting backed by over 15 years of in-house threat research and proprietary analysis technology.

3) 100% private – private file analysis and private data corpus not accessible to the public.

4) Better and faster hunting - more file context means better YARA hunting and a more extensive Retro-search capability.

5) Real enterprise-class support – not only to help product usage but also to support your hunting efforts.

Tags:Products & Technology

More Blog Posts

So, stop putting your company at risk – give us a call!

A Risk Not Worth Taking

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Get all of RL's malware analysis and threat hunting updates with this H1 product update post — and join the webinar to discuss what a modern SOC looks like.
  • Get on top of Malware-as-a-Service with RL's report, "Copy, Paste, Compromise: The Tale of ClickFix" — and grab the related YARA rule.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Update your understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Related

How to Leverage Spectra Analyze's Search for SVG AnalysisRL Malware Analysis and Threat Hunting Updates for H1 2026Hunting Device Code Phishing Pages

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Leveraging the Spectra Analyze Search Function for SVG Analysis

How to Leverage Spectra Analyze's Search for SVG Analysis

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Learn More about How to Leverage Spectra Analyze's Search for SVG Analysis
How to Leverage Spectra Analyze's Search for SVG Analysis
MATH H1 2026

RL Malware Analysis and Threat Hunting Updates for H1 2026

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

Learn More about RL Malware Analysis and Threat Hunting Updates for H1 2026
RL Malware Analysis and Threat Hunting Updates for H1 2026
Spectra Analyze in Action: Hunting Device Code Phishing Pages

Hunting Device Code Phishing Pages

RL recently discovered active Microsoft 365 device code phishing. Here's a walkthrough of how our researchers found the campaign.

Learn More about Hunting Device Code Phishing Pages
Hunting Device Code Phishing Pages