RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
5 takeaways

2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

The Magic Quadrant™ for Software Supply Chain Security is a 45-minute read. Here's what we feel security leaders need to pull from it.

Read More about 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways
2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Products & TechnologyJuly 30, 2026

RL Malware Analysis and Threat Hunting Updates for H1 2026

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

black and white woman headshot amy pace
Amy PaceAmy Pace
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
MATH H1 2026

Three themes run through RL's Malware Analysis and Threat Hunting portfolio updates for the first half of 2026: Infrastructure Modernization, Automated Incident Response, and AI-ready Architecture.

Here are the key highlights:

Spectra Detect v6.1: Kubernetes-Native Deployment for Enterprise Scale

Spectra Detect is engineered for speed, scalability, and extensibility, with the ability to process millions of files per day. With the release of version 6.1, Spectra Detect introduces Kubernetes microservices to simplify infrastructure management and reduce total cost of ownership. This architectural shift enables auto-scaling and decoupling of applications from operating systems.

  • Kubernetes Microservices Architecture: Connector, receiver, pre-processor, processor, post-processor and egress functions now run as independently scaling pods rather than fixed hub-and-worker appliances. Each layer scales up under load and back down when idle, which removes the need to provision and pre-size appliances for peak volume.
  • Helm Chart-based Deployment: Configuration and rollout are managed through Helm charts, aligning with standard DevOps and Kubernetes tooling rather than a proprietary management layer. RL provides starter templates that teams can adapt to their environment.
  • Built-in Resiliency: Deployments inherit Kubernetes-native redundancy and self-healing. Capacity flexes to ingest load per service – no manual VM cloning.
  • Connector Support at Launch: Version 6.1 ships with AWS, manual API and ICAP Server connectors, with additional connectors planned to reach parity with the existing appliance model.

Spectra Analyze v9.8–9.9: SOC Workflow Empowerment

Spectra Analyze empowers all levels of the SOC with a private, in-depth, malware analysis workbench. Across versions 9.8.0 through 9.9.0, Spectra Analyze added capabilities that speed up investigation, expand hunting coverage, and prepare the platform for AI-assisted workflows.

  • Spectra Analyze MCP Server: The MCP server gives AI assistants a standardized, secure interface into Spectra Analyze for malware reporting, indicator of compromise (IoC) triage, file and network reputation lookups, and natural-language search. It supports multi-modal prompts and includes a pre-built prompt library, providing easy, out of the box functionality.
  • Expanded EDR Integrations and Connector Setup Wizard:  Spectra Analyze now has direct integrations with CrowdStrike Falcon, Palo Alto Cortex, SentinelOne and Microsoft Defender for seamless two-way enrichment. Plus, a new step-by-step wizard provides quick and easy set up to ensure connectors are configured correctly, enabling reliable two-way data flow. Suspicious files flagged in the EDR platform are automatically submitted for analysis, with enriched verdicts flowing back to strengthen detection and response.
  • Similarity Search with TLSH and SSDEEP: Analysts can now pivot from a known sample to related or variant files using fuzzy hashing instead of relying on exact hash matches alone. Matches are ranked by similarity distance, surfacing the closest 1,000 related samples, which helps threat hunters and threat intel teams track malware families and variants that a single hash would miss.
  • Configurable Risk Tolerance Levels: Administrators can now tune classification sensitivity (RL Default, High, Medium or Low) to adjust how heavily additional signals, such as RL Cloud Sandbox, network threat intelligence, Auxiliary analysis, YARA Forge rules, and other sandboxes weigh into a verdict, thereby balancing detection rate against false-positive tolerance for their environment.
  • Quishing Analysis: This capability identifies and extracts URLs, domains, IP addresses and QR-code links embedded in images and PDF attachments, surfacing indicators commonly used in phishing and business email compromise that text-based scanning alone would miss.
  • Expanded Network Verdict Coverage: Third-party verdict sources for URLs, domains and IPs have more than doubled, growing from ~20 to ~50 sources, broadening visibility and confidence in network-based classifications.
  • RL Cloud Sandbox Enhancements: Interactive analysis now supports locale and geolocation selection to better simulate regional conditions, and the sandbox added an Android 12 environment for dynamic analysis of mobile malware samples.
  • YARA Hunting Improvements: Multiple YARA improvements have been made, including enhancements to YARA export capabilities for easier integration with external tools and workflows. Users can now also filter YARA matches by multiple classifications simultaneously (e.g., Malicious and Suspicious). And, API support has been added for clearing continuous YARA matches automatically. Lastly, enhanced RBAC controls have been added for more granular permission separation.
  • New Streamlined UI (PREVIEW): A submission-first interface lands analysts directly on Search & Submissions rather than a metrics dashboard, with clickable network indicators that support one-click pivoting between related URL, domain and IP reports – helping to streamline investigations and better align with how analysts work.

Spectra Intelligence: Private URL Analysis for Regulated Investigations

Spectra Intelligence provides SOC teams with the most up-to-date and accurate file and network reputation data and context-rich, automation-ready intelligence to fuel security workflows and enrichment pipelines.

In addition to private file analysis, which has always been in place, Spectra Intelligence now supports private URL analysis, which keeps network threat intelligence lookups scoped to the requesting organization. Reputation lookups, dynamic detonation and classification still run in full; only the visibility of the lookup changes. This is aimed at highly regulated enterprises and legal or compliance teams that need to investigate indicators without exposing an active investigation before findings are ready to disclose.

Integration and Extensibility: ServiceNow Connector

ReversingLabs continues to build new connectors and expand our ecosystem with leading SOC platforms and enterprise security stacks -- helping ensure seamless integrations with our threat intelligence and malware analysis portfolio. With our latest release, we now have a direct integration with ServiceNow's Security Incident Response (SIR) application.

  • ServiceNow SIR connector: Available free in the ServiceNow Store, this connector automatically enriches SIR incidents with RL threat intelligence as soon as observables (file hashes, IPs, domains, URLs) populate an incident, no flow configuration required. Verdicts appear as clearly labeled RL tags directly in the incident view, and suspicious file attachments uploaded to SIR are automatically submitted to Spectra Analyze for analysis. 

AI and Automation: Building for Agentic SOC Workflows

Alert volumes keep climbing, and a fixed severity cutoff for triage is a shrinking strategy as adversaries adapt faster than manual review can keep pace. H1 2026 extended RL's AI and automation surface to meet that shift:

  • MCP Servers for Spectra Analyze and Spectra Intelligence: With MCP support now available for both products, AI agents can query malware verdicts and threat intelligence data using a standardized, AI-native interface rather than custom API integration work. 
  • SOC Automation Agents and Skills: New automation agents can take an alert through validation, false-positive/true-positive adjudication and documented incident response, reducing the manual triage work that consumes analyst time on lower-severity alerts.

With ReversingLabs, the Agentic SOC gets access to the world’s largest threat intelligence dataset and unrivaled, deterministic context for higher-fidelity detections, faster triage, and fewer false positives. 

What This Means for Your Detection and Response Workflow

Taken together, these updates give security teams three concrete outcomes: infrastructure flexibility and scalability, less manual work between an alert firing and an analyst getting context, and a growing set of AI-native interfaces that make it possible to automate triage, significantly streamline investigation and response, and enable faster threat hunting.

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security. Plus: Why Gartner® said binary analysis is a must-have control.
  • Get up to speed on the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.
  • Learn how to build high-fidelity threat intel feeds for agentic AI in this webinar.
  • Take a deep dive into suspicious file triage and best practices in this whitepaper.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:Products & Technology

More Blog Posts

Spectra Analyze in Action: Hunting Device Code Phishing Pages

Spectra Analyze in Action: Hunting Device Code Phishing Pages

RL recently discovered active Microsoft 365 device code phishing. Here's a walkthrough of how our researchers found the campaign.

Learn More about Spectra Analyze in Action: Hunting Device Code Phishing Pages
Spectra Analyze in Action: Hunting Device Code Phishing Pages
MQ for SSCS blog

This Report from Gartner Defines the Software Supply Chain Security Market

Explore the new Gartner® Magic Quadrant™ for software supply chain security and learn why ReversingLabs is recognized. 

Learn More about This Report from Gartner Defines the Software Supply Chain Security Market
This Report from Gartner Defines the Software Supply Chain Security Market
Mario Vuksan

Software Supply Chain Security Just Got Its Own Magic Quadrant — and RL Is In It 

SSCS is a footnote that grew up, moved out, and got its own report. 

Learn More about Software Supply Chain Security Just Got Its Own Magic Quadrant — and RL Is In It 
Software Supply Chain Security Just Got Its Own Magic Quadrant — and RL Is In It 
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Learn More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top