<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ReversingLabs Blog</title>
    <link>https://www.reversinglabs.com/blog</link>
    <description>Latest blog posts from ReversingLabs</description>
    <language>en-US</language>
    <pubDate>Sat, 06 Jun 2026 04:09:12 GMT</pubDate>
    <dc:date>2026-06-06T04:09:12.397Z</dc:date>
    <dc:language>en</dc:language>
    <lastBuildDate>Sat, 06 Jun 2026 04:09:12 GMT</lastBuildDate>
    <atom:link href="https://www.reversinglabs.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title><![CDATA[How 56 npm packages used binding.gyp to steal CI/CD secrets]]></title>
      <link>https://www.reversinglabs.com/blog/npm-bindinggyp-cicd-secrets</link>
      <guid>https://www.reversinglabs.com/blog/npm-bindinggyp-cicd-secrets</guid>
      <pubDate>Thu, 04 Jun 2026 21:30:00 GMT</pubDate>
      <dc:date>2026-06-04T21:30:00.000Z</dc:date>
      <description><![CDATA[The attack is notable for its breadth, with the threat actor flooding npm with malicious package versions.]]></description>
      <dc:creator><![CDATA[RL Research Team]]></dc:creator>
      <author><![CDATA[content@reversinglabs.com (RL Research Team)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Blog-Thousands-of-developer-projects-compromised-in-npm%20hack.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Dependency remediation bolstered with CVE Lite CLI]]></title>
      <link>https://www.reversinglabs.com/blog/cve-lite-cli</link>
      <guid>https://www.reversinglabs.com/blog/cve-lite-cli</guid>
      <pubDate>Thu, 04 Jun 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-06-04T15:00:00.000Z</dc:date>
      <description><![CDATA[OWASP's new dependency scanner gives developers actionable fixes. But today's supply chain attacks aren’t in any advisory database.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/dependency-cve-lite.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Get ahead of frontier AI: 5 AppSec strategy upgrades]]></title>
      <link>https://www.reversinglabs.com/blog/frontier-ai-update-your-appsec</link>
      <guid>https://www.reversinglabs.com/blog/frontier-ai-update-your-appsec</guid>
      <pubDate>Wed, 03 Jun 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-06-03T15:00:00.000Z</dc:date>
      <description><![CDATA[Frontier AI is collapsing the time from vulnerability discovery to exploit. Here are 5 ways to update your AppSec before it hits.]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/out-front-race.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[CVE noise drowns out supply chain threats]]></title>
      <link>https://www.reversinglabs.com/blog/noise-to-signal-malware-matters</link>
      <guid>https://www.reversinglabs.com/blog/noise-to-signal-malware-matters</guid>
      <pubDate>Tue, 02 Jun 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-06-02T15:00:00.000Z</dc:date>
      <description><![CDATA[48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/db-meter.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[31 Red Hat npm packages backdoored in 72 seconds]]></title>
      <link>https://www.reversinglabs.com/blog/red-hat-cloud-service-npm-packages-backdoored-in-72-seconds</link>
      <guid>https://www.reversinglabs.com/blog/red-hat-cloud-service-npm-packages-backdoored-in-72-seconds</guid>
      <pubDate>Mon, 01 Jun 2026 21:30:00 GMT</pubDate>
      <dc:date>2026-06-01T21:30:00.000Z</dc:date>
      <description><![CDATA[RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.]]></description>
      <dc:creator><![CDATA[RL Research Team]]></dc:creator>
      <author><![CDATA[content@reversinglabs.com (RL Research Team)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/malicious-npm-patch-delivers-reverse-shell.webp" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Forrester Names RL in Agentic Development Security Market]]></title>
      <link>https://www.reversinglabs.com/blog/forrester-agentic-development-security-landscape</link>
      <guid>https://www.reversinglabs.com/blog/forrester-agentic-development-security-landscape</guid>
      <pubDate>Thu, 28 May 2026 18:00:00 GMT</pubDate>
      <dc:date>2026-05-28T18:00:00.000Z</dc:date>
      <description><![CDATA[The new landscape report maps 35 vendors addressing an emerging category of risk: AI agents writing insecure code at machine speed.]]></description>
      <dc:creator><![CDATA[Jasmine Noel]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Forrester-Securing%20Agentic%20Development%201400x732%20-%20HubSpot%20Featured%20image-1.png" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[5 lessons from vulnerability management's front lines]]></title>
      <link>https://www.reversinglabs.com/blog/5-lessons-vulnerability-management</link>
      <guid>https://www.reversinglabs.com/blog/5-lessons-vulnerability-management</guid>
      <pubDate>Thu, 28 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-28T15:00:00.000Z</dc:date>
      <description><![CDATA[VM success is determined by findings reaching developers with context — which is getting more challenging. Here's why to shift gears. ]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/shift%20lanes.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Dependency attack takes down ed-tech platform at scale]]></title>
      <link>https://www.reversinglabs.com/blog/canvas-dependency-attack-scale</link>
      <guid>https://www.reversinglabs.com/blog/canvas-dependency-attack-scale</guid>
      <pubDate>Wed, 27 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-27T15:00:00.000Z</dc:date>
      <description><![CDATA[The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/ransomware.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Researcher's Notebook: Hunting Megalodon Fossils]]></title>
      <link>https://www.reversinglabs.com/blog/hunting-megalodon-fossils</link>
      <guid>https://www.reversinglabs.com/blog/hunting-megalodon-fossils</guid>
      <pubDate>Tue, 26 May 2026 15:30:00 GMT</pubDate>
      <dc:date>2026-05-26T15:30:00.000Z</dc:date>
      <description><![CDATA[Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.]]></description>
      <dc:creator><![CDATA[Robert Simmons]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Hunting-Megalodon-Fossils-Researchers-Notebook.webp" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[GitHub breach: The development ecosystem is in the hot seat]]></title>
      <link>https://www.reversinglabs.com/blog/github-compromise-development-ecosystem</link>
      <guid>https://www.reversinglabs.com/blog/github-compromise-development-ecosystem</guid>
      <pubDate>Fri, 22 May 2026 16:30:00 GMT</pubDate>
      <dc:date>2026-05-22T16:30:00.000Z</dc:date>
      <description><![CDATA[This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/developer-attacks.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[AI agents are the new insider threat]]></title>
      <link>https://www.reversinglabs.com/blog/ai-agents-new-insider-threat</link>
      <guid>https://www.reversinglabs.com/blog/ai-agents-new-insider-threat</guid>
      <pubDate>Thu, 21 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-21T15:00:00.000Z</dc:date>
      <description><![CDATA[AI security leader and author Steve Wilson explains why you need to rethink security — and treat AI agents as digital workers.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/robot-army.jpg" type="image/jpeg" />
      <category><![CDATA[Artificial Intelligence (AI)/Machine Learning (ML)]]></category>
    </item>
    <item>
      <title><![CDATA[Hackers Abuse Parental Controls to Hijack Google Accounts]]></title>
      <link>https://www.reversinglabs.com/blog/parental-control-flaw-google-account</link>
      <guid>https://www.reversinglabs.com/blog/parental-control-flaw-google-account</guid>
      <pubDate>Wed, 20 May 2026 17:30:00 GMT</pubDate>
      <dc:date>2026-05-20T17:30:00.000Z</dc:date>
      <description><![CDATA[Learn how attackers are re-casting adults as minors to bypass recovery and lock users out.]]></description>
      <dc:creator><![CDATA[Zaria Vuksan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Hackers-Abuse-Parental-Controls.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Spectra Analyze, Spectra Core Update: Deeper Detection, Smarter Analysis]]></title>
      <link>https://www.reversinglabs.com/blog/spectra-analyze-spectra-core-update52026</link>
      <guid>https://www.reversinglabs.com/blog/spectra-analyze-spectra-core-update52026</guid>
      <pubDate>Wed, 20 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-20T15:00:00.000Z</dc:date>
      <description><![CDATA[RL threat detection and binary analysis can now close the gap for threat hunters.]]></description>
      <dc:creator><![CDATA[Igor Lasic]]></dc:creator>
      <author><![CDATA[ilasic@reversinglabs.com (Igor Lasic)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Spectra-Analyze-Product-Update.png" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[Shai-Hulud code drop: It’s open season for attacks]]></title>
      <link>https://www.reversinglabs.com/blog/the-shai-hulud-code-drop</link>
      <guid>https://www.reversinglabs.com/blog/the-shai-hulud-code-drop</guid>
      <pubDate>Fri, 15 May 2026 02:00:00 GMT</pubDate>
      <dc:date>2026-05-15T02:00:00.000Z</dc:date>
      <description><![CDATA[The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.]]></description>
      <dc:creator><![CDATA[Jaikumar Vijayan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/open-sign-window.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[RL Joins NATO Locked Shields Cyber Event: 3 Takeaways]]></title>
      <link>https://www.reversinglabs.com/blog/locked-shields-2026</link>
      <guid>https://www.reversinglabs.com/blog/locked-shields-2026</guid>
      <pubDate>Thu, 14 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-14T15:00:00.000Z</dc:date>
      <description><![CDATA[ReversingLabs joined defensive teams with its malware analysis platform. Here are key lessons.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Locked-Shields-2026.jpg" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[Think AI agents are risky? Your underlying stack is too]]></title>
      <link>https://www.reversinglabs.com/blog/ai-agents-risk-underlying-stack</link>
      <guid>https://www.reversinglabs.com/blog/ai-agents-risk-underlying-stack</guid>
      <pubDate>Wed, 13 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-13T15:00:00.000Z</dc:date>
      <description><![CDATA[To manage agentic AI risk, organizations need to focus more on the infrastructure they run on.]]></description>
      <dc:creator><![CDATA[Jaikumar Vijayan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/ai-infrastructure.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Mini Shai-Hulud tears at OSS trust]]></title>
      <link>https://www.reversinglabs.com/blog/mini-shai-hulud-tears-at-oss-trust</link>
      <guid>https://www.reversinglabs.com/blog/mini-shai-hulud-tears-at-oss-trust</guid>
      <pubDate>Tue, 12 May 2026 19:00:00 GMT</pubDate>
      <dc:date>2026-05-12T19:00:00.000Z</dc:date>
      <description><![CDATA[This latest compromises of popular and infrastructure-level npm packages are rocking the foundations open source. ]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Shai-hulud%20worm.png" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[How Dirty Frag rose from the Copy Fail exploit ]]></title>
      <link>https://www.reversinglabs.com/blog/dirtyfrag-linux-privilege-escalation-exploit</link>
      <guid>https://www.reversinglabs.com/blog/dirtyfrag-linux-privilege-escalation-exploit</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <dc:date>2026-05-12T16:00:00.000Z</dc:date>
      <description><![CDATA[RL documented 163 samples of the Linux exploit's new variants, active malware — and developed YARA rules.]]></description>
      <dc:creator><![CDATA[Igor Lasic]]></dc:creator>
      <author><![CDATA[ilasic@reversinglabs.com (Igor Lasic)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/DirtyFrag.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Selective NVD enrichment: Why it matters]]></title>
      <link>https://www.reversinglabs.com/blog/nist-selective-nvd-enrichment</link>
      <guid>https://www.reversinglabs.com/blog/nist-selective-nvd-enrichment</guid>
      <pubDate>Thu, 07 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-07T15:00:00.000Z</dc:date>
      <description><![CDATA[AI vulnerability reporting is overwhelming teams — and NIST. But for AppSec, scaling back analysis is cause for alarm.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/nvd-selective-enrichment.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Spectra Analyze in Action: Retrohunting Bots]]></title>
      <link>https://www.reversinglabs.com/blog/spectra-analyze-retrohunting-telegram-bots</link>
      <guid>https://www.reversinglabs.com/blog/spectra-analyze-retrohunting-telegram-bots</guid>
      <pubDate>Wed, 06 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-06T15:00:00.000Z</dc:date>
      <description><![CDATA[Learn how to use ReversingLabs’ Spectra Analyze to expand your detection of malicious Telegram C2 bots. ]]></description>
      <dc:creator><![CDATA[Zaria Vuksan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Spectra-Analyze-in-Action-Retrohunting-Telegram-Bots.jpg" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[How Mythos changes the AppSec calculus]]></title>
      <link>https://www.reversinglabs.com/blog/how-mythos-changes-the-appsec-calculus</link>
      <guid>https://www.reversinglabs.com/blog/how-mythos-changes-the-appsec-calculus</guid>
      <pubDate>Tue, 05 May 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-05-05T15:00:00.000Z</dc:date>
      <description><![CDATA[Here are the facts on Claude Mythos — and why a layered application security framework is essential.]]></description>
      <dc:creator><![CDATA[Doug Levin]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/math-strategy.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Copy Fail Flaw: 5 YARA Rules for Detection]]></title>
      <link>https://www.reversinglabs.com/blog/copy-fail-5-yara-rules</link>
      <guid>https://www.reversinglabs.com/blog/copy-fail-5-yara-rules</guid>
      <pubDate>Fri, 01 May 2026 20:00:00 GMT</pubDate>
      <dc:date>2026-05-01T20:00:00.000Z</dc:date>
      <description><![CDATA[Here’s what you need to know about the Linux kernel privilege escalation — and how to use YARA rules to get on top of it.]]></description>
      <dc:creator><![CDATA[Maik Morgenstern]]></dc:creator>
      <author><![CDATA[maik.morgenstern@reversinglabs.com (Maik Morgenstern)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/linux-penguin-copy-fail-yara-rules.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[How agentic AI flips the trust model]]></title>
      <link>https://www.reversinglabs.com/blog/agentic-ai-trust-model</link>
      <guid>https://www.reversinglabs.com/blog/agentic-ai-trust-model</guid>
      <pubDate>Thu, 30 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-30T15:00:00.000Z</dc:date>
      <description><![CDATA[ As AppSec shifts focus from the components to data, your strategy needs updating. Are you on top of your trust debt?]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/trust-flip.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Claude adds malware to crypto agent]]></title>
      <link>https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto</link>
      <guid>https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto</guid>
      <pubDate>Wed, 29 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-29T15:00:00.000Z</dc:date>
      <description><![CDATA[PromptMink has evolved into a malicious dependency in a package that allows access to crypto wallets and funds.]]></description>
      <dc:creator><![CDATA[Vladimir Pezo]]></dc:creator>
      <author><![CDATA[vladimir.pezo@reversinglabs.com (Vladimir Pezo)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/AI-Malware-Crypto.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[MCP rug-pull attack worries mount]]></title>
      <link>https://www.reversinglabs.com/blog/mcp-rug-pull-attack-worries</link>
      <guid>https://www.reversinglabs.com/blog/mcp-rug-pull-attack-worries</guid>
      <pubDate>Wed, 29 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-29T15:00:00.000Z</dc:date>
      <description><![CDATA[This new class of AI tool supply chain attack highlights how trust of agents can be exploited.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/mcp-attacks.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Can AppSec keep pace with AI coding?]]></title>
      <link>https://www.reversinglabs.com/blog/appsec-keep-up-ai-coding</link>
      <guid>https://www.reversinglabs.com/blog/appsec-keep-up-ai-coding</guid>
      <pubDate>Thu, 23 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-23T15:00:00.000Z</dc:date>
      <description><![CDATA[AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.]]></description>
      <dc:creator><![CDATA[Jaikumar Vijayan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/race-ai-coding-risk.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[LLMmap puts its finger on ML attacks]]></title>
      <link>https://www.reversinglabs.com/blog/llmmap-puts-its-finger-on-ml-attacks</link>
      <guid>https://www.reversinglabs.com/blog/llmmap-puts-its-finger-on-ml-attacks</guid>
      <pubDate>Wed, 22 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-22T15:00:00.000Z</dc:date>
      <description><![CDATA[Researchers show how LLM fingerprinting can be used to automate generation of customized attacks.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/llmmap-finger-ml-attacks.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[QR Code Phishing Evolves: How to Keep Up]]></title>
      <link>https://www.reversinglabs.com/blog/qr-code-phishing-evolves</link>
      <guid>https://www.reversinglabs.com/blog/qr-code-phishing-evolves</guid>
      <pubDate>Tue, 21 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-21T15:00:00.000Z</dc:date>
      <description><![CDATA[Here's what you need to know about the rise of quishing — and how your threat hunting team can get out in front of it.]]></description>
      <dc:creator><![CDATA[Igor Lasic]]></dc:creator>
      <author><![CDATA[ilasic@reversinglabs.com (Igor Lasic)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/quishing-blog-cover.webp" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[Vibeware: More than bad vibes for AppSec]]></title>
      <link>https://www.reversinglabs.com/blog/vibeware-bad-vibes-appsec</link>
      <guid>https://www.reversinglabs.com/blog/vibeware-bad-vibes-appsec</guid>
      <pubDate>Thu, 16 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-16T15:00:00.000Z</dc:date>
      <description><![CDATA[Threat actors are leveraging the freewheeling vibe-coding trend to deliver malicious software at scale.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/vibeware.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[The CRA is coming: Are you ready?]]></title>
      <link>https://www.reversinglabs.com/blog/cyber-resilience-act-get-ready</link>
      <guid>https://www.reversinglabs.com/blog/cyber-resilience-act-get-ready</guid>
      <pubDate>Wed, 15 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-15T15:00:00.000Z</dc:date>
      <description><![CDATA[Here's how the EU's Cyber Resilience Act will reshape the software industry — and how that accelerates advantages.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/accelerate-cra.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Why RL Built Spectra Assure Community]]></title>
      <link>https://www.reversinglabs.com/blog/why-rl-built-spectra-assure-community</link>
      <guid>https://www.reversinglabs.com/blog/why-rl-built-spectra-assure-community</guid>
      <pubDate>Tue, 14 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-14T15:00:00.000Z</dc:date>
      <description><![CDATA[We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.]]></description>
      <dc:creator><![CDATA[Kadi McKean]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Why-RL-Built-Spectra-Assure-Community.jpg" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[Graphalgo fake recruiter campaign returns]]></title>
      <link>https://www.reversinglabs.com/blog/graphalgo-campaign-respawned</link>
      <guid>https://www.reversinglabs.com/blog/graphalgo-campaign-respawned</guid>
      <pubDate>Thu, 09 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-09T15:00:00.000Z</dc:date>
      <description><![CDATA[An attack targeting crypto developers has been respawned — with an LLC and new techniques.]]></description>
      <dc:creator><![CDATA[Karlo Zanki]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Graphalgo-supply-chain-campaign-respawned.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Claude Mythos: Get your AppSec game on]]></title>
      <link>https://www.reversinglabs.com/blog/mythos-ai-appsec</link>
      <guid>https://www.reversinglabs.com/blog/mythos-ai-appsec</guid>
      <pubDate>Wed, 08 Apr 2026 18:30:00 GMT</pubDate>
      <dc:date>2026-04-08T18:30:00.000Z</dc:date>
      <description><![CDATA[Anthropic's new AI is a 'step change' for exposing software flaws — but also ramps up exploits. Are you ready?]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/robot-ai-agents-risk.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[28 application security stats that matter]]></title>
      <link>https://www.reversinglabs.com/blog/28-application-security-stats-that-matter</link>
      <guid>https://www.reversinglabs.com/blog/28-application-security-stats-that-matter</guid>
      <pubDate>Tue, 07 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-07T15:00:00.000Z</dc:date>
      <description><![CDATA[AI and open source are redefining the software threat landscape. Here are the key statistics you need to know.]]></description>
      <dc:creator><![CDATA[Jaikumar Vijayan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/28.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Axios: How AppSec teams should respond]]></title>
      <link>https://www.reversinglabs.com/blog/axios-appsec-respond</link>
      <guid>https://www.reversinglabs.com/blog/axios-appsec-respond</guid>
      <pubDate>Thu, 02 Apr 2026 18:05:45 GMT</pubDate>
      <dc:date>2026-04-02T18:05:45.922Z</dc:date>
      <description><![CDATA[Here's a mitigations checklist and best practices. Plus: How RL’s xBOM and Spectra Assure Community can help.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/axios-secure.software.png" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[ClickFix: YARA Rules Catch What AV Misses]]></title>
      <link>https://www.reversinglabs.com/blog/clickfix-yara-rule</link>
      <guid>https://www.reversinglabs.com/blog/clickfix-yara-rule</guid>
      <pubDate>Thu, 02 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-02T15:00:00.000Z</dc:date>
      <description><![CDATA[Learn about the antivirus detection gap — and how to develop a simple YARA rule using Spectra Analyze. ]]></description>
      <dc:creator><![CDATA[Toni Dujmović]]></dc:creator>
      <author><![CDATA[toni.dujmovic@reversinglabs.com (Toni Dujmović)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/How-a-Simple-YARA-Rule-Catches-What-AV-Misses.jpg" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[How JPMC tackles software ‘trust debt’]]></title>
      <link>https://www.reversinglabs.com/blog/opet-jpmc-software-trust-debt-rsac</link>
      <guid>https://www.reversinglabs.com/blog/opet-jpmc-software-trust-debt-rsac</guid>
      <pubDate>Wed, 01 Apr 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-04-01T15:00:00.000Z</dc:date>
      <description><![CDATA[JPMorgan Chase CISO Patrick Opet discussed his letter on third-party software risk — and how that has played out.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/software-trust-debt-jpmc.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[GenAI Security Project ramps up guidance]]></title>
      <link>https://www.reversinglabs.com/blog/owasp-genai-security-project-updates</link>
      <guid>https://www.reversinglabs.com/blog/owasp-genai-security-project-updates</guid>
      <pubDate>Tue, 31 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-31T15:00:00.000Z</dc:date>
      <description><![CDATA[With AI ramping up risk, OWASP stepped up its project to help AppSec teams get up to speed — and take action.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/ramp-up-risk.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[AppSec as attacker: Inside Trivy–LiteLLM ]]></title>
      <link>https://www.reversinglabs.com/blog/appsec-weaponized-trivylitellm</link>
      <guid>https://www.reversinglabs.com/blog/appsec-weaponized-trivylitellm</guid>
      <pubDate>Fri, 27 Mar 2026 21:30:00 GMT</pubDate>
      <dc:date>2026-03-27T21:30:00.000Z</dc:date>
      <description><![CDATA[The perimeter isn't your firewall — it's your CI/CD pipeline. Here’s what to know about TeamPCP's supply chain attack.]]></description>
      <dc:creator><![CDATA[Igor Lasic]]></dc:creator>
      <author><![CDATA[ilasic@reversinglabs.com (Igor Lasic)]]></author>
      <enclosure url="https://www.reversinglabs.com/api/media/file/cascading-dolls.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[The TeamPCP supply chain attack evolves]]></title>
      <link>https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads</link>
      <guid>https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads</guid>
      <pubDate>Fri, 27 Mar 2026 19:30:00 GMT</pubDate>
      <dc:date>2026-03-27T19:30:00.000Z</dc:date>
      <description><![CDATA[The malicious campaign started with Trivy and Checkmarx and has shifted to LiteLLM  — and now telnix. Here's how.]]></description>
      <dc:creator><![CDATA[Paul Roberts]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/teampcp-supply-chain-attack.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Decouple SIEM data to reshape your AppSec]]></title>
      <link>https://www.reversinglabs.com/blog/decouple-your-siem-data</link>
      <guid>https://www.reversinglabs.com/blog/decouple-your-siem-data</guid>
      <pubDate>Thu, 26 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-26T15:00:00.000Z</dc:date>
      <description><![CDATA[Shift to a data security pipeline platform to get software visibility that modern supply chain threats demand.]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/decouple-siem-data.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[How AI agents can weaponize IDEs]]></title>
      <link>https://www.reversinglabs.com/blog/how-ai-agents-can-weaponize-ides</link>
      <guid>https://www.reversinglabs.com/blog/how-ai-agents-can-weaponize-ides</guid>
      <pubDate>Wed, 25 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-25T15:00:00.000Z</dc:date>
      <description><![CDATA[Research shows that AI coding can tap integrated development environments to become privileged insider threats. ]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/robot-inside-ide-threat.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Fake install logs in npm packages load RAT]]></title>
      <link>https://www.reversinglabs.com/blog/npm-fake-install-logs-rat</link>
      <guid>https://www.reversinglabs.com/blog/npm-fake-install-logs-rat</guid>
      <pubDate>Tue, 24 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-24T15:00:00.000Z</dc:date>
      <description><![CDATA[The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.]]></description>
      <dc:creator><![CDATA[Lucija Valentić]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Malicious-npm-packages-use-fake-install-logs-to-load-RAT.jpg" type="image/jpeg" />
      <category><![CDATA[Threat Research]]></category>
    </item>
    <item>
      <title><![CDATA[Crypto group ushers in post-quantum security]]></title>
      <link>https://www.reversinglabs.com/blog/ethereum-post-quantum-security</link>
      <guid>https://www.reversinglabs.com/blog/ethereum-post-quantum-security</guid>
      <pubDate>Thu, 19 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-19T15:00:00.000Z</dc:date>
      <description><![CDATA[Here’s a look at the Ethereum Foundation’s new PQC security effort — and why you need to modernize your SecOps.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/post-quantum-security.jpg" type="image/jpeg" />
      <category><![CDATA[Security Operations]]></category>
    </item>
    <item>
      <title><![CDATA[OpenClaw lesson: AI agents are a black hole]]></title>
      <link>https://www.reversinglabs.com/blog/openclaw-ai-agents-black-hole-risks</link>
      <guid>https://www.reversinglabs.com/blog/openclaw-ai-agents-black-hole-risks</guid>
      <pubDate>Wed, 18 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-18T15:00:00.000Z</dc:date>
      <description><![CDATA[AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/openclaw-aiagents-blackhole-risk.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[How to Examine Polyglot Files with Spectra Analyze]]></title>
      <link>https://www.reversinglabs.com/blog/examine-polyglot-files-spectra-analyze</link>
      <guid>https://www.reversinglabs.com/blog/examine-polyglot-files-spectra-analyze</guid>
      <pubDate>Tue, 17 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-17T15:00:00.000Z</dc:date>
      <description><![CDATA[Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.]]></description>
      <dc:creator><![CDATA[Josh Morin]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/Polyglot-File-Examination.webp" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[Make Your SBOMs Actionable with PURLs]]></title>
      <link>https://www.reversinglabs.com/blog/why-your-sboms-need-purls</link>
      <guid>https://www.reversinglabs.com/blog/why-your-sboms-need-purls</guid>
      <pubDate>Thu, 12 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-12T15:00:00.000Z</dc:date>
      <description><![CDATA[Learn how Package URLs improve vulnerability matching, which reduces alert fatigue and simplifies compliance.]]></description>
      <dc:creator><![CDATA[Dave Ferguson]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/sbom-check.jpg" type="image/jpeg" />
      <category><![CDATA[Products & Technology]]></category>
    </item>
    <item>
      <title><![CDATA[OWASP adopts DockSec: Why it matters]]></title>
      <link>https://www.reversinglabs.com/blog/owasp-adopts-docksec</link>
      <guid>https://www.reversinglabs.com/blog/owasp-adopts-docksec</guid>
      <pubDate>Wed, 11 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-11T15:00:00.000Z</dc:date>
      <description><![CDATA[OWASP has adopted the container security tool to slow information overload. Here’s what you need to know.]]></description>
      <dc:creator><![CDATA[John P. Mello Jr.]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/docksec-container-security-owasp.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[OpenClaw and AI risk: 3 AppSec lessons]]></title>
      <link>https://www.reversinglabs.com/blog/openclaw-agentic-ai-risk</link>
      <guid>https://www.reversinglabs.com/blog/openclaw-agentic-ai-risk</guid>
      <pubDate>Tue, 10 Mar 2026 15:00:00 GMT</pubDate>
      <dc:date>2026-03-10T15:00:00.000Z</dc:date>
      <description><![CDATA[The OpenClaw saga is a case study on the threat from agentic AI, showing how it increases software risk.]]></description>
      <dc:creator><![CDATA[Ericka Chickowski]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/openclaw-agentic-ai-risk.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
    <item>
      <title><![CDATA[Claude Code Security: The pros and cons]]></title>
      <link>https://www.reversinglabs.com/blog/claude-code-security</link>
      <guid>https://www.reversinglabs.com/blog/claude-code-security</guid>
      <pubDate>Thu, 05 Mar 2026 16:00:00 GMT</pubDate>
      <dc:date>2026-03-05T16:00:00.000Z</dc:date>
      <description><![CDATA[The new tool is a step forward on AI coding risk — but it trips on modern threats because it looks only at source code.]]></description>
      <dc:creator><![CDATA[Jaikumar Vijayan]]></dc:creator>
      <enclosure url="https://www.reversinglabs.com/api/media/file/tripping-hazard-sign.jpg" type="image/jpeg" />
      <category><![CDATA[AppSec & Supply Chain Security]]></category>
    </item>
  </channel>
</rss>