
Red flags flew over software supply chain-compromised 3CX update
The VOIP software company missed signs that its client had been tampered with before it pushed the update to customers.

The VOIP software company missed signs that its client had been tampered with before it pushed the update to customers.

A Visual Studio Code Extensions Marketplace flaw highlights the risk potential. Here's how the VS Code IDE can proliferate to npm.

ReversingLabs YARA detection rule for NB65 can help you find this ransomware in your environment.

Here are the key takeaways from the Colour-Blind remote access trojan, with insights from supply chain security experts

ReversingLabs researchers discovered dozens of malicious packages on Python Package Index that mimic popular libraries

This is not a drill: Denis Pushkarev has big debts — and his code is EVERYWHERE

ReversingLabs’ YARA detection rule for Lorenz can help you find this ransomware in your environment.

Aabquerys is a malicious npm package discovered typosquatting on a legitimate module that downloads malicious components

Researcher Eaton Zveare discloses massive back door in Toyota web app exploiting a JsonWebToken used for authentication

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

ReversingLabs’ YARA detection rule for Black Basta can help you find this ransomware in your environment.

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

As attacks become more sophisticated, it is imperative to harden machine learning (ML) models and reduce the adversary’s ability to evade detection.

A malicious Python file found on the PyPI repository adds backdoor and data exfiltration features to what appears to be a legitimate SDK client from SentinelOne.

Days after researchers for Phylum and Checkmarx revealed an ongoing software supply chain attack spreading the W4SP Stealer malware through malicious packages on the Python Package Index (PyPI), ReversingLabs researchers discovered 10 additional PyPI packages pushing modified versions of W4SP that were overlooked.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial