
From the Labs: YARA Rule for Detecting HermeticRansom
The ReversingLabs YARA detection rule for HermeticRansom can help you find this ransomware in your environment.

The ReversingLabs YARA detection rule for HermeticRansom can help you find this ransomware in your environment.

The ReversingLabs research team has identified a novel attack on PyPI using compiled Python code to evade detection — possibly the first attack to take advantage of PYC file direct execution.

ReversingLabs researchers discovered two malicious packages that contained TurkoRat, an open source infostealer that lurked on npm for two months before being detected.

Quantum, once a popular ransomware gang, is no longer an active threat. However, ReversingLabs researchers created detection rules for a debugger evasion recently added to the Malware Behavior Catalog as Exception Flooding.

It takes a village... Researchers play capture the flag to find vulns in tools like ChatGPT — with a White House assist.

What’s in a name? Here's how bad actors are pushing malware on the Python Package Index under the guise of legitimate yet abandoned open source modules.

The VOIP software company missed signs that its client had been tampered with before it pushed the update to customers.

A Visual Studio Code Extensions Marketplace flaw highlights the risk potential. Here's how the VS Code IDE can proliferate to npm.

ReversingLabs YARA detection rule for NB65 can help you find this ransomware in your environment.

Here are the key takeaways from the Colour-Blind remote access trojan, with insights from supply chain security experts

ReversingLabs researchers discovered dozens of malicious packages on Python Package Index that mimic popular libraries

This is not a drill: Denis Pushkarev has big debts — and his code is EVERYWHERE

ReversingLabs’ YARA detection rule for Lorenz can help you find this ransomware in your environment.

Aabquerys is a malicious npm package discovered typosquatting on a legitimate module that downloads malicious components

Researcher Eaton Zveare discloses massive back door in Toyota web app exploiting a JsonWebToken used for authentication
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial