RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityJuly 26, 2023

Tools gap leaves you exposed to supply chain attacks

Traditional application security can't defend against today's attacks. Our report explains why — and why you need to upgrade your AppSec strategy.

smiling woman with glasses
Carolynn van Arsdale, Writer, ReversingLabs.Carolynn van Arsdale
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
Tools gap leaves you exposed to supply chain attacks: Upgrade your AppSec

Software supply chain attacks are an enterprise-wide risk, and traditional application security testing tools are leaving organizations exposed — and mired in outdated security strategies. These are the key findings of a recent survey of 321 IT professionals, conducted by Dimensional Research.

What does this mean for your organization? The tooling gap — and a lack of maturity in approach — is leaving companies exposed to the increasing risks highlighted by recent attacks, including those on 3CX and CircleCI.

Chris Wilder, research director at TAG Cyber, reviewed the survey's findings with ReversingLabs field CISO Matt Rose. Their analysis is included in a new report, the Software Supply Chain Security Risk Report.

Here are key highlights from the report — and an explanation of why you need to upgrade your AppSec tools and supply chain security approach.

Download Today: The Software Supply Chain Security Risk Report

Traditional AppSec tools alone don’t cut it

Tools such as static and dynamic application security testing (SAST and DAST) and software composition analysis (SCA) are effective in detecting threats in software applications such as exploitable software vulnerabilities or dependencies. However, these legacy AppSec tools focus on open-source and source-code analysis, overlooking the risk posed by modern software supply chain attacks, including active malware, secrets, and tampering.

This gap in tooling has become a reality for enterprises today. In the Dimensional Research survey, 74% of IT and security professionals reported that tools such as SAST, DAST, and SCA aren’t adequate in fully protecting their organizations from software supply chain threats. This signifies that security teams currently need more comprehensive tools to handle software supply chain attacks.

The attacks on 3CX and CircleCI showcased that organizations need to go beyond vulnerability management in their efforts to secure their software supply chain and manage risk. This represents a fundamental shift in the requirements for application security tools.

The software supply chain is increasingly complex

In addition to the problem traditional AppSec tools missing the mark, the survey found that the increased complexity of development environments posed security risks to organizations. Nearly half of respondents said that their organization’s internally developed and open-source software are sources of risk.

Open-source software, which is used in an estimated 97% of all applications, has become a clear risk to supply chains this past year, with the amount of attacks on the open-source repositories npm and PyPI increasing by about 300% over the past four years.

What has received less attention however, is how internally developed software has become more complex, with increasing reliance on external contractors and third-party platforms and code to streamline development processes. This supply chain complexity adds to the challenges security teams are facing.

The lack of effective tools for detecting supply chain attacks is having very real consequences for enterprises this year. Nearly 9 in 10 of the practitioners surveyed said that their companies have detected security issues in their software supply chains in the last 12 months. And 88% said software supply chain security presents an enterprise-wide risk to their organizations.

Upgrade your AppSec tooling

Despite the sobering statistics on risk, nearly two-thirds of the survey respondents (65%) reported that their organization does not have a mature software supply chain security program. This likely contributes to the overwhelming number of organizations that have dealt with security issues in their supply chains this past year.

The report highlights the new requirement for tools that fully analyze the security of a software package before it ships. This means that teams should deploy a security tool that pinpoints the possible risks in the version of a software package or container to be deployed in production or delivered to customers.

Modern tooling that utilizes binary analysis is the best method to go about finding these risks, the report finds. Binary analysis can also provide a comprehensive software bill of materials (SBOM), which can serve as a guide for identifying software risks in a software package.

Rose outlines in the report why modern AppSec tooling that goes beyond vulnerabilities and source code analysis is key.

It’s not about doing a runtime analysis to see what the application is doing from a functional standpoint — you’re programmatically reverse engineering it down to the most granular level to say, 'Here’s everything this application does. Is this what’s expected?'

Matt Rose

Supply chain security maturity: A new requirement

Upgrading your software supply chain security tools is just a starting point for organizations looking to develop more mature programs. Wilder and Rose write that for security teams to successfully manage software supply chain security, they cannot go at it alone.

The report recommends that software development teams, application security. risk and compliance, the security operations center (SOC), and others all need to play a part in securing an organization's software supply chain.

Wilder, the main author of the new Software Supply Chain Risk Report, argues that taking a modern approach to software supply chain security is now a requirement for managing risk.

[Companies must] adopt a proactive, holistic approach to software supply chain security that goes beyond vulnerability management and detection to include comprehensive visibility into supply chain risks, consistent threat remediation, and an enterprise-wide approach to risk management.

Chris Wilder

Keep learning

  • Get up to speed on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar to discussing the findings.
  • Learn why binary analysis is a must-have in the Gartner® CISO Playbook for Commercial Software Supply Chain Security.
  • Take action on securing AI/ML with our report: AI Is the Supply Chain. Plus: See RL's research on nullifAI and watch how RL discovered the novel threat.
  • Get the report: Go Beyond the SBOM. Plus: See the CycloneDX xBOM webinar.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:AppSec & Supply Chain Security

More Blog Posts

AI coding racing

Can AppSec keep pace with AI coding?

AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.

Learn More about Can AppSec keep pace with AI coding?
Can AppSec keep pace with AI coding?
Finger on map

LLMmap puts its finger on ML attacks

Researchers show how LLM fingerprinting can be used to automate generation of customized attacks.

Learn More about LLMmap puts its finger on ML attacks
LLMmap puts its finger on ML attacks
Vibeware bad vibes

Vibeware: More than bad vibes for AppSec

Threat actors are leveraging the freewheeling vibe-coding trend to deliver malicious software at scale.

Learn More about Vibeware: More than bad vibes for AppSec
Vibeware: More than bad vibes for AppSec
CRA accelerates advantage

The CRA is coming: Are you ready?

Here's how the EU's Cyber Resilience Act will reshape the software industry — and how that accelerates advantages.

Learn More about The CRA is coming: Are you ready?
The CRA is coming: Are you ready?

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top