
CVE noise drowns out supply chain threats
48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.

The new landscape report maps 35 vendors addressing an emerging category of risk: AI agents writing insecure code at machine speed.

48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.

The new landscape report maps 35 vendors addressing an emerging category of risk: AI agents writing insecure code at machine speed.

VM success is determined by findings reaching developers with context — which is getting more challenging. Here's why to shift gears.

The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.

This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.

AI security leader and author Steve Wilson explains why you need to rethink security — and treat AI agents as digital workers.

Learn how attackers are re-casting adults as minors to bypass recovery and lock users out.

RL threat detection and binary analysis can now close the gap for threat hunters.

The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.

ReversingLabs joined defensive teams with its malware analysis platform. Here are key lessons.

To manage agentic AI risk, organizations need to focus more on the infrastructure they run on.

This latest compromises of popular and infrastructure-level npm packages are rocking the foundations open source.

RL documented 163 samples of the Linux exploit's new variants, active malware — and developed YARA rules.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial