<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1076912843267184&amp;ev=PageView&amp;noscript=1">

News (3)

January 24, 2024

Help Net Security: Software supply chain attacks are getting easier

ReversingLabs identified close to 11,200 unique malicious packages across three major open-source software platforms in 2023: npm, PyPI, and RubyGems.
January 11, 2024

Axios - Exclusive: Open-source tools fire up supply chain attacks

Open-source code and legitimate hacking tools have contributed to the rising popularity of a once-rare and complicated type of cyberattack, according to new research shared exclusively with Axios.
August 14, 2023

Cybersecurity Insiders: Supply chain attacks demand a 3rd party risk re-think

Looked at from one angle, the recent attack on JumpCloud, a cloud-based identity and access management provider, was unsurprising.
August 6, 2023

Hack Read: VMCONNECT: Malicious PyPI Package Mimicking Common Python Tools

Threat researchers at ReversingLabs, a software supply chain security and malware analysis platform, have discovered a malicious new PyPI package dubbed VMConnect on the Python Package Index (PyPI) repository.
August 4, 2023

The Hacker News: Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information.
August 4, 2023

Infosecurity Magazine: VMConnect: Python PyPI Threat Imitates Popular Modules

A new malicious campaign has been found on the Python Package Index (PyPI) open-source repository involving 24 malicious packages that closely imitate three popular open-source tools: vConnector, eth-tester and databases.