ReversingLabs
@reversinglabs.com
📤 111
📥 85
📝 275
ReversingLabs is the trusted name in file and software security. RL - Trust Delivered.
🤖 A new report on
#AIsecurity
from the Cloud Security Alliance finds that enterprise governance of
#AI
usage & potential threats makes a huge difference:
https://bit.ly/459MYrk
loading . . .
Why governance is essential for safe AI adoption | ReversingLabs
A new CSA report stresses getting out in front of AI risk — and offers insights into AI in SecOps. Here’s why you need guardrails.
https://bit.ly/459MYrk
3 days ago
0
0
0
🚨New Feature Alert:
secure.software
now offers free, single click
#SBOM
delivery in the CycloneDX format. See it in action:
app.arcade.software/share/oBBgnr...
#Dev
#AppSec
#DevSecOps
loading . . .
3 days ago
0
0
0
📆 Next Thursday: RL researchers break down real-world campaigns uncovered in the closing months of 2025 across NuGet, PyPI, PowerShell & VS Code: https://bit.ly/4sCIh3f
#SoftwareSupplyChainSecurity
#Dev
#Cybersecurity
4 days ago
0
1
0
⚠️ According to a recent report from the Google Threat Intelligence Group, adversaries are now deploying novel
#AI
-enabled
#malware
in active operations: https://bit.ly/45v4FBR
#Cybersecurity
loading . . .
Adversarial AI is on the rise: What you need to know | ReversingLabs
Researchers explain how as threat actors move to AI-enabled malware in active operations, existing defenses will fail.
https://bit.ly/45v4FBR
5 days ago
0
0
0
⛓️💥 Eligibility for
#CyberInsurance
could hinge on the strength of
#SoftwareSupplyChainSecurity
& third-party risk management controls: https://bit.ly/3NmbJu5
#Cybersecurity
#DevSecOps
loading . . .
How supply chain risk can affect your cyber insurance | ReversingLabs
Here's why gaining visibility into supply chain threats -- and adding controls for software risk -- are essential to insurability.
https://bit.ly/3NmbJu5
10 days ago
0
0
0
🧵Introducing: 🚨New Feature Alert → a series dedicated to RL product updates! This week, we’re excited to unveil a dedicated
#Malware
page in the RL-SAFE Report:
app.arcade.software/share/H7euVM...
#SoftwareSupplyChainSecurity
#DevSecOps
loading . . .
11 days ago
0
0
0
😵💫
#AI
technical debt is all the more perilous for being poorly understood. Learn how it forms & can fuel a breach your org can't afford: https://bit.ly/4qHPL3d
#AISecurity
#Cybersecurity
loading . . .
AI technical debt: What it is -- and why it matters | ReversingLabs
AI platforms exacerbate existing security risks in the enterprise. Here's what you need to know to stay out of technical debt.
https://bit.ly/4qHPL3d
11 days ago
0
0
0
🔎 In the next installment of the RL Researcher's Notebook series,
#malware
analyst Rob Simmons unpacks the malicious Windows packer ‘pkr_mtsi’. Read on to learn about it's evolution, & access a
#YARA
rule for it: https://bit.ly/3YrHvrW
#Cybersecurity
12 days ago
0
0
0
⛓️ The open-source SF² presents security scaling as a strategic resource-allocation challenge rather than a staffing problem. Here's how it helps: https://bit.ly/3YijlQz
#SoftwareSupplyChainSecurity
#DevSecOps
#CISO
loading . . .
SF² framework aims to help you scale SecOps wisely | ReversingLabs
The Software Factory Security Framework looks at scaling security operations as a resource-allocation problem -- not just head count.
https://bit.ly/3YijlQz
19 days ago
0
1
0
🤖 As cyber attacks become
#AI-optimized
& internal AI use rises, enterprises are scrambling to secure files. Here's why your org needs to modernize its
#FileSecurity
:
www.reversinglabs.com/blog/ai-file...
#Cybersecurity
loading . . .
AI is upending file security. Here’s how to fight back | ReversingLabs
As attacks become AI-optimized and internal AI use rises, enterprises are scrambling to secure files. Here’s how to modernize your security strategy.
https://www.reversinglabs.com/blog/ai-file-security-fight-back
25 days ago
0
0
0
🤖
@owasp.org
has released a top 10 list of security risks for
#AgenticAI
, an AI testing guide, & an
#AI
vulnerability assessment tool. Here's what you need to know regarding the new
#AISecurity
efforts:
https://bit.ly/4qfBxGo
loading . . .
OWASP tackles AI risk in bold new push | ReversingLabs
The Open Worldwide Application Security Project now includes an Agentic Top 10, an AI testing guide, and an AI vulnerability scoring tool.
https://bit.ly/4qfBxGo
about 1 month ago
0
0
0
🪱
@forbes.com
spoke with RL co-founder & CSA Tomislav Peričin about the 2nd wave of the malicious Shai-hulud worm that hit
#npm
:
https://bit.ly/4pHZoyC
loading . . .
Microsoft Worm Attack Warning -- Act Rapidly And Change Passwords Now
Rapidly change your password, the Microsoft security team urges as Shai-Hulud Dune Worm cloud attacks continue.
https://bit.ly/4pHZoyC
about 1 month ago
0
0
0
⚠️ RL researchers have discovered 14 malicious
#NuGet
packages that impersonate
#crypto
-related tools. Each delivers
#malware
that steals either wallet info, crypto-funds, or Google Ads OAuth credentials:
https://bit.ly/4pILLiV
loading . . .
NuGet malware targets crypto wallets, OAuth tokens | ReversingLabs
Highlighting an alarming trend, RL has discovered malicious packages that impersonate Nethereum -- but copy functionality to enable attacks.
https://bit.ly/4pILLiV
about 1 month ago
0
0
0
Pairing RL Spectra Assure for
#SoftwareSupplyChainSecurity
with an
#EDR
solution like
#CrowdStrike
Falcon offers robust third-party software risk management.👇
https://bit.ly/48GeONR
loading . . .
Leveraging Spectra Assure and EDR to Mitigate Third-Party Software Risk | ReversingLabs
Here's how to create a compensating control in Crowdstrike to mitigate specific risks in a commercial software package.
https://bit.ly/48GeONR
about 1 month ago
0
0
0
📣 RL has won the 2025 Intellyx Digital Innovator Award! We are so appreciative.
#Cybersecurity
about 1 month ago
0
0
0
reposted by
ReversingLabs
The Vertex Project
about 1 month ago
@invisig0th.bsky.social
underscores why security frameworks are a starting point, not a finish line. Strong supply-chain security is in the execution. Read more from
@reversinglabs.com
:
www.reversinglabs.com/blog/securit...
loading . . .
Security frameworks fail on software supply chain risk | ReversingLabs
Researchers studied how well the top frameworks mitigate modern attack techniques. They found serious security gaps.
https://www.reversinglabs.com/blog/security-frameworks-fail-supply-chain
0
5
3
🪖 RL chief trust officer Sasa Zdjelar reflects on the new
#SBOM
requirements coming for the U.S. military’s use of
#AI
:
https://bit.ly/3MxUZzE
loading . . .
NDAA puts AI cyber risk in the crosshairs | ReversingLabs
What does the future of AI security look like? The latest National Defense Authorization Act gives us a glimpse.
https://bit.ly/3MxUZzE
about 1 month ago
0
0
0
🔎
#VirusTotal
isn't the only option for your
#ThreatIntel
needs. As a matter of fact, there's an even better
#VirusTotalAlternative
out there: Us. See why:
https://bit.ly/3MkWQb5
loading . . .
On Demand: Beyond VirusTotal: Modern Threat Intel with RL | ReversingLabs
Discover why teams are switching from VirusTotal to ReversingLabs for flexible, cost-effective threat intel--without paying for what they don't need.
https://bit.ly/3MkWQb5
about 1 month ago
0
0
0
Further details about this malicious campaign on
#VSCode
are now available at RL Blog:
www.reversinglabs.com/blog/malicio...
#Dev
#DevSecOps
#Cybersecurity
add a skeleton here at some point
about 1 month ago
0
2
0
🛡️
#AI
is poised to reshape the
#SOC
, from alleviating alert fatigue to streamlining manual workflows: https://bit.ly/3KwXl1d
#Cybersecurity
#SecOps
loading . . .
5 ways AI will transform Security Operations Centers | ReversingLabs
AI is poised to reshape SOCs, from alleviating alert fatigue to streamlining manual, repetitive workflows. Here's what to expect.
https://bit.ly/3KwXl1d
about 1 month ago
0
1
0
📆 Happening in 1 week: A live roundup of 2025's
#SoftwareSupplyChain
breaches. Register: https://bit.ly/4iLpa2t
#DevSecOps
#Dev
#Cybersecurity
about 1 month ago
0
1
0
This Friday, we'll break down how to build a custom
#ThreatIntel
feed that reduces noise, improves data quality, & supports
#AI
-driven
#SecOps
:
https://bit.ly/48jBXWb
about 1 month ago
0
0
0
📣 RL has just pushed out an update to detect the
#React2Shell
vulnerability. It has a CVSS score of 10, & it’s a pre-authentication vuln that allows RCE in web apps using a specific version of the extremely popular
#React
framework.
#Dev
#AppSec
about 1 month ago
1
0
0
⛓️💥 Can frameworks stop software supply chain attacks? We ask this in the latest episode of ConversingLabs
#podcast
: https://bit.ly/3MferkI
#Cybersecurity
#SoftwareSupplyChainSecurity
#GRC
loading . . .
Can Frameworks Stop Supply Chain Attacks? | ReversingLabs
Professor Laurie Williams and Ph.D. student Sivana Hamer of NC State discuss the effectiveness of software supply chain security frameworks.
https://bit.ly/3MferkI
about 2 months ago
0
0
0
A new guide on
#threatmodeling
for the cloud in the era of AI has been released by the CSA. It calls out that existing security practices aren't cutting it for the new era: https://bit.ly/447HlJD
#AISecurity
#CloudSecurity
#SoftwareSupplyChainSecurity
loading . . .
Why AI and cloud-native are security game-changers | ReversingLabs
Existing security practices weren't designed to tackle today's risks, CSA notes in new guide -- making updating tooling essential.
https://bit.ly/447HlJD
about 2 months ago
0
0
0
🚨 AI has redefined software risk — shaping how both attackers & defenders operate. Register now to get the breakdown on these shifting dynamics: https://bit.ly/4oqSV9T
#AISecurity
#SoftwareSupplyChainSecurity
#AppSec
about 2 months ago
0
0
0
RL researchers have found 19
#VSCode
extensions belonging to a campaign that's been running since February 2025 containing hidden malware masquerading as a picture:
secure.software/vscode/packa...
loading . . .
bashling Theme Remake - Visual Studio Code | ReversingLabs Spectra Assure Community
Supply chain risk analysis for bashling Theme Remake. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
https://secure.software/vscode/packages/malkolm/theme-bashling-remake
about 2 months ago
1
1
1
🎉 ConversingLabs
#Podcast
has been featured in FeedSpot's list of 10 best
#IncidentResponse
podcasts! The show features some of the best experts in
#cybersecurity
. 🎧 Listen wherever you get your podcasts:
https://bit.ly/443uzMd
about 2 months ago
0
1
0
🔎 ICYMI: The newly-released ReversingLabs Browser Extension empowers customers to operationalize the RL
#threatintelligence
cloud in new & powerful ways 👉 https://bit.ly/4iu5Xlw
#threathunting
#SOC
loading . . .
ReversingLabs Threat Intelligence: Context Changes Everything | ReversingLabs
Eliminate guesswork with the ReversingLabs Browser Extension, which operationalizes RL threat intelligence cloud in new and powerful ways.
https://bit.ly/4iu5Xlw
about 2 months ago
0
0
0
⚠️ RL researchers have discovered vulnerable code in legacy
#Python
packages that could make possible an attack on
#PyPI
via a domain compromise:
https://bit.ly/48jatP4
loading . . .
Bootstrap script exposes PyPI to domain takeover attacks | ReversingLabs
Proving the road to takeover is paved with setuptools alternatives, the script for a popular Python package for building and installing PyPI packages leaves them vulnerable.
https://bit.ly/48jatP4
about 2 months ago
0
1
0
👀 Blog with full details & more updates can be found here:
t.co/YP35k2Mweq
#npm
#OSS
#SoftwareSupplyChainSecurity
add a skeleton here at some point
about 2 months ago
0
0
0
⚠️ RL automated threat detection system has flagged a new wave of Shai-hulud
#npm
packages. Look out for RL's TH15502 policy violation on
secure.software
. The campaign affects popular [@]asyncapi packages with millions of downloads. Example:
secure.software/npm/packages...
#Dev
#Cybersecurity
loading . . .
@asyncapi/
[email protected]
- npm | ReversingLabs Spectra Assure Community
Supply chain risk analysis for @asyncapi/
[email protected]
. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
https://secure.software/npm/packages/@asyncapi/specs/6.8.3
about 2 months ago
0
2
1
🚩 RL researchers have discovered a new malicious
#VSCode
extension that uses an interesting technique to execute the malicious code:
secure.software/vscode/packa...
loading . . .
vscodepython - Visual Studio Code | ReversingLabs Spectra Assure Community
Supply chain risk analysis for vscodepython. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
https://secure.software/vscode/packages/dfadhel/vscodepython
about 2 months ago
1
2
0
@owasp.org
has proposed an update to its Top 10 list, which serves as a global standard for
#AppSec
. Here's what experts are saying about it: https://bit.ly/4iasFPq
#SoftwareSupplyChainSecurity
#DevSecOps
loading . . .
OWASP Top 10 takes on software supply chain risk | ReversingLabs
The Open Worldwide Application Security Project's widely used AppSec priority list is expanding to cover systemic risk to software security.
https://bit.ly/4iasFPq
about 2 months ago
0
0
0
#AIcoding
assistants aren’t just creating code 10x faster; they’re also introducing software quality & security issues at similarly blistering velocity: https://bit.ly/48ahUby
#AppSec
#DevSecOps
loading . . .
Software quality's collapse: How AI is accelerating decline | ReversingLabs
Development is in freefall toward software entropy and insecurity. Can spec-driven development help?
https://bit.ly/48ahUby
2 months ago
0
0
0
📣 The RL Browser Extension is now available in both the Google Chrome & Microsoft Edge stores. It adds contextual
#ThreatIntel
to all browser based workflows (EDR, XDR, SIEM, etc): https://bit.ly/3XyIYvZ
#SecOps
2 months ago
0
0
0
📣 ICYMI: Devs can now vet the security of
#PowerShell
modules for free with
secure.software
. Try it now & learn more:
https://bit.ly/484lK64
2 months ago
1
0
0
📆 This Wednesday: Join us to learn why it's time for
#ZeroTrust
in
#SoftwareSupplyChainSecurity
👉
https://bit.ly/4hYBJXF
2 months ago
0
0
0
Our latest
#ConversingLabs
#podcast
is livestreaming now. Host Carolynn Van Arsdale is interviewing
@ncstate.bsky.social
professor Laurie Williams and Ph.D student Sivana Hamer on their new report on the effectiveness of software supply chain security frameworks...
www.youtube.com/live/PxqYrnZ...
loading . . .
ConversingLabs: Can Frameworks Stop Supply Chain Attacks?
YouTube video by ReversingLabs
https://www.youtube.com/live/PxqYrnZQ5sI?si=a9vsMNWosV0CLM3a
2 months ago
0
1
0
#OpenSource
powers nearly every modern app, but behind the commits - maintainers quietly fight an uphill battle. Join us next week to learn how we can build a more secure, sustainable, & human-centered future for
#OSS
: https://bit.ly/4qS4Sbj
#SoftwareSupplyChainSecurity
#DevSecOps
loading . . .
Register: Empowering Maintainers to Thrive, Not Just Survive | ReversingLabs
Explore the real challenges facing open source maintainers--from security and compliance to burnout--and the solutions shaping a sustainable future.
https://bit.ly/4qS4Sbj
2 months ago
0
1
0
Google, OpenAI, Meta, & others have been aggressively pursuing efforts to automate the discovery of software flaws using
#AI
. While innovative - it's inundating
#OSS
maintainers. Could AI-enabled fixes be the answer?
#DevSecOps
#AppSec
https://bit.ly/4p09lXs
loading . . .
AI-driven vulnerability reporting overwhelms OSS maintainers | ReversingLabs
Google and others are inundating development teams with AI-powered reporting. Are AI-enabled fixes the answer?
https://bit.ly/4p09lXs
2 months ago
0
0
0
🔖 Cloud Security Alliance released Risk Rubric, a tool that acts as an
#AI
leaderboard that grades LLMs from A-F across 6 risk pillars. Here's what experts are saying about it: https://bit.ly/47ZNKJ1
#AISecurity
#LLMSecurity
loading . . .
New AI security tool lays out key exposures | ReversingLabs
Risk Rubric provides assessments for LLM transparency, reliability, security and more. But it's only one tool in a comprehensive security tool box.
https://bit.ly/47ZNKJ1
2 months ago
0
0
0
Vendors are beginning to release purpose-built tools to
#dev
teams that are meant to tame
#VibeCoding
. But do they provide comprehensive control? ➡️ https://bit.ly/47PGluO
#DevSecOps
#AppSec
loading . . .
Why core security controls for vibe coding are critical | ReversingLabs
Vibe coding is not going away -- and the threat is real. But are developer tools like VibeSec that shift controls left up to the job?
https://bit.ly/47PGluO
2 months ago
0
1
0
🔍 While macOS
#malware
is less widespread than Windows malware, the ability to identify, detect, & classify old & new threats alike is increasingly important. That's where
#YARArules
come into play:
https://bit.ly/4nJKq9I
loading . . .
Evaluating YARA Rules for macOS Malware Hunting in Spectra Analyze | ReversingLabs
With a constantly evolving OSX malware domain, it is important to write clear, specific, and accurate YARA rules. Here's how.
https://bit.ly/4nJKq9I
2 months ago
0
0
0
🎙️In the latest episode of ConversingLabs
#Podcast
,
@bugcrowd.com
founder
@cje.io
discusses AI's impact on vulnerability management:
bit.ly/43O0vnx
2 months ago
0
1
1
#WeaselStore
is an
#infostealer
used by the
#APT
group
#DeceptiveDevelopment
, which targets developers on multiple systems in web & cryptocurrency. Protect yourself by deploying our public
#YARArules
:
https://bit.ly/3x34FdW
loading . . .
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules
ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.
https://github.com/reversinglabs/reversinglabs-yara-rules
3 months ago
0
1
0
⚠️ RL researchers have observed an attack vector on
#PowerShell
known as command hijacking that enables clobbering: https://bit.ly/3X7Ct38
#OpenSource
#SoftwareSupplyChainSecurity
loading . . .
How PowerShell Gallery simplifies supply chain attacks | ReversingLabs
The automation tool's Install-Module command presents threat actors with one key link in the kill chain of a possible attack.
https://bit.ly/3X7Ct38
3 months ago
1
1
0
EggStremeFuel is a
#backdoor
that is part of a file-less
#malware
framework used by a Chinese
#APT
group, which recently attacked a military company in the Philippines. Don't become a victim, deploy our public
#YARArules
:
https://bit.ly/3x34FdW
loading . . .
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules
ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.
https://bit.ly/3x34FdW
3 months ago
0
0
0
🛡️ Shout out to RL community manager
@kadigrigg.bsky.social
for taking part in this
#cybersecurity
panel at the rvatech/
#WomenInTech
conference!
3 months ago
0
2
1
⚠️ AI is producing code up to 4 times faster — but with 10 times more
#AppSec
lapses: https://bit.ly/49un2cH
#AIcoding
#DevSecOps
loading . . .
AI is ramping up coding velocity -- and risk | ReversingLabs
AI is producing code up to four times faster -- but with 10 times more AppSec lapses. Here's what you need to know to keep software safe.
https://bit.ly/49un2cH
3 months ago
0
0
0
Load more
feeds!
log in