It’s a conundrum for application security (AppSec) today: How do you square agentic-assisted development with the basic security principles that keep software trustworthy? Chris Romeo, managing ...
The volume of malware on public repositories hasn’t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software ...
Security is an engineering problem. Saša Zdjelar’s recent article makes that responsibility concrete: enforceable controls, named owners, and evidence that protections work. Saltzer and Schroeder’s ...
AI has collapsed the exploit window. Now the patch itself can become intelligence for the attacker. Mean time to exploit crossed zero in 2024, meaning exploitation is increasingly happening before a ...
Enterprise file scanning covers the file sources endpoint antivirus was never built for: email gateways, web proxies, cloud storage, MFT platforms, and network shares. Ingestion channel breadth ...
What made this package stand out was a short list of characteristics present in the majority of malicious open source and commercial, third-party software packages the RL research team has discovered.
The Open Worldwide Application Security Project’s newest OWASP Top 10 for LLM Applications includes a change that puts a spotlight on the rise of AI risk. While prompt injection and the disclosure of ...
In the last few months, ReversingLabs (RL) researchers have encountered multiple malicious packages that target cryptocurrency users and developers. In May, RL researcher Karlo Zanki wrote a blog ...
The ReversingLabs research team has identified a new branch of a fake recruiter campaign conducted by the North Korean hacking team Lazarus Group. The campaign, which the team named graphalgo, based ...
ReversingLabs is analyzing a supply chain compromise of the firm 3CX Ltd., a maker of enterprise voice over IP (VOIP) solutions. Beginning on March 22nd, 2023, compromised versions of the ...
RL has discovered an active Microsoft 365 device code phishing campaign that abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to obtain access to victim accounts. Rather than ...
Security experts are warning of widespread phishing attacks that have compromised the accounts of prominent open-source software (OSS) developers. The campaign has placed malicious code designed to ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results