RL Blog
The immutable laws of cybersecurity

‘The Immutable Laws of Security’ at 25: 5 corollaries

Scott Culp’s formulation still holds true — though some additions are needed that account for software supply chain security. 

Read More about ‘The Immutable Laws of Security’ at 25: 5 corollaries
‘The Immutable Laws of Security’ at 25: 5 corollaries
OWASP AI incident response

OWASP GenAI IR Guide 1.0: How to put it to work

Here's how to integrate AI-specific risks into your existing security incident response (IR) playbook.

Read More about OWASP GenAI IR Guide 1.0: How to put it to work
OWASP GenAI IR Guide 1.0: How to put it to work
Thousands of developer projects compromised in npm hack

Compromised npm package threatens projects

The eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.

Read More about Compromised npm package threatens projects
Compromised npm package threatens projects
Speed kills: AI coding risk

AI coding tools revive old-school hacks

Researchers at Black Hat discussed how these tools can leave development teams vulnerable to hacks like remote-code execution.

Read More about AI coding tools revive old-school hacks
AI coding tools revive old-school hacks
DevSecOps is giving way to DevEx

Move over, DevSecOps — DevEx is king

Leading firms are using DevEx to achieve application security gains at speed. Here's how it works — and how to get started.

Read More about Move over, DevSecOps — DevEx is king
Move over, DevSecOps — DevEx is king
Developers at speed

State of development: 5 key AppSec steps

Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.

Read More about State of development: 5 key AppSec steps
State of development: 5 key AppSec steps
AIVSS helps secure agentic AI

OWASP AIVSS targets agentic AI risk

The new AI Vulnerability Scoring System (AIVSS) picks up where the Common Vulnerability Scoring System (CVSS) falls short.

Read More about OWASP AIVSS targets agentic AI risk
OWASP AIVSS targets agentic AI risk
Policy as Code helps secure your SDLC

How to implement PaC for a more secure SDLC

Policy as Code is emerging as a key area of focus for AppSec teams in the age of cloud-native development. But implementation can be daunting.

Read More about How to implement PaC for a more secure SDLC
How to implement PaC for a more secure SDLC
sample alt text

SharePoint zero-day: What we know

The software supply chain incident highlights how quickly threat actors can turn newly revealed vulnerabilities into widespread attacks.

Read More about SharePoint zero-day: What we know
SharePoint zero-day: What we know
person using calculator

The true cost of CVEs: Go beyond vulnerabilities

Triaging and patching, plus meeting compliance demands, all bog down modern software teams — and divert time away from development.

Read More about The true cost of CVEs: Go beyond vulnerabilities
The true cost of CVEs: Go beyond vulnerabilities
cogs with different web-related icons inside

Autonomous dev is coming: Is your AppSec ready?

Replacing software engineers with AI won't be happening soon — but AI coding is already changing the software risk landscape. Is your company prepared?

Read More about Autonomous dev is coming: Is your AppSec ready?
Autonomous dev is coming: Is your AppSec ready?
two wooden signs: good vibes pointing one way, bad vibes pointing the opposite

Vibe coding is seductive — and a serious risk

AI coding has many attractions, but organizations must have humans in the loop to keep good software risk management vibes flowing.

Read More about Vibe coding is seductive — and a serious risk
Vibe coding is seductive — and a serious risk
announcing spectra analyze 9.5

Announcing RL Spectra Analyze Version 9.5

In this product release highlight, ReversingLabs is proud to announce new features for Spectra Analyze (formerly A1000).

Read More about Announcing RL Spectra Analyze Version 9.5
Announcing RL Spectra Analyze Version 9.5
angular blue logo

Vet VS Code Plugins with Spectra Assure Community

Spectra Assure Community empowers VS Code users to verify an extension’s level of risk before trusting it to run with privileged system access.

Read More about Vet VS Code Plugins with Spectra Assure Community
Vet VS Code Plugins with Spectra Assure Community
blue geometric logo

Malicious pull request infects VS Code extension

ETHcode, a VS Code extension for Ethereum smart contract development, was compromised following a GitHub pull request.

Read More about Malicious pull request infects VS Code extension
Malicious pull request infects VS Code extension
Previous1...111213...59Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top