RL Blog
close-up of man wearing glasses with computer reflection

5 best practices for securing your CI/CD with software bills of materials

SBOMs are essential — but making them useful in CI/CD environments is tricky. Here are 5 key best practices.

Read More about 5 best practices for securing your CI/CD with software bills of materials
5 best practices for securing your CI/CD with software bills of materials
galaxy planet atom nucleus abstract

IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations

ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

Read More about IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
How mature is your open-source risk management? S2C2F helps map dependencies

How mature is your open-source risk management? S2C2F helps map dependencies

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Read More about How mature is your open-source risk management? S2C2F helps map dependencies
How mature is your open-source risk management? S2C2F helps map dependencies
App sec prioritization is priority No. 1 for CISOs

App sec prioritization is priority No. 1 for CISOs

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Read More about App sec prioritization is priority No. 1 for CISOs
App sec prioritization is priority No. 1 for CISOs
file folders labeled restricted, secret, confidential

GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Read More about GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk
GitHub boosts secrets scanning: A necessary step, but supply chain security is key to managing risk
rusty cog gear

Rust on Android goes bare metal: 3 key security benefits

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

Read More about Rust on Android goes bare metal: 3 key security benefits
Rust on Android goes bare metal: 3 key security benefits
rusty chain links near open body of water

Are APIs the weak link in your supply chain security?

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

Read More about Are APIs the weak link in your supply chain security?
Are APIs the weak link in your supply chain security?
The state of OSS security: Changes in attack methods, policy

The state of OSS security: Changes in attack methods, policy

What’s to come for the security of open source software? ConversingLabs caught up with Mikaël Barbero of the Eclipse Foundation to answer that question. Watch (or listen) and learn.

Read More about The state of OSS security: Changes in attack methods, policy
The state of OSS security: Changes in attack methods, policy
red cubes with letter s on them amid block cubes

Typosquatting campaign delivers r77 rootkit via npm

ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

Read More about Typosquatting campaign delivers r77 rootkit via npm
Typosquatting campaign delivers r77 rootkit via npm
new features for reversinglabs a1000 version 8.3

ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward

Version 8.3 of RL's A1000 Malware Analysis Platform delivers better visuals, search, and an improved cloud sandbox. Here are all of the updates.

Read More about ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward
ReversingLabs A1000 Threat Analysis and Hunting Solution Update Drives SecOps Forward
pipeline

NIST supply chain security guidance for CI/CD environments: What you need to know

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Read More about NIST supply chain security guidance for CI/CD environments: What you need to know
NIST supply chain security guidance for CI/CD environments: What you need to know
pipeline with red shutoff wheel valve

NIST supply chain security guidance for CI/CD environments: What you need to know

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Read More about NIST supply chain security guidance for CI/CD environments: What you need to know
NIST supply chain security guidance for CI/CD environments: What you need to know
BlackCat (ALPHV): What we know about the MGM hack

BlackCat (ALPHV): What we know about the MGM hack

Ransomware-as-a-service gang ALPHV (a.k.a. BlackCat) carried out a sophisticated attack on the hotel and casino company MGM. Here’s what the ReversingLabs threat team understands.

Read More about BlackCat (ALPHV): What we know about the MGM hack
BlackCat (ALPHV): What we know about the MGM hack
conversinglabs podcast title card apple devices as a growing attack vector

With growing threats to Apple devices, Kandji ramps up

Kandji Director of Threat Intelligence Devin Byrd talks about the growing enterprise threats to macOS and iOS endpoints.

Read More about With growing threats to Apple devices, Kandji ramps up
With growing threats to Apple devices, Kandji ramps up
pressure gauge needle movement increasing

EPSS vs. CVSS: Exploit prediction could move the needle on software risk

Will the Exploit Prediction Scoring System improve application security now — and software supply chain security in the future? Here's what you need to know.

Read More about EPSS vs. CVSS: Exploit prediction could move the needle on software risk
EPSS vs. CVSS: Exploit prediction could move the needle on software risk
Previous1...272829...56Next

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.

Read More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top