
Energy Pipeline Podcast: Software Supply Chain Security | EP 105
Supply Chain and Energy/Utilities

Supply Chain and Energy/Utilities

The majority opinion is that a cybersecurity professional body is long overdue and would benefit cybersecurity and cybersecurity practitioners.

AI coding is a big security problem when most security teams are still relying on tools designed for a world where human-written code remains prevalent.

Multi-layered payloads can yield clues to hacker identity and intentions when successfully unpacked and analyzed.

At ReversingLabs, we’ve identified seven critical risks that plague commercial software, or what we call Commercial Software’s Seven Deadly Sins.

As package registries find better ways to combat cyberattacks, threat actors are finding other methods for spreading their malware to developers.

ReversingLabs' analysis of ethers-provider2 has revealed that it's nothing but a trojanized version of the widely-used ssh2 npm package.

Microsoft Security’s artificial intelligence (AI) security team recently shared its findings from a multi-year study that involved red teaming 100 generative AI (GenAI) products.

Researchers have spotted two machine learning (ML) models containing malicious code on Hugging Face Hub, the popular online repository for datasets and pre-trained models.

Companies pursing internal AI development using models from Hugging Face and other open source repositories need to focus on supply chain security and checking for vulnerabilities.

The popular Python Pickle serialization format offers ways for attackers to inject malicious code that will be executed on computers when loading models with PyTorch.

Researchers at Reversing Labs have discovered two malicious machine learning (ML) models available on Hugging Face, the leading hub for sharing AI models and applications.

A widely used python module for machine-learning developers can be loaded with malware and bypass detection measures.

Olympic scammers go for gold.

Developers targeted by malicious Microsoft VSCode extensions