In The News
August 4, 2023

The Hacker News: Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information.
August 4, 2023

Infosecurity Magazine: VMConnect: Python PyPI Threat Imitates Popular Modules

A new malicious campaign has been found on the Python Package Index (PyPI) open-source repository involving 24 malicious packages that closely imitate three popular open-source tools: vConnector, eth-tester and databases.
July 6, 2023

CSO: Malicious campaign uses npm packages to support phishing attacks

This newly discovered "dual use" campaign enables software supply chain compromise as well as phishing.
June 15, 2023

TechTarget: CISA SBOM standards efforts stymied by confusion, inertia

Efforts to establish SBOM standards and guidance have progressed, but unanswered questions persist -- including how the federal government plans to enforce its own requirements.
June 6, 2023

Supply Chain Brain: DigiCert and ReversingLabs Agree to Partnership

DigiCert announced that it had partnered with ReversingLabs June 6 to enhance supply chain software security by combining ReversingLabs’ binary analysis and threat detection services with DigiCert’s secure code signing solution.
June 6, 2023

DevOps.com: DigiCert Allies With ReversingLabs to Secure Software Supply Chains

DigiCert today announced it has allied with ReversingLabs to integrate binary analysis and threat detection capabilities