Sign in

ReversingLabs

@reversinglabs.com
133 followers 85 following 334 posts

ReversingLabs is the trusted name in file and software security. RL - Trust Delivered.

PostsRepliesMedia
ReversingLabs @reversinglabs.com · 24/09/2026
The patching window has collapsed. Mean time to exploit crossed zero in 2024, and AI can turn disclosed vulnerabilities into working exploits in ~10-15 minutes. A patch can now be an answer key for the attacker. New analysis from ReversingLabs: www.reversinglabs.com/resources/th...
reversinglabs.com
AI and Patch Security: The Patch Is the Attack Payload | ReversingLabs
See how AI is collapsing the exploit window, turning patches into attacker intelligence, and forcing security teams to rethink software risk.
000
ReversingLabs @reversinglabs.com · 22/09/2026
ReversingLabs researchers uncovered a malicious npm package posing as an authorized Twilio bug bounty tool. The package targeted Twilio Account SIDs and Auth Tokens and exfiltrated them via webhook. We reported it to npm. It was removed within an hour. ⬇️ www.reversinglabs.com/blog/malicio...
reversinglabs.com
Malicious npm campaign targets developers integrating Twilio | RL Blog
The package poses as a security tool targeting developers looking to integrate Internet-based apps with telecom networks using Twilio.
100
ReversingLabs @reversinglabs.com · 03/09/2026
"Agents are only going to be as smart as the context they can reason on." ExtraHop's Kanaiya Vasani explains why the agentic SOC is an architecture problem before it's a model problem: www.reversinglabs.com/blog/how-to-... #CyberSecurity
reversinglabs.com
How to build effective agentic SOCs: What you need to know | RL Blog
ExtraHop's Kanaiya Vasani unpacks the concept of the agentic SOC — and how the Agentic SOC Alliance is working to build them out.
000
ReversingLabs @reversinglabs.com · 28/08/2026
A behavioral verdict tells you what a process did. It doesn't tell you what the file is, what else it can do, or who else is running it. Spectra Analyze gives every CrowdStrike Falcon detection a second opinion that doesn't expire. Learn more: www.reversinglabs.com/blog/extend-... #SecOps
reversinglabs.com
Extend CrowdStrike Falcon With Permanent Intelligence | RL Blog
ReversingLabs built a Spectra Analyze integration with CrowdStrike Falcon. The connector is available now as part of Spectra Analyze v9.6.0.
000
ReversingLabs @reversinglabs.com · 28/08/2026
1/ Three infostealer families, one business model. AuraStealer, ACRStealer/Amatera, and Remus Stealer are all sold as malware-as-a-service, and ReversingLabs tracked all three across July and August.
100
ReversingLabs @reversinglabs.com · 17/07/2026
When the user becomes the vulnerability, new threats emerge. No exploits, just trust breaches. Dive into our #ClickFix report by Toni Dujmović for more insights! #CyberAwareness #ReversingLabs youtube.com/shorts/MHm4K...
youtube.com
ClickFix: The Fake CAPTCHA That Hijacks Your Clipboard
YouTube video by ReversingLabs
000
ReversingLabs @reversinglabs.com · 14/07/2026
📢 New ReversingLabs research: Copy, Paste, Compromise: The Tale of ClickFix The complete #ClickFix attack chain, the MaaS economy behind it, and an open-source #YARA rule validated against 4K+ samples — 123 of them lures that evaded every #Antivirus engine. 👇 www.reversinglabs.com/clickfix
reversinglabs.com
ClickFix Threat Report: Copy, Paste, Compromise | ReversingLabs | ReversingLabs
Original RL research on ClickFix: the attack chain, the MaaS economy behind it, and the YARA detection strategy that catches what AV and EDR miss.
000
ReversingLabs @reversinglabs.com · 02/07/2026
Gartner just defined a new market — and that matters more than it sounds. ReversingLabs was named a Visionary in the new Gartner® Magic Quadrant™ for the category we helped build. www.reversinglabs.com/blog/gartner... #SoftwareSupplyChain
reversinglabs.com
This Report from Gartner Defines the Software Supply Chain Security Market | RL Blog
Explore the new Gartner® Magic Quadrant™ for software supply chain security and learn why ReversingLabs is recognized.
101
ReversingLabs @reversinglabs.com · 25/06/2026
The question is no longer "Is this software secure?" It's "Can this software be trusted?" Trust should be verified, not assumed. Download your copy of the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security report here: www.reversinglabs.com/2026-gartner...
010
ReversingLabs @reversinglabs.com · 16/06/2026
npm v12 turns off install script execution by default — the vector Shai-Hulud, Mini Shai-Hulud, and Miasma all relied on. Security experts break down what it fixes and what attackers are already doing instead: www.reversinglabs.com/blog/npm-v12...
reversinglabs.com
npm v12 blocks install scripts: What it means for software supply chain security | RL Blog
By disabling install scripts by default, it closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.
000
ReversingLabs @reversinglabs.com · 09/06/2026
Threat actors are using #TikTok & #Instagram tutorials to deliver #Vidarstealer. One video hit 100K views and 1,700 saves — because attackers know which metrics move the algorithm. Research breakdown + IoCs: www.reversinglabs.com/blog/social-... #SocialEngineering #Phishing
reversinglabs.com
Phishing Attacks Leverage TikTok, Instragram Reels | RL Blog
RL has discovered two social engineering attack techniques targeting users via short-form videos. Here’s how they work.
000
ReversingLabs @reversinglabs.com · 03/06/2026
48,000 CVEs in 2025. Only 58 posed a real, exploitable threat to enterprise supply chains. "Patch everything" is mathematically dead. The signal that matters: malware, tampering, exposed secrets. Go from noise to signal: www.reversinglabs.com/blog/noise-t... #AppSec #SoftwareSupplyChainSecurity
reversinglabs.com
CVE noise drowns out software supply chain threats | RL Blog
48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.
000
ReversingLabs @reversinglabs.com · 01/06/2026
🚨 Supply Chain Attack Alert! 🚨 31 @redhat-cloud-services hashtag#npm packages backdoored in 72 seconds! ReversingLabs has confirmed a large-scale, coordinated supply chain attack targeting the "@redhat-cloud-services" npm scope.
100
ReversingLabs @reversinglabs.com · 27/05/2026
Megalodon compromised GitHub Actions YAML files across dozens of repos — base64-encoded credential stealer, C2 on RouterHosting LLC. RL retrohunted to a related campaign 2 weeks earlier. Same C2 pattern. Same adversary. IOCs + YARA rule published: hubs.ly/Q04hVW-v0
hubs.ly
Researcher's Notebook: Hunting Megalodon Fossils | RL Blog
Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.
000
ReversingLabs @reversinglabs.com · 12/05/2026
RL documented 163 samples of the Dirty Frag Linux exploit (formerly Copy Fail), active malware — and developed YARA rules for identification. Patch the kernel. Run the queries. Deploy the rules. The detection gap is now. www.reversinglabs.com/blog/dirtyfr...
reversinglabs.com
How Dirty Frag rose from the Linux exploit Copy Fail | RL Blog
RL researchers documented 163 samples tied to CVE-2026-31431, identified active malware adoption — and developed YARA rules to identify them.
010
ReversingLabs @reversinglabs.com · 05/05/2026
Is frontier #AI risk keeping your #AppSec team up at night? Doug Levin shares the facts on #ClaudeMythos. Doug also lays out the case for why a layered #AppSec framework is essential — and what it should look like. 👇 www.reversinglabs.com/blog/how-myt...
reversinglabs.com
How Claude Mythos changes the application security calculus | ReversingLabs
Here are the facts on Mythos — and why your organization must adopt a layered security framework to match the new frontier models.
000
ReversingLabs @reversinglabs.com · 04/05/2026
A new class of #AI-derived threats is raising red flags: #MCP post-deployment drift ("rug pull") attacks. They exploit trust of agents over time rather than at the initial point of compromise, which requires deeper visibility. Here's what you need to know. hubs.ly/Q04fhLR30
hubs.ly
MCP client rug-pull attack worries mount for AppSec | ReversingLabs
This class of AI tool supply chain attack highlights how trust of agents can be exploited by threat actors.
000
ReversingLabs @reversinglabs.com · 28/04/2026
Malware is evolving—and targeting AI workflows. Our research on the PromptMink campaign shows how attackers are abusing AI coding agents like Claude to deliver crypto-stealing malware. This isn’t just prompt injection. It’s supply chain risk in a new form. Read: www.reversinglabs.com/blog/claude-...
reversinglabs.com
Claude adds PromptMink malicious dependency to crypto agent | ReversingLabs
The malicious npm package has evolved into a dependency that allows attackers to access users’ crypto wallets and funds.
030
ReversingLabs @reversinglabs.com · 22/04/2026
It looks like #TeamPCP has again compromised #Checkmarx #VSCode extensions and #Docker images. Newly published VSCode extensions checkmarx.cx-dev-assist (1.17.0 & 1.19.0) and checkmarx.ast-results (2.63.0 & 2.66.0) contain malicious code. secure.software/vscode/packa...
Report: threats detected in Checkmarx Developer Assist - image from secure.software.
221
ReversingLabs @reversinglabs.com · 15/04/2026
It’s no secret modern #AppDev relies on #OpenSource — what’s catching up is how teams secure it. RL’s free Spectra Assure Community helps teams make smarter decisions about the software they use and ship. 👇 www.reversinglabs.com/blog/why-rl-...
reversinglabs.com
Securing the Village: Why RL Built Spectra Assure Community | ReversingLabs
ReversingLabs built it to help development and AppSec teams secure open source dependencies, detect malware — and prevent supply chain attacks.
120
ReversingLabs @reversinglabs.com · 14/04/2026
High-end AppSec isn’t just for the Fortune 500. Spectra Assure Community gives devs, AppSec teams & OSS maintainers pro-grade supply chain security insights — without the cost or complexity. Move beyond blind trust 👉 secure.software/user/signup
000
Reposted by ReversingLabs
Cyber Threat Alliance @cyberalliance.bsky.social · 10/04/2026
CTA Member @reversinglabs.com on a fake recruiter campaign: www.reversinglabs.com/blog/graphal... #cybersecurity #scam #fakerecruiter
reversinglabs.com
Graphalgo fake recruiter-test campaign respawned | ReversingLabs
NK threat actors targeting crypto developers are back with an LLC and new techniques to hide malware. Here's RL's analysis.
011
ReversingLabs @reversinglabs.com · 09/04/2026
🚨 New RL #ThreatResearch: The #Graphalgo fake developer recruiter interview campaign is back. RL researchers have uncovered a broader network of fake companies tied to this fake recruiter operation — plus new attacker techniques. Read what the RL team found: www.reversinglabs.com/blog/graphal...
reversinglabs.com
Graphalgo fake recruiter-test campaign respawned | ReversingLabs
NK threat actors targeting crypto developers are back with an LLC and new techniques to hide malware. Here's RL's analysis.
000
ReversingLabs @reversinglabs.com · 03/04/2026
The axios supply chain attack should be front an center for #AppSec teams given it's wide reach. Here's RL's immediate-response checklist — and best practices for ongoing defense. Also learn how RL’s xBOM and Spectra Assure Community can help. 👇 www.reversinglabs.com/blog/axios-a...
reversinglabs.com
Axios supply chain attack: How AppSec teams should respond | ReversingLabs
Here's an incident-response checklist and ongoing best practices. Plus: How RL’s xBOM and Spectra Assure Community can help.
000
ReversingLabs @reversinglabs.com · 02/04/2026
At #RSAC, JPMorgan Chase CISO Patrick Opet revisited third-party risk — and the supplier changes that followed. Is your organization learning the lesson on “trust debt”? Learn how to move beyond blind trust: www.reversinglabs.com/blog/opet-jp...
reversinglabs.com
How JPMorgan Chase tackles third-party software ‘trust debt’ | ReversingLabs
JPMC CISO Patrick Opet discussed his open letter on third-party software risk — and the changes suppliers have made since.
000
ReversingLabs @reversinglabs.com · 31/03/2026
🚨 RL Research Alert! Look out for the compromised versions 1.14.1 and 0.30.4 of axios npm package with almost 11 billion downloads. secure.software/npm/packages...
secure.software
axios@1.14.1 - npm | ReversingLabs Spectra Assure Community
Supply chain risk analysis for axios@1.14.1. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
100
ReversingLabs @reversinglabs.com · 27/03/2026
Look out for compromised versions 4.87.1 and 4.87.2 of telnyx PyPI package with more than 3.75 million downloads. secure.software/pypi/package...
secure.software
telnyx@4.87.2 - PyPI | ReversingLabs Spectra Assure Community
Supply chain risk analysis for telnyx@4.87.2. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
100
ReversingLabs @reversinglabs.com · 24/03/2026
📢 Just dropped: New RL research! 👻 Ghost campaign returns via malicious #npm packages ⚠️ Phishes sudo passwords + hides behind fake install logs 🔍 www.reversinglabs.com/blog/npm-fak... 🛡️ Ask us about it — + Spectra Assure Community — at Booth #4328 #RSAC2026
reversinglabs.com
Malicious npm packages use fake install logs to load RAT | ReversingLabs
The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.
000
ReversingLabs @reversinglabs.com · 22/03/2026
Security Advisory: our research team is tracking threat actor #TeamPCP, who hacked the #Trivy supply chain and infected over 140 npm packages with self-propagating malware #CanisterWorm. View our platform's analysis of a known infected package here: secure.software/npm/packages...
secure.software
@teale.io/eslint-config@1.8.9 - npm | ReversingLabs Spectra Assure Community
Supply chain risk analysis for @teale.io/eslint-config@1.8.9. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
000
Reposted by ReversingLabs
Cyber Threat Alliance @cyberalliance.bsky.social · 13/03/2026
"Ambiguous package names & fragmented tracking methods leave organizations vulnerable to sophisticated supply chain attacks. By demanding PURLs in your SBOMs, you enforce a strict standard of visibility and accountability" www.reversinglabs.com/blog/why-you... #cybersecurity #SBOM @reversinglabs.com
reversinglabs.com
How to Make Your SBOMs Actionable with PURLs | ReversingLabs
Package URLs give software components an exact address to improve vulnerability matching, which reduces alert fatigue and simplifies compliance.
011
ReversingLabs @reversinglabs.com · 05/03/2026
BSIMM16 reinforces that #AIcoding is the new reality — and it will further destabilize #softwaresupplychainsecurity. So step up your #AppSec. 👇 www.reversinglabs.com/blog/bsimm16...
reversinglabs.com
BSIMM16 confirms it: AI redefines the AppSec landscape | ReversingLabs
AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.
000
ReversingLabs @reversinglabs.com · 26/02/2026
🚨 RL researchers discovered a malicious package impersonating a legitimate Stripe package on #NuGet — marking a move away from blockchain-related targets while staying focused on financial development tools. Read here: www.reversinglabs.com/blog/malicio...
reversinglabs.com
Malicious NuGet package targets Stripe | ReversingLabs
In this latest incident, threat actors target developers with a bogus package — a shift away from cryptocurrency development targets.
010
ReversingLabs @reversinglabs.com · 19/02/2026
ReversingLabs' Ashlee Benge shares how to use YARA retrohunting for detection engineering by leverageing RL's dynamic analysis of "pkr_mtsi" for defense in Spectra Analyze. 👉 hubs.ly/Q043qJY-0 #yararules #detectionengineering #malwareanalysis
hubs.ly
How to Use YARA Retrohunting for Detection Engineering | ReversingLabs
Learn how to leverage ReversingLabs’s dynamic analysis of <em>pkr_mtsi</em> for defense using YARA Rules in Spectra Analyze.
000
ReversingLabs @reversinglabs.com · 11/02/2026
⚠️ RL #ThreatResearch: A new branch of a fake job recruitment campaign by the NK Lazarus Group, dubbed "graphalgo," is targeting #Javascript & #Python devs with a remote access trojan (RAT). Read more: hubs.ly/Q042HLPR0
hubs.ly
Fake recruiter campaign targets crypto developers with RAT | ReversingLabs
A new branch of a well-coordinated fake job recruitment campaign is targeting Javascript and Python developers via social channels.
000
ReversingLabs @reversinglabs.com · 05/02/2026
⛓️ The recent compromise of Notepad++ underscores supply chain attack method diversification. It also serves as a reminder for why going beyond implicit trust is a must: hubs.ly/Q041-Cb30 #SoftwareSupplyChainSecurity #AppSec #DevSecOps
hubs.ly
Notepad++ hack marks an evolution of supply chain threats | ReversingLabs
A months-long compromise of the popular source code editor underscores a diversification of attack methods. Here's why going beyond trust is key.
000
ReversingLabs @reversinglabs.com · 04/02/2026
🤖 #MCP provides a standardized way for #AI agents to connect directly to apps, tools, & data sources. But because they have real authority, they're attractive targets. The new Vulnerable MCP Servers Lab aims to solve this: bit.ly/3MaNXAY
bit.ly
Vulnerable MCP Servers Lab: 9 ways to boost ML security | ReversingLabs
The new GitHub-based lab aims to tame MCP servers with security server and tool-integration training, demos, and instruction on attack methods.
000
Reposted by ReversingLabs
Help Net Security @helpnetsecurity.com · 03/02/2026
Open-source attacks move through normal development workflows 📖 Read more: www.helpnetsecurity.com/2026/02/03/o... #cybersecurity #cybersecuritynews #opensource #supplychain #vulnerabilitymanagement @reversinglabs.com
helpnetsecurity.com
Open-source attacks move through normal development workflows - Help Net Security
Open source supply chain attacks move through normal development workflows, turning routine updates and trusted code into delivery paths.
021
ReversingLabs @reversinglabs.com · 03/02/2026
🪞We looked back on what we predicted the #SoftwareSupplyChainSecurity threat landscape would be in 2025. Here's what we got right — & wrong: bit.ly/49UKS19
bit.ly
Software Supply Chain Security Report: A 2025 retrospective | ReversingLabs
ReversingLabs looked at last year's report in the rear-view mirror. Here's a retrospective with what the team got right -- and wrong.
000
ReversingLabs @reversinglabs.com · 29/01/2026
⛓️‍💥 Former CEO & founder of Black Duck Software Doug Levin writes in his Substack how trust in the reliability of the #SoftwareSupplyChain has sharply deteriorated: bit.ly/4qLx66N
bit.ly
The Collapse of Trust in the Software Supply Chain
The software supply chain is the end-to-end pathway through which software components are sourced, assembled, and deployed into production.
020
ReversingLabs @reversinglabs.com · 29/01/2026
🔎 In the latest edition of the RL Researcher's Notebook Series, #malware analyst Robert Simmons offers a deep dive of the recent #EmEditor supply chain compromise: bit.ly/4rgniBK
011
Reposted by ReversingLabs
The Security Ledger @securityledger.bsky.social · 29/01/2026
The #StrangerThings concept of the “Upside Down” is a pretty useful way to think about the risks lurking in the software we all rely on. A new report from @reversinglabs.com shines a light into that dark world. #appsec #softwaresupplychain securityledger.com/2026/01/tech...
securityledger.com
Technology’s “Upside Down”? Software Supply Chain
The concept of an “Upside Down” is a good way to think about software risks, as the latest Software Supply Chain Security Report makes clear.
022
Reposted by ReversingLabs
Help Net Security @helpnetsecurity.com · 29/01/2026
Open-source malware zeroes in on developer environments 📖 Read more: www.helpnetsecurity.com/2026/01/29/r... #cybersecurity #cybersecuritynews #opensource #malware @reversinglabs.com
helpnetsecurity.com
Open-source malware zeroes in on developer environments - Help Net Security
Open source malware activity increased in 2025, with attackers using public registries and installs to reach developers and CI systems.
021
ReversingLabs @reversinglabs.com · 28/01/2026
🤖 #AI tools are making #Rust a favorite language of devs — even those maintaining codebases like Microsoft’s. Keep reading to learn how #AIcoding bolsters Rust: bit.ly/49O7wIs
bit.ly
How AI coding is breathing new life into Rust  | ReversingLabs
AI coding tools are making the memory-safe language Rust a favorite of developers -- even those maintaining massive codebases like Microsoft's.
000
ReversingLabs @reversinglabs.com · 27/01/2026
📣 RL's 4th annual report on the state of #SoftwareSupplyChainSecurity is now available: bit.ly/3Fq6F3W #AppSec #DevSecOps
120
ReversingLabs @reversinglabs.com · 22/01/2026
🐍 @python.org announced a 2-year partnership with #Anthropic, which will contribute $1.5 million to support the foundation's security initiatives for #PyPI: bit.ly/4a6uvhU
bit.ly
Anthropic's $1.5M Python investment: Why it matters | ReversingLabs
Here's what the $1.5M investment in the Python Software Foundation will mean for AI security and open-source management.
000
Reposted by ReversingLabs
Cyber Threat Alliance @cyberalliance.bsky.social · 22/01/2026
CTA has "helped raise the bar for collaboration across the cybersecurity community, demonstrating that sharing does not weaken competitive advantage — it strengthens collective resilience" @reversinglabs.com tinyurl.com/6xtnck5y #CTA9Years #strongertogether #cybersecurity #threatintelligence
tinyurl.com
Celebrating 9 Years of the Cyber Threat Alliance: Advancing Collective Defense Together - Cyber Threat Alliance
By Mario Vuksan, CEO & Co-founder, ReversingLabs This year marks the 9th anniversary of the Cyber Threat Alliance (CTA) — a milestone that highlights nearly a decade of collaboration, trust, and share...
022
ReversingLabs @reversinglabs.com · 21/01/2026
NIST has broadened the Secure Software Development Framework (SSDF) to include the full SDLC. Here's what your #AppSec team needs to know: bit.ly/3ZksCbk #DevSecOps #SoftwareSupplyChainSecurity
bit.ly
SSDF 1.2 recognizes AppSec is a journey | ReversingLabs
NIST has broadened the Secure Software Development Framework to include the full software development lifecycle. Here's why it matters.
000
ReversingLabs @reversinglabs.com · 20/01/2026
📝 The Cyber Resilience Act legally obliges software producers to create, maintain, & retain an #SBOM for all products with digital elements marketed within the EU. Here's what you need to know: bit.ly/4b4XSSV
bit.ly
Mandatory SBOMs: What CRA is -- and why it matters | ReversingLabs
The EU's Cyber Resilience Act introduces a legal obligation for software producers to create, maintain, and retain an SBOM. Are you prepared?
000
ReversingLabs @reversinglabs.com · 15/01/2026
🤖 A new report on #AIsecurity from the Cloud Security Alliance finds that enterprise governance of #AI usage & potential threats makes a huge difference: bit.ly/459MYrk
bit.ly
Why governance is essential for safe AI adoption | ReversingLabs
A new CSA report stresses getting out in front of AI risk — and offers insights into AI in SecOps. Here’s why you need guardrails.
000
ReversingLabs @reversinglabs.com · 15/01/2026
🚨New Feature Alert: secure.software now offers free, single click #SBOM delivery in the CycloneDX format. See it in action: app.arcade.software/share/oBBgnr... #Dev #AppSec #DevSecOps
000