[su_panel border="1px solid #ddd" radius="3" text_align="center"] [/su_panel]
Blog (Main)
SharePoint ‘ToolShell’ zero-day: What we know
Microsoft notified customers this past weekend regarding in-the-wild attacks targeting its SharePoint products following exploits of several vulnerabilities within the software ...
The true cost of CVEs: Why you need to shift beyond vulnerabilities
Lowering the risks that common vulnerabilities and exposures (CVEs) pose to organizations can be a costly endeavor — but shifting your team's focus away from the deluge can free up your software ...
Fully autonomous development is coming: Is your AppSec ready?
John P. Mello Jr. | | AppSec & Supply Chain Security, Artificial Intelligence (AI)/Machine Learning (ML)
A trio of AI experts raised eyebrows earlier this year when they revealed their ambitious plans to use artificial intelligence (AI) tools to automate all white-collar jobs "as fast as possible." At ...
Vibe coding is seductive — but also a risk that requires security controls
Vibe coding is having its moment as the latest hoped-up AI technology, but busy enterprise development and security operations teams have to be aware of its risks ...
Announcing RL Spectra Analyze Version 9.5
Spectra Analyze v9.5 Release Highlights RL Spectra Analyze empowers all levels of the SOC with a private, in-depth, malware analysis workbench. Analysts, incident responders, and threat hunters are enabled with distinct threat ...
Devs: Vet Your VS Code Plugins with Spectra Assure Community
The steady flow of news about malicious attacks on open source repositories like npm, PyPi, RubyGems and NuGet can be deceptive. Open source dependencies are only part of the software supply chain ...
Malicious pull request infects VS Code extension
In the last few months, ReversingLabs (RL) researchers have encountered multiple malicious packages that target cryptocurrency users and developers. In May, RL researcher Karlo Zanki wrote a blog about malicious PyPI packages ...
3CX’s Software Supply Chain Compromise: Lessons Learned
About two years after 3CX's supply chain compromise, the voice-over-IP vendor has remade its software development process and continuous delivery/continuous integration (CI/CD) pipeline to prioritize the security, integrity, and resilience of its ...
AI security tools and hype: Report breaks down key considerations
Jai Vijayan | | AppSec & Supply Chain Security, Artificial Intelligence (AI)/Machine Learning (ML), security operations
The AI security landscape has become a maze of overlapping vendor claims and made-up categories, leaving organizations struggling to distinguish between products that can actually help and those that are just marketing ...

