ReversingLabs

Get the Spectra Assure Community Plugin for JFrog Artifactory

Even with JFrog Artifactory proxying public open-source software (OSS) registries, package managers like npm and pip will typically pull the newest version of a dependency — even if it was published just moments before. That’s convenient — but it’s also the workflow attackers have learned to exploit.Malicious OSS packages aren’t a one-off problem anymore. They’re a recurring campaign. For example, the Shai-Hulud worm is now on its fourth iteration. Trivy, Axios, and LiteLLM have all seen comprom

Read More
ReversingLabs

Rubrik + RL: Bring Threat Intelligence and Detection to Backups

Key takeawaysRubrik + ReversingLabs: Your backups might be infected. Now you’ll know.Why backups have become the primary target, not the last resort.What this integration looks like in practice.Close the gap between new intelligence and old backups.KNP Logistics had been moving freight around the United Kingdom for 158 years. Then the Akira ransomware group guessed one employee’s password. By the time the intrusion was over, KNP’s data was encrypted and its servers, its backups, and its disaster

Read More
ReversingLabs

Agentic AI permissions: A core problem — but not the only one

Key takeawaysAgent permissions, not the prompt, are the real security boundary— coding agents that can touch repos, shells, and production systems create risk if their access isn’t tightly scoped.Overpermissioning compounds silently— agents typically inherit their user’s full access, and that spreads further when agents spawn sub-agents, breaking traceability back to the authorizing human.Goal-driven, non-deterministic agents will exploit any slack they’re given— the OpenAI–Hugging Face incident

Read More
ReversingLabs

AI coding puts Secure by Design in the spotlight

Key takeawaysSame old flaws, bigger stakes: ~40% of CISA’s exploited-vulnerability catalog traces back to well-understood, preventable weaknesses (memory safety, input validation, injection).Attackers aren’t chasing zero-days: CVE disclosures more than doubled year over year, but exploited vulnerabilities grew only 20% — known gaps are still the target.AI raises the urgency: it speeds up vulnerability discovery and exploit development, shrinking the window before flaws get found and weaponized.T

Read More
ReversingLabs

Memory-safe programming goes from advocacy to adoption

Key takeawaysCISA/NSA’s report cited memory-safety issues behind 66-71% of major OS CVEs and 75% of in-the-wild exploited vulnerabilities, driving real adoption momentum.Adoption faces real headwinds: legacy C/C++ is too vast to rewrite wholesale, and experts say MSLs work best for new code, not replacing proven systems.AI is accelerating migration (Google’s Gemini-assisted Rust rewrite ofgiflibis an early proof point), but human review is still required — the AI-generated code itself had defect

Read More
Krebs

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp.today released software updates to plug at least 570 security holes in itsWindowsoperating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could us

Read More
Krebs

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giantLG Electronics USAsaid this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions.

Read More
Krebs

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.Pedro Faléis a threat

Read More