ReversingLabs

Can advanced math make AI systems safer?

Key takeawaysTop mathematicians are moving into AI safety.Fields Medalist Jacob Tsimerman launched MAISI, and Turing winner Shafi Goldwasser co-founded RESI.Proofs can verify what AI does.Zero-knowledge proofs could confirm an agent’s actions and claims without exposing its model or data.Guarantees are only as good as their assumptions.The Hugging Face sandbox escape shows how easily reality can diverge from what a proof assumed.Hard limits beat universal proofs for now.Rules enforced outside th

Read More
ReversingLabs

Software Supply Chain Security Just Got Its Own Magic Quadrant — and RL Is In It

For years, software supply chain security (SSCS) lived like a teenager in the basement of a bigger house. It was a line item inside the sprawling application security testing (AST) world — important, occasionally praised at dinner, but never quite trusted with its own keys. Everybody nodded along about software bills of material (SBOMs) and provenance the way you nod along about flossing.On June 17, the basement kid got the keys. Gartner published its very firstMagic Quadrant™ for Software Suppl

Read More
Krebs

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker groupShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from theFBIand extorting the Russian ransomware groupCl0p.According to three sources familiar with the matter, the Dutch man arrested by authorities this month isPepi

Read More
ReversingLabs

The race to secure AI coding: 4 steps to rein agents in

The rapid adoption of AI coding agents is outpacing the security controls organizations have put in place to govern them.According to JetBrains’ 2025 Developer Survey,85% of developersnow regularly use AI tools for coding and development, and 62% use at least one AI coding assistant.Gartnerprojects that figure will reach 90% of enterprise software engineers by 2028.The security implications are significant. Coding agents have broad access to source code, repositories, credentials, and CI/CD pipe

Read More
ReversingLabs

2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

The inaugural Gartner Magic Quadrant™ for Software Supply Chain Security evaluates 18 vendors across more than 37  pages of research. Most security teams will read the executive summary, look at the graphic, and move on.That’s a miss because the evaluation criteria, the Mandatory Features list, Gartner identified across the field give AppSec leaders exactly the framework they need to run a sharper, faster vendor evaluation.In our experience, here are the five things that matter most.[ Learn howR

Read More
ReversingLabs

The tale of ClickFix: 5 takeaways from RL’s new threat report

Somewhere between a fake CAPTCHA page and an open Run dialog, the security model at most organizations breaks down. That is the uncomfortable conclusion of ReversingLabs’ new threat research report,”Copy, Paste, Compromise: The Tale of ClickFix,”by RL researcher Toni Dujmović and the RL Threat Intelligence Research team.ClickFix, a social engineering technique first identified in 2023, is one of the most widely deployed attack methodologies in the current threat landscape — precisely because to

Read More
ReversingLabs

This Report from Gartner Defines the Software Supply Chain Security Market

We believe the release of a new Gartner Magic Quadrant is always a watershed moment for the technology sector. In our opinion,  it signals that a specific category of software has matured from a niche collection of tools into a vital, formalized market. For software engineering and security testing teams, the latest report covering software supply chain security represents a massive shift in how organizations protect their code, their infrastructure, and their customers.Before this formal recogn

Read More
ReversingLabs

‘Download pumping’ joins the trust-abuse bandwagon

When appraising the legitimacy of packages in software repositories, developers and even security tools often rely on download counts. Nonetheless, the metric can be weaponized by threat actors who use automated systems such as repository mirrors and analysis bots to poison software packages and infect supply chains.Researchers at Tenable discovered the new technique, which they’re calling “download pumping,” while analyzing npm packages uploaded to the public registry, senior security researche

Read More