ReversingLabs

New OWASP tool structures AI threat modeling

Organizations looking for a faster and more structured way to threat model their AI systems now have access to an open-source resource designed to help identify security risks before they become exploitable vulnerabilities.The OWASP Foundation’sThreat Advisoris an AI-powered assistant that guides users through the threat modeling process by first asking them to describe their AI system and then conducting an interactive interview to identify relevant threats, assess risk, and recommend mitigatio

Read More
ReversingLabs

Hidden in plain sight: How SVGs carry malicious scripts

In early 2026, sources began reporting an uptick in SVG based malware. SVG, standing for scalable vector graphics, is a filetype usually utilized to create vector images. SVGs are special due to their ability to utilize Javascript.Threat actors use this functionality to craft SVG files that can act maliciously. Malicious SVGs can take the form of fake login pages, data exfiltrators, or malicious downloaders, amongst other things. SVGs are frequently overlooked, as they are assumed to be benign i

Read More
ReversingLabs

Akrites marshals the open source community to counter AI threats

Open-source software underpins some of the world’s most critical infrastructure. Banking, telecommunications, and utilities all run on software that shares the same OSS libraries. Finding vulnerabilities in that software is pressingly important, but it can take experts weeks to do so. Now, artificial intelligence can find them in minutes.As good as that might sound, the speed of discovery does bring problems. With that in mind, the Linux Foundation and industry heavyweights including Amazon Web

Read More
ReversingLabs

Security teams ditch AI-only pen testing

A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop.A year ago, nearly three of every 10 organizations were comfortable letting AI run their penetration testing end to end — no humans required. Today, confidence in that model has collapsed.Cobalt’s newAI and Pentesting Pulse Report 2026— based on a survey of 455 cybersecurity professionals — found the share of organizations relying solely on AI automation for testing fell from 29% in 2025 to ju

Read More
ReversingLabs

AI coding agents: A call to action on dependency cooldowns

Remember those words of advice for the over-eager fromWest Side Story? “Boy, boy, crazy boy, be cool boy.” They should be heeded by developers hell-bent on installing the latest updates to open-source software. Adopting a “cooldown” policy on updates can be a simple but effective way to avoid downloading malicious code.Noelle Murata, a senior security engineer at Xcape, said organizations should enforce a three-to-four-day minimum age requirement for new packages and updates.“A short delay gives

Read More
ReversingLabs

Why AI coding makes zero trust an AppSec requirement

Feeling comfortable about the safety of your software supply chain because your organization has invested in SBOMs, signing, and provenance? You shouldn’t.In the AI coding era, those tenets of the traditional trust model aren’t enough to ensure software safety. That’s because that model fails to answer an important security question: What is the code capable of doing?CodeHunter CEO Ken Ammon,writing for Help Net Security, summarized the trust vacuum.“[T]raditional trust models are insufficient w

Read More
ReversingLabs

How to Leverage Spectra Analyze’s Search for SVG Analysis

For this installment of Spectra Analyze in Action, the threat intelligence research team at ReversingLabs explores hunting for Scalable Vector Graphics (SVGs) files. SVGs are a sneaky way attackers can target your organization. Due to their nature as image files, they are typically seen as benign, but recently they have been used as a vector for credential phishing sites, malicious redirection, and infected downloads.To aid in protecting your organization, you can use Spectra Analyze to hunt and

Read More
ReversingLabs

AI domain takeover takeaway: Focus on the harness not the model

Mention offensive AI and expect the discussion to focus on vulnerability discovery, malware creation, and exploit generation, butrecent researchby Cato Networks identified another — and very potent — application for offensive AI.Cato explained in ablog postthat it evaluated in a controlled Active Directory lab environment, how frontier models behave when combined with agent platforms, MCP-enabled tooling, and operational guidance. “The objective was straightforward: determine how effectively an

Read More