Krebs

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker groupShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from theFBIand extorting the Russian ransomware groupCl0p.According to three sources familiar with the matter, the Dutch man arrested by authorities this month isPepi

Read More
ReversingLabs

The race to secure AI coding: 4 steps to rein agents in

The rapid adoption of AI coding agents is outpacing the security controls organizations have put in place to govern them.According to JetBrains’ 2025 Developer Survey,85% of developersnow regularly use AI tools for coding and development, and 62% use at least one AI coding assistant.Gartnerprojects that figure will reach 90% of enterprise software engineers by 2028.The security implications are significant. Coding agents have broad access to source code, repositories, credentials, and CI/CD pipe

Read More
ReversingLabs

2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

The inaugural Gartner Magic Quadrant™ for Software Supply Chain Security evaluates 18 vendors across more than 37  pages of research. Most security teams will read the executive summary, look at the graphic, and move on.That’s a miss because the evaluation criteria, the Mandatory Features list, Gartner identified across the field give AppSec leaders exactly the framework they need to run a sharper, faster vendor evaluation.In our experience, here are the five things that matter most.[ Learn howR

Read More
ReversingLabs

The tale of ClickFix: 5 takeaways from RL’s new threat report

Somewhere between a fake CAPTCHA page and an open Run dialog, the security model at most organizations breaks down. That is the uncomfortable conclusion of ReversingLabs’ new threat research report,”Copy, Paste, Compromise: The Tale of ClickFix,”by RL researcher Toni Dujmović and the RL Threat Intelligence Research team.ClickFix, a social engineering technique first identified in 2023, is one of the most widely deployed attack methodologies in the current threat landscape — precisely because to

Read More
ReversingLabs

This Report from Gartner Defines the Software Supply Chain Security Market

We believe the release of a new Gartner Magic Quadrant is always a watershed moment for the technology sector. In our opinion,  it signals that a specific category of software has matured from a niche collection of tools into a vital, formalized market. For software engineering and security testing teams, the latest report covering software supply chain security represents a massive shift in how organizations protect their code, their infrastructure, and their customers.Before this formal recogn

Read More
ReversingLabs

‘Download pumping’ joins the trust-abuse bandwagon

When appraising the legitimacy of packages in software repositories, developers and even security tools often rely on download counts. Nonetheless, the metric can be weaponized by threat actors who use automated systems such as repository mirrors and analysis bots to poison software packages and infect supply chains.Researchers at Tenable discovered the new technique, which they’re calling “download pumping,” while analyzing npm packages uploaded to the public registry, senior security researche

Read More
ReversingLabs

Hunting Device Code Phishing Pages

Last week, RL discovered an active Microsoft 365 device code phishing campaign that abuses Microsoft’s legitimate OAuth 2.0 Device Authorization Grant flow to obtain access to victim accounts.Rather than stealing passwords through a counterfeit login page, the phishing kit persuades victims to complete a legitimate Microsoft authentication process that authorizes an attacker-controlled device.In this companion Spectra Analyze in Action post, you’ll find a deep dive on how it works, including the

Read More
ReversingLabs

AI-BOM push borrows from the SBOM playbook

Organizations investing in software bill of materials (SBOM) practices are starting to see the payoff as it becomes easier and less of a time sink to chase down what’s actually running in production when supply chain incidents make headlines. The only problem is that with AI, the software supply chain visibility goalposts are moving.AI supply chain attacks are in their infancy, but this spring has given us a preview of what life with AI-embedded software is going to look like. In March, two PyPI

Read More