Krebs

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data brokerRadaris.comhas long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in

Read More
Krebs

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 millionAT&Tcustomers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.One of several selfies from the Facebook page of Cameron Wagenius.Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “Kiberphant0m.” Worki

Read More
ReversingLabs

31 Red Hat npm packages backdoored by Miasma in 72 seconds

RL researchers have uncovered a large-scale, coordinated supply chain attack targeting the@redhat-cloud-servicesnpm scope. On June 1, an attacker published malicious versions of 31 packages (update) in a 72-second window, injecting obfuscated preinstall malware into every one.The affected packages collectively represent approximately 9.8 million total downloads and cover the full breadth of Red Hat’s Hybrid Cloud Console JavaScript ecosystem — UI components, API clients, build tooling, configura

Read More
ReversingLabs

Agentic AI risk isn’t a model problem. It’s an architecture problem.

With artificial intelligence, trust isn’t what it used to be. AI is prodding security teams to move from static, binary, identity-based trust toward dynamic, probabilistic, behavior-based trust. They’re also adjusting to a shift in security from the component layer of applications to the data layer.AI pushes a meaningful portion of security risk up from static components — libraries, services, containers — and into the data and context the system consumes at runtime, said Christopher Jess, senio

Read More
ReversingLabs

Restrospective: How Malicious Updates Poison Your Environment

In 2026, supply chain attacks took center stage. Thespring was a stormof open source packages being compromised into pushing malicious updates, infecting a variety of targets and causinguntold amounts of damages. Recently, two actors associated withTeamPCP were arrested. TeamPCP was responsible for many of the recent supply chain compromises, making this an apt time to reflect on those attacks. This retrospective covers attacks from late 2025 to present day, explains how and why they work — and

Read More
ReversingLabs

Update to npm blocks install scripts: What it means for AppSec

A longstanding security deficiency in the popular npm package manager — having the installation of scripts turned on by default — will be addressed in the next version of the software, expected to be released in July.The change, in version 12 of npm, meansthe commandnpm-installwill no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in a project,the npm team explained in a GitHub blog.For years, a single compromised package could run

Read More
ReversingLabs

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

In the space of a few years, software supply chain security has moved from a niche problem to a major threat and board-level concern for most companies. Every organization depends on software built from code, components, services and AI models created by people they’ll never meet and by organizations they’ll never be able to directly assess.That’s why as the CEO of ReversingLabs, I am thrilled that Gartner® has issued its inaugural Magic Quadrant™ for Software Supply Chain Security (SSCS) — and

Read More
ReversingLabs

ClickFix doesn’t attack your knowledge. It attacks your trust.

It started with a phone call from a friend. He’d tried to log into his university’s Student Association website — a site he used constantly and trusted — and hit a strange CAPTCHA screen. Something felt off. He asked me to take a look.I did. Working with RL’s Spectra Analyze, I ran interactive dynamic analysis. What I found was a textbook ClickFix attack. The student site was compromised and used as a “watering hole” to draw in potential victims. Key to the attack was a pixel-perfect fake Google

Read More