OpenAI's post-mortem calls the Hugging Face incident a "warning shot": agents chained ordinary infrastructure flaws and reached host-level control across clusters in under 13 hours, with no human ...
Rubrik + ReversingLabs: Your backups might be infected. Now you'll know. Why backups have become the primary target, not the last resort. What this integration looks like in practice. Close the gap ...
Nearly half the content passed to the model was invisible to the reader: 1,009 characters sent, 537 displayed, 472 hidden. The summaries contained fabricated data and omitted facts, with no cue to the ...
With this integration, Rubrik users can now tap ReversingLabs' ransomware feed to decide whether each file in their backup is safe. ReversingLabs built a Spectra Analyze integration with CrowdStrike ...
The Open Worldwide Application Security Project’s newest OWASP Top 10 for LLM Applications includes a change that puts a spotlight on the rise of AI risk. While prompt injection and the disclosure of ...
In February, the ReversingLabs research team described a malicious campaign featuring fake job interviews that the team called “graphalgo.” Two months later, RL researchers detected a larger set of ...
This blog post presents an in-depth technical analysis of pkr_mtsi, a malicious Windows packer first observed in the wild on April 24, 2025, and continuously deployed through the time of writing. The ...
Short-form videos on social media apps are currently being leveraged by threat actors as a phishing vector, utilizing tutorial style content with the promise of free premium software to lure victims ...
In the last few months, artificial intelligence (AI) is popping up in all kinds of headlines, ranging from technical software developer websites to the Sunday comics. There’s no secret why. Given the ...
Earlier this week, the TeamPCP attack spread from GitHub Actions and npm to the PyPI ecosystem. The victim: The LiteLLM package, an open-source Python library and proxy server that provides a unified ...
ReversingLabs has identified connections between a malicious campaign that was recently discovered and reported by the firm Phylum and several hundred malicious packages published to the NuGet package ...
Two newly discovered extensions on the VS Code Marketplace are designed to steal sensitive information, showing that open source attacks are expanding. Lucija Valentić, Software Threat ...