Reports

Claude Code (AdobeStock)

How Claude Planted Malicious Code In A Crypto-Trading App

A malicious campaign by North Korean state actors saw a malicious npm package dependency slipped into a crypto trading agent by an AI coding agent, according to a new report by ReversingLabs. The incident highlights a troubling new frontier in software supply chain attacks: hackers targeting developers…and the AI tools writing their code.

Developer secrets detected on public GitHub repos by year. GitGuardian image.

Exposed Developer Secrets Surge: AI Drives 34% Increase in 2025

GitGuardian’s latest Secrets Sprawl report found more than 28 million new secrets exposed via public GitHub commits in 2025, a 34% increase over 2024 and the largest annual jump the company has recorded. The spike reflects a broader transformation in software creation, as AI tools lower the barrier to coding.

Stranger Things - The Upside Down

Technology’s “Upside Down”? Software Supply Chain

Stranger Things concept of the “Upside Down” is a useful way to think about the risks lurking in the software we all rely on. A new report from ReversingLabs shines a light into that dark world.

Stock Image: Compromised IP Camera

How Hackers Take Over Security Cameras (and What You Can Do About It): A Conversation With Claroty’s Noam Moshe

Cybersecurity researcher Noam Moshe of Claroty met up with The Security Ledger Podcast at this year’s Black Hat Briefings to discuss his presentation on critical Axis IP camera vulnerabilities that could let hackers spy, manipulate video feeds, and pivot into sensitive networks—and what organizations can do to defend against these (and other) IoT threats.

RL SSCSR Feature Image

Report: Epidemic of Flaws in Commercial and Open Source Code

ReversingLabs’ 2025 Software Supply Chain Security Report finds that security flaws in commercial and open source code are epidemic as hackers target supply chains including those for cryptocurrency and AI in a play for access to sensitive data and IT assets.