Monday, March 2, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ReversingLabs Annual Software Supply Chain Security Report Spotlights Mounting Attacks on AI, Crypto, Open Source, and Commercial Software

March 12, 2025
in Artificial Intelligence, Cryptocurrencies, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
244
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

CAMBRIDGE, Mass., March 12, 2025 (GLOBE NEWSWIRE) — ReversingLabs (RL), the trusted name in file and software security, today released its third annual Software Supply Chain Security Report. The 2025 report details the growing sophistication of software supply chain attacks fueled by widespread flaws in open-source and third-party commercial software, along with malicious campaigns targeting AI and cryptocurrency development pipelines.

According to RL data, open-source software remained a key element of supply chain risk in 2024. For example, incidents of exposed development secrets via publicly accessible, open-source packages rose 12% compared to 2023. And critical and exploitable software flaws continued to lurk in even the most widely used open-source packages. A scan of 30 open-source packages that account for more than 650 million total downloads across three leading open-source package managers found an average of 6 critical-severity and 33 high-severity flaws per package.

But open-source software is just one source of software supply chain risk. A scan by RL of more than two dozen widely used commercial-software binaries, including commercial and open-source operating systems, password managers, web browsers, and virtual private network (VPN) software, found evidence of software risks lurking in third-party commercial binaries. Many of the packages scanned by RL received a failing security grade due to the discovery of exposed secrets, actively exploited software vulnerabilities, evidence of possible code tampering, and inadequate application hardening.

“The 2025 report highlights the challenges faced by software vendors and their enterprise buyers,” said Mario Vuksan, Co-Founder and CEO of ReversingLabs. “First is the increasing sophistication of the attackers, and their willingness to invest years to plan and carry out their attacks. Second is the move beyond open source to target commercial software. This reinforces the need to establish better controls over the software we build and deploy. This is especially true with the rise of AI across the software supply chain.”

Industry analyst firm Gartner underscored this need for focus in its Gartner Security & Risk Management Summit 2024 London, saying that the “security of the software supply chain is now as critical as the security of the software itself.”

Additional key findings for the 2025 SSCRR report include:

Third-Party Commercial Software Is Targeted and Exposed
While much of the conversation about software supply chain security focuses on open-source software packages, the most prominent risks lie in closed-source, commercial software. To underscore this problem, RL scanned 20 distinct versions of VPN clients from six prominent vendors and found worrying trends including:  

  • Seven of the 20 VPN packages contained one or more patch-mandated and/or exploited software vulnerabilities.
  • Four of the 20 VPN packages scanned contained exposed developer secrets

Serious Risks Continue to Lurk in Open-Source Packages
While prominent risks lay in third-party commercial software, open-source software modules and code repositories still accounted for the vast majority of supply chain risks in 2024. RL identified serious, exploitable software flaws, configuration errors, and other problems lurking in widely used open-source modules, which present a significant risk. Additional examples of open-source risks include:

  • Rampant “code rot:” RL’s analysis of popular npm, PyPI, and RubyGems packages found that many widely used open-source modules contain old and outdated open-source and third-party software modules.
  • RL’s scan of an npm package with close to 3,000 weekly downloads and 16 dependent applications, identified:
    • No code updates in more than 7 years
    • 164 distinct code vulnerabilities with 43 rated “critical” severity and 81 rated “high” severity.
    • Seven software vulnerabilities that are known to have been actively exploited by malware

Attacks on Crypto Apps Send Warnings for Software Producers
2024 saw a parade of sophisticated software supply chain attacks targeting cryptocurrency exchanges, wallets, and end-user applications. The crypto-focused attackers employed sophisticated and high-touch techniques to gain access to sensitive cryptocurrency applications and infrastructure. The report outlines research on detected malicious code in an established Python package, aiocpa.

Threats to AI Supply Chains are Growing
The SSCS Report also documents a series of malicious software supply chain campaigns targeting development infrastructure and code used by developers of AI and large language model machine learning applications. RL researchers discovered a malicious technique dubbed “nullifAI” in which malicious code was placed in Pickle serialization files, while evading protections built into the Hugging Face open-source platform – a main resource for AI and ML developers.

To learn more about current and emerging trends in software supply chain risk, download the full report HERE and attend the upcoming RL webinar “The Year In Software Supply Chain Threats.”

Additional Reading

About ReversingLabs
ReversingLabs is the trusted name in file and software security. We provide the modern cybersecurity platform to verify and deliver safe binaries. Trusted by the Fortune 500 and leading cybersecurity vendors, RL Spectra Core powers the software supply chain and file security insights, tracking over 422 billion searchable files daily with the ability to deconstruct full software binaries in seconds to minutes. Only ReversingLabs provides that final exam to determine whether a single file or full software binary presents a risk to your organization and your customers.

Media Contact
Doug Fraim
Guyer Group
Doug@Guyergroup.com

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Red Cat Announces Appointment of Christian Koji Ericson as Chief Financial Officer

Next Post

Smart Bot for the Easy Life: ANTHBOT Genie Launches, Revolutionizing the AI-Powered Lawn Care

Related Posts

Stovex Global Deepens Strategic Cooperation, Investing $5 Million in Dedicated Funds to Support Casder Vanguard AI 5.0 Live Testing and System Upgrades

Global digital asset trading platform Stovex Global officially announced today that it is further deepening its partnership with long-term strategic partner Casder Institute of Wealth INC. According to the dedicated cooperation plan reached by both parties, Stovex Global will provide a total of $5 million in specialized funding to drive...

Read moreDetails

Digi Power X Announces ARMS 200 Commissioning and Timetable for Generating its First AI Revenues

This news release constitutes a "designated news release" for the purposes of the Company's amended and restated prospectus supplement dated November 18, 2025, to its short form base shelf prospectus dated May 15, 2025. MIAMI, FL / ACCESS Newswire / March 2, 2026 / Digi Power X Inc. ("Digi Power...

Read moreDetails

HighPoint Announces Acquisition of CloudView Partners to Accelerate Hybrid-Cloud and Platform Engineering Capabilities

Acquisition expands HighPoint's hybrid-cloud and platform engineering capabilities, accelerating cloud modernization and automation for enterprise customers. SPARTA, NJ / ACCESS Newswire / March 2, 2026 / HighPoint, a leader in modern networking and advanced cybersecurity solutions, today announced the acquisition of CloudView Partners, a specialized cloud consulting firm. The acquisition...

Read moreDetails

Matador Announces Intention to Spinout its Gold Treasury Platform, GODL Corp., into a Public Company

TORONTO, ON / ACCESS Newswire / March 2, 2026 / Matador Technologies Inc. ("Matador" or the "Company") (TSXV:MATA)(OTCQB:MATAF)(FSE:IU3), The Bitcoin Ecosystem Company™, intends to spin out (the "Spinout") its existing wholly-owned subsidiary, GODL Corp. ("GODL"), a company focused on a yield-generating gold treasury strategy and gold tokenization. The transaction is...

Read moreDetails

Performance Marketing Lead Livin Varghese Meleadan Recognized as 2025 ‘Elite Photographer’ by realme Global Community

Livin Varghese Meleadan, Performance Marketing Lead and 2025 Elite Photographer. - March 1, 2026 - Livin Varghese Meleadan, a veteran Performance Marketing Lead at Webandcrafts, has been officially recognized as one of the "Elite Photographers of the Year" for 2025 by the realme Global Community. This prestigious title, awarded to...

Read moreDetails

European-Grade Material Handling Tech ‘Leonidas’ Rumored to Disrupt Indian Crane Market

Leaked render of the anticipated Leonidas heavy-duty crane system, featuring hybrid German-Italian lifting technology. A massive shift is anticipated in the Indian overhead crane and material handling sector, driven by the rumored arrival of Leonidas Cranes. For years, the market has been dominated by legacy players offering slow, outdated technology...

Read moreDetails

Home Security Systems Market Trends, Growth Drivers, and Future Outlook

Market OverviewThe Home Security Systems Market encompasses a wide range of technologies and services designed to protect residences, family members, and personal property from unauthorized access, theft, vandalism, and other threats. These systems include devices such as surveillance cameras, motion sensors, alarms, smart locks, access control mechanisms, and advanced monitoring...

Read moreDetails

DRAM Market Growth, Trends, and Future Forecast (2026-2035)

Market OverviewThe DRAM Market, representing Dynamic Random-Access Memory, is an essential segment of the global semiconductor industry that forms the backbone of computing performance in devices ranging from servers and desktops to smartphones and IoT systems. DRAM functions as the primary working memory in computing architectures, enabling temporary storage that...

Read moreDetails

Artificial Intelligence in Law Market Growth | Trends, Opportunities & Future Outlook

Market OverviewThe Artificial Intelligence in Law Market refers to the adoption and integration of AI technologies in legal services to automate, augment, and streamline traditional legal processes. With rapid advancements in machine learning, natural language processing (NLP), predictive analytics, and cognitive computing, AI is reshaping how legal professionals conduct research,...

Read moreDetails

Master Data Management Market Set for Explosive Growth to US$ 90.26 Billion by 2034, Led by North America’s 42.5% Market Share | Key Players – IBM, Oracle, SAP

Master Data Management Market The Master Data Management Market reached US$ 22.03 billion in 2024 and is expected to reach US$ 90.26 billion by 2034, growing at a robust CAGR of 15% during the forecast period 2025-2034.Market growth is driven by the increasing demand for unified enterprise‐grade data platforms, rising...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    153 shares
    Share 61 Tweet 38
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    79 shares
    Share 32 Tweet 20
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    82 shares
    Share 33 Tweet 21
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    48 shares
    Share 19 Tweet 12
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    92 shares
    Share 37 Tweet 23
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Stovex Global Deepens Strategic Cooperation, Investing $5 Million in Dedicated Funds to Support Casder Vanguard AI 5.0 Live Testing and System Upgrades
  • Digi Power X Announces ARMS 200 Commissioning and Timetable for Generating its First AI Revenues
  • HighPoint Announces Acquisition of CloudView Partners to Accelerate Hybrid-Cloud and Platform Engineering Capabilities
  • vMOX Merges with Advantage Communications Group
  • Matador Announces Intention to Spinout its Gold Treasury Platform, GODL Corp., into a Public Company

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.