IT company ReversingLabs has introduced the product Spectra Assure in the USA, a leading solution for software supply chain security. It is the first product of its kind in the security industry that performs complex binary analysis using artificial intelligence. It protects software manufacturers from supply chain attacks while enabling customers to assess the risks they may be exposed to when purchasing software.
– “Spectra Assure answers a very important question for those who deliver software or release it into production: How do you know if your software has been compromised or altered without authorization? How do you know if your software is actually malware?” said Mario Vuksan, CEO and co-founder of ReversingLabs.
– “Our product fills the gap left by traditional application security verification tools. It quickly identifies malware and malicious code, both in proprietary, commercial, and open-source software,” he added.
According to a recent Gartner report, attacks on the software supply chain are on the rise, and ‘the lack of transparency and trust in the global software supply chain is a pressing issue for organizations of all types.’
According to research by ReversingLabs, in the last three years, threats to the software supply chain in open source alone have increased by as much as 1300 percent. In 2023, the number of malicious packages in PyPI, the repository for the Python programming language, increased by 400 percent.
Traditional application security testing solutions such as SAST, SCA, or DAST are not designed to detect malware and malicious components and cannot analyze the entire software package, warn ReversingLabs. Companies and organizations that rely solely on these tools risk leaving a blind spot in their software supply chain, which can have serious consequences for both manufacturers and business users of software.
