ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

ReversingLabs Delivers Software Supply Chain Security with Next Generation Secrets Detection

CAMBRIDGE, Mass., March 14, 2023 (GLOBE NEWSWIRE) -- ReversingLabs, the leader in software supply chain security, today unveiled new secrets detection features within its Software Supply Chain Security (SSCS) platform. ReversingLabs is the first solution of its kind to improve secrets detection coverage by providing teams with the context and transparency needed to prioritize developer’s remediation efforts, reduce manual triage fatigue and improve security controls for preventing leakage.

“These new capabilities underscore ReversingLabs commitment to address growing software supply chain complexity and increasingly sophisticated threats. Our comprehensive solution enables teams to securely control the release of software via the detection of software supply chain threats, malware, malicious behaviors, tampering and secrets exposures,” said Mario Vuksan, CEO and Co-founder of ReversingLabs. “Supply chain risks demand evolved application security capabilities that confront the full spectrum of challenges introduced by open source- and third party components, commercial software, and binary misconfigurations. Our SSCS platform goes beyond existing solutions that only provide open-source licensing compliance and vulnerability detection or analyze source code quality for vulnerabilities to fill in the gaps they leave behind.”

The Risk of Secrets
Complex software today includes components that rely on digital authentication credentials commonly referred to as secrets, which include tools such as login credentials, API tokens, and encryption keys. While critical for the software to function, managing secrets across every component of code, Software Development Life Cycle (SDLC), or Continuous Integration and Continuous Delivery (CI/CD) stages is a challenge that can result in secrets being left exposed. Potential exposure can stem from the use of plain text, weak cryptography, build scripts including directories with secrets configuration files, CI/CD or packaging automation mistakes and inclusion by compromised developer accounts or malicious insiders.

“Exposed secrets included in software release packages leave businesses vulnerable to a software supply chain breach. Look no further than the CircleCI and CodeCov incidents,” added Vuksan. “With these new secrets capabilities, we are giving software publishers something other available offerings don’t. That's better visibility into their supply chain risks with specific capabilities for secrets detection and management.”

Detect and Remediate Secrets Exposure
Current secrets detection tools fall short because they are unable to remove false positives, itemize all secrets in builds or provide actionable results. As a result, many developers bypass discovered features rather than triage and fix them. These offerings also cannot determine which secrets have already been exposed, when to underscore the level of risk or to automatically suppress third party secrets and other false positive results that are not actionable. ReversingLabs new capabilities give developers the visibility and confidence they need to prioritize detected secrets and issue actionable warnings to developers that help provide immediate resolution.

ReversingLabs Software Supply Chain Security solution can identify more than 250 secret-types out of the box, including private keys, version control, certs, tokens, and more. Once identified, its transparent detection capabilities allow teams to view discovered secrets for immediate true positive confirmation, determine its precise location, which services are affected, and if those secrets are exposed or leaked elsewhere. The solution prioritizes all remediation efforts by suppressing third party, open-source, testing keys, and other commonly shared secrets while reducing the fatigue that results from manual triage.

ReversingLabs secrets capabilities include superior detection coverage and contextual prioritization, “just in time” secrets management, canary token management and custom detection policies. Additionally, ReversingLabs provides publicly available guidance for sensitive information policies, including documentation of public exposures and secrets breakdown by service for web service access credentials, web service access tokens, web service API keys and webhook service access keys.

For more insights about today’s news visit New Secrets Management Capabilities for Mitigating Software Supply Chain Risk. To learn more about the ReversingLabs Software Supply Chain Security platform and its secrets detection capabilities, visit Detect, Prioritize and Manage Exposed Secrets at ReversingLabs.

About ReversingLabs
ReversingLabs protects the modern enterprise from sophisticated software supply chain security attacks, malware, ransomware, and other threats. 

The ReversingLabs Software Supply Chain Security Platform analyzes any file, binary, or software package, including those that evade traditional security solutions. The hybrid-cloud, privacy centric platform democratizes insights across the enterprise, enabling development teams to securely release applications; third-party risk teams to safely procure software; and security operations teams to monitor, isolate and quickly respond to threats. 

ReversingLabs data is used by more than 65 of the world's most advanced security vendors and their tens of thousands of security professionals. ReversingLabs enterprise customers span all industries, leveraging integrations with popular DevSecOps and SOC platforms that enable teams to access the analysis they need to make quick security verdicts, eliminate threats, and release software with confidence.

Media Contacts

ReversingLabs
Guyer Group – Doug Fraim
doug@guyergroup.com


Primary Logo

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.