#sbom
56 posts · Last used 11d
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
I always get questions like "What can we expect from an EMBA #firmware scan" or "How does a EMBA report look like" or "Where is the #SBOM in EMBA" or "Where can we try it" ... Now you can try it by yourself and click on everything you like in our HTML demo report here: https://securefirmware.de/emba/
Microsoft will require a Windows driver SBOM and VEX statement for signing from March 2027, aligning WHCP with the EU CRA.
#Windows #SBOM #VEX #WHCP #CyberResilienceAct #DriverSecurity #SupplyChainSecurity
https://securityonline.info/windows-driver-sbom-vex-2027/?utm_source=mastodon&utm_medium=jetpack_social
Boosted by @welcome@friends.deko.cloud
#introduction
I work on software supply-chain evidence, and I have one argument I would like to be wrong about.
The CRA's two dates get planned in the wrong order. Reporting an exploited vulnerability within 24 hours starts 11 September 2026. The machine-readable SBOM is only required from 11 December 2027 — fifteen months after the clock starts.
On a 24-hour clock the first question is not how to word the notification. It is which of your services ship the component.
#CRA #SBOM
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
Guess I need to update my slides. Seriously though, use a tool to produce SBOMs. Building them by hand causes FBOMs.
https://www.securityweek.com/us-and-allies-update-sbom-guidance/
#ntia #sbom
OWASP Dependency-Track v5.0.4 released
https://secburg.com/posts/dependency-track-v504-released/
#DependencyTrack #OWASP #SBOM #SupplyChainSecurity #DevSecOps
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for how much of the software an hashtag#SBOM should actually cover.
https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
OWASP Dependency-Track v5.0.3 released
https://secburg.com/posts/dependency-track-v503-released/
#DependencyTrack #OWASP #SBOM #SupplyChainSecurity #DevSecOps
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
"Bring Your Own SBOM" sounds simple...
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)
Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.
Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.
If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!
🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.
#FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
A zero-day vulnerability is inevitable. The question is whether your organization is ready. Our latest on-demand webinar highlights the contrast between manual searches and an SBOM-powered response. Stop the chaos and start executing a plan.
➡️ Ready to see the difference? Watch the on-demand webinar: https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM #IncidentResponse #Cybersecurity
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database.
https://dependencytrack.org/ #OWASP #SBOM
🚨 The EU just made SBOMs mandatory for all software products!
Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline.
Don't wait—start building your SBOM strategy today.
🔗 https://anchore.com/sbom/eu-cra/
#SBOM #CRA




