#sbom

56 posts · Last used 12d

#introduction I work on software supply-chain evidence, and I have one argument I would like to be wrong about. The CRA's two dates get planned in the wrong order. Reporting an exploited vulnerability within 24 hours starts 11 September 2026. The machine-readable SBOM is only required from 11 December 2027 — fifteen months after the clock starts. On a 24-hour clock the first question is not how to word the notification. It is which of your services ship the component. #CRA #SBOM
0
0
1
0
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA) Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference. Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry. If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss! 🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community. #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
0
0
0
0
A zero-day vulnerability is inevitable. The question is whether your organization is ready. Our latest on-demand webinar highlights the contrast between manual searches and an SBOM-powered response. Stop the chaos and start executing a plan. ➡️ Ready to see the difference? Watch the on-demand webinar: https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM #IncidentResponse #Cybersecurity
0
0
0
0
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database. https://dependencytrack.org/ #OWASP #SBOM
6
0
2
0
🚨 The EU just made SBOMs mandatory for all software products! Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline. Don't wait—start building your SBOM strategy today. 🔗 https://anchore.com/sbom/eu-cra/ #SBOM #CRA
0
0
0
0