I chatted to Olimpiu Pop on the @infoq.com Podcast about this year's QCon London security track, and some plans for next year's.
We talk about hardware (#CHERI), #CRA and #SBOM, #postquantum_cryptography and of course #LLM and #AI

I chatted to Olimpiu Pop on the @infoq.com Podcast about this year's QCon London security track, and some plans for next year's.
We talk about hardware (#CHERI), #CRA and #SBOM, #postquantum_cryptography and of course #LLM and #AI
Signed your SBOM? That is the middle, not the end. How I store, verify and rescan it with Harbor, Dependency-Track, GUAC, Ratify and Kyverno, with CRA in mind. www.msbiro.net/posts/sbom-s... #SBOM #SupplyChain
Neue Sicherheitsmeldung: Welche unserer Maschinen ist betroffen? Ein Rundgang durch IPC, PLC und Sensoren zeigt, wie wir die Meldung konkreten Installationen zuordnen: <https://lunaris.digital/blog/articles/2026-10-06-cra-product-identifiers> #SBOM #IndustrialSecurity
Security Tip: You can't secure what you don't know you have. 🛡️ Generate a Software Bill of Materials (SBOM) for every application. It’s the "ingredients list" for your code, making it easier to track and respond to new CVEs.
Stay informed: https://cvedatabase.com
#SBOM #InfoSec
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
Syft users! 📣 We want to hear from YOU! Take our quick 5-question survey to help shape the future of Syft. Your feedback is invaluable! 👉 https://forms.gle/VJZ7idKZgchminYD7
#Syft #SBOM #OpenSource
With the EU's Cyber Resilience Act, #SoftwareTransparency isn't optional. It's a global mandate.
We're thrilled to announce #SBOM pioneer @allanfriedman.bsky.social is joining the Anchore board to help nav... https://anchore.com/blog/anchore-welcomes-sbom-pioneer-dr-allan-friedman-as-board-advisor/
Release-SBOM und installierter Maschinenzustand gehören in unterschiedliche Systeme. lunaris.digital/blog/article... #sbom #dependencytrack
Save the date: Sep 29 | 15:00 CEST / 6:00 PST
Register now: us02web.zoom.us/webi...
#CyberResilienceAct #CRA #SecureBoot #SBOM
Open source is exempt from the EU Cyber Resilience Act.
True or false? We put it and five other CRA claims to Cresco's tech lawyers. Answers in the full recording 👇
Security Tip: Implement a Software Bill of Materials (SBOM) strategy. 🛡️ Knowing exactly what's in your software stack is the first step to securing it. Use tools to automate SBOM generation and track component risks. Learn more: https://cvedatabase.com #SBOM #InfoSec #AppSec
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Security Tip: Transparency is key to supply chain security. 🛡️ Generate a Software Bill of Materials (SBOM) for your projects. Knowing exactly what’s in your software stack helps you respond faster to new CVEs. Learn more: https://cvedatabase.com #CyberSecurity #SBOM #InfoSec
Zero-day incidents like Log4Shell highlight the need for a better way to respond.
This on-demand webinar explains how an SBOM-powered approach helps go from discovering a new vuln to creating a remediation list in minutes. https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM
「その医療AIは、何でできているのか。」
精度や承認の前に、構成要素と依存関係を把握できているか。
日本のSBOM、英国・米国の基盤モデルをめぐる文書から考えました。
Actively exploited dependencies now get a stop sign in your CI.
The CRA Kit GitHub Action just landed on the Marketplace.
https://github.com/marketplace/actions/cra-kit-scan
Not legal advice.
#DevSecOps #CyberResilienceAct #SBOM
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
Security Tip: Visibility is key to supply chain security. 🛡️ Use a Software Bill of Materials (SBOM) to inventory all third-party components. When a new CVE drops, you'll know exactly if you're affected. Stay informed at https://cvedatabase.com #CyberSecurity #SBOM #InfoSec
Riesgos en la Cadena de Suministro: Robo de secreto en repositorios de código