Key Takeaways The 2026 LaPorte Report defines Embedded Runtime Security (ERS) as a distinct discipline for protecting deployed embedded software at runtime. ERS makes exploit attempts fail at execution, rather than relying solely on vulnerability discovery and...
The European Union’s Cyber Resilience Act (CRA) began requiring manufacturers of connected products to report actively exploited vulnerabilities on a tight schedule in September 2026. Medical device makers have lived with similar post-market expectations from...
“Trying to chase one bug at a time” isn’t a cybersecurity strategy, as anyone who has tried to keep up with patch cycles can tell you. Recently, Joe Saunders and Doug Britton joined Paul Ducklin on Exploited: The Cyber Truth for a conversation on what Claude Mythos...
AI is changing the speed and scale of vulnerability discovery. With Anthropic’s Claude Mythos showing how quickly AI can uncover vulnerabilities and zero days, product security teams are facing a new reality: the time between finding a vulnerability and turning it...
Open source software is deeply woven into modern embedded development. From compilers and build systems to networking stacks and device libraries, it enables teams to move faster and innovate more efficiently. But speed introduces tradeoffs. The same open source...
If you’ve ever run an SBOM tool on a C/C++ codebase and gotten results that felt wrong, you’re not imagining it. Teams evaluating tools like Black Duck, Syft, Trivy, and FOSSA on embedded projects routinely find that outputs are incomplete, inconsistent,...