3 Steps to Reduce IOT Security Update Frustration, While Increasing Deployment Velocity

In this short webinar, IOT device engineers and developers will see how they can immunize their devices against the root-cause of more than 50% of post-deployment updates. Using the customer example of a feature-rich, yocto-based server management solution from Vertiv™, attendees will see how to get these benefits in 3-steps, without any software changes. Attendees will leave with a 30-day trial license to use RunSafe’s tools in their own environments and demo in the RunSafe self-service portal.

Vertiv™ Avocent® Core Insight is built on top of the openBMC yocto project, designed to securely add powerful, lights-out management features to servers and other infrastructure. Avocent® Core Insight chief architect, Joerg Weedermann will walk through the product architecture and software stack. Joerg will then show how that entire stack became protected against a class of security exploitation risk by the simple addition of RunSafe’s Alkemist.

Because the images running on each yocto-built embedded system are identical, a single vulnerability can expose thousands of systems and attackers can easily scale their attacks. Alkemist can mitigate this concern by using a patented technique called Loadtime Function Randomization (LFR). Alkemist performs randomization at runtime instead of buildtime, preserving “Binary Reproducibility,” one of the yocto project’s core features, while dramatically increasing security against memory-based attacks.

RunSafe’s recent blog on security in yocto can be found here: http://run-safe-security.test/blog/5-minute-memory-threat-immunization-for-yocto-build-environments/

CRA Readiness: Build an SBOM You Can Act On

CRA Readiness: Build an SBOM You Can Act On

Under the Cyber Resilience Act, having an SBOM is only the beginning. Manufacturers need to know exactly what software is in each product release and be able to quickly determine which products are affected when a new vulnerability emerges. For embedded software, that...

read more
Operational Software Assurance

Operational Software Assurance

Security Cannot Stop When Software Ships Critical software can remain deployed for years or even decades. During that time, new vulnerabilities emerge, threats evolve, and AI is accelerating both vulnerability discovery and exploit development. But patching, testing,...

read more
6 Steps to CRA Readiness

6 Steps to CRA Readiness

The EU Cyber Resilience Act (CRA) is reshaping how connected and embedded products must be secured, maintained, and supported. Is your organization ready? Watch this short video to learn six practical steps that can help product manufacturers prepare: Test your...

read more