Most scanners scratch the surface.
Finite State goes deeperβdissecting firmware, source code & SBOMs to flag hidden secrets, weak configs & zero-days, enriched with 200+ threat intel feeds.
Cut through noisy scan results β
finitestate.io/resources/vu...
#IoTSecurity #VulnerabilityManagement
11.08.2025 16:48 β π 0 π 0 π¬ 0 π 0
Join Beth Linker for the panel β#AgenticAI: Redefining Decision-Making, Trust, & Liabilityβ at #Ai4.
Dive into how autonomous AI systems are transforming decision-making & what it means for accountability & trust in critical industries.
t.co/sNpbVDRqdr
#ResponsibleAI
08.08.2025 15:18 β π 1 π 0 π¬ 0 π 0
Get ready, #AppSecVillage, IoT Pentest Blitz is back!
Think you have what it takes to out-hack your peers? Come & test your skills:
πΉ August 8: 11am - 3pm
πΉ August 9: 1pm - 5pm
See you there!
#DEFCON #AppSecVillage #IoT #PenTesting #CyberSecurity
07.08.2025 16:11 β π 0 π 0 π¬ 0 π 0
π¨ Webinar Alert
Join leading voices in #AutomotiveCybersecurity, policy & law to unpack how the #ConnectedVehicleRule is reshaping the industry & what #OEMs & suppliers must do to stay compliant & competitive.
Register now & submit your questions π
info.finitestate.io/connected-ve...
#Automotive
06.08.2025 21:45 β π 0 π 0 π¬ 0 π 0
Think you can out-hack the hackers?
Join us in DEF CONβs #AppSecVillage for IoT Pen-test Blitz to prove it!
Game Times:
πΉ Friday, August 8: 11 AM β 3 PM
πΉ Saturday, August 9: 3 β 5 PM
Reserve your spot π info.finitestate.io/defcon-33
#DEFCON33 #IoTSecurity
04.08.2025 16:07 β π 0 π 1 π¬ 0 π 0
π² Finite State is bringing IoT Pentest Blitz to #DEFCON33 in the AppSec Village!
Join our high-stakes card game & test your skills building & breaking IoT exploit chains.
Plus meet the team to talk supply chain security! info.finitestate.io/defcon-33
#AppSecVillage #IoTSecurity
31.07.2025 21:53 β π 0 π 1 π¬ 0 π 0
Automatically resolve unreachable findings with a single click, update VEX status & free your team to focus on real threats with Auto-Resolve.
No more manual triage. Just clarity on what's reachable. Learn more π finitestate.io/blog/auto-re...
#IoTSecurity #VulnerabilityManagement
31.07.2025 17:45 β π 0 π 0 π¬ 0 π 0
OSS Trojan Horse: The Hidden Risks of Open Source in Embedded Systems
Open source powers IoT, but hidden components and transitive risks expose your products. Learn how to secure what you didnβt even know you shipped.
Open-source software powers innovation but itβs also a hidden risk.
Our latest blog explores how to truly secure your OSS supply chain. Take a look π finitestate.io/blog/secure-...
#CyberSecurity #OpenSourceSecurity #SBOM #IoTSecurity #ProductSecurity #SoftwareSupplyChain
30.07.2025 19:52 β π 0 π 0 π¬ 0 π 0
Simply dropping an #SBOM into an LLM & asking, βIs this secure?β wonβt cut it.
#AI models β just like human experts β need context to deliver meaningful risk assessments.
The richer the context you provide, the better the AIβs outputs.
#CyberSecurity #LLMs #ProductSecurity
30.07.2025 16:06 β π 0 π 1 π¬ 0 π 0
Securing IoT products demands deep #BinaryAnalysis. Why? Because todayβs IoT software is a tangled web of global supply chains, legacy code & opaque binaries.
In our Security Short, Edwin makes it clear: to protect IoT products, you have to go deeper than the surface.
#IoT
29.07.2025 23:51 β π 0 π 0 π¬ 0 π 0
Something big is coming to #ProductSecurity.
Matt & Tim will be on the ground at #BlackHatUSA sharing the next evolution of connected device security. Schedule a time to meet with us & get the inside story before anyone else. π
info.finitestate.io/finite-state...
#IoTSecurity #Cybersecurity
29.07.2025 18:00 β π 0 π 0 π¬ 0 π 0
Building a Compliance-Ready DevSecOps Pipeline for IoT Systems
Build a compliance-ready DevSecOps pipeline for IoT & embedded systems with automated security, SBOMs, and CRA/RED/NIST-aligned tools.
DevSecOps β one-size-fits-all.
IoT & connected products demand unique DevSecOps workflows for compliance, binary analysis, & SBOMs.
Learn how to adapt DevSecOps for IoT π
finitestate.io/blog/devseco...
#CyberSecurity #DevSecOps #IoTSecurity #ProductSecurity #SoftwareSupplyChain
23.07.2025 21:00 β π 1 π 0 π¬ 0 π 0
Your code. Vendor code. Their vendorβs code.
Finite State inspects everything inside your binaries. No blind spots.
#SBOM #SupplyChainSecurity #ProductSecurity
23.07.2025 16:11 β π 0 π 0 π¬ 0 π 0
βIoT PenTest Blitzβ is coming to #DEFCON32!
Join us in the #AppSecVillage to:
π Analyze real firmware
π οΈ Build your attack chain
π Rack up points like a pro
Swing by & show us what youβve got.
#IoTSecurity #PenTestBlitz #FirmwareSecurity #Cybersecurity
22.07.2025 19:05 β π 1 π 1 π¬ 0 π 0
#LLMs aren't magic. True #ProductSecurity still relies on specialized tools but the real power comes when LLMs & trad tools work together.
Feed LLMs the data, give it context & guide it with good questions, & it can deliver incredible insights that transform security workflows.
21.07.2025 23:10 β π 1 π 0 π¬ 0 π 0
Precompiled binaries are a black box risk. Without source code, youβre left with vendor docs & guesswork.
In our "Security Short", Edwin stresses that the only way to truly understand whatβs inside precompiled binaries is through #BinaryAnalysis.
Visibility matters.
18.07.2025 22:15 β π 0 π 0 π¬ 0 π 0
π¨ #EURED cybersecurity requirements go live Aug 1st. Don't let it delay your launch.
Finite State delivers
β‘οΈ 10-day turnaround
π Binary-native analysis
β
CRA-ready #SBOM
π Docs your NB will accept
Fast-track your compliance today π
finitestate.io/request-a-co...
#EN18031
18.07.2025 18:44 β π 0 π 0 π¬ 0 π 0
Many manufacturers think theyβre compliant if they generate an SBOM. But thatβs just step one.
Our latest blog explains whatβs beyond the #SBOM for true product security & compliance. Take a look π finitestate.io/blog/beyond-...
#ProductSecurity #IoTSecurity #SoftwareSupplyChain
18.07.2025 15:10 β π 0 π 0 π¬ 0 π 0
Think Your Source Code Is Secure? Check Your Firmware First
Attackers target what runs, not whatβs written. Learn why binary-level firmware analysis is essential for real IoT security and regulatory compliance.
Source code scans β full security.
Firmware hides risks SCA tools canβt see: proprietary binaries, vendor code, secrets, misconfigs.
Discover why firmware analysis is essential for secure connected products π finitestate.io/blog/firmwar...
#FirmwareSecurity #IoTSecurity
17.07.2025 16:17 β π 0 π 0 π¬ 0 π 0
Opaque Vendors: How to Secure Components Without Source Code Access
Learn how to secure IoT components from opaque vendors without source code access, using binary analysis and penetration testing for compliance.
Opaque vendors are the silent threat lurking in your supply chain.
Edwin's been exploring how to break through the opacity in his latest blog.
If opaque vendors keep you up at night, this article is for you.
π finitestate.io/blog/securin...
#IoTSecurity #SupplyChainSecurity
16.07.2025 17:37 β π 0 π 0 π¬ 0 π 0
AI doesnβt just detect vulnerabilities β it helps security teams triage and fix them.
In our latest Security Short, Matt Wyckhouse shares how LLMs cut human effort by 90% in software supply chain security.
#CyberSecurity #AI
16.07.2025 16:36 β π 0 π 1 π¬ 0 π 0
One of the most dangerous misconceptions in product security? Thinking upstream vulnerabilities βarenβt your problem.β
Customers donβt care whose fault it is when products are vulnerable & itβs a dangerous bet to assume upstream flaws wonβt impact you.
#ProductSecurity
15.07.2025 21:20 β π 0 π 0 π¬ 0 π 0
β³24 Hours to Go
Join us live tomorrow for a webinar on building a SPDL that aligns with multiple regulations at once.
Canβt make it? Register anyway for the on-demand recording πhttps://info.finitestate.io/securing-the-product-lifecycle
#IoTCompliance #CyberRegulations
15.07.2025 16:30 β π 0 π 0 π¬ 0 π 0
Finite Stateβs Reachability Analysis shows which vulns in your firmware are truly exploitable so you can fix what matters.
β
Slash time spent triaging false positives
β
Scale security even for proprietary, encrypted or RTOS-based firmware
Learn more π finitestate.io/request-demo
14.07.2025 16:36 β π 0 π 0 π¬ 0 π 0
Hidden threats often lurk in unseen places.
Full-scope #PenTesting uncovers missing controls, insecure ops, or debug featuresβwhether 1st- or 3rd-party.
At Finite State, we believe security demands a holistic view. Are you looking deep enough?
#CyberSecurity #ProductSecurity
14.07.2025 16:17 β π 1 π 0 π¬ 0 π 0
Building a Modern IoT Security Stack: Securing From Source to Firmware
Donβt just scan your sourceβsecure your full IoT stack. Learn how to build a modern, layered security strategy from code to firmware and beyond.
We explored what a modern #IoTsecurity stack looks like & how to
β
Move beyond patchwork tools to integrated security workflows
β
Gain deep visibility into firmware, binaries & #SoftwareSupplyChains
β
Align security investment with evolving global regs
π finitestate.io/blog/buildin...
11.07.2025 22:45 β π 0 π 0 π¬ 0 π 0
60% of IoT attacks come from unpatched flaws but itβs likely closer to 90%.
#IoTSecurity isnβt a one-time fix. Updates & secure-by-default designs are essential & now required by new regulations.
Tackle this challenge head-on with Finite State π finitestate.io/request-demo
11.07.2025 15:18 β π 0 π 0 π¬ 0 π 0
Request a Compliance Consultation
Take advantage of industry-leading services designed to help organizations navigate evolving regulations, enhance product security, and mitigate cyber threats.
π¨ EU RED cyber rules hit Aug 1, 2025.
Finite Stateβs fast-track services:
β‘ 10-day turnaround
π SBOMs + CRA-ready evidence
π οΈ Root-cause remediation help
Donβt risk delays. Book a compliance consult β finitestate.io/request-a-co...
#CyberSecurity #EURED #IoTSecurity
10.07.2025 21:41 β π 1 π 0 π¬ 0 π 0
Don't miss our expert-led session on building compliance into your product development from the ground up for
- A repeatable, regulation-aligned #SPDL framework
- Insights from seasoned practitioners
- Tools to simplify SBOM & remediation workflows
Register now π hubs.ly/Q03tCPBl0
10.07.2025 16:41 β π 0 π 0 π¬ 0 π 0
#AI went from basic tasks to wielding tools in just a year.
The result?
An unprecedented opportunity to automate time-consuming work in cybersecurity & #SoftwareSupplyChainSecurity, freeing humans to focus on the truly critical problems.
#CyberSecurity #ProductSecurity #LLMs t.co/LKAqvsZwcQ
09.07.2025 22:39 β π 1 π 0 π¬ 0 π 0
NPR Cybersecurity Correspondent (currently) reporting on the transformation of the federal government including by DOGE.
Send me a tip: Text JennaMcLaughlin.54 on Signal from personal (nonwork) devices.
Law professor. Editor @justsecurity.org. Working on foreign relations, cybersecurity, and national security.
Global CTO, CPO, CMO - strategist, technologist, innovator, communicator, author, cyclist, cook, skier, traveler ...
Was @andimann on the bird site.
Personal account. My work is on LinkedIn - https://linkedin.com/in/andimann
IDC Analyst focused on software development, such as DevOps, DevSecOps, and AI.
Consultant, developer, evangelist, gardener. Co-founder of SBOMEurope.eu. Team lead of OWASP Transparency Exchange API (Projekt Koala). Member of CycloneDX industry working group, OWASP SBOM Forum. IETF and much more.
SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account. Food, drink, dogs, SBOM
Hacker of stuff, builder of things.
ICS/OT posts from a GICSP. ISA member working on ISA 62443 Certs. Canadian.
My posts are my own and are not a reflection of my place of work or employer.
X: @Secure_ICS_OT
Mastodon: https://infosec.exchange/@Secure_ICS_OT
#ICS #OT #GICSP #IEC62443
Husband, Dad & Sikh. Technologist, Cyber Security. Chief Technology Officer @penninecarenhs.bsky.social
Always Learning. Views my own.
Blog: https://medium.com/@jaswant-sagoo
Senior reporter at @CybersecurityDive.bsky.social covering all things digital security. I also co-host Hoth Takes. | Send me tips: bit.ly/contactejg
Cybersecurity Specialist, Public Speaker, Ex-Hacker.
https://marcushutchins.com
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
She/Her. Cybersecurity Educator & Engineer. Writer. Keynote Speaker. LinkedIn Learning Author (150K+ learners). Neurospicy (ADHD). Sharing insights to inspire growth and connection. Black and proud.
Stephandsec.com
Principal Product Manager @Microsoft #security focused on #Entra #Identity and Identity Governance
- π & #Cybersecurity
- Star Wars π nerd
- Disney Adult π°
My posts are not official support of my employer
My info and content is at https://jeftek.com
CISO Inversion6.com, CTO Octopi Managed Services, CyberEd Board Member, Gartner Peer, Defcon SOC Goon, Amateur Dentist & Infosec Fashionista - opinions expressed are my own.
Grump, keynote, breaker of things, dad, podcaster, creator of (-:|3, OG, raconteur, gentleman spy, investor, whisky distillery owner
Former NSA hacker; Cyber Expert; Current CISO, TV Cyber Expert & Keynote Speaker
Twitch.tv/cyber_insecurity
topmate.io/neal_bridges
https://linktr.ee/cyber_insecurity
#cybersecurity #redteam #hacking #blueteam #securityoperations #ciso
CEO, CISO, Trainer, Hacker, and Speaker.
AI + hacking + sec leadership.
ex:BuddoBot-Ubisoft-Bugcrowd-Fortify-HP-Redspin-Citrix.
Deputy CISO @ Stripe. I like art. cDc β€οΈοΏΌπ«΅
I accidentally became the CISO. I didn't want this job, but the job chose me. I'm scared, and I want to go home.
https://www.accidentalciso.net