Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
Guess I need to update my slides. Seriously though, use a tool to produce SBOMs. Building them by hand causes FBOMs.
https://www.securityweek.com/us-and-allies-update-sbom-guidance/
#ntia #sbom
OWASP Dependency-Track v5.0.4 released
https://secburg.com/posts/dependency-track-v504-released/
#DependencyTrack #OWASP #SBOM #SupplyChainSecurity #DevSecOps
Allan Friedman
@allanfriedman@infosec.exchange
#SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, and occasionally getting paid for it. Poster of food pics.
infosec.exchange
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for how much of the software an hashtag#SBOM should actually cover.
https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
OWASP Dependency-Track v5.0.3 released
https://secburg.com/posts/dependency-track-v503-released/
#DependencyTrack #OWASP #SBOM #SupplyChainSecurity #DevSecOps
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
"Bring Your Own SBOM" sounds simple...
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)
Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.
Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.
If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!
🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.
#FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
A zero-day vulnerability is inevitable. The question is whether your organization is ready. Our latest on-demand webinar highlights the contrast between manual searches and an SBOM-powered response. Stop the chaos and start executing a plan.
➡️ Ready to see the difference? Watch the on-demand webinar: https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM #IncidentResponse #Cybersecurity
OWASP Foundation
@owasp@infosec.exchange
We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide
infosec.exchange
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database.
https://dependencytrack.org/ #OWASP #SBOM
🚨 The EU just made SBOMs mandatory for all software products!
Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline.
Don't wait—start building your SBOM strategy today.
🔗 https://anchore.com/sbom/eu-cra/
#SBOM #CRA
Tired of noisy vulnerability scanners? 🎯
Our own Chadd Owen explains how eliminating heuristic assumptions drastically improves scan accuracy: "We look at what's on disk, what's in the file system. The result is extremely accurate data."
Read more: https://anchore.com/blog/mattermost-container-vulnerability-scanning/
#SBOM #VulnerabilityManagement
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡
https://anchore.com/platform/
#SoftwareSupplyChain #SBOM #CyberSecurity
SBOMs are essential for "software archaeology." What did your build environment look like six months ago? Which past releases might be affected by a new vulnerability? This on-demand webinar explains why preserving lightweight SBOMs can answer these questions and provide critical historical context. #SBOM #Security #AppSec #DevSecOps
✅ See the power of historical SBOM data in action. Watch our expert webinar now: https://go.anchore.com/rapid-incident-response-with-sboms/
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
https://anchore.com/platform/
#SBOM #CRA #SoftwareSupplyChain #Compliance
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance