720-891-1663

The Strategy is “Wait to get Hacked and then Panic”

As millions upon millions of IoT and Industrial IoT devices get deployed every month, we seem to have forgotten what we learned the hard way about our computers: if we don’t patch them, the hackers will invade. #1: A set of bugs called Urgent/11 affected a network module that has been around since the 90s […]

Continue reading → [DISPLAY_ACURAX_ICONS]

SBoM is NOT a Four Letter Word

I have been ranting about Software Bills of Material or SBoM for a while. This week I have two examples of why this is important – even critical. The first story is about a TCP/IP network stack and the vulnerability is called Amnesia:33. It impacts four open source libraries – uIP, FNET, picoTCP and Nut/Net. […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Default Passwords on Gov Websites – What Could Go Wrong?

You would think that in 2020 we wouldn’t have to tell people not to use default passwords. You would certainly think that we wouldn’t have to tell government IT folks not to do that. But if you thought that, apparently, you would have thought wrong. We are still telling end users to change the password […]

Continue reading → [DISPLAY_ACURAX_ICONS]