Compliance guidance is everywhere. Examples of how embedded teams are putting it into practice are harder to find.
On September 9, join RunSafe, Lynx, Rockwell, and the medical device community to compare what is actually working.
Register: runsafe.ly/4yUa0j3
With another incredible DEF CON behind us, we want to say THANK YOU to our sponsors! As a tiny non-profit, our sponsors make our work possible. MHV is incredibly lucky to have you as our partners. 🙏💜
Beyond your generous financial support, your participation legitimizes our work 🎤, strengthens our community 🤝, enables transition of our value and results into the real-world maritime and defense environments 🔁, and allows us to create more exceptional hands-on experiences for maritime hacking and cybersecurity education than would ever be possible otherwise 🎓🚀
THANK YOU for investing in MHV and the maritime cybersecurity community! We are so excited for a long-term partnership with each of you.
@anduriltech, @nwc__foundation, @RunSafeSecurity, @NMFTA, @hirschbachml / @hirschbachsol, Liberas, RUDRA, Maritime Cyber Security Institute, @defcon#DEFCON#DEFCON34#DC34#MHV#MaritimeVillage#Gratitude
RunSafe CSO Doug Britton is presenting at the Emerging Technologies for Defense conference in Washington, D.C.
Doug will share how runtime protection stops exploitation to help defense systems stay resilient against AI-enabled threats.
Learn more: runsafe.ly/4zCpokp
What can industrial teams learn from medical device security?
Medical device teams have spent years building postmarket cybersecurity processes. Now, industrial manufacturers face similar pressure under the CRA.
Join us on September 9 at 10:00 AM ET.
runsafe.ly/4c3ofbF
What do the supplier fields in a #CycloneDX#SBOM represent?
▸ metadata.supplier: the issuing org
▸ metadata.component.supplier: the vendor of the product it describes
▸ runsafe.ly/45ouH97.component…: the tool that generated it
Keep this graphic handy!
RunSafe’s C/C++ SBOM checklist helps teams evaluate whether their SBOM is a basic inventory or a release-ready, build-attested record.
Evaluate yours: runsafe.ly/4pGe4iB
How are embedded teams using AI?
Testing and validation lead at 27.5%.
Code generation follows at 19%, with deployment automation close behind at 18.5%.
See the full 2025 AI in Embedded Systems Report: runsafe.ly/4fAH5aG
The #CRA deadline is approaching, and embedded teams are searching for #SBOM tools.
Can the tool see static libraries, vendored code, conditional builds, and the exact components in a released artifact?
Learn more: runsafe.ly/4yBa72G
CRA readiness has to work beyond the checklist.
Leaders from Schneider Electric, May Mobility, GE Healthcare, and RunSafe share practical lessons on SBOMs, supplier risk, secure updates, and long-term product support.
Watch now:
runsafe.ly/3TRE1Qk
OT incident response cannot live in a binder.
Derrick Bethea, Joe Saunders, and Paul Ducklin discuss what energy teams need to work through before a crisis, from vendor access and recovery decisions to clear ownership and faster AI-driven attacks.
runsafe.ly/44Q0boz
The #CRA reporting deadline lands two days after this webinar.
On September 9, leaders from RunSafe Security, Lynx, Rockwell, and the Zimmer Biomet will compare how their industries are responding.
Register here: runsafe.ly/4bUAIOA
Software supply chain risk is growing.
Open source dependencies are expanding the attack surface. AI is accelerating attacks. Vulnerability backlogs keep getting longer.
Learn how to reduce risk across the software lifecycle:
runsafe.ly/4gYNord
The United States cannot patch its way out of the AI vulnerability wavem, Shane Fry, CTO of RunSafe, writes in @securityblvd.
Patching cannot be the only line of defense. Runtime protections reduce exploitability.
Read more: runsafe.ly/4wc3m5e
When software controls vehicles and critical systems, cybersecurity becomes a safety issue.
Learn how organizations can protect autonomous systems, build software resilience, and earn public trust with Hemanth Tadepalli from May Mobility.
🎧 Listen: runsafe.ly/4z21Uoy
Security is often seen as slowing the business down because it enters the conversation too late and is not tied to clear goals.
For more productive conversations, reframe the value:
“If I secure this system, I help protect uptime.”
Watch the webinar: runsafe.ly/4bdxW6J
Join RunSafe’s Katie Fejer at the Aerospace Village at @defcon on August 7th for “Cleared for Takeoff: Cybersecurity Certified,” a look at what it takes to qualify cybersecurity tools for safety-critical systems.
runsafe.ly/3RCTqmY
Some security tools find more CVEs, create more tickets, and tell you to wait for a patch.
That is visibility.
Mitigation should reduce the ability to exploit the software itself.
This is why runtime protection matters: runsafe.ly/4bZdeHY
CISA's 2026 #SBOM Minimum Elements reflects that.
In this article, Shane Fry summarizes the changes and then maps the exact property paths in CycloneDX 1.6, SPDX 2.3, and SPDX 3.0 for implementers.
Take a look and see how the changes may affect you!
runsafe.ly/3RHZmuQ