home.social

#blacklotus — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blacklotus, aggregated by home.social.

  1. Tomorrow, I start as Director of Product Marketing at Eclypsium, Inc. I am excited to work alongside an extremely smart and thoughtful team.

    Increasingly, attackers are targeting firmware to evade OS-level protections and maintain persistence. It's an "out of sight, out of mind" attack vector, but extremely critical. Watch this space because it could get real messy, real fast. Think of what an APT can do with with root access to enterprise network appliances, or what malware syndicates could do with an easy-to-use boot kit.

    What controls do you currently have in place to assess and mitigate the risk of firmware attacks, especially those delivered through your supply chain? Eclypsium makes this easy for IT and security teams. Delivered as SaaS, the platform helps you to establish trust in your software, firmware, and hardware supply chain. Eclypsium has the largest library of firmware profiles and can verify the observed firmware matches the firmware profile that should be on the device, as well as report on firmware configurations.

    This blog post from @paulasadoorian chronicles recent real-world firmware attacks and explains why attackers focus on firmware: eclypsium.com/blog/endpoint-fi

    #supplychainsecurity #firmwaresecurity #blacklotus #malware