---
title: Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness
description: Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness
image: https://blog.adolus.com/hubfs/Imported_Blog_Media/windows10-CVE-820x1024-1.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[Code Signing](https://blog.adolus.com/tag/code-signing) [Software Validation](https://blog.adolus.com/tag/sw-validation) [Vulnerability Tracking](https://blog.adolus.com/tag/vulnerability-tracking) [Supply Chain Management](https://blog.adolus.com/tag/supply-chain)

# Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January, 17 2020

[Back](https://blog.adolus.com)

Windows 10 Certificate Validation Bug Exposes a Fundamental Weakness

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> [mailto:?subject=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness%20&body=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/windows10-CVE-820x1024-1.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness%20&body=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/windows10-CVE-820x1024-1.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> <http://www.facebook.com/share.php?u=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness> [mailto:?subject=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness%20&body=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/windows10-CVE-820x1024-1.png](mailto:?subject=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness%20&body=Check%20out%20https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness&media=https://f.hubspotusercontent40.net/hubfs/6687498/Imported_Blog_Media/windows10-CVE-820x1024-1.png)

The announcement Tuesday from the [NSA about the new cryptographic vulnerability in the Microsoft Windows](https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF) operating system sent ripples of shock through our entire community. In case you missed it, this devastating vulnerability ([CVE-2020-0601](https://nvd.nist.gov/vuln/detail/CVE-2020-0601)) allows attackers to bypass trust mechanisms to falsify certificates, making them appear to come from a trusted source. It also allows attackers to [falsely authenticate themselves](https://krebsonsecurity.com/2020/01/patch-tuesday-january-2020-edition/) on [vulnerable HTTPS connections and remotely execute code](https://arstechnica.com/information-technology/2020/01/patch-windows-10-and-server-now-because-certificate-validation-is-broken/). Let’s hope everyone is on top of their Microsoft security patches or there could be some serious damage done.

This week’s warning isn’t the usual story of forged certificates or somebody using stolen keys. We all remember Stuxnet ([read more on that here](https://www.tofinosecurity.com/blog/summing-stuxnet-4-easy-sections-plus-handy-presentation)), but that exploit required the attackers to penetrate and then steal the code signing keys from two trusted software manufacturers. The theft was non-trivial and the stolen keys were only dangerous while the theft remained undiscovered. Once the world learned about the theft, any certificate created from the stolen keys could be revoked and rendered useless. In other words, the Stuxnet code signing problem was serious but the fix was simple.

But what happens to trust when you can’t trust the trust system? With this latest vulnerability, we’re talking about the very underpinnings of digital signing and software validation for any software running on any current Windows-based platform. And while the vulnerability doesn’t impact the actual controllers on the plant floor, I’m willing to bet that 99.9% of today’s industrial systems are running the Windows operating system for all the operator HMIs, engineering stations, data historians, and management servers. In other words, while this vulnerability doesn’t impact the actual PLCs, it will allow counterfeit and malicious software to sneak onto all the computers that communicate with, manage, or report on industrial processes.

This isn’t the first time that the limitations of code signing have been laid bare. In 2017, [researchers at the University of Maryland](http://users.umiacs.umd.edu/~tdumitra/papers/CCS-2017.pdf) showed that there were, at the time, **over one million malware files in the wild that were signed**. Such files are signed by bad guys as a means of fooling poorly-written antivirus software into thinking the malware is legitimate software, causing the software to skip over it.

So, as I point out frequently at conferences, code signing and digital certificates are **necessary but not sufficient** to ensure software is tamper-free and legitimate. This is especially true in critical infrastructures, where the use of code-signing is [limited\*](https://blog.adolus.com/2020/01/18/windows-10-certificate-validation-bug-exposes-a-fundamental-weakness#footnote) and multiple validation mechanisms are necessary to keep our industrial processes reliable and our people safe.

This all ties back to why, over a half-decade ago, I became interested in alternative methods of validating software. My current project, the Framework for Analysis and Coordinated Trust (FACT), provides a collection of validation checks for vulnerabilities, malware, and subcomponent analysis, and does a deep dive into a file’s full certificate chain. Then, after thorough scrutiny, the platform provides a “FACT trust score” that technicians and managers can use to be confident in the decision to install a package (or the decision not to).

Certainly, any single test that FACT performs could be misled by a vulnerability like this latest one. However, by combining multiple tests and enabling the community to share intelligence, we stand a much better chance of outing rogue packages, counterfeits, and deprecated versions.

The ICS world needs ways it can trust software and firmware that cannot be signed (e.g., controller binaries) and confirms the validity of files that are signed, but with invalid certificates. I hope you’ll join the FACT community and help make ICS safer and more secure.

If you want to learn more, check out a quick video on [how FACT handles Code Signing Validation](https://www.youtube.com/watch?v=EulV9sCL0FY).

If you want to kick the tires for yourself, [try the FACT platform for free](https://fact.adolus.com).

\_\_

\* For most embedded devices in the industrial world, code signing isn’t even an option. The operating systems found in most industrial devices don’t have the ability to validate certificates. ICS vendors are making progress in having the newest controllers offer validation features, but it will be many years before we can expect code signing to be broadly deployed in ICS.

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/hubfs/Unsolicited-Response-Eric-and-Dale.png)](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 2 min read

##### [Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December:...

[Continue Reading](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 2 min read

##### [Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 15, 2021

Seasoned financial and advisory executive to drive growth VICTORIA, BC, CANADA, June 15, 2021 /EINPresswire.com/ -- ...

[Continue Reading](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/hubfs/newventuresbc_social-media-banner-1.png)](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 2 min read

##### [aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on December 1, 2020

aDolus Technology Inc. bested 240 of BC’s most innovative tech startups, winning the New Ventures contest in Canada’s...

[Continue Reading](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

[![Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/hubfs/Imported_Blog_Media/monsterUSB-e1536780548901.png)](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 3 min read

##### [Who Infected Schneider Electrics’ Thumbdrive?](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 12, 2018

On 24 August 2018 Schneider Electric issued a security notification alerting users that the Communications and...

[Continue Reading](https://blog.adolus.com/2018/09/12/who-infected-schneider-electrics-thumbdrive)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 4 min read

##### [Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 18, 2020

Just in case you missed it, a software supply chain attack on the US government and industries is consuming the waking...

[Continue Reading](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Building (or Losing) Trust in our Software Supply Chain](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

 3 min read

##### [Building (or Losing) Trust in our Software Supply Chain](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 10, 2018

Back in 2014, when I was managing Tofino Security, I became very interested in the Dragonfly attacks against industrial...

[Continue Reading](https://blog.adolus.com/2018/05/10/building-or-losing-trust-in-our-software-supply-chain)

[![ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/hubfs/Refirm-aDolus.png)](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 2 min read

##### [ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 3, 2020

aDolus Technology Inc., a global authority on software intelligence for critical infrastructure, and ReFirm Labs, a...

[Continue Reading](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

[![Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/hubfs/Verve-aDolus.png)](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 3 min read

##### [Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on February 4, 2021

Verve embeds aDolus’ ability to generate SBOMs and validate components aDolus Technology Inc., a global authority on...

[Continue Reading](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

[![aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/hubfs/NVBC-Top10-small.png)](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 2 min read

##### [aDolus Technology Selected as One of 2020’s Top 10 Startups](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on August 28, 2020

NANAIMO, BC, CANADA, August 27, 2020: aDolus Technology Inc., a global authority on software intelligence for critical...

[Continue Reading](https://blog.adolus.com/adolus-technology-selected-as-one-of-2020s-top-10-startups)

[![Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/hubfs/Bayshore-aDolus.png)](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 3 min read

##### [Bayshore Networks and aDolus Forge Supply Chain Security Partnership](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on July 23, 2020

The aDolus FACT™ platform provides independent software update validation to ensure safe upgrades and a more secure...

[Continue Reading](https://blog.adolus.com/bayshore-networks-and-adolus-announce-supply-chain-security-partnership)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)