---
title: Harnessing FACT for Swift Cyberthreat Response
description: "A summary of aDolus' response to the vulnerability in the #XZ Utils library and how we reassured our customers that they were at no risk from this threat."
image: https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[malware](https://blog.adolus.com/tag/malware)

# Harnessing FACT for Swift Cyberthreat Response

 By [Marcello Delcaro](https://blog.adolus.com/author/marcello-delcaro) on May, 1 2024

[Back](https://blog.adolus.com)

Harnessing FACT for Swift Cyberthreat Response

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> <http://www.facebook.com/share.php?u=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> [mailto:?subject=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response%20&body=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/XZ%20Backdoor%20thumbnail-aspect-corrected.png](mailto:?subject=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response%20&body=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/XZ%20Backdoor%20thumbnail-aspect-corrected.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> <http://www.facebook.com/share.php?u=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/harnessing-fact-for-swift-threat-response> [mailto:?subject=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response%20&body=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/XZ%20Backdoor%20thumbnail-aspect-corrected.png](mailto:?subject=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response%20&body=Check%20out%20https://blog.adolus.com/harnessing-fact-for-swift-threat-response&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/XZ%20Backdoor%20thumbnail-aspect-corrected.png)

In the cybersecurity world, anticipation and rapid response are crucial in safeguarding against emerging threats. Recent events, such as the discovery of a vulnerability in the XZ Utils library used in many software applications, underscore this need. 

For background, a weakness was deliberately created in the open-source compression library liblzma (XZ). This library is a downstream dependency of sshd — a remote connection library typically used for administration and is widely deployed across the software industry. 

Affected versions can include 5.6.0 (released February 24, 2024) and 5.6.1 (released March 9, 2024). Because these two versions are relatively new, it’s probable that the spread is minimal.

This overview from [Akamai Security](https://www.akamai.com/blog/security-research/critical-linux-backdoor-xz-utils-discovered-what-to-know) sums up the level of covertness applied to this attack: “In what seems like an attempt to avoid detection, instead of pushing parts of the backdoor to the public git repository, the malicious maintainer only included it in source code tarball releases. This caused parts of the backdoor to remain relatively hidden, while still being used during the build process of dependent projects.” 

The following graphic demonstrates the execution chain:

![Akamai Security graphic showing compromise of liblzma](https://blog.adolus.com/hs-fs/hubfs/Akamai%20Security%20graphic.png?width=1066&height=600&name=Akamai%20Security%20graphic.png)

*Original graphic by Akamai Security, redesigned for use in this blog post*

But while this particular threat was mitigated quickly after a random developer stumbled across it, the event serves as a reminder of the continuous risks in software dependencies. In this post, I’ll share how a platform like FACT can be instrumental in preparing for and responding to similar cybersecurity challenges. In a digital landscape — be it IT, OT, or IoT (or most often a combination of all three) — we face increasingly sophisticated threats to the software supply chain.

## Understanding the Cyberthreat Landscape

The backdoor found in liblzma versions 5.6.0 and 5.6.1 not only underscores the necessity for rapid detection and response mechanisms but also casts light on broader issues within the open-source community. These include the mental health of open source developers (often unpaid) who face increasing pressures to secure and maintain critical libraries, and the extensive measures that malicious actors are willing to undertake to exploit these people and systems. A relentless campaign to get a compromised version of the library merged into the GitHub repository eventually bore fruit once the bad actors secured the trust they needed.

Such vulnerabilities highlight the complex interplay between technological diligence and human factors in cybersecurity.

A really good technical timeline was written by Evan Boehs: [Everything I know about the XZ backdoor](https://boehs.org/node/everything-i-know-about-the-xz-backdoor). It is incredible to see the lengths the threat actor went through to introduce this vulnerability first into the XZ library and then into a number of common Linux distributions like Fedora and Debian.

## The Response Investigation from aDolus

On March 29th, Microsoft developer Andres Freund uncovered the liblzma backdoor; aDolus quickly mobilized our resources to assess and communicate the potential impact on our customers. Our data lake contains software frequently deployed within critical infrastructure and operational technology (OT) environments, where security breaches can have particularly severe consequences. We used FACT to help triage the incident for our customers (and their suppliers) by rapidly identifying the presence (or absence) of the XZ vulnerability and advising on mitigation opportunities.

Here's a detailed look at the steps we took during this incident…

What aDolus did first was perform a comprehensive scan through FACT’s database for any metadata related to the affected libraries. This incisive search was done to identify all instances of the affected versions across our entire database, ensuring comprehensive threat coverage with no blind spots.

In our examination, we discovered approximately 250 instances of the library with versions ranging from 5.0.4 to 5.2.9. A review of historical commits indicated that Jia Tan, the malicious maintainer, began contributing fixes around version 5.2.10. However, malicious code was not introduced until the versions 5.6.0 and 5.6.1. Notably, the most prevalent versions found in FACT were 5.2.0 to 5.2.5, suggesting that the perpetrator's nefarious activities had not impacted the products we manage or monitor.

![FACT screenshot with unaffected XZ versions highlighted](https://blog.adolus.com/hs-fs/hubfs/FACT%20screenshot%20XZ%20versions%20highlighted.png?width=521&height=390&name=FACT%20screenshot%20XZ%20versions%20highlighted.png)

Manual Investigation of Anomalies: For files that did not match the known affected versions but were added to our data lake within the relevant release date window, we conducted detailed manual investigations to uncover any discrepancies or hidden versions that might have escaped the initial automated screening. Happily, no anomalies were uncovered.

Leveraging our Internal File Similarity Model: Finally, we used FACT’s File Similarity Model to look up extraneous samples, aiming to uncover misrepresented or stripped metadata and files masquerading as others. This also let us detect modifications that weren’t initially evident. To give more breadth and accuracy to the model, we sourced affected versions of the library from external sources and trusted partners. This deep-dive analysis is pivotal in identifying subtle issues that could indicate more extensive problems within the files.

## The Role of FACT and Proactive Behaviour in Future Cyberthreats

As we navigate an ever-evolving software supply chain and its security, having the correct tools to triage quickly and effectively becomes imperative. FACT has proven its value in past incidents, notably during the [Log4j vulnerability crisis](https://adolus.com/vulnerabilities/log4j/), where our product enabled customers to identify and mitigate risks within hours rather than weeks. The ability to react quickly to new threats can drastically reduce the window of opportunity for attackers. FACT both aids in immediate threat mitigation and supports ongoing vigilance through continuous monitoring and updates. This proactive approach is essential for maintaining the integrity of systems and protecting critical infrastructure.

### How FACT can play a critical role in triaging future supply chain incidents

Advanced Decomposition of Binaries: FACT uses sophisticated methods to effectively find and extract nested binaries, creating a robust foundation for granular analysis that helps pinpoint vulnerabilities and increase the efficiency of triage processes.

Enhanced Metadata Extrapolation: By extracting, correlating, and normalizing metadata across the platform, FACT provides deeper insights into known security risks, facilitating a more informed and proactive security posture.

Extensive YARA Scanning: FACT employs the best-in-class YARA ruleset from our partners at Nextron Systems, which is run against every extracted binary within our cloud environment. This ensures that the most effective and up-to-date detection logic is applied to identify known threats as quickly as possible.

Holistic Component Analysis: FACT offers a comprehensive view of how individual components are integrated across various product libraries within your organization. This holistic approach is crucial for understanding the full scope of a potential threat and for ensuring that all vectors of attack are addressed.

## Lessons Learned

This backdoor incident is a potent reminder of the persistent and evolving nature of cyber threats. Targeting the open source community is hardly novel and will no doubt be repeated, given the maintainers of these libraries are underpaid, overworked, and essentially volunteering their time. Open-source software is simply more susceptible to these types of attacks, underpinning the need for more support and resources to maintain both security best practices and the mental health of developers. Without tools like FACT, product managers and security analysts could spend an enormous amount of time determining if their systems include a vulnerable version of the latest affected library. This challenge makes supply chain attacks on corporate entities both silent and effective, as tracking such vulnerabilities within an ecosystem can be exceptionally intricate without the right tools.

Fortunately, in the case of the XZ backdoor event, the malicious code was introduced into very recent versions of the library so it hadn’t yet had the chance to be widely adopted (as evidenced by the fact that none of our customers were using those versions). Nevertheless, we were able to quickly reassure our customers that they were at no risk from this threat and to spare them the costly task of wading through false positives to find it. In turn, they could reassure their customers that their software was free of the vulnerability. 

This event also highlights the critical need for rapid response and ongoing vigilance in cybersecurity. Tools like FACT — as part of a wide range of security capabilities — are essential for managing and mitigating threats efficiently and helping to protect critical digital infrastructure. 

Logic-based attacks, such as those hidden in code from what was believed to be a trusted maintainer, are extremely difficult to detect. But by having all of your deployed software scanned by FACT and knowing where it all is (including new updates), you will be able to quickly track down affected products in your environment and begin assigning remediation efforts — just like after the [Log4j discovery](https://blog.adolus.com/log4j-panic-or-lesson) or whatever new vulnerability is discovered tomorrow.

![Marcello Delcaro](https://blog.adolus.com/hubfs/marcello-whitebg.png)

###### Marcello Delcaro

 Marcello is a software analyst and renaissance man with an extremely wide set of skills. (If we need something done, we give it to Marcello — he’ll figure it out.) Marcello manages all of our customer pilot projects and implementation projects.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/marcello-delcaro-ab5847221/> <https://twitter.com/aDolus_Inc>

[Previous Post](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security) [View All](https://blog.adolus.com)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/hubfs/Imported_Blog_Media/NERC-CIPC-Training-Session-1024x451.jpeg)](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 3 min read

##### [3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on April 21, 2020

Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that...

[Continue Reading](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 4 min read

##### [The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our...

[Continue Reading](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 5 min read

##### [EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European...

[Continue Reading](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![An Analysis of Generative AI: How to Be Confidently Wrong](https://blog.adolus.com/hubfs/Robot%20Interpretation.png)](https://blog.adolus.com/how-to-be-confidently-wrong)

 7 min read

##### [An Analysis of Generative AI: How to Be Confidently Wrong](https://blog.adolus.com/how-to-be-confidently-wrong)

 By [Marcello Delcaro](https://blog.adolus.com/author/marcello-delcaro) on April 11, 2023

The recent release of the National Cybersecurity Strategy document by the White House prompted me to test Microsoft's...

[Continue Reading](https://blog.adolus.com/how-to-be-confidently-wrong)

[![A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/hubfs/Regulatory%20Action.png)](https://blog.adolus.com/a-flurry-of-regulatory-action)

 5 min read

##### [A Flurry of Regulatory Action and the Need for SBOMs](https://blog.adolus.com/a-flurry-of-regulatory-action)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a...

[Continue Reading](https://blog.adolus.com/a-flurry-of-regulatory-action)

[![aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/hubfs/Mark-Weatherford-Appointment.png)](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 2 min read

##### [aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 23, 2021

Cybersecurity veteran tapped to accelerate growth of ICS supply chain security leader VICTORIA, BC, CANADA, June 23 -- ...

[Continue Reading](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/hubfs/Timeline-thumbnail2.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

[![Sorry Blackberry: You Are Part of the Supply Chain](https://blog.adolus.com/hubfs/Blackberry-SBOM-share-main-image.png)](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

 2 min read

##### [Sorry Blackberry: You Are Part of the Supply Chain](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on November 2, 2021

Today, reporters Betsy Woodruff Swan and Eric Geller at Politico published a story: “BlackBerry resisted announcing...

[Continue Reading](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)