Nordic Semiconductor announced that firmware vulnerability scanning is coming to nRF Cloud, further bolstering its capabilities for empowering device makers to prepare for the EU Cyber Resilience Act (CRA).
With firmware vulnerability scanning in nRF Cloud, developers will be able to upload their software bill of materials (SBOM) to nRF Cloud and automatically identify common vulnerabilities and exposures (CVEs) present in the SBOM and analyse their exposure across their nRF Cloud-connected production fleet.
nRF Cloud’s new capability is designed to help device manufacturers meet the CRAs vulnerability monitoring requirement, without taking on the burden of building and maintaining their own CVE identification systems. This new capability works in tandem with nRF Cloud’s firmware over-the-air (FOTA) service, which allows updates to be deployed at scale to devices in the field.
Shortening CRA compliance to-do lists
The CRA requires the security of connected devices to be maintained across the full device lifespan, which can extend many years into the future, meaning compliance work does not stop once devices are deployed.
With nRF Cloud’s features including vulnerability detection and FOTA, developers can more effectively manage their compliance burden and stay focused on building innovative products. This means a faster path to market, and once products ship, meeting ongoing compliance obligation with less strain on stretched resources.
Continuous vulnerability detection with real-world exposure analysis
With nRF Cloud’s new firmware vulnerability scanning, developers upload their SBOMs for each software version, and nRF Cloud will automatically and continuously scan that SBOM.
The service also highlights exactly how many deployed devices are exposed to each identified vulnerability. This exposure data enables more confident prioritisation decisions, and allows real-time monitoring of remediation via security patches, as those updates roll out.
Detection and remediation in one system
Alongside nRF Cloud’s existing FOTA update capability, firmware vulnerability scanning lets device makers move from an identified security issue, to a deployed patch, to a confirmed fix, all in one system backed by a complete audit trail.
Remediation can be monitored in real time as security patches roll out across the fleet. With the help of nRF Cloud, developers will be able to check several important requirements around vulnerability monitoring and security update delivery off their CRA to-do list.
Intelligent video processing Rugged Interconnect Technologies
Computer/Embedded Technology
The CHARM150AGX is based on a NVIDIA AGX Orin embedded processor, which incorporates a multicore ARM processor and powerful AI/ML accelerator.
Read more...Practical design strategies for 5G RF Design
Telecoms, Datacoms, Wireless, IoT
The Cavli CQM211 aims to provide a platform that combines strong 5G connectivity with onboard compute capability, as well as interface flexibility that suits both new designs and rapid migrations from earlier products.
Read more...Arrival of the Epic-PTH9 Vepac Electronics
Computer/Embedded Technology
AAEON introduces the EPIC-PTH9, a compact 4-inch industrial single-board computer powered by Intel Core Ultra Series 3 (formerly Panther Lake) processors.
Read more...An industry-first Android 16 smart module solution RF Design
Computer/Embedded Technology Telecoms, Datacoms, Wireless, IoT
The MeiG Smart SLM580 4G Smart Module features native support for Android 16 and covers core frequency bands in major countries and regions worldwide.
Read more...MIKROE celebrates 2000th Click board
Computer/Embedded Technology
MIKROE has launched its 2000th Click board, the RTC 27 Click, designed for low-power real-time clock and calendar functionality, time tracking, alarm event generation, watchdog timing, and timestamp capture.
While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.