Security experts and hardware hackers are emphasizing the need for closer engagement between device vendors and the security research community to improve hardware security. At the Hardware.io conference in Amsterdam, leaders such as Alex Guzman, CISO for Cisco Network Devices, highlighted that hardware vulnerabilities are often the result of business decisions and trade-offs, such as prioritizing speed to market over security. The importance of bug bounty programs and providing researchers with access to devices was underscored as a way to uncover and address vulnerabilities before they can be exploited in the wild.
The discussion also addressed the challenges of supply chain security, side channel attacks, and the need for organizations to act on vendor-provided mitigation advice. Security teams are encouraged to communicate risks in business terms to drive better decision-making, and the OWASP Internet of Things Project was cited as an initiative to foster improved understanding of IoT security. Ultimately, the consensus is that proactive collaboration between vendors and the security community is essential for addressing the evolving landscape of hardware threats.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.