logo

Spotlight Podcast: Fixing Supply Chain Hacks with Strong Device Identities

ID: b75b2a35-0dd0-5b95-9947-ac85dbfa215f

STIX ID: report--b75b2a35-0dd0-5b95-9947-ac85dbfa215f

Feed Name: Security Ledger

Threat Score
80/100

Date Published: 2019-04-11

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The article discusses the growing threat of software supply chain attacks — citing the ASUS update-server compromise and the NotPetya outbreak — and explains why current signature-only update verification is insufficient. It presents the Trusted Computing Group’s DICE architecture as a mitigation for creating strong device identities and attestation to prevent malicious signed-but-tainted updates on IoT and other endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.