๐ Meet Interlynk at the RSA Conference 2025 ๐ค
Join us at RSA Conference 2025 in San Francisco to explore how Interlynk is revolutionizing SBOM management and software supply chain security.
Whether you're navigating compliance with FDA, NIS2, CRA, or EO 14028โor looking to automate your SBOM workflowsโwe'd love to connect and show you how Interlynk can help.
What to expect during the meeting:
๐ก๏ธ Live demo of Interlynk's SBOM automation platform
๐ก๏ธ AI-powered vulnerability remediation and compliance reporting
๐ก๏ธ Personalized guidance for your security and compliance needs
๐ Location: Moscone Center / Mariott Marquis, San Francisco
๐ Dates: April 28โMay 1st, 2025
๐ค Schedule your meeting: https://t.co/3umjiCSKox
Secure your spot now and step forward in securing your software supply chain.
Empo Health Selects Interlynk to Enhance Cybersecurity & FDA Compliance for Remote Diabetic Foot Ulcer Monitoring https://t.co/YIIudIQMSF via @ein_news
๐ณ๏ธ Interlynk v3.1.9 is live to simplify product grouping ๐ณ๏ธ
This week's platform release allows you to label products automatically based on import, control the availability of the component support status field in SBOM, and add filtering by product life stage status across multiple views.
๐ฃ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ ๐ฅ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ
๐ ๐๐ถ๐ด๐ต๐น๐ถ๐ด๐ต๐๐:
๐ Auto labeling:ย ย Added ability to automatically group products by label at the time of Bitbucket import
๐ Lifestage Filter:ย Updated ability to filter products and versions by the life stage status across all views
๐ Component Support Status: SBOM exporterย supports the ability to embed component support status within the SBOM in CycloneDX
๐ ๐จ๐/๐จ๐ซ ๐๐บ๐ฝ๐ฟ๐ผ๐๐ฒ๐บ๐ฒ๐ป๐๐:
โจย Added hover row highlight for intuitiveย navigation
โคต๏ธย Updated organization activity card layout (More coming soon..)
๐๏ธย Updated archived versions of the side-drawer
โก๏ธย Simplified action buttons in link and relationship editors
๐ ๐๐๐ด ๐๐ถ๐ ๐ฒ๐:
16 big and tiny bug fixes, including:ย JIRA user list hitting limit, the vulnerability edit permission not showing up for some users,ย handling of invalid CWE link, and missing part name from CSV exports
Read our official release notes here: https://t.co/Aj7YTzKNje
๐ข๐ฝ๐ฒ๐ป ๐ฆ๐ผ๐๐ฟ๐ฐ๐ฒ ๐ฅ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ
SBOM Quality: sbomqsย v1.0.4 Released
๐ New Feature:ย ย list components with missing compliance data
๐ More details: https://t.co/EjF1xoKeBv
๐ ๏ธ TR-03183: BSI compliance fixes for large PURL strings
SBOM Editing: sbomasmย v1.0.2 Released
๐ More details: https://t.co/O8jrsvdnEo
๐ Fixed SBOM edit version reporting
SBOM Management: sbommvย v0.0.4 Released
๐ New Feature: Folder monitoring added to speed up SBOM uploads.
๐ More details: https://t.co/5bKPGnJZXz
๐ ๐ฒ๐ฒ๐ ๐๐ ๐ฎ๐ ๐๐ต๐ฒ ๐ฅ๐ฆ๐ ๐๐ผ๐ป๐ณ๐ฒ๐ฟ๐ฒ๐ป๐ฐ๐ฒ
There are less than two weeks left to RSA, but there is still time to book a meeting with Interlynkย here: https://t.co/F2ToONS6Fw.
๐ You will also win an Interlynk surprise gift bag just for booking the slot.
๐ก๏ธ From Reactive to Proactive: The Future of SBOMs ๐ก๏ธ
The software supply chain has become a favorite target for attackers, as seen in incidents like SolarWinds and xz-utils.
In response, mandates like the U.S. Executive Order 14028 and the EUโs Cyber Resilience Act now require Software Bills of Materials (SBOMs).
But todayโs SBOMs are primarily reactive and are used after the incident comes to light.
Hamed Okhravi, Ph.D. , Nathan Burow, and Fred B. Schneider - researchers at MIT Lincoln Laboratory and Cornell University, propose a shift: SBOMs as a proactive defense.
Imagine an SBOM that goes beyond components to include:
๐ Reproducible build metadata
๐ Test coverage and methods
๐ DevSecOps practices
๐ Trust indicators across supply chains
These additions could help assess trustworthiness before software is deployed, not after it's compromised.
This vision turns SBOMs from mere โingredient listsโ into full recipes for software assurance.
๐ฏ The goal? A more resilient digital ecosystem where trust is built-inโnot bolted on.
Source: https://t.co/AiZGO3yHZB
With Interlynk, you don't have to wait for this vision to come true.
Interlynk SBOM Automation Platform already collects build metadata, builds supply chain insights, and monitors DevSecOps best practices automatically.
With Interlynk, letโs make SBOMs more intelligent, profound, and proactive.
๐ Indiaโs SEBI extends CSCRF compliance deadline ๐
Securities and Exchange Board of India (SEBI) - India's market regulator - has extended its Cybersecurity and Cyber Resilience Framework (CSCRF) deadline for SEBI-regulated industries.
CSCRF mandates regulated entities like stockbrokers, depositories, and asset managers to adopt robust cybersecurity measures to protect against evolving threats. Now, SEBI regulated entities (REs) have upto June 30th, 2025 to meet CSCRF compliance.
๐ก Key Highlights:
๐ SBOM Requirements: REs to obtain SBOM for critical systems software products / SaaS at the time of procurement
๐ Mandatory Vulnerability Assessments: Regular VAPT after major software changes.
๐ Engagement with Experts: Use of CERT-In empanelled auditing organizations.
๐ Continuous Monitoring: Establishment of Security Operations Centers (SOCs).
๐ Strict Timelines: Prompt reporting and resolution of vulnerabilities.
๐ Flexibility for Small Entities: Certain relaxations while maintaining periodic assessments.
This framework is a significant step in fortifying Indiaโs financial ecosystem against cyber risks.
Learn how Interlynk can help meet SBOM and reporting requirements by reaching out to us here: https://t.co/QjdOhf1N8U
๐ณ๏ธ Interlynk v3.1.6 makes it easy to monitor CWE Top 25 ๐ณ๏ธ
This week's release of the Interlynk SBOM Management Platform adds Common Weakness Enumeration (CWE) and Vulnerability Advisory access across the NVD and OSV, allowing users to easily track OWASPยฎ Foundation Top 10 / MITRE CWE Top 25 across products and versions.
Additionally, this release improves PURL lookup and editing, enables version life cycle metric tracking, normalizes UX across 14 controls, and makes many usability fixes.
๐ฃ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ ๐ฅ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ
๐ Highlights
โ Enhanced Vulnerability Management: Added support for CWE & Advisories persistence, improved NVD client implementation, and custom vulnerability handling
โ Improved UI Components: Integrated LynkSelect experience across multiple platform areas for a better user experience
โ Lifecycle Support: Implemented version lifecycle for dashboard based on project and enabled lifecycle support at the version level
โ Performance Optimizations: Refactored package lookup and storage logic to use normalized PURL format
๐ UI/UX Improvements
โจย Added dashboard card for version life stage
๐ฉบย Updated support status check form
๐ย Improved component links preview
๐ Bug Fixes
12 big and tiny bugs squished, including CSV export with commas and metric ignoring selection of environment in short cards
Sign up for the Interlynk community tier here: https://t.co/cORKo9vQ92
Read our official release notesย here: https://t.co/pYFC7n7GLb
๐๐ผ๐บ๐ถ๐ป๐ด ๐๐ผ ๐ฅ๐ฆ๐?
Letโs set up a quick meeting at RSA. Let us know a time that works for you, or book directlyย here: https://t.co/IWYrHcpMMa
๐ You will also win an Interlynk surprise gift bag just for booking the slot.
๐ณ๏ธ Interlynk v3.1.5 release is loaded with simplifying integrations ๐ณ๏ธ
This week's release improves integrations for easier user workflow1s, eliminates deprecated flows, and removes unusable controls from viewer view.
๐ฃ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ ๐ฅ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ
This week's release improves integrations for easier user workflows, eliminates deprecated flows, and removes unusable controls from viewer view.
๐ Highlights
โ Enrich Java Packages:ย Enrich Java components from maven central.
โ Bitbucket:ย Support Searching & Pagination.
โ CPE:ย Deprecated CPEs are now removed from CPE helper workflows.
โ Security Enhancements: Added KEV details for CSV exports from Vulnerabilities
โ Enhanced Component Management: Improved SBOM vulnerability component code and refactored component links for better performance
๐ UI/UX Improvements
โจ Consistency in select controls across six views
๐จ Fixed misc styling issue in column width and icon controls
โช๏ธ Updated Bitbucket icons
Read our official release notesย here: https://t.co/pYFC7n7GLb
๐ข๐ฝ๐ฒ๐ป ๐ฆ๐ผ๐๐ฟ๐ฐ๐ฒ ๐ฅ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ
Interlynk's latest open-source tool, sbommv, facilitates seamless SBOM transfers across various platforms and destinations, including the Interlynk platform, OWASP DependencyTrack, S3, and GitHub repositories.
Learn moreย hereย or try the toolย here: https://t.co/olx9kLWEOe
๐๐ผ๐บ๐ถ๐ป๐ด ๐๐ผ ๐ฅ๐ฆ๐?
Letโs set up a quick meeting at RSA โ let us know a time that works for you, or book directlyย here.
๐ You will also win an Interlynk surprise gift bag just for booking the slot: https://t.co/QjdOhf1N8U
๐ Connected Vehicles SBOM Compliance: Final Rule๐ก๏ธ
The latest Federal Register notice outlines key requirements for "Declarations of Conformity" that may include SBOM and HBOM obligations for manufacturers to secure the supply chain for connected vehicles.
Here's the breakdown:
1๏ธโฃ Create and Maintain SBOMs: Ensure every software component (including open-source and third-party) is documented for transparency.
2๏ธโฃ Adopt Standard Formats: Use industry standards like SPDX, CycloneDX, or SWID for interoperability and automation.
3๏ธโฃ SBOM Elements Requirements: Maintain a separate set of SBOM elements requirements that builds on but clarifies NTIA MInimum Elements requirements.
4๏ธโฃ Regular Updates: Keep SBOMs current as components change to support effective vulnerability management.
5๏ธโฃ Manage Vulnerabilities: Establish processes to monitor and address risks as per NTIA guidelines.
6๏ธโฃ Document and Comply: Maintain records of SBOM practices for compliance and share with authorities when required.
๐ข While alternative methods of Declarations of Conformity are supported, by meeting these requirements with SBOM and HBOM, manufacturers can enhance cybersecurity and resilience in connected vehicles.
At Interlynk, we will be rolling out support for new elements and requirements to integrate into our open-source tools and the SBOM automation platform.
Source: https://t.co/BlQIPZBPj9
๐ Korean Govt shows enthusiasm for connected car SBOM rules ๐
Kudos to the South Korean industry ministry for successfully advocating clarity and practicality in the U.S.'s finalized rule on connected cars!
This milestone addresses critical uncertainties for automakers, especially regarding the use of SBOM.
The U.S. regulation now mandates:
โ Carmakers to maintain SBOM records for at least 10 years.
โ Declaration of conformity to ensure transparency in exporting to the U.S. market.
โ A phased approach to prohibiting China and Russia-made software (2027) and hardware (2030).
This progress further underscores SBOM's growing significance as a foundation for compliance, security, and trust in the automotive industry.
SBOM empowers automakers to innovate confidently while adhering to global standards by ensuring visibility into software components.
Source: https://t.co/rE4bPu06MD
๐ New Blog: sbommv in Action! ๐
Our latest blog explores how to use sbommv to enable seamless SBOM transfers across platforms like GitHub Releases, S3, local folders, free and open-source OWASP Dependency-Track, security tools, and the Interlynk SBOM platform (including the free community edition).
sbommv is part of Interlynkโs open-source toolset:
๐ sbomqs โ SBOM Compliance Analysis
๐ sbomasm โ SBOM In-line Editing & Merging
๐ sbomgr โ SBOM Contextual Search
Interlynk is making SBOM management more efficient and automated. If you're dealing with SBOM distribution challenges, this blog is for you!
๐ Read the full post: https://t.co/HLRzVXSOkp
๐ ๏ธ Try sbommv: https://t.co/olx9kLWEOe
๐ OwnersBox Selects Interlynk to Strengthen PCI DSS Compliance ๐
OwnersBox, a leading fantasy sports and gaming innovator, has chosen Interlynk to enhance its compliance with PCI DSS4 (Payment Card Industry Data Security Standard) and improve security through the total product lifecycle. By leveraging Interlynkโs industry-leading Software Bill of Materials (SBOM) automation platform, OwnersBox is taking proactive steps to ensure robust security, regulatory adherence, and continuous risk management for its payment processing infrastructure.
"At OwnersBox, the security of our usersโ financial transactions is a top priority," said Brian Kipp, CEO at OwnersBox. "After reviewing many options, we found the Interlynk platform to be the most innovative and best suited for strengthening our compliance posture while ensuring that our payment ecosystem remains secure, transparent, and resilient against emerging cyber threats."
About OwnersBox
OwnersBox is a leading fantasy sports platform providing fans an engaging and dynamic experience. With innovative gameplay and a commitment to user security, OwnersBox redefines how Daily fantasy sports are played.
OwnersBox has established itself as an emerging platform in the fantasy sports sector, delivering a dynamic and engaging experience for users. The company's innovative gameplay models, coupled with a robust commitment to user security, are redefining the daily fantasy sports landscape
About Interlynk
Interlynk is a leading provider of SBOM automation solutions, helping organizations manage software supply chain security, vulnerability management, and regulatory compliance. Its platform is trusted by businesses across various industries to enhance transparency and mitigate cyber risks.
Thank you, Cosimo Commisso, for your insights, trust and for being an incredible partner.
Press Release: https://t.co/GBzFEjF6Eu
๐จ FDA CDRH sharing SBOM pitfalls for MDMs๐จ
The FDA's Center for Devices and Radiological Health (CDRH)'s Nastassia T. shared some of the FDA's findings in working with SBOM for Medical Device Manufacturers.
โ๏ธ Human-readable SBOM will be gone - Manufacturers are sometimes asked for human-readable SBOM for the devices. As the FDA matures its processes for SBOM evaluation, that will no longer be the case.
โ ๏ธ SBOMs accuracy on the manufacturer - The FDA doesn't necessarily validate that an SBOM is "accurate", but not providing the appropriate information to the FDA could result in enforcement.
๐จVulnerability management - The FDA prefers proactive risk management to a reactive one but does not expect SBOM to be without vulnerabilities. The key area of focus is the manufacturer's plan to provide a fix for the vulnerability.
โ๏ธ Legacy device management - With the new authorities, the FDA is focused on ensuring that devices are still maintainable and patchable throughout the entire product lifecycle as they age. This has been a problem for devices built years ago, so the FDA wants to ensure that that will not be the status quo from this time onwards.
โ๏ธ Data Normalization - FDA encounters SBOM with many different names for the same component or operating system. This is a real challenge in understanding and evaluating SBOM for effective risk management.
Manufacturers, are you considering these while SBOM?
Source: https://t.co/fHa0qvHPFJ
#SBOM #Cybersecurity #FDACompliance #MedTech
๐ Friday is SBOM Jobs Day! ๐
Are you looking to advance your career in software supply chain security? Several leading companies hire professionals with SBOM expertise to help ensure product security and compliance with regulations like the US FDA, EU NIS2, EU DORA, US Executive Order 14028, EU Product Liability Directive (PLD), EU Cyber Resilience Act (CRA) and PCI DSS4.0.
If you're passionate about securing open-source software and third-party components, these roles offer a fantastic opportunity to be at the forefront of innovation in SBOM automation and software security.
Check out the open positions and take the next step in your career! ๐๐ผ
[Emerson] Product Security Architect, Marshalltown (IA)
https://t.co/ubuCmpDBZf
[Emerson] Software Supply Chain Security Engineer, Shakopee (MN)
https://t.co/atfHy9Oq75
[Mirion] Product Cybersecurity Manager, Atlanta (GA), Remote
https://t.co/9W2oMV8mzY
[Clarity Innovations] Senior Principal Platform Engineer (Lead), Herndon (VA)
https://t.co/ogANAQ0DFM
Good luck, and reach out to Interlynk if you need help getting started: https://t.co/XUG9edeSG2
๐ 5 Non-Obvious Ways SBOMs Help Development Teams ๐
When most security professionals think of SBOM, they imagine compliance checkboxes or security audits. However, for development teams, SBOMs are a secret weapon that can transform how they build, manage, and deliver software.
Here are five surprising ways SBOMs add value to developers:
1๏ธโฃ Speed Up Security Analysis
Imagine knowing every library, dependency, and version at a glance. SBOMs offer unparalleled transparency into your tech stack, helping developers pinpoint the root cause of issues faster. It's like having a roadmap when you hit a detour!
2๏ธโฃ Simplify Tech Debt Management
Tech debt grows when dependencies aren't tracked or updated. With an SBOM, teams can proactively monitor outdated components and plan upgrades systematically, preventing "dependency hell." This is also useful for system architects and senior management to track, as leaving the systems "as-is" incurs tech debt that becomes harder to pay back.
3๏ธโฃ Improve Collaboration Across Teams
Everyone benefits from having a shared source of truth, from security to DevOps and QA. An SBOM bridges the gaps between teams, ensuring everyone speaks the same language regarding dependencies, risks, and updates, especially when questions arise from vulnerabilities in transitive dependencies.
4๏ธโฃ Enable Better Dependency Negotiations
SBOMs provide complex data for organizations that rely on third-party vendors to evaluate the quality and security of their dependencies. This insight strengthens negotiating power with vendors and ensures secure, well-maintained libraries.
5๏ธโฃ Support Continuous Innovation
Git repositories significantly boosted development velocity because source code management became an afterthought. Similarly, by automating dependency tracking, SBOM frees developers to focus on delivering value rather than mapping vulnerabilities to releases! With fewer manual tasks and fewer surprises from hidden risks, teams can confidently ship faster.
๐ Nuclei Vulnerability Management: An SBOM Essential ๐
A recently disclosed vulnerability in the popular Nuclei vulnerability scanner (CVE-2024-43405) reminds us of the importance of maintaining a comprehensive and up-to-date SBOM of an organization's toolset - even if they are open-source.
This vulnerability, affecting versions 3.0.0 to 3.3.1, allows attackers to execute arbitrary code by exploiting a weakness in the template signature verification process.
๐ How does an SBOM help?
An SBOM provides an inventory of all software components, including their versions and associated metadata, and as a result, acts as an inventory of tools used within the organization.
With an accurate SBOM in place:
โ Security teams can get timely notifications for the reported vulnerability.
โ Organizations can act swiftly to mitigate risks, like patching or upgrading.
โ Supply chain transparency is improved, ensuring all stakeholders are aware of potential risks.
In the case of Nuclei, an SBOM would allow teams to:
1๏ธโฃ Spot affected versions in their systems.
2๏ธโฃ Apply necessary updates proactively to reduce exposure.
As vulnerabilities like these continue to emerge, SBOMs play a critical role in enhancing software supply chain security, enabling organizations to:
๐ Stay ahead of threats.
๐ก๏ธ Improve compliance with regulations and frameworks.
๐ Build trust with users and stakeholders.
๐ In today's threat landscape, an SBOM isn't just a nice-to-haveโit's a necessity.
๐ Strengthening Cybersecurity in Indiaโs Financial Sector ๐
Securities and Exchange Board of India (SEBI) - India's market regulator - has unveiled its Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-regulated industries. This groundbreaking initiative mandates regulated entities like stockbrokers, depositories, and asset managers to adopt robust cybersecurity measures to protect against evolving threats.
๐ก Key Highlights:
๐ SBOM Requirements: REs to obtain SBOM for critical systems software products / SaaS at the time of procurement
๐ Mandatory Vulnerability Assessments: Regular VAPT after major software changes.
๐ Engagement with Experts: Use of CERT-In empanelled auditing organizations.
๐ Continuous Monitoring: Establishment of Security Operations Centers (SOCs).
๐ Strict Timelines: Prompt reporting and resolution of vulnerabilities.
๐ Flexibility for Small Entities: Certain relaxations while maintaining periodic assessments.
This framework is a significant step in fortifying Indiaโs financial ecosystem against cyber risks.
๐ ๐พ FDA guidance for AI-enabled medical devices! ๐๐พ
Today, the FDA has published its final guidance to enhance AI-driven medical technologies' safety, effectiveness, and lifecycle management. Link: https://t.co/ZjwEbAIXFv
Unlike software, AI-enabled devices have the potential to 'change' behavior with the underlying model. Therefore, this recommendation is intended to simplify change management for previously approved devices.
Key highlights of the guidance:
๐ Lifecycle Perspective: Emphasizing continuous oversight of AI-enabled devices from development to deployment and beyond.
๐ Performance Monitoring: Recommendations for tracking AI system performance to ensure reliability and patient safety.
๐ Transparency: Clear guidance on what information should be communicated to users about the device's AI functionality.
๐ Public Input: The FDA is inviting feedback on these draft guidelines through April 7, fostering a collaborative approach to regulation.
๐ FDA Webinar detailshere:
https://t.co/YjOGGk4tCQ
This guidance builds on the lessons learned from over 1,000 authorized AI-enabled devices, aiming to streamline innovation while ensuring regulatory clarity.
Interlynk is committed to helping organizations meet and stay up-to-date with FDA cybersecurity requirements.
๐ EU Legislative Landscape ๐
Cybersecurity faces a unique challenge: proving a negative.
Without standardized metrics to demonstrate risk reduction, much focus remains on regulations and compliance.
Yet, the evolving regulatory landscape is often overlookedโand it's transforming right before our eyes.
Take the regulations moving through the European Union as an example.
We're witnessing tectonic shifts in how software must be built, packaged, and monitored and how incidents must be reported. Many of these changes are already in the implementation phase.
A stronger security posture won't just be about complianceโit will soon become a strategic advantage.
Is your organization ready for this shift?
Source: https://t.co/kRwd2kx1B8
๐ BSI Vulnerability Notification Guidelines for Cyber Resilience ๐
Cyber Resilience Act (CRA) officially becomes the law on Wednesday, December 11th.
In preparation, Germany's Federal Office for Information Security (BSI) has just released updated guidelines for Technical Directive TR-03183, with a clear focus on SBOM (Software Bill of Materials) and Vulnerability reporting requirements!
These new guidelines strengthen transparency and security in software supply chains, ensuring organizations can better manage open-source and third-party risks in compliance with the CRA. This is a significant step towards enhancing cyber resilience and building trust in every digital product sold across Europe.
๐ Stay tuned as we explore these updates and their implications for security, compliance, and risk management. We have also updated the Interlynk open-source utility hashtag#sbomqs and platform to check against updated requirements and vulnerability notifications.
Source: https://t.co/c9MKzffCns
sbomqs : https://t.co/SZRbn6TCGt
Free SBOM Automation Platform: https://t.co/cORKo9vQ92
#CyberResilienceAct
#SBOM
#BSI
#Cybersecurity
#SoftwareSupplyChain
#TR03183
#Compliance
#CycloneDX
#SPDX