Cybersecurity

Blog articles, webinars, and podcasts you need to gain a deeper understanding of how to keep your devices secure during their lifecycle.

Vulnerability management lifecycle for embedded systems

Vulnerability management lifecycle in embedded devices

Whether you're working on the OS or the application layer of your embedded system, security is non-negotiable. One of the most effective ways to prevent attacks is to find and patch vulnerabilities (also called CVE) regularly. This is the essence of the vulnerability management lifecycle. Let’s break it down.

Embedded Linux vulnerability management with AI

Embedded Linux vulnerabilities management with AI: too good to be true?

We all know it—managing vulnerabilities is becoming critical. Not only to ensure our products remain secure, but also to stay compliant with the growing number of cybersecurity regulations (Cyber Resilience Act in Europe, and its counterparts in the US). So, what if AI could help us save time? Isn’t this the secret dream of every R&D team?

DevOps vs DevSecOps definitions and best practices

DevSecOps: definition & best practices for embedded systems

At Embedded World Nuremberg 2025, Laurent Sustek from STMicroelectronics and Pierre Gal from The Embedded Kit shared their expertise on DevSecOps. They provided practical insights and best practices to enhance quality, efficiency, and security throughout all stages of product development. Below is a summary of their discussion, which stems from a close collaboration between the two companies.

embedded Linux in medical devices

Linux in medical devices: how to achieve compliance?

Developing medical devices presents unique challenges, particularly when it comes to integrating advanced features like connectivity and user-friendly interfaces vs complying with stringent industry regulations like the IEC62304.
These advanced features introduce complexity and risk, making it essential to choose the right operating system. Linux, if we focus on medical use cases, offers a robust solution to these challenges. In this article, we will discuss how to implement embedded Linux in medical devices to add advanced features while meeting compliance standards.

sbom generation with yocto project

How to generate a Software Bill of Materials (SBOM) with Yocto

A SBOM is a comprehensive inventory that lists all the software components and dependencies used in an embedded device. It represents a useful tool to make sure systems - like embedded Linux systems created using The Yocto Project - stay secure and comply with cybersecurity regulations. This article will guide you through the process of generating an SBOM using Yocto.

cyclonedx sbom

Generating CycloneDX SBOM

CycloneDX has become a frequently used format for generating Software Bill of Materials (SBOM) over recent years. Designed to enhance security and compliance, CycloneDX offers a detailed and structured approach to documenting all software components and their interdependencies.

SPDX SBOM (Software Bill of Materials)

Generating SPDX SBOM

With increasing cybersecurity threats and regulations, embedded software teams must manage software components and dependencies. Software Bills of Materials (SBOM) provide a detailed inventory of all software elements in an embedded system. Among various formats, SPDX (Software Package Data Exchange) is widely adopted and detailed. Let’s deep dive.

i.MX93 support - NXP x The Embedded Kit

Simplifying security implementation on i.MX93-based devices with The Embedded Kit and NXP

Embedded systems development comes with its own set of challenges. From integrating advanced hardware to ensuring long-term software security, the complexities only grow as new technologies emerge. For software engineers working on embedded systems, streamlining processes while maintaining robust security protocols is crucial.
To address these concerns, The Embedded Kit has rolled out support for NXP’s i.MX9 processors within its production-ready embedded Linux distribution. This integration not only simplifies hardware-software collaboration but also eases long-term system maintenance. As a result, developers can concentrate more on application development and less on low-level configurations.

AAEON - The Embedded Kit - New partnership

AAEON and The Embedded Kit announce strategic partnership and launch a fully integrated hardware/software bundle

September 2024 - AAEON, a leading manufacturer of AI Edge hardware solutions, and The Embedded Kit, a Witekio brand renowned for its innovative embedded systems software products, are thrilled to announce their strategic partnership this week at SIDO Lyon. This collaboration aims to streamline the development process for industrial companies by providing a fully integrated hardware and software bundle.