Knowledge Base & Masterclasses

In-depth articles on the Cyber Resilience Act, SBOM complexity and current European legislation. Featured weekly on LinkedIn — always available here in full.

Edition 2 / 10 3 min

Phantom Components: The Invisible Threat in Your Software Supply Chain

Your SBOM scanner gives the green light, but a time bomb is ticking beneath the surface. Learn how 'phantom dependencies' end up invisibly in your production environment.

Read article
Edition 3 / 10 3 min

The Invisible Hand: Why Build Tools Belong in Your SBOM

The notorious SolarWinds hack didn't happen through a vulnerable library, but because the factory itself was infected. Time for the 'Build SBOM'.

Read article
Edition 4 / 10 2 min

Java Dependency Hell: Why Your Java SBOM Is Probably Wrong

Generating an accurate SBOM for Java is absolute hell. An SBOM of exactly the same code can differ from one day to the next.

Read article
Edition 5 / 10 2 min

Software's Identity Crisis: Why PURL Beats CPE

How does a vulnerability scanner know whether 'Library X' in your SBOM is the same as in the database? The battle between CPE and PURL explained.

Read article
Edition 6 / 10 2 min

SPDX versus CycloneDX: Which SBOM Standard Should You Choose?

The cybersecurity industry is locked in a standards war. Do you choose the ISO-certified veteran (SPDX) or the DevOps favourite (CycloneDX)?

Read article
Edition 7 / 10 2 min

The Illusion of the Static SBOM: Why Runtime Analysis Is Indispensable

An SBOM generated during the build is just a theoretical blueprint. What happens when applications dynamically load plugins or mutate?

Read article
Edition 8 / 10 3 min

Drowning in Noise: How VEX Makes SBOMs Scalable

Panic! The scanner finds 480 vulnerabilities. How VEX (Vulnerability Exploitability eXchange) counters alert fatigue and separates reality from noise.

Read article
Edition 9 / 10 2 min

More Than Security: The Legal Minefield of SBOMs

The SBOM was originally devised not for hackers but for lawyers. Discover the legal pitfalls of the open-source supply chain.

Read article
Edition 10 / 10 2 min

The Distribution Paradox: How Sigstore Brings Trust to SBOMs

How do you share an SBOM (the blueprint of your weaknesses) securely with a customer? And how do you cryptographically prove it's genuine? Sigstore is the answer.

Read article