All Insights

  • July 2026 – CRA Updates, AI usage in open source and secure boot risks

    July 2026 – CRA Updates, AI usage in open source and secure boot risks

    Published: August 5, 2026 Last modified: August 5, 2026 Hello, The summer holidays are in full swing across much of the Northern Hemisphere. While many people are taking a well-deserved break, the embedded security world is not.This edition brings together a selection of news and resources from the past few weeks.And I also wanted to share…

  • MIND and Ygreky Join Forces to Strengthen Embedded Cybersecurity Expertise and Services

    MIND and Ygreky Join Forces to Strengthen Embedded Cybersecurity Expertise and Services

    Published: July 7, 2025 Last modified: July 7, 2026 Leuven, Belgium and Grenoble, France, 07/07/2026 – MIND and Ygreky today announced a strategic collaboration to combine their expertise in embedded cybersecurity, helping manufacturers, software vendors, and technology companies address growing security challenges throughout the lifecycle of connected products. As cybersecurity requirements continue to evolve, organizations…

  • June 2026 – vulnerability storm, overlayfs, EU Open Source Strategy

    June 2026 – vulnerability storm, overlayfs, EU Open Source Strategy

    Published: June 30, 2026 Last modified: June 30, 2026 Linux kernel updates – overlayfs Some technical conferences go really deep into specific topics, and that is certainly the case for the Linux Storage, Filesystem, Memory Management, and BPF Summit. At the recent event in May, Amir Goldstein presented updates to overlayfs, a feature widely used…

  • Ygreky Obtains Qualiopi Certification for Professional Training Activities

    Ygreky Obtains Qualiopi Certification for Professional Training Activities

    Published: May 15, 2025 Last modified: May 15, 2026 Ygreky is pleased to announce that it has officially obtained the Qualiopi certification for its professional training activities. Issued under the French national quality framework for training providers, Qualiopi certifies the quality of the processes implemented by organizations delivering professional training. The certification was awarded following…

  • Ygreky becomes a CVE Numbering Authority (CNA) under ENISA Root

    Ygreky becomes a CVE Numbering Authority (CNA) under ENISA Root

    Published: May 5, 2026 Last modified: May 5, 2026 Ygreky is now a CVE Numbering Authority (CNA) in the CVE™ Program under the European Union Agency for Cybersecurity (ENISA) Root. This decision is driven by several practical needs. First, Ygreky develops and operates its own tools, including systems used to deliver remote training. Acting as…

  • Embedded Security – A Shared Learning Journey

    Embedded Security – A Shared Learning Journey

    Published: December 29, 2025 Last modified: December 29, 2025 It has now been more than a year since I started running the “Embedded Security| course, and this feels like a good moment to pause and reflect. First and foremost, thank you. Thank you to everyone who attended a session, asked hard questions, shared real-world constraints,…

  • Yocto Project Summit 2025.12

    Yocto Project Summit 2025.12

    Published: December 9, 2025 Last modified: December 9, 2025 The Yocto Project Virtual Summit 2025.12 covered a wide range of topics over three days last week. I could not attend every talk, and I am looking forward to the videos for several sessions I missed. Fortunately, the slides are already available from the conference site:…

  • Understanding the Cyber Resilience Act

    Understanding the Cyber Resilience Act

    Published: December 1, 2025 Last modified: December 29, 2025 UPDATE: The video of “Introduction to the Cyber Resilience Act for Embedded Developers” is online now. Two webinars to help embedded developers prepare for 2026 The Cyber Resilience Act (CRA) is one of the biggest regulatory changes the European tech industry has faced in years. Its…

  • The CVE Program status: what embedded developers should know

    The CVE Program status: what embedded developers should know

    Published: May 6, 2025 Last modified: May 6, 2025 What is CVE? The CVE program (Common Vulnerabilities and Exposures) is the most widely recognized database of known vulnerabilities. Each CVE entry receives a unique identifier such as CVE-1900-1234, where “CVE-” is a prefix, 1900 is the year, and 1234 is the unique number assigned within…

  • VulnCon 2025 Impressions

    VulnCon 2025 Impressions

    Published: April 15, 2025 Last modified: June 3, 2025 VulnCon is a unique conference focused on vulnerability management. I attended the inaugural edition in 2024 (virtually), and just participated in the second one, held from April 7 to 10, 2025 (also virtually). This year, I presented two talks. The first one, titled “Distribution Builders Meet…