Blog
The Finite State Blog

Practical insights and articles from our SMEs to help product security teams cut triage noise, fix what matters faster, and deliver audit-ready proof to customers and regulators.

59 results

3D render of a black indoor security camera with a horizontal scan line across its midsection. Above the line, the housing is solid matte black; below, it's translucent, exposing a circuit board lit in teal with one distinct orange chip at its center. Dark background with soft teal reflections.
Software Supply Chain Security

A 20-Year-Old IoT Vulnerability Is Still Shipping in a 2026 Home Camera

A software flaw first disclosed in 2002 was still shipping inside a home security camera in 2026, sitting in plain sight because no one along the supp...

Larry Pesce
Larry PesceJULY 21, 2026
Dark, technical illustration of a hardware module with a glowing teal scan line revealing circuit board internals above a translucent panel of binary code, framed by corner brackets on a dark background..
Software Supply Chain Security

Why AppSec SCA Tools Fail for Firmware

Source-based SCA misses the components compiled into firmware and flags CVEs on version numbers that no longer hold. See what reading the binary catch...

R
Roland LindseyJULY 16, 2026
What is software supply chain security? - A Definition
Software Supply Chain Security

What Is Software Supply Chain Security? A 2026 Guide

What is Software Supply Chain Security? Explore the rise of software supply chain attacks and discover the pivotal factors driving these breaches.

Larry Pesce
Larry PesceMARCH 27, 2026
Source Code vs. Binary Analysis: How Dual-Layer Security Protects Software Supply Chains
Software Supply Chain SecurityProduct Security

Binary Analysis vs Source Code Analysis: Why Software Supply Chain Security Needs Both

One security scan method creates blind spots. Learn why combining source code & binary analysis is key to closing software supply chain security gaps.

Larry Pesce
Larry PesceMARCH 15, 2026
All You Need to Know About Open Source License Compliance
Software Supply Chain Security

Open Source License Compliance: Risks, Requirements, and Best Practices

What open source software compliance means, the obligations you have to meet, the risks of getting it wrong, and the practices and tools that keep you...

Doc McConnell
Doc McConnellJANUARY 25, 2026
Black Box to Clarity: Breaking Open Firmware Security
Software Supply Chain Security

Black Box to Clarity: Breaking Open Firmware Security

See how automated firmware analysis turns opaque binaries into clear, actionable insights—helping manufacturers uncover vulnerabilities before attacke...

Robert Kelley
Robert KelleySEPTEMBER 22, 2025
Beyond SBOMs: How Deep Binary Analysis and Exploitability Insights Set Finite State Apart
SBOM ManagementSoftware Supply Chain Security

Beyond SBOMs: How Deep Binary Analysis and Exploitability Insights Set Finite State Apart

Discover how Finite State goes beyond SBOMs with deep binary analysis, reachability insights, and exploitability scoring for real-world risk reduction...

R
Roland LindseyAUGUST 18, 2025
How to Deal with Opaque Vendors: Securing Components Without Source Code Access
Software Supply Chain SecurityAI in Cybersecurity

How to Deal with Opaque Vendors: Securing Components Without Source Code Access

Learn how to secure IoT components from opaque vendors without source code access, using binary analysis and penetration testing for compliance.

Edwin Shuttleworth
Edwin ShuttleworthJULY 5, 2025
Software Supply Chain Security Metrics: What to Measure & Why
Software Supply Chain Security

Software Supply Chain Security Metrics: What to Measure & Why

Discover essential software supply chain security metrics that drive visibility, compliance, and proactive risk management across connected devices.

Ali Siddiqui
Ali SiddiquiJUNE 27, 2025
The Open Source Trojan Horse — Hidden Risk in Reused Code
Software Supply Chain SecurityProduct Security

The Open Source Trojan Horse — Hidden Risk in Reused Code

Open source powers IoT, but hidden components and transitive risks expose your products. Learn how to secure what you didn’t even know you shipped.

Larry Pesce
Larry PesceJUNE 2, 2025
Think Your Source Code Is Secure? Check Your Firmware
Software Supply Chain SecurityProduct Security

Think Your Source Code Is Secure? Check Your Firmware

Attackers target what runs, not what’s written. Learn why binary-level firmware analysis is essential for real IoT security and regulatory compliance.

Larry Pesce
Larry PesceJUNE 2, 2025
Shellfish, SBOMs, and Firmware: A Security Tale You Won’t Forget
Software Supply Chain Security

Shellfish, SBOMs, and Firmware: A Security Tale You Won’t Forget

Many scanners miss critical IoT risks hidden in binaries and firmware. Learn why visibility beyond source code is essential for secure, compliant prod...

Larry Pesce
Larry PesceMAY 30, 2025
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions
Finite StateFinite State
Finite StateFinite State
Get a DemoGet a Demo