CRA just days away: Are you ready?
The biggest obstacle to ensuring compliance to the EU Cyber Resilience Act (CRA) is knowing what third-party software is embedded inside a product, according to Doc McConnell, head of policy and compliance at Finite State. Effective worldwide and starting 11 September 2026, all manufacturers of goods shipped into the EU must notify the European Union’s […]
Read More
Security vulnerability found in Shark robot vacuum
Security researcher Tokay0 has found a serious vulnerability affecting robot vacuum cleaners from Massachusetts firm SharkNinja. A certificate extracted from one compromised Shark robot vacuum could be used to access other devices, exposing live camera feeds, stored home maps and wifi credentials held in plain text. During a 24-hour observation, the researcher identified more than […]
Read More
Finite State finds 20-year-old vulnerabilities in wifi camera
Finite State researchers have found a 2026 consumer camera that’s been shipping with a web server vulnerability first disclosed more than 20 years ago, allowing attackers to access credentials and cloud tokens and potentially compromise cameras. The research team identifies three critical vulnerabilities in the Wansview WVC Q5 indoor wifi camera, a low-cost device commonly […]
Read More
Finite State wins industrial IoT award
Finite State has won the 2026 IoThinkTank industrial IoT award for its Product Security OS. The AI-native platform helps connected-device organisations continuously understand, prioritise and manage firmware and embedded software risk, including the long-lived operational environments that define industrial systems. Finite State was recognised for a practical, scalable approach to securing the embedded software, connected […]
Read More
Finite State issues CRA cyber-security warning
Companies need to prepare for the first major enforcement milestone of the EU’s Cyber Resilience Act (CRA) coming in September, warns Finite State. Cyber-security experts, OEMs, software publishers and end user organisations have focused on the CRA’s ultimate December 2027 compliance deadline for years. What’s received far less attention is the first major enforcement milestone […]
Read More
Finite State calls for transparency in Luxembourg outage
Finite State and Suzu Labs are calling for the vulnerabilities that caused a nationwide telecoms outage in Luxembourg last year to be made public following reports that Huawei enterprise router software was to blame. A previously undisclosed vulnerability in Huawei enterprise router software was reportedly exploited in the cyber attack that caused the nationwide telecommunications […]
Read More
Finite State backs FCC decision on router waivers
Finite State has announced support for the FCC decision to extend temporary waivers allowing certain foreign-made routers and drones already deployed in the USA to continue receiving software and firmware updates until at least January 2029. The move reverses earlier restrictions that would have blocked updates after 2027 for devices placed on the FCC’s Covered […]
Read More
Finite State warns Taiwan train hack could happen again
The type of vulnerabilities that let a university student paralyse parts of Taiwan’s high-speed rail network last month exist in critical infrastructures around the world, warns Larry Pesce, vice president at Finite State. The 23-year-old university student in Taiwan was arrested after gaining unauthorised access to the radio communication system used by Taiwan High Speed […]
Read More
Finite State makes third executive appointment of 2026
In its third executive appointment of 2026, Finite State, a specialist in product security and software supply chain risk management, has named Ann Miller as vice president of marketing. Miller brings more than 15 years of experience scaling high-growth technology companies, with expertise in cyber security and AI-driven platforms, and is known for turning emerging […]
Read More
Finite State comments on US router import ban
Three experts from Ohio-based Finite State have commented on the US FCC’s banning of the authorisation and import of new consumer-grade routers manufactured outside the USA. Finite State’s autonomous product security platform is built to secure connected devices, IoT and embedded systems. Its platform analyses firmware and source code to identify risks, generate SBoMs, and […]
Read More
Who will win the race to CRA compliance?
Steve Rogerson compares the upcoming Cyber Resilience Act (CRA) with the problems Formula One racing teams are having with their new regulations. It was rather fitting that this year’s Embedded World was sandwiched between the first two Formula One grands prix of the season. As the top racing teams grappled with a host of new […]
Read More
Somos partners Finite State to strengthen security
Security expert Somos is integrating Finite State’s binary and source code analysis capabilities with SomosID, enhancing its IoT connected asset registry’s ability to deliver deeper, device-level metrics. As regulatory requirements for IoT security continue to evolve – including NIS2, the Cyber Resilience Act (CRA) and US federal mandates – organisations are facing increasing pressure to […]
Read More