Sign in

Marta Rybczynska

@mrybczyn.bsky.social
40 followers 13 following 16 posts

Talking about open source security & tech. Founder of Ygreky ygreky.com

PostsRepliesMedia
Marta Rybczynska @mrybczyn.bsky.social · 20/08/2026
Firmware for most IoT devices is a black box and the security model based on the assumption that nobody would take the time to disassemble the binary. And well... this assumption is going away with AI. Paper link: arxiv.org/pdf/2608.06960
Statistical Analysis of Executability and Program Equivalence in Decompilation for IoT Vulnerbility Detection - paper extracts (authors: Yoda, Li, Tahara, Sei)
000
Marta Rybczynska @mrybczyn.bsky.social · 06/08/2026
The new issue of the Embedded Security Timeline is out. In the latest episode: - a number of CRA-releated updates including the Single Reporting Platform news and the Guidelines - secure boot issues with outdated shims - poll results of the month Read it online: ygreky.com/2026/08/july...
Embedded Security timeline logo
010
Marta Rybczynska @mrybczyn.bsky.social · 15/02/2026
Under the #CRA (Cyber Resilience Act), manufacturers must report actively exploited vulnerabilities and serious security incidents. How? Through the Single Reporting Platform. Starting when? September 11, 2026. Yes, this year. Link to the FAQ: www.enisa.europa.eu/topics/produ...
ENISA Single Reporting Platform FAQ - https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
043
Marta Rybczynska @mrybczyn.bsky.social · 30/12/2025
What does your factory reset actually wipe? Have you ever checked? A device leaves your factory. Years later, it is resold, returned, or thrown away. And yet, on many products, sensitive data is still there. All of our challenges: ygreky.com/challenge/
000
Marta Rybczynska @mrybczyn.bsky.social · 11/12/2025
Today is Thursday, the day of the Embedded Security Challenge. Your task for this week: review the "private" networks your devices rely on. Are they truly private? And even if they are, how do you protect the device when someone plugs a modem into the network?
Embedded security challenge: private network
000
Marta Rybczynska @mrybczyn.bsky.social · 10/12/2025
The Yocto Project Virtual Summit 2025.12 wrapped up last week with three days of great content. The new security track worked especially well (in my opinion), with strong interest in CVE-related tooling, secure boot, and vulnerability reporting. ygreky.com/2025/12/yoct...
Yocto Project Summit 2025.11 - My impressions: the "security day" and way more
010
Marta Rybczynska @mrybczyn.bsky.social · 08/12/2025
Solid embedded teams keep track of everything they deliver: hardware, software, and configuration. Every time they deliver. 👉 The Embedded Security Challenge for this week: create or review your release storage. Make sure every single component you ship is recorded and stored.
000
Marta Rybczynska @mrybczyn.bsky.social · 04/12/2025
We are running research on what embedded developers actually need for vuln management, which tools they use today, and which ones they would like to use in the future. The survey is open until the end of December 2025, and the results will be published in January. docs.google.com/forms/d/e/1F...
docs.google.com
Next generation vulnerability checking and management tool for embedded - survey
This form aims at collecting requirements and needs of all interested developers and embedded companies to find out what the exact needs in the field are. Thank you!
000
Marta Rybczynska @mrybczyn.bsky.social · 01/12/2025
I am happy to announce two upcoming webinars on the Cyber Resilience Act for embedded developers. Many of you have asked for a condensed overview of the CRA and an update on where things stand after the recent waves of public reviews. Here it comes. All details here: ygreky.com/2025/12/unde...
ygreky.com
Understanding the Cyber Resilience Act – Ygreky
120
Marta Rybczynska @mrybczyn.bsky.social · 30/05/2025
On June 3rd and 10th with my colleagues from the Eclipse Foundation we will be running a free security training on vulnerability management and related subject. More details and registration links on blogs.eclipse.org/post/marta-r...
blogs.eclipse.org
Announcing Security Training on Vulnerability Management, SBOM and related subjects
Do you want to know more about
021
Marta Rybczynska @mrybczyn.bsky.social · 14/03/2025
VulnCon is a quite unique conference focus on software (and not only) vulnerability management. It is happening at the beginning of April and I will be speaking twice.
141
Marta Rybczynska @mrybczyn.bsky.social · 29/01/2025
We're organizing a BoF on the CRA (Cyber Resilience Act) conformance by embedded vendors on Sunday 2nd February 2025 at FOSDEM! Join us at 14h in H.3244. It is for: - embedded developers (Linux or any RTOS) - people working for "manufacturers" The schedule: fosdem.org/2025/schedul...
fosdem.org
000
Marta Rybczynska @mrybczyn.bsky.social · 13/01/2025
Monday morning: Last week's code is working on the first run and passing tests. Me: There's a serious problem here, so let's plan for a week of debugging.
110
Marta Rybczynska @mrybczyn.bsky.social · 10/01/2025
The second week of our embedded security challenge has started. How do attackers get into a router or an industrial device? Not by the primary function but by the web application you can use to monitor and administer the device. Check the challenge at ygreky.com/challenge/
000
Marta Rybczynska @mrybczyn.bsky.social · 08/01/2025
Embedded Security Challenge week 1 (until Jan 9, 2025): What are your product's services (applications, daemons) communicating, or potentially communicating with the Internet? Check all network interfaces. Also, check for both applications sending data and those listening. ygreky.com/challenge/
110
Marta Rybczynska @mrybczyn.bsky.social · 21/11/2024
Hello world!
010