Exiger Acquires aDolus
August 05, 2024

Exiger announced the acquisition of software supply chain risk visibility platform aDolus Technology Inc.

This acquisition enhances Exiger's software supply chain visibility capabilities by integrating aDolus' ability to generate software bills of material (SBOMs) and analyze binary for software provenance. This capability extends Exiger's Ion Channel platform for SBOM analysis to binaries that have no SBOMs, as well as device firmware, operational technology (OT) and IoT.

"While the public and private sector are adopting policies and solutions to address supply chain risks in new software going forward, there's a glaring blind spot when it comes to spotting and rooting out vulnerabilities in operational or legacy technologies," said Exiger President Carrie Wibben. "When you consider that the cost of simply maintaining these legacy systems exceeds $1 trillion, you start to appreciate the scale of the gap in security across our software supply chains. Today, even our largest, most recognizable organizations are trying to bridge this gap in visibility with written vendor questionnaires. But with the acquisition and integration of aDolus, Exiger's customers can independently verify suppliers' attestations about the composition and security of their software."

"Organizations across energy, telecom, manufacturing, defense and other high assurance environments are grappling with these black swan cyber events and regulatory headwinds," said aDolus Founder and CEO Eric Byres. "Working with Exiger over the past year has made clear the enormous need in the market but also the enormous opportunity presented by combining our capabilities to generate SBOMs directly from binary files, uncover hidden third-party risk and expose the full provenance of software components even if they've been rebranded, misattributed or counterfeited."

aDolus analyzes operational technology, real-time operating systems and Windows / Linux-based IT software. Its FACT platform delivers high-precision risk analytics, provides results tuned to maximize accuracy, generates retroactive SBOMs for legacy systems and verifies and validates current supplier SBOMs.

"This acquisition allows our customers to 'trust but verify' when it comes to software visibility," said JC Herz, Exiger SVP of Cyber Supply Chain. "Firmware and OT is packed with proprietary files that don't appear in public package managers or open source data. Vulnerability scanners and DevOps tools have no coverage for these systems. But aDolus has analyzed millions of these proprietary files in industrial operations and with AI can identify their point of origin. We have already used this capability to unmask software suppliers that critical equipment manufacturers didn't know were there."

The combination of Exiger's AI, the Ion Channel platform and aDolus empowers customers to achieve full cyber supply chain visibility, even in the absence of contractual leverage.

Share this

Industry News

September 16, 2024

Docker is introducing a new way for developers and organizations to access its suite of products – including Docker Desktop, Docker Hub, Docker Trusted Content, Docker Scout, Docker Build Cloud, and Testcontainers Cloud.

September 16, 2024

The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the launch of the OpenSearch Software Foundation, a community-driven initiative that will support OpenSearch and its search software, which is used by developers around the world to build search, analytics, observability, and vector database applications.

September 16, 2024

Copado announced the Copado AI platform encompassing a suite of AI-powered DevOps agents.

September 16, 2024

Kong announced the release of Kong Gateway 3.8, a major update that sets a new standard for API management.

September 16, 2024

Perforce Software announced that its mobile application testing platform, Perfecto, will support Apple's latest iOS version, iOS 18, on Monday, September 16, 2024.

September 12, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader in the latest GigaOm Radar Report for Security Policy as Code.

September 12, 2024

JFrog announced the addition of JFrog Runtime to its suite of security capabilities, empowering enterprises to seamlessly integrate security into every step of the development process, from writing source code to deploying binaries into production.

September 12, 2024

Kong unveiled its new Premium Technology Partner Program, a strategic initiative designed to deepen its engagement with technology partners and foster innovation within its cloud and developer ecosystem.

September 11, 2024

Kong announced the launch of the latest version of Kong Konnect, the API platform for the AI era.

September 10, 2024

Oracle announced new capabilities to help customers accelerate the development of applications and deployment on Oracle Cloud Infrastructure (OCI).

September 10, 2024

JFrog and GitHub unveiled new integrations.

September 10, 2024

Opsera announced its latest platform capabilities for Salesforce DevOps.

September 09, 2024

Progress announced it has entered into a definitive agreement to acquire ShareFile, a business unit of Cloud Software Group, providing SaaS-native, AI-powered, document-centric collaboration, focusing on industry segments including business and professional services, financial services, healthcare and construction.

September 05, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux (RHEL) AI across the hybrid cloud.