<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CycloneDX on IntelliXBOM</title><link>https://intellixbom.com/tags/cyclonedx/</link><description>Recent content in CycloneDX on IntelliXBOM</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 09 Apr 2026 12:00:00 +0530</lastBuildDate><atom:link href="https://intellixbom.com/tags/cyclonedx/index.xml" rel="self" type="application/rss+xml"/><item><title>Don't Trust the SBOM Your Vendor Gave You</title><link>https://intellixbom.com/blog/dont-trust-vendor-sbom-certin/</link><pubDate>Thu, 09 Apr 2026 12:00:00 +0530</pubDate><guid>https://intellixbom.com/blog/dont-trust-vendor-sbom-certin/</guid><description>&lt;p&gt;Regulators across the world are finally getting serious about the software supply chain. India&amp;rsquo;s CERT-In SBOM Technical Guidelines (v2.0, July 2025) go beyond just SBOMs they extend to a broader BOM ecosystem, including CBOM, QBOM, AIBOM, and HBOM. This makes the requirement not just about software components, but about understanding the full composition of modern systems.&lt;/p&gt;
&lt;p&gt;Globally, the direction is the same whether it&amp;rsquo;s the US Executive Order 14028, the EU Cyber Resilience Act, RBI Advisory 11/2024, or MeitY&amp;rsquo;s 2025 guidelines.&lt;/p&gt;</description></item><item><title>Beyond SCA: Generating SBOMs, CBOMs, QBOMs, and AIBOMs at Runtime</title><link>https://intellixbom.com/blog/beyond-sca-runtime-bom/</link><pubDate>Wed, 09 Jul 2025 10:00:00 +0530</pubDate><guid>https://intellixbom.com/blog/beyond-sca-runtime-bom/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Your SBOM is only telling you half the story here&amp;rsquo;s what it&amp;rsquo;s missing&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;p&gt;Somewhere in your production environment right now, code is running that your SBOM doesn&amp;rsquo;t capture. A library is loaded that never made it into your inventory. A cryptographic routine is executing without ever being audited. An AI model serves requests from an untracked registry. Meanwhile, your SCA tool the one behind that reassuring green dashboard has no visibility into any of it.&lt;/p&gt;</description></item></channel></rss>