News from the Wire
ONEKEY: AI alone Is not enough for firmware security
Thursday, September 17, 2026 — 18:31:26 (UTC)
ONEKEY: AI Alone Is Not Enough for Firmware Security
The most effective way to ensure the security of software in devices, machines and systems is to using a combination of deterministic analysis, artificial intelligence and automation.
Düsseldorf, September 17, 2026 — Artificial intelligence (AI) is a double-edged sword in cybersecurity. While attackers can use it to uncover vulnerabilities faster than ever before, AI is also an excellent tool for detecting and fixing hidden security vulnerabilities. According to Düsseldorf-based cybersecurity specialist ONEKEY, the situation is particularly critical when it comes to firmware—the control software for devices, machines, and systems.
Experts cite two main reasons for this. First, control systems often comprise hundreds or even thousands of software components that interact with one another, and their exact origins and security status are frequently unknown. Second, cyberattacks can have particularly severe consequences because the affected devices, machines, and systems operate in both the physical and digital worlds.
"Large language models, such as Mythos, have demonstrated how swiftly and thoroughly AI can identify and exploit vulnerabilities," said ONEKEY CEO Jan Wendenburg. He added: "A single security vulnerability in a widely used library can affect numerous products that have been in use for years. That’s why it’s essential for manufacturers to know exactly which components are used in which products and where security updates are needed.”
AI Still Has Room for Improvement When It Comes to Identifying Security Vulnerabilities
"AI alone does not inherently make firmware secure," emphasized Jan Wendenburg. That is why ONEKEY combines deterministic firmware analysis with targeted AI support. The ONEKEY platform lists software components in the form of SBOMs (Software Bills of Materials), compares them against known vulnerabilities (Common Vulnerabilities and Exposures, or CVEs), and tracks new CVE reports. Language models are used on a case-by-case basis for closer analysis and classification of findings or unknown vulnerabilities.
ONEKEY points out that large language models (LLMs) do not necessarily find every vulnerability on the first run. The same language model can discover new vulnerabilities with each successive run. Anthropic, the developer of Mythos, documented how its AI performed around 1,000 independent analysis runs in iterative loops to identify several dozen vulnerabilities in a target component. "The use of large language models for vulnerability detection is not currently a process that yields reproducible results," said ONEKEY CEO Jan Wendenburg, highlighting the limitations of AI in firmware security. Before a new firmware version is released, developers must be able to distinguish between insecure code and a fluctuating model response.
A Deterministic Foundation Before Deploying AI
That is why ONEKEY relies on deterministic testing before deploying AI. The platform dissects the firmware, creates a software bill of materials, and compares it against known vulnerabilities. Additionally, static binary analysis scans the code for vulnerabilities. The advantage of this method is that running the same firmware through the same analysis process again yields the same results.
Furthermore, deterministic verification analyzes firmware systematically and comprehensively. This provides security teams with transparency into what is actually inside the device. Based on this information, the platform can identify known vulnerabilities affecting the components contained within and deliver this information in the appropriate context.
ONEKEY was specifically designed to reduce the “noise” that traditional security scans often generate. Embedded developers often receive long lists of CVEs from generic scanners, many of which later prove to be irrelevant or already fixed. That’s why ONEKEY relies on version-aware and binary-specific analyses. These analyses show which vulnerabilities are relevant to the specific firmware and help filter out false positives. AI is used as a supplement in complex cases, such as with unknown or obfuscated components. Vulnerability management involves maintaining a comprehensive inventory of all software installed on devices, machines, and systems.
Combining the Benefits of AI and Deterministic Analysis
In this way, ONEKEY addresses another important aspect of AI-powered firmware security: efficient time and budget management. Since language models realize their full potential through numerous analysis runs, it makes sense to use AI agents that examine different segments of the program code simultaneously and share their findings. However, the practical implementation of such multi-agent systems is complex. It requires custom scripts and simulated runtime environments, as well as extensive prompt engineering and expert knowledge. For most companies, this level of effort is not feasible for every new firmware version, especially given the significant time and costs involved.
Jan Wendenburg explained: "LLM-based code analysis and deterministic analysis complement each other. AI enables creative, context-aware vulnerability detection, while deterministic analysis methods ensure reproducibility, consistency, and scalability."
Automation and Integration into Development
In addition to advanced vulnerability detection, automation and integration into the software development process are increasingly important given the growing number of identified vulnerabilities—a trend being further accelerated by AI. The ONEKEY platform can be integrated into existing development and release processes to ensure that every new firmware version is analyzed automatically and known vulnerabilities are detected before release.
Furthermore, ONEKEY continuously monitors firmware security throughout its entire lifecycle. Once a firmware version has been analyzed, users are automatically notified if new vulnerabilities affecting that firmware are discovered. An indexed inventory of components across the entire product portfolio ensures that all devices, machines, and systems are continuously included in security checks.
"In the age of AI, security updates must be developed and deployed ever more quickly, so centralized, automated monitoring for firmware vulnerabilities is essentially indispensable," said Jan Wendenburg. Whenever a new vulnerability is reported, the ONEKEY platform performs all necessary analyses and assessments related to the firmware across the entire product range in the background. Rather than spending time on this time-consuming preparatory work, security teams can focus on resolving issues clearly identified by the platform.
ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.
Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated Software Bills of Materials (SBOMs) generation. "Digital Cyber Twins" enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle.
The integrated ONEKEY Compliance Wizard already supports compliance with requirements from IEC 62443-4-2, ETSI EN 303 645, UNECE R155, and many other standards and regulations.
As part of the EU-funded CRACoWi (Cyber Resilience Act Compliance Wizard) project, ONEKEY is collaborating with 13 European partners to develop an AI-powered assistant for the automated implementation of the EU Cyber Resilience Act (CRA).
The solution will guide companies through the entire compliance process—from the initial CRA scope assessment to the generation of the required Declaration of Conformity.
The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritization of vulnerabilities, significantly reducing the time to remediation.
Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform (OCP) and ONEKEY Cybersecurity Experts.
Further information: ONEKEY GmbH, Sara Fortmann, email: sara.fortmann@onekey.com, Toulouser Allee 19A, 40211 Düsseldorf, Germany, web: onekey.com
PR Agency: euromarcom public relations GmbH, Mühlhohle 2, 65205 Wiesbaden, Germany, email: team@euromarcom.de, web: www.euromarcom.de
Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.
Source: Company press release. 
Categories: Reports and research