Your Software IS/NOT Vulnerable: CSAF, VEX, and the Future of Advisories

Описание к видео Your Software IS/NOT Vulnerable: CSAF, VEX, and the Future of Advisories

As more attention is paid to security and the underlying components used in developing software, more organizations will be sending out security advisories. As SBOMs become more widespread, many of these advisories will actually be "false positives," when the underlying component vulnerability isn't actually exploitable. Organizations developing and using software will thus face an increasing amount of information to process and prioritize if they want to address the constantly evolving risk...

By: Allan Friedman & Thomas Schmidt

Full Abstract & Presentation Materials:
https://www.blackhat.com/us-21/briefi...

Комментарии

Информация по комментариям в разработке